Other > Viruses and worms |
Questions regarding key logging software that was installed on a laptop |
<< < (3/7) > >> |
ahullsb:
Next came Jotti's log Here is a scan from Jotti's log Scan taken on 17 Aug 2008 19:27:17 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found Program.eBlaster.origin F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found not-a-virus:Monitor.Win32.EBlaster.b Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found Trojan-Downloader.Obfuscated.29 (paranoid heuristics) (probable variant) Last file scanned at least one scanner reported something about: pccillin2007_2008_Keygen.rar (MD5: 654c537106445111ec37b1372c7b098d, size: 112355 bytes), detected by: Scanner Malware name A-Squared X AntiVir TR/Dldr.Delf.jub ArcaVir X Avast X AVG Antivirus Downloader.Generic7.XNO BitDefender X ClamAV X CPsecure X Dr.Web X F-Prot Antivirus X F-Secure Anti-Virus X Fortinet Crackin.EBBA9CBC Ikarus Trojan-Spy.Win32.Bancos.xe Kaspersky Anti-Virus X NOD32 X Norman Virus Control X Panda Antivirus X Sophos Antivirus Sus/Keygen-A VirusBuster X VBA32 Trojan-Downloader.Win32.Delf.jub |
ahullsb:
Next was malwarebytes. Here is the malwarebytes log Malwarebytes' Anti-Malware 1.25 Database version: 1062 Windows 5.1.2600 Service Pack 2 6:55:42 AM 4/14/2008 mbam-log-04-14-2008 (06-55-42).txt Scan type: Full Scan (C:\|D:\|E:\|) Objects scanned: 89007 Time elapsed: 43 minute(s), 0 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 57 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 17 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\antiviruscom.avofficeprotect (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\antiviruscom.avofficeprotect.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\avexplorer.shellextension (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\avexplorer.shellextension.2 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\iefwbho.iefw (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\iefwbho.iefw.2 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\wav6com.avofficeprotect (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\wav6com.avofficeprotect.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\winpgintegrator.ieintegrator (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\winpgintegrator.ieintegrator.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{367a86a5-d048-4785-86be-4e2706aafdd9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{732b6533-7f78-4c47-9c01-2979ba0829b9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\winantivirus pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\winantivirus pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\WinPGI.DLL (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fopn (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. |
ahullsb:
(continued) Registry Values Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootStera (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntivirus) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006\AVScheduler.dat (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Feedback on Support Quality.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Report Software Defect.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Request for Instructions.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Share Your Suggestions.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Uninstall WinAntiVirus Pro 2006.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Knowledge base.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Manual.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\PGE.dat (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully. C:\WINDOWS\system32\stera.exe (Rogue.WinAntivirus) -> Quarantined and deleted successfully. |
ahullsb:
Next came the Panda scan log. (The tracking cookies were from the ex by the way) ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2008-04-14 16:41:18 PROTECTIONS: 1 MALWARE: 15 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== Avira AntiVir PersonalEdition 8.0.1.27 No Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== |
ahullsb:
(continued) 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOozcvup 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOabuwli 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERysjzlr 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERaetfwc 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOoqvuhz 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOjvuohy 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERqrfsvb 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERntzsjt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERjqztsb 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERgmzcco 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOuwtaia 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\erin marston\Cookies\erin marston@atdmt[2].txt 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERtugthk 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERykjbhj 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlinfnc 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\WA6P\Quar\ERjjbcoj 00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\WA6P\Quar\JOpyedkt 00167770 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOellwoh 00168058 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtkbdoj 00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\WA6P\Quar\ERwtxujy 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOentaoy 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOeptlgx 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOucktsn 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtzjfzb 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOftfhgv 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOdyklku 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOghajbi 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOsvyhyd 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOrfkdlh 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOqvcckz 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOdnifrd 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOgslorv 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOcsirpr 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOblzykv 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JObkdfir 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOgugtzb 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOhvshdi 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtscviu 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOniukot 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOmfjouq 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOnhzloz 00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOneuwlo 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\WA6P\Quar\ERltiycd 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\WA6P\Quar\ERmjeqpu 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERvkdosr 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERxnmtks 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERkighzb 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERkimfqe 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlmhfnb 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERfyvgpz 00171982 Cookie/QuestonMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlnycol 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERbjqczk 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERddxcrj 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERrnglum 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERdjqapi 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlqvpvs 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERtrvrka 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERwfdqgf 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERiiymon 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOanipik 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOknreci 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOzdmyrj 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOopeoli 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOfikzsn 00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOxkixhs |
Navigation |
Message Index |
Next page |
Previous page |