# # this list of ponmocup malware redirection domains and infected web-servers is maintained by # email: toms.security.stuff -at- gmail.com # twitter: @c_APT_ure # blog: http://c-apt-ure.blogspot.com/ # # for use with CIF see malware-feeds here: # http://security-research.dyndns.org/pub/malware-feeds/ # date started: Sun Mar 29 12:00:01 PDT 2015 checking domain: www.feger-nentwich.at --> seems to be INFECTED: http://harikai.softmn.com/new/www/delivery/lg.php --> DNS: harikai.softmn.com (harikai.softmn.com) / 31.210.96.157 checking domain: www.segelclubhochheim.de --> seems to be INFECTED: http://zoulys.fatlosstoolkit.com/pview --> DNS: zoulys.fatlosstoolkit.com (zoulys.fatlosstoolkit.com) / 31.210.96.156 checking domain: abus-spirituel.org --> seems to be INFECTED: http://transforminator.juddnelsonstudio.com/delivery/lg.php --> DNS: transforminator.juddnelsonstudio.com (transforminator.juddnelsonstudio.com) / 31.210.96.158 checking domain: www.dynasun.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.177.20 checking domain: www.agliran.co.il --> seems to be INFECTED: http://mercysiste.vehicleservicediscount.com/__utm.gif --> DNS: mercysiste.vehicleservicediscount.com (mercysiste.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.ccpa.org.tw --> seems to be INFECTED: http://sandercoe.gliscentrifugal.com/pview --> DNS: sandercoe.gliscentrifugal.com (sandercoe.gliscentrifugal.com) / 31.210.96.155 checking domain: b-my.de --> seems to be INFECTED: http://zailawatikarim.automotiveeventregistration.com/__utm.gif --> DNS: zailawatikarim.automotiveeventregistration.com (zailawatikarim.automotiveeventregistration.com) / 31.210.96.157 checking domain: cioks.com --> seems to be INFECTED: http://rimei.integratedpipe.com/p --> DNS: rimei.integratedpipe.com (rimei.integratedpipe.com) / failed: Name or service not known. checking domain: www.toisondor.be --> seems to be INFECTED: http://radolinski.makingwaves-salon.com/t.gif --> DNS: radolinski.makingwaves-salon.com (radolinski.makingwaves-salon.com) / 31.210.96.158 checking domain: www.aca-uccle.be --> seems to be INFECTED: http://omonkhegbele.wenerdhard.com/pagead/ads --> DNS: omonkhegbele.wenerdhard.com (omonkhegbele.wenerdhard.com) / 31.210.96.155 checking domain: www.lesscouts.be --> seems to be INFECTED: http://andryukov.whichcameratookthis.com/cgi-bin/m --> DNS: andryukov.whichcameratookthis.com (andryukov.whichcameratookthis.com) / 31.210.96.157 checking domain: www.centrumgregoriaans.be --> seems to be INFECTED: http://wanthegreat.pinkdollaratm.com/_xhr/ugccomments/ --> DNS: wanthegreat.pinkdollaratm.com (wanthegreat.pinkdollaratm.com) / 31.210.96.156 checking domain: www.trikalasport.gr --> seems to be INFECTED: http://siene.webrunchhard.com/delivery/lg.php --> DNS: siene.webrunchhard.com (siene.webrunchhard.com) / 31.210.96.155 checking domain: www.destrangers.org --> seems to be INFECTED: http://bidin.golfnewslouisiana.com/delivery/lg.php --> DNS: bidin.golfnewslouisiana.com (bidin.golfnewslouisiana.com) / 31.210.96.157 checking domain: www.vtf.co.at --> seems to be INFECTED: http://santamore.vehicleexchangeprogram.com/www/delivery/lg.php --> DNS: santamore.vehicleexchangeprogram.com (santamore.vehicleexchangeprogram.com) / 31.210.96.157 checking domain: gezinsbondzarren.be --> seems to be INFECTED: http://kumher.savedalyfield.com/s --> DNS: kumher.savedalyfield.com (kumher.savedalyfield.com) / 31.210.96.157 checking domain: www.silvergrey.es --> seems to be INFECTED: http://ambalanchery.drdekloet.com/delivery/lg.php --> DNS: ambalanchery.drdekloet.com (ambalanchery.drdekloet.com) / failed: Name or service not known. checking domain: www.dioxinnz.com --> seems to be INFECTED: http://plapplatong.workoutebook.com/new2/www/delivery/lg.php --> DNS: plapplatong.workoutebook.com (plapplatong.workoutebook.com) / 141.8.224.239 checking domain: 1980622.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.194, 208.73.210.212, 208.73.211.199, / checking domain: ads.thinkingaustralia.tv --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: afag.com.br --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: agirazul.com.br --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 64.74.223.30 checking domain: agroservis.rs --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 185.53.179.19 checking domain: akhbaralyom.net --> seems to be INFECTED: http://sazdoski.chelseyfatula.com/delivery/lg.php --> DNS: sazdoski.chelseyfatula.com (sazdoski.chelseyfatula.com) / 185.53.177.13 checking domain: alastech.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: allandalla.ro --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: anzaisekizaiten.co.jp --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: apprendre-l-arabe.fr --> seems to be INFECTED: http://yasnid.vehicleservicediscount.com/www/delivery/lg.php --> DNS: yasnid.vehicleservicediscount.com (yasnid.vehicleservicediscount.com) / 31.210.96.157 checking domain: area-press.eu --> seems to be INFECTED: http://yerme.techsupportauctions.com/__utm.gif --> DNS: yerme.techsupportauctions.com (yerme.techsupportauctions.com) / 31.210.96.158 checking domain: arlington.ph --> seems to be INFECTED: http://voutilainen.wenerdhard.com/_xhr/ugccomments/ --> DNS: voutilainen.wenerdhard.com (voutilainen.wenerdhard.com) / 31.210.96.155 checking domain: article-marketing.eu --> seems to be INFECTED: http://yerme.techsupportauctions.com/b/ss/wmg,wmgatl,wmgd2cparamore,wmgparamoreall/1/H.20.3/s51794836064800 --> DNS: yerme.techsupportauctions.com (yerme.techsupportauctions.com) / 31.210.96.158 