Other > Viruses and worms
Questions regarding key logging software that was installed on a laptop
<< < (3/7) > >>
ahullsb:
Next came Jotti's log

Here is a scan from Jotti's log

Scan taken on 17 Aug 2008 19:27:17 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found Program.eBlaster.origin
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found not-a-virus:Monitor.Win32.EBlaster.b
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found Trojan-Downloader.Obfuscated.29 (paranoid heuristics) (probable variant)


Last file scanned at least one scanner reported something about: pccillin2007_2008_Keygen.rar (MD5: 654c537106445111ec37b1372c7b098d, size: 112355 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir TR/Dldr.Delf.jub
ArcaVir X
Avast X
AVG Antivirus Downloader.Generic7.XNO
BitDefender X
ClamAV X
CPsecure X
Dr.Web X
F-Prot Antivirus X
F-Secure Anti-Virus X
Fortinet Crackin.EBBA9CBC
Ikarus Trojan-Spy.Win32.Bancos.xe
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
Panda Antivirus X
Sophos Antivirus Sus/Keygen-A
VirusBuster X
VBA32 Trojan-Downloader.Win32.Delf.jub
ahullsb:
Next was malwarebytes. Here is the malwarebytes log

Malwarebytes' Anti-Malware 1.25
Database version: 1062
Windows 5.1.2600 Service Pack 2

6:55:42 AM 4/14/2008
mbam-log-04-14-2008 (06-55-42).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 89007
Time elapsed: 43 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 57
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 17

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\antiviruscom.avofficeprotect (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\antiviruscom.avofficeprotect.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\avexplorer.shellextension (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\avexplorer.shellextension.2 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iefwbho.iefw (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\iefwbho.iefw.2 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\wav6com.avofficeprotect (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\wav6com.avofficeprotect.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\winpgintegrator.ieintegrator (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\winpgintegrator.ieintegrator.1 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{367a86a5-d048-4785-86be-4e2706aafdd9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{732b6533-7f78-4c47-9c01-2979ba0829b9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\winantivirus pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\winantivirus pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\WinPGI.DLL (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fopn (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
ahullsb:
(continued)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\BootStera (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntivirus) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006\AVScheduler.dat (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Feedback on Support Quality.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Report Software Defect.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Request for Instructions.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Share Your Suggestions.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Uninstall WinAntiVirus Pro 2006.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Knowledge base.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Manual.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006.lnk (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\PGE.dat (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\jordan adenwala\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\erin marston\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\stera.exe (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
ahullsb:
Next came the Panda scan log. (The tracking cookies were from the ex by the way)

;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-04-14 16:41:18
PROTECTIONS: 1
MALWARE: 15
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
Avira AntiVir PersonalEdition 8.0.1.27 No Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
ahullsb:
(continued)

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOozcvup
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOabuwli
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERysjzlr
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERaetfwc
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOoqvuhz
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOjvuohy
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERqrfsvb
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERntzsjt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERjqztsb
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERgmzcco
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\WA6P\Quar\JOuwtaia
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\erin marston\Cookies\erin marston@atdmt[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERtugthk
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\WA6P\Quar\ERykjbhj
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlinfnc
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\WA6P\Quar\ERjjbcoj
00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\WA6P\Quar\JOpyedkt
00167770 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOellwoh
00168058 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtkbdoj
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\WA6P\Quar\ERwtxujy
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOentaoy
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOeptlgx
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOucktsn
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtzjfzb
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOftfhgv
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOdyklku
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOghajbi
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOsvyhyd
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOrfkdlh
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOqvcckz
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOdnifrd
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOgslorv
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOcsirpr
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOblzykv
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JObkdfir
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOgugtzb
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOhvshdi
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOtscviu
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOniukot
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOmfjouq
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOnhzloz
00169286 Cookie/Sextracker TrackingCookie No 0 Yes No C:\WA6P\Quar\JOneuwlo
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\WA6P\Quar\ERltiycd
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\WA6P\Quar\ERmjeqpu
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERvkdosr
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERxnmtks
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERkighzb
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERkimfqe
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlmhfnb
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERfyvgpz
00171982 Cookie/QuestonMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlnycol
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERbjqczk
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERddxcrj
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERrnglum
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERdjqapi
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERlqvpvs
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERtrvrka
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERwfdqgf
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\WA6P\Quar\ERiiymon
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOanipik
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOknreci
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOzdmyrj
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOopeoli
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOfikzsn
00175950 Cookie/cs.sexcounter TrackingCookie No 0 Yes No C:\WA6P\Quar\JOxkixhs
Navigation
Message Index
Next page
Previous page

Go to full version