checking domain: autokompleks-jastrzebie.pl --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.199, 208.73.211.191, 208.73.210.212, / checking domain: avionhome.com.tw --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 141.8.225.80 checking domain: avkolik.net --> seems to be INFECTED: http://shijothomas.softmn.com/servlet/ajrotator/123508/0/vj --> DNS: shijothomas.softmn.com (shijothomas.softmn.com) / 31.210.96.157 checking domain: bcrwd.com --> seems to be INFECTED: http://youshawna.docneil.com/url --> DNS: youshawna.docneil.com (youshawna.docneil.com) / 178.211.33.203 checking domain: between2rivers.net --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.177.20 checking domain: bintanworld.com --> seems to be INFECTED: http://yangad.automotiveservicesavings.com/__utm.gif --> DNS: yangad.automotiveservicesavings.com (yangad.automotiveservicesavings.com) / 31.210.96.157 checking domain: blackcanyoncoffee.com --> seems to be INFECTED: http://mudras.jordandowney.net/1pix.gif --> DNS: mudras.jordandowney.net (mudras.jordandowney.net) / 31.210.96.155 checking domain: blog.autourdeminuit.com --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 141.8.225.80 checking domain: bluewingz.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.200, 208.73.211.178, 208.73.210.214, / checking domain: boisdolivier.biz --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 199.59.243.120 checking domain: bralux-saiko.com --> seems to be INFECTED: http://philosophymercer.com/cgi-bin/r.cgi --> DNS: philosophymercer.com (philosophymercer.com) / 192.64.147.205 checking domain: bridalcookie.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: bsiderats.nl --> seems to be INFECTED: http://zulibs.thisweekinwhiteness.com/delivery/ajs.php --> DNS: zulibs.thisweekinwhiteness.com (zulibs.thisweekinwhiteness.com) / 31.210.96.158 checking domain: businessbythespirit.com --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 69.43.161.177 checking domain: californiaoutdoorproperties.com --> seems to be INFECTED: http://jelow.be3ny.com/pview --> DNS: jelow.be3ny.com (jelow.be3ny.com) / 31.210.96.156 checking domain: cbm.esp.br --> seems to be INFECTED: http://nalaras.farremuebles.com/imghover --> DNS: nalaras.farremuebles.com (nalaras.farremuebles.com) / 81.92.219.62 checking domain: cdcookingbook.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: cemerhn.com --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: chadflick.ws --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.199, 208.73.211.191, 208.73.210.212, / checking domain: chardonrecords.com --> seems to be INFECTED: http://indanetwall.net/cgi-bin/r.cgi --> DNS: indanetwall.net (indanetwall.net) / 199.59.243.120 checking domain: clarkpoolinteriors.com.au --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.199, 208.73.211.191, 208.73.210.212, / checking domain: classroom334.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: cloudflood.com --> seems to be INFECTED: http://reportedtechniques.org/cgi-bin/r.cgi --> DNS: reportedtechniques.org (reportedtechniques.org) / 5.61.39.56 checking domain: coachingteams.eu --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: coloresmedia.com --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.9 checking domain: comunicati-stampa.ws --> seems to be INFECTED: http://yerme.techsupportauctions.com/tracker --> DNS: yerme.techsupportauctions.com (yerme.techsupportauctions.com) / 31.210.96.158 checking domain: coolnet.com.pl --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 141.8.225.80 checking domain: cpmprint.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: cyberairlines.net --> seems to be INFECTED: http://56537.thomasyohannan.com/url --> DNS: 56537.thomasyohannan.com (56537.thomasyohannan.com) / 178.211.33.203 checking domain: darraghkelly.me --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 185.53.179.19 checking domain: demo.crg-sa.com --> seems to be INFECTED: http://sslabssys.com/cgi-bin/r.cgi --> DNS: sslabssys.com (sslabssys.com) / 69.172.201.208 checking domain: desarrollos.localhost.net.ar --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: desifucker.com --> seems to be INFECTED: http://hardenburger.myredhomingpidgeon.com/safe_image.php --> DNS: hardenburger.myredhomingpidgeon.com (hardenburger.myredhomingpidgeon.com) / 69.43.160.163 checking domain: dgmarketingdesign.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: dialolinks.de --> seems to be INFECTED: http://hartrup.kemperfitness.com/__utm.gif --> DNS: hartrup.kemperfitness.com (hartrup.kemperfitness.com) / 81.92.219.60 checking domain: diningcity.net --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: d-math1.com --> seems to be INFECTED: http://renolla.golfnewsnewyork.com/delivery/lg.php --> DNS: renolla.golfnewsnewyork.com (renolla.golfnewsnewyork.com) / 31.210.96.157 checking domain: drdenmarksaidit.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: duikeninzutphen.nl --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: eagle-software.co.uk --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: ecoswaycolombia.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: ekrosno.pl --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: elderdayservices.com --> seems to be INFECTED: http://ciciretto.prestigehonda.net/url --> DNS: ciciretto.prestigehonda.net (ciciretto.prestigehonda.net) / 31.210.96.157 checking domain: eniaktesting.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: epicboardskins.com --> seems to be INFECTED: http://vasimon.theknowledgekingdom.com/t.gif --> DNS: vasimon.theknowledgekingdom.com (vasimon.theknowledgekingdom.com) / 31.210.96.158 checking domain: equestrianinfluence.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: espn-la.com --> seems to be INFECTED: http://guillaran.newcarsat.com/~piwiksan/piwik.php --> DNS: guillaran.newcarsat.com (guillaran.newcarsat.com) / 31.210.96.157 checking domain: essa-lyon.org --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: exclusivesms.com --> seems to be INFECTED: http://ifteiha.lions-mark.com/b --> DNS: ifteiha.lions-mark.com (ifteiha.lions-mark.com) / 31.210.96.158 checking domain: ezkahuda.cz --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.9 checking domain: famedomain.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.211.178, 208.73.210.200, 208.73.210.217, / checking domain: fiatclubpt.com --> seems to be INFECTED: http://yovette.javaemulator.com/__utm.gif --> DNS: yovette.javaemulator.com (yovette.javaemulator.com) / 31.210.96.156 checking domain: firstsaturday.hu --> seems to be INFECTED: http://vertica.reikisolar.com/_xhr/ugccomments/ --> DNS: vertica.reikisolar.com (vertica.reikisolar.com) / 31.210.96.157 checking domain: floridadeluxevillas.com --> seems to be INFECTED: http://sslabssys.com/cgi-bin/r.cgi --> DNS: sslabssys.com (sslabssys.com) / 69.172.201.208 checking domain: foropicos.net --> seems to be INFECTED: http://43642.flatblastard.com/url --> DNS: 43642.flatblastard.com (43642.flatblastard.com) / 91.207.4.51 checking domain: forum.auto.am --> seems to be INFECTED: http://witchwyd.bestsilvercufflinks.com/t.gif --> DNS: witchwyd.bestsilvercufflinks.com (witchwyd.bestsilvercufflinks.com) / 31.210.96.156 checking domain: freexxsbikinis.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: ftiindia.com --> seems to be INFECTED: http://wangga.autoeventregistration.com/url --> DNS: wangga.autoeventregistration.com (wangga.autoeventregistration.com) / 31.210.96.157 checking domain: gandmand.com --> seems to be INFECTED: http://mindarto.myabadi.com/url --> DNS: mindarto.myabadi.com (mindarto.myabadi.com) / 31.210.96.158 checking domain: greeni-shop.eu --> seems to be INFECTED: http://henessa.webdeploymenttool.com/url --> DNS: henessa.webdeploymenttool.com (henessa.webdeploymenttool.com) / 178.211.33.205 checking domain: gujaratnewsdesk.com --> seems to be INFECTED: http://gtracking.org/cgi-bin/r.cgi --> DNS: gtracking.org (gtracking.org) / 141.8.224.239 checking domain: hackshark.com --> seems to be INFECTED: http://zemres.unlockiphonedallas.com/url --> DNS: zemres.unlockiphonedallas.com (zemres.unlockiphonedallas.com) / 178.211.33.205 checking domain: harlawacademy.org --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: hazmester.etrend.hu --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: healthnews8at8.com --> seems to be INFECTED: http://youjizzboy.autoserviceevent.com/ --> DNS: youjizzboy.autoserviceevent.com (youjizzboy.autoserviceevent.com) / 31.210.96.157 checking domain: highextreme.co.uk --> seems to be INFECTED: http://alintanahin.greatserviceforless.com/pview --> DNS: alintanahin.greatserviceforless.com (alintanahin.greatserviceforless.com) / 31.210.96.157 checking domain: hippiehalloween.org --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: homeimprovement.com --> seems to be INFECTED: http://mikuz.animalgenetics.com/__utm.gif --> DNS: mikuz.animalgenetics.com (mikuz.animalgenetics.com) / 31.210.96.158 checking domain: hospitalesangeles.com --> seems to be INFECTED: http://crdoba.hartford-capital.com/api/getCount2.php --> DNS: crdoba.hartford-capital.com (crdoba.hartford-capital.com) / 31.210.96.155 checking domain: hungryviki.com --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 141.8.225.80 checking domain: images.wiltec.info --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: infobunda.com --> seems to be INFECTED: http://54737.clickbanksite.org/url --> DNS: 54737.clickbanksite.org (54737.clickbanksite.org) / 141.8.224.239 checking domain: intermundos.org --> seems to be INFECTED: http://poumtas.effectsllc.com/p --> DNS: poumtas.effectsllc.com (poumtas.effectsllc.com) / 31.210.96.158 checking domain: janeece.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: jornalsodesporto.com --> seems to be INFECTED: http://yononz.totalslipsolutions.net/url --> DNS: yononz.totalslipsolutions.net (yononz.totalslipsolutions.net) / 178.211.33.205 checking domain: jornalvakio.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: jwegener.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: karavelle.com.br --> seems to be INFECTED: http://britts.oharvest.net/__utm.gif --> DNS: britts.oharvest.net (britts.oharvest.net) / 31.210.96.156 checking domain: kewb.co.ke --> seems to be INFECTED: http://ugwuezumba.iconarchitects.net/v1/counter --> DNS: ugwuezumba.iconarchitects.net (ugwuezumba.iconarchitects.net) / failed: Name or service not known. checking domain: key2debtfreedom.co.za --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.9 checking domain: killerbee.dk --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: koninskiozpn.pl --> seems to be INFECTED: http://zhezha.theafternoonjoker.com/spc.php --> DNS: zhezha.theafternoonjoker.com (zhezha.theafternoonjoker.com) / 31.210.96.158 checking domain: koznejaknekodzic.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: kw-dl.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.191, 208.73.210.212, 208.73.211.199, / checking domain: ladidah.net --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.177.20 checking domain: laserme.de --> seems to be INFECTED: http://dauginas.mittromneyinternetcampaign.com/pview --> DNS: dauginas.mittromneyinternetcampaign.com (dauginas.mittromneyinternetcampaign.com) / 85.17.25.202 checking domain: leandromauricio.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.194, 208.73.210.212, 208.73.211.199, / checking domain: leftiesshowroom.com --> seems to be INFECTED: http://agiula.agentonpoint.com/fpc.pl --> DNS: agiula.agentonpoint.com (agiula.agentonpoint.com) / 31.210.96.156 checking domain: legno-olivo.biz --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: lesmanguiers.com --> seems to be INFECTED: http://jernighan.sullivan-county.com/b/ss/jobsdb-prd-id/1/H.23.6/s93187398763191 --> DNS: jernighan.sullivan-county.com (jernighan.sullivan-county.com) / 31.210.96.158 checking domain: levantdistribution.com --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 199.59.243.120 checking domain: ligaparque.com.uy --> seems to be INFECTED: http://curuvija.prestigehonda.net/delivery/ajs.php --> DNS: curuvija.prestigehonda.net (curuvija.prestigehonda.net) / 31.210.96.157 checking domain: livretsbaroques.fr --> seems to be INFECTED: http://suhaifah.psychictx.com/url --> DNS: suhaifah.psychictx.com (suhaifah.psychictx.com) / 178.211.33.205 checking domain: masterweaverindia.com --> seems to be INFECTED: http://quirarte.dealerholidayevent.com/b --> DNS: quirarte.dealerholidayevent.com (quirarte.dealerholidayevent.com) / 31.210.96.157 checking domain: matzlpage.de --> seems to be INFECTED: http://forhed.dealerholidayevent.com/neo/darla/php/fc.php --> DNS: forhed.dealerholidayevent.com (forhed.dealerholidayevent.com) / 31.210.96.157 checking domain: mehfil.urdustan.net --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 185.53.178.7 checking domain: meredithbrooks.com --> seems to be INFECTED: http://34906.flatblastard.com/url --> DNS: 34906.flatblastard.com (34906.flatblastard.com) / 91.207.4.51 checking domain: meteomaastricht.nl --> seems to be INFECTED: http://46086.p-balls.com/url --> DNS: 46086.p-balls.com (46086.p-balls.com) / 91.207.4.51 checking domain: metrotecegypt.info --> seems to be INFECTED: http://hobart.softmn.com/t.gif --> DNS: hobart.softmn.com (hobart.softmn.com) / 31.210.96.157 checking domain: mile2000.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: ministerfortson.com --> seems to be INFECTED: http://bazti.momsagainstmercury.com/s --> DNS: bazti.momsagainstmercury.com (bazti.momsagainstmercury.com) / 31.210.96.156 checking domain: m.kfc.fr --> seems to be INFECTED: http://53398.politcalnews.com/url --> DNS: 53398.politcalnews.com (53398.politcalnews.com) / failed: Name or service not known. checking domain: mvrccc.com.au --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: myexfuzeoffice.com --> seems to be INFECTED: http://batilekaleka.laallstars.com/url --> DNS: batilekaleka.laallstars.com (batilekaleka.laallstars.com) / 178.211.33.205 checking domain: myomnistar.com --> seems to be INFECTED: http://radeth.joeywilliamsdrums.com/__utm.gif --> DNS: radeth.joeywilliamsdrums.com (radeth.joeywilliamsdrums.com) / 185.53.177.6 checking domain: myyogasource.com --> seems to be INFECTED: http://ushean.8jutawan.com/pview --> DNS: ushean.8jutawan.com (ushean.8jutawan.com) / 31.210.96.156 checking domain: nancyhudsonassociates.com --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: ncpo.cc --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: northbatonrougejournal.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: ofarroupilha.com.br --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: optionpixel.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: parngkhaw.com --> seems to be INFECTED: http://kuckenbecker.strevel.net/s --> DNS: kuckenbecker.strevel.net (kuckenbecker.strevel.net) / 81.92.219.62 checking domain: partitionsbaroques.fr --> seems to be INFECTED: http://suhaifah.psychictx.com/url --> DNS: suhaifah.psychictx.com (suhaifah.psychictx.com) / 178.211.33.205 checking domain: perca.pl --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.199, 208.73.211.191, 208.73.210.212, / checking domain: perthcrew.com.au --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: php2.twinner.com.tw --> seems to be INFECTED: http://39486.flatblastard.com/url --> DNS: 39486.flatblastard.com (39486.flatblastard.com) / 91.207.4.51 checking domain: phuongdanhvonghe.edu.vn --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 69.43.161.177 checking domain: piccolistudio.com.br --> seems to be INFECTED: http://handsexual.com/cgi-bin/r.cgi --> DNS: handsexual.com (handsexual.com) / 141.8.225.77 checking domain: pileus.fr --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: playgroundpups.com --> seems to be INFECTED: http://usva.automotiveeventregistration.com/__utm.gif --> DNS: usva.automotiveeventregistration.com (usva.automotiveeventregistration.com) / 31.210.96.157 checking domain: plural.ca --> seems to be INFECTED: http://doosani.aliquidcorporation.com/images/rt.gif --> DNS: doosani.aliquidcorporation.com (doosani.aliquidcorporation.com) / 185.53.177.8 checking domain: pmmilrec.com --> seems to be INFECTED: http://elinah.midnightastronomy.com/s --> DNS: elinah.midnightastronomy.com (elinah.midnightastronomy.com) / 31.210.96.155 checking domain: pntc.ac.th --> seems to be INFECTED: http://twowayserf.com/cgi-bin/r.cgi --> DNS: twowayserf.com (twowayserf.com) / 50.117.120.250 checking domain: police.moraga.ca.us --> seems to be INFECTED: http://clubshop.boeckman.net/b2 --> DNS: clubshop.boeckman.net (clubshop.boeckman.net) / 31.210.96.158 checking domain: porntamil.com --> seems to be INFECTED: http://germanattention.org/cgi-bin/r.cgi --> DNS: germanattention.org (germanattention.org) / 8.5.1.33 checking domain: proreha.net --> seems to be INFECTED: http://wedcheel.gliscentrifugal.com/imgres --> DNS: wedcheel.gliscentrifugal.com (wedcheel.gliscentrifugal.com) / 31.210.96.155 checking domain: prp.co.th --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: puntomascotas.cl --> seems to be INFECTED: http://mchal.vehicleservicediscount.com/__utm.gif --> DNS: mchal.vehicleservicediscount.com (mchal.vehicleservicediscount.com) / 31.210.96.157 checking domain: quantica.cl --> seems to be INFECTED: http://gamecomes.org/cgi-bin/r.cgi --> DNS: gamecomes.org (gamecomes.org) / 185.53.177.9 checking domain: radiogurbeti.com --> seems to be INFECTED: http://sonagara.slyforkfarm.com/pview --> DNS: sonagara.slyforkfarm.com (sonagara.slyforkfarm.com) / 141.8.224.93 checking domain: ravdaniel.brinkster.net --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: re4m.me --> seems to be INFECTED: http://vhinmhy.serenehomeandlandscapes.com/_xhr/ugccomments/ --> DNS: vhinmhy.serenehomeandlandscapes.com (vhinmhy.serenehomeandlandscapes.com) / 81.92.219.61 checking domain: redbarrack.net --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 64.74.223.30 checking domain: registrovip.com.br --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: reimagery.com --> seems to be INFECTED: http://stiepcic.z-sat.com/spc.php --> DNS: stiepcic.z-sat.com (stiepcic.z-sat.com) / 31.210.96.158 checking domain: rhs-airco.com --> seems to be INFECTED: http://kaliosa.mrsstyleseeker.com/hb/i/sg/adv/infinity/sg_prom_ysm_iframe_20110425.html --> DNS: kaliosa.mrsstyleseeker.com (kaliosa.mrsstyleseeker.com) / 31.210.96.157 checking domain: rhs-klima.de --> seems to be INFECTED: http://kaliosa.autoeventregistration.com/v1/beacons/log --> DNS: kaliosa.autoeventregistration.com (kaliosa.autoeventregistration.com) / 31.210.96.157 checking domain: rohanwaterpark.in --> seems to be INFECTED: http://larnchester.crowncitycomputer.com/b/ss/marthacom,marthacomglobal/1/H.22.1/s0264389380411 --> DNS: larnchester.crowncitycomputer.com (larnchester.crowncitycomputer.com) / 81.92.219.61 checking domain: rose.kuro-tejina.com --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 141.8.225.80 checking domain: saibabamandirs.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: saobacdau.com.vn --> seems to be INFECTED: http://underbuild.net/cgi-bin/r.cgi --> DNS: underbuild.net (underbuild.net) / 184.172.106.42 checking domain: sap.org.ar --> seems to be INFECTED: http://stasiauskaite.custom-chocolate-favors.com/b --> DNS: stasiauskaite.custom-chocolate-favors.com (stasiauskaite.custom-chocolate-favors.com) / 31.210.96.155 checking domain: saranf.net --> seems to be INFECTED: http://hombrado.yourspartanmovers.com/__utm.gif --> DNS: hombrado.yourspartanmovers.com (hombrado.yourspartanmovers.com) / 31.210.96.158 checking domain: sesc-sc.com.br --> seems to be INFECTED: http://shatto.8jutawan.com/lg.php --> DNS: shatto.8jutawan.com (shatto.8jutawan.com) / 31.210.96.156 checking domain: southindia-tourism.net --> seems to be INFECTED: http://reportedtechniques.org/cgi-bin/r.cgi --> DNS: reportedtechniques.org (reportedtechniques.org) / 5.61.39.56 checking domain: spitzer-onlinemarketing.de --> seems to be INFECTED: http://vuruya.avuzedesigns.com/delivery/lg.php --> DNS: vuruya.avuzedesigns.com (vuruya.avuzedesigns.com) / 178.211.33.205 checking domain: sportprnews.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: sports-rehab-and-education.co.uk --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 199.59.243.120 checking domain: sseo.elk.pl --> seems to be INFECTED: http://gensapa.valentinesalesevent.com/api/getCount2.php --> DNS: gensapa.valentinesalesevent.com (gensapa.valentinesalesevent.com) / 31.210.96.156 checking domain: stalders.com --> seems to be INFECTED: http://phalangy.hartford-capital.com/widget/get_form_comment/ --> DNS: phalangy.hartford-capital.com (phalangy.hartford-capital.com) / 31.210.96.155 checking domain: stillcatholic.com --> seems to be INFECTED: http://zahasky.greatserviceforless.com/www/delivery/lg.php --> DNS: zahasky.greatserviceforless.com (zahasky.greatserviceforless.com) / 31.210.96.157 checking domain: stw-eu.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: suitesofdorchester.com --> seems to be INFECTED: http://kek.invisatred.com/url --> DNS: kek.invisatred.com (kek.invisatred.com) / failed: Name or service not known. checking domain: sunliktrading.com --> seems to be INFECTED: http://wsbj.ancestorworshippublishing.com/b/ss/wmg,wmgatl,wmgd2cparamore,wmgparamoreall/1/H.20.3/s52007832601666 --> DNS: wsbj.ancestorworshippublishing.com (wsbj.ancestorworshippublishing.com) / 31.210.96.158 checking domain: swchan.com --> seems to be INFECTED: http://mustaqbal.totalcaminhoes.com/pview --> DNS: mustaqbal.totalcaminhoes.com (mustaqbal.totalcaminhoes.com) / failed: Name or service not known. checking domain: syrena.gminanekla.pl --> seems to be INFECTED: http://apartliberal.com/cgi-bin/r.cgi --> DNS: apartliberal.com (apartliberal.com) / 69.43.161.177 checking domain: tappukidukaan.com --> seems to be INFECTED: http://primeiro.faustoteran.com/delivery/lg.php --> DNS: primeiro.faustoteran.com (primeiro.faustoteran.com) / 81.92.219.62 checking domain: teamgod.net --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: theflightattendantlife.com --> seems to be INFECTED: http://skagger.automotiveservicesavings.com/delivery/lg.php --> DNS: skagger.automotiveservicesavings.com (skagger.automotiveservicesavings.com) / 31.210.96.157 checking domain: thepennystockblog.com --> seems to be INFECTED: http://gtracking.org/cgi-bin/r.cgi --> DNS: gtracking.org (gtracking.org) / 141.8.224.239 checking domain: theredpill.com.sg --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.177.20 checking domain: tikokupon.com --> seems to be INFECTED: http://tryko.omobia.com/b --> DNS: tryko.omobia.com (tryko.omobia.com) / 31.210.96.156 checking domain: tkne.net --> seems to be INFECTED: http://tytui.tri-swelding.com/statapi/stat/add --> DNS: tytui.tri-swelding.com (tytui.tri-swelding.com) / 31.210.96.158 checking domain: toyboxinnovations.com --> seems to be INFECTED: http://bonusforall.net/cgi-bin/r.cgi --> DNS: bonusforall.net (bonusforall.net) / 208.73.211.97 checking domain: tpm-corp.es --> seems to be INFECTED: http://yolivet.automotiveservicesavings.com/img/3.gif --> DNS: yolivet.automotiveservicesavings.com (yolivet.automotiveservicesavings.com) / failed: No address associated with hostname. checking domain: triconinnovations.com --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: upunder.com --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 69.43.161.177 checking domain: valsystem.cl --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: vbcc.fr --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: vetrocolorito.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: watchourvideo.net --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: wbu.wroc.pl --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: webdesignfm.com --> seems to be INFECTED: http://berethalmi.libertywildlife.net/pview --> DNS: berethalmi.libertywildlife.net (berethalmi.libertywildlife.net) / 178.211.33.205 checking domain: weterynarz-zawiercie.pl --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 64.74.223.30 checking domain: windomallergy.com --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: winegasmeatery.com --> seems to be INFECTED: http://mykole.dealerholidayevent.com/__utm.gif --> DNS: mykole.dealerholidayevent.com (mykole.dealerholidayevent.com) / 31.210.96.157 checking domain: wirdumonline.nl --> seems to be INFECTED: http://luckyhosting.org/cgi-bin/r.cgi --> DNS: luckyhosting.org (luckyhosting.org) / failed: No address associated with hostname. checking domain: wodzirejka.com.pl --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: workandlifebalance.eu --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: workpanel.de --> seems to be INFECTED: http://creighton.wenerdhard.com/delivery/ajs.php --> DNS: creighton.wenerdhard.com (creighton.wenerdhard.com) / 31.210.96.155 checking domain: wroclawpanorama.rotary.org.pl --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: www.accomo-metall.de --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 69.43.161.177 checking domain: www.actiogen.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: www.addbeton.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.aguadarocha.com.br --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.9 checking domain: www.alexnorrieswimwear.com --> seems to be INFECTED: http://twowayserf.com/cgi-bin/r.cgi --> DNS: twowayserf.com (twowayserf.com) / 50.117.120.250 checking domain: www.alhassanain.com --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: www.alnimrexpo.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: www.am830klaa.com --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 185.53.179.19 checking domain: www.amcmp.com --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: www.americanshaolinkungfu.org --> seems to be INFECTED: http://56762.restoreuganda.org/url --> DNS: 56762.restoreuganda.org (56762.restoreuganda.org) / 178.211.33.202 checking domain: www.amikoslovakia.sk --> seems to be INFECTED: http://yespicture.org/cgi-bin/r.cgi --> DNS: yespicture.org (yespicture.org) / 69.162.80.50 checking domain: www.apmc.com.hk --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: www.arlington.ph --> seems to be INFECTED: http://voutilainen.wenerdhard.com/tracker --> DNS: voutilainen.wenerdhard.com (voutilainen.wenerdhard.com) / 31.210.96.155 checking domain: www.asia-federblumen.de --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.211.178, 208.73.210.200, 208.73.210.217, / checking domain: www.aspi.ag --> seems to be INFECTED: http://umxamzah.mrsstyleseeker.com/__utm.gif --> DNS: umxamzah.mrsstyleseeker.com (umxamzah.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.aztechprep.org --> seems to be INFECTED: http://mathanie.renzograciemexico.com/neo/darla/php/fc.php --> DNS: mathanie.renzograciemexico.com (mathanie.renzograciemexico.com) / 31.210.96.156 checking domain: www.backupdunyasi.com --> seems to be INFECTED: http://twiceseparate.com/cgi-bin/r.cgi --> DNS: twiceseparate.com (twiceseparate.com) / 185.2.66.16 checking domain: www.baliindividuellreisen.com --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 185.53.178.7 checking domain: www.baliniksoma.com --> seems to be INFECTED: http://dirdam.castlelawpa.com/_xhr/ugccomments/ --> DNS: dirdam.castlelawpa.com (dirdam.castlelawpa.com) / 31.210.96.158 checking domain: www.banksglobaltransport.com --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 185.53.179.7 checking domain: www.batasnatin.com --> seems to be INFECTED: http://morsh.joannheilman.com/lg.php --> DNS: morsh.joannheilman.com (morsh.joannheilman.com) / 31.210.96.158 checking domain: www.bebenatur.com --> seems to be INFECTED: http://poeya.cubpack910.com/url --> DNS: poeya.cubpack910.com (poeya.cubpack910.com) / failed: Connection timed out. checking domain: www.bel.com --> seems to be INFECTED: http://60957.southwestdiscus.com/url --> DNS: 60957.southwestdiscus.com (60957.southwestdiscus.com) / 178.211.33.203 checking domain: www.berdee.com --> seems to be INFECTED: http://ugiwa.rled.net/openx/www/delivery/spc.php --> DNS: ugiwa.rled.net (ugiwa.rled.net) / 31.210.96.158 checking domain: www.berera.com --> seems to be INFECTED: http://jojua.remodelgreaterphoenix.com/lg.php --> DNS: jojua.remodelgreaterphoenix.com (jojua.remodelgreaterphoenix.com) / 31.210.96.157 checking domain: www.bharatinfoline.com --> seems to be INFECTED: http://lesbon.ksupridewrestling.com/lg.php --> DNS: lesbon.ksupridewrestling.com (lesbon.ksupridewrestling.com) / 31.210.96.155 checking domain: www.bienenmilch.com --> seems to be INFECTED: http://jonestown.serenehomeandlandscapes.com/s --> DNS: jonestown.serenehomeandlandscapes.com (jonestown.serenehomeandlandscapes.com) / 81.92.219.61 checking domain: www.bikersandbabesatthebeach.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.bitbank.com.lb --> seems to be INFECTED: http://rungbahadoor.oharvest.net/pview --> DNS: rungbahadoor.oharvest.net (rungbahadoor.oharvest.net) / 31.210.96.156 checking domain: www.bitcell.com.mx --> seems to be INFECTED: http://ushiar.vehicleservicediscount.com/hb/i/sg/adv/infinity/sg_prom_ysm_iframe_20110425.html --> DNS: ushiar.vehicleservicediscount.com (ushiar.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.bluechipsportfishing.com --> seems to be INFECTED: http://treffinah.rled.net/hb/i/sg/adv/infinity/sg_prom_ysm_iframe_20110425.html --> DNS: treffinah.rled.net (treffinah.rled.net) / 31.210.96.158 checking domain: www.bluestar.us --> seems to be INFECTED: http://twowayserf.com/cgi-bin/r.cgi --> DNS: twowayserf.com (twowayserf.com) / 50.117.120.250 checking domain: www.bluraymods.com --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: www.bobthebugman.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.bodasexclusivas.com --> seems to be INFECTED: http://compass.automotiveeventregistration.com/safe_image.php --> DNS: compass.automotiveeventregistration.com (compass.automotiveeventregistration.com) / 31.210.96.157 checking domain: www.bralicias.com --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: www.brianpatten.co.uk --> seems to be INFECTED: http://bjrneset.ahtcna.com/BurstingPipe/adServer.bs --> DNS: bjrneset.ahtcna.com (bjrneset.ahtcna.com) / 31.210.96.158 checking domain: www.buybutcherblock.com --> seems to be INFECTED: http://underbuild.net/cgi-bin/r.cgi --> DNS: underbuild.net (underbuild.net) / 184.172.106.42 checking domain: www.californiaoutdoorproperties.com --> seems to be INFECTED: http://jelow.be3ny.com/new/www/delivery/ajs.php --> DNS: jelow.be3ny.com (jelow.be3ny.com) / 31.210.96.156 checking domain: www.calltoislam.com --> seems to be INFECTED: http://griscom.mrsstyleseeker.com/__utm.gif --> DNS: griscom.mrsstyleseeker.com (griscom.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.carlosmeschini.com.br --> seems to be INFECTED: http://fulpagar.tropicaltoner.com/b --> DNS: fulpagar.tropicaltoner.com (fulpagar.tropicaltoner.com) / 31.210.96.158 checking domain: www.carlosvuam.com --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 64.74.223.30 checking domain: www.cases.batasnatin.com --> seems to be INFECTED: http://morsh.joannheilman.com/ttj --> DNS: morsh.joannheilman.com (morsh.joannheilman.com) / 31.210.96.158 checking domain: www.cepsuisse.com --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: www.chiangkongonline.com --> seems to be INFECTED: http://zoenna.newlogiq.com/pview --> DNS: zoenna.newlogiq.com (zoenna.newlogiq.com) / 31.210.96.155 checking domain: www.chingssecret.com --> seems to be INFECTED: http://twiceseparate.com/cgi-bin/r.cgi --> DNS: twiceseparate.com (twiceseparate.com) / 185.2.66.16 checking domain: www.choice.md --> seems to be INFECTED: http://rangihaeata.kemperfitness.com/__utm.gif --> DNS: rangihaeata.kemperfitness.com (rangihaeata.kemperfitness.com) / 81.92.219.60 checking domain: www.ciren.net --> seems to be INFECTED: http://treescha.automotiveservicesavings.com/pview --> DNS: treescha.automotiveservicesavings.com (treescha.automotiveservicesavings.com) / 31.210.96.157 checking domain: www.civilunderground.co.nz --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.clarkcoky.com --> seems to be INFECTED: http://panalangin.automotiveeventregistration.com/t.gif --> DNS: panalangin.automotiveeventregistration.com (panalangin.automotiveeventregistration.com) / 31.210.96.157 checking domain: www.clubescuelagr.com --> seems to be INFECTED: http://nakashian.mrsstyleseeker.com/v1/counter --> DNS: nakashian.mrsstyleseeker.com (nakashian.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.comune.santa-maria-capua-vetere.ce.it --> seems to be INFECTED: http://gesneriaceae.telecomillinois.com/t.gif --> DNS: gesneriaceae.telecomillinois.com (gesneriaceae.telecomillinois.com) / 31.210.96.155 checking domain: www.crcnk.com.au --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.214, 208.73.210.217, 208.73.211.178, / checking domain: www.creatingyourfreedom.com --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: www.creativ-art1.com --> seems to be INFECTED: http://vermillon.serenehomeandlandscapes.com/__utm.gif --> DNS: vermillon.serenehomeandlandscapes.com (vermillon.serenehomeandlandscapes.com) / 81.92.219.61 checking domain: www.dallascustomfurniture.com --> seems to be INFECTED: http://bonusforall.net/cgi-bin/r.cgi --> DNS: bonusforall.net (bonusforall.net) / 208.73.211.97 checking domain: www.damiannowak.pl --> seems to be INFECTED: http://jianjia.teeboxpromo.com/b --> DNS: jianjia.teeboxpromo.com (jianjia.teeboxpromo.com) / 31.210.96.158 checking domain: www.deauville.org --> seems to be INFECTED: http://merluzzo.thenightlyjoker.com/b --> DNS: merluzzo.thenightlyjoker.com (merluzzo.thenightlyjoker.com) / 31.210.96.158 checking domain: www.defensepenale.com --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 141.8.225.80 checking domain: www.depednaga.com.ph --> seems to be INFECTED: http://alliovida.newcarsat.com/s --> DNS: alliovida.newcarsat.com (alliovida.newcarsat.com) / 31.210.96.157 checking domain: www.designerdogwear.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: www.detailformation.com --> seems to be INFECTED: http://chitlinlover.vehicleservicediscount.com/b --> DNS: chitlinlover.vehicleservicediscount.com (chitlinlover.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.diamondswindon.co.uk --> seems to be INFECTED: http://checkforsec.com/cgi-bin/r.cgi --> DNS: checkforsec.com (checkforsec.com) / 69.172.201.208 checking domain: www.dieta-dimagrante.com --> seems to be INFECTED: http://yerme.techsupportauctions.com/tracker --> DNS: yerme.techsupportauctions.com (yerme.techsupportauctions.com) / 31.210.96.158 checking domain: www.dimclay.com --> seems to be INFECTED: http://aujikar.golfnewsiowa.com/pview --> DNS: aujikar.golfnewsiowa.com (aujikar.golfnewsiowa.com) / 31.210.96.157 checking domain: www.dixielectricar.com --> seems to be INFECTED: http://redzhebova.midjerseymasonry.com/delivery/lg.php --> DNS: redzhebova.midjerseymasonry.com (redzhebova.midjerseymasonry.com) / failed: Name or service not known. checking domain: www.doctorhelp.de --> seems to be INFECTED: http://switchett.virtualsofts.com/event.js --> DNS: switchett.virtualsofts.com (switchett.virtualsofts.com) / 31.210.96.158 checking domain: www.dogtreatrecipes.com.au --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: www.dolphinnaples.com --> seems to be INFECTED: http://denhard.golfnewssouthcarolina.com/t.gif --> DNS: denhard.golfnewssouthcarolina.com (denhard.golfnewssouthcarolina.com) / 31.210.96.156 checking domain: www.downgradeps3.com --> seems to be INFECTED: http://trolleeroy.ancestorworshippublishing.com/new/www/delivery/lg.php --> DNS: trolleeroy.ancestorworshippublishing.com (trolleeroy.ancestorworshippublishing.com) / 31.210.96.158 checking domain: www.dreamboxturk.com --> seems to be INFECTED: http://baylet.autoeventregistration.com/url --> DNS: baylet.autoeventregistration.com (baylet.autoeventregistration.com) / 31.210.96.157 checking domain: www.dulceselsombreron.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.177.20 checking domain: www.dumontduneriders.com --> seems to be INFECTED: http://sslabssys.com/cgi-bin/r.cgi --> DNS: sslabssys.com (sslabssys.com) / 69.172.201.208 checking domain: www.dwowvod.com --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 199.59.243.120 checking domain: www.eaf.edu.mx --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: www.ejmii.com --> seems to be INFECTED: http://mahaphontrakoon.vehicleservicediscount.com/s --> DNS: mahaphontrakoon.vehicleservicediscount.com (mahaphontrakoon.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.elsiedesigns.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: www.enimex.gr --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.210.212, 208.73.211.199, 208.73.211.191, / checking domain: www.extremebusa.com --> seems to be INFECTED: http://mehyaoui.newcarsat.com/__utm.gif --> DNS: mehyaoui.newcarsat.com (mehyaoui.newcarsat.com) / 31.210.96.157 checking domain: www.farmasanmodababy.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.214, 208.73.210.217, 208.73.211.178, / checking domain: www.fastflowtransport.com.au --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.fatherlinh.com --> seems to be INFECTED: http://germanattention.org/cgi-bin/r.cgi --> DNS: germanattention.org (germanattention.org) / 8.5.1.33 checking domain: www.fcc.com --> seems to be INFECTED: http://mikuz.animalgenetics.com/dcsour5e80000008ybade4ttg_1i1l/dcs.gif --> DNS: mikuz.animalgenetics.com (mikuz.animalgenetics.com) / 31.210.96.158 checking domain: www.femecog.org.mx --> seems to be INFECTED: http://rodli.automotiveeventregistration.com/t.gif --> DNS: rodli.automotiveeventregistration.com (rodli.automotiveeventregistration.com) / 31.210.96.157 checking domain: www.firm.batasnatin.com --> seems to be INFECTED: http://morsh.joannheilman.com/delivery/lg.php --> DNS: morsh.joannheilman.com (morsh.joannheilman.com) / 31.210.96.158 checking domain: www.fishingtackleindia.com --> seems to be INFECTED: http://urladyms.newlogiq.com/__utm.gif --> DNS: urladyms.newlogiq.com (urladyms.newlogiq.com) / 31.210.96.155 checking domain: www.flushingpheasantrussells.com --> seems to be INFECTED: http://37834.southwestdiscus.com/url --> DNS: 37834.southwestdiscus.com (37834.southwestdiscus.com) / 178.211.33.203 checking domain: www.foto-weller.de --> seems to be INFECTED: http://praylu.nutritionbydesign.com/st --> DNS: praylu.nutritionbydesign.com (praylu.nutritionbydesign.com) / 31.210.96.156 checking domain: www.freesure.com.tr --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 185.53.179.7 checking domain: www.freilandschwein.info --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 185.53.179.7 checking domain: www.gamanteles.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: www.gastronj.com --> seems to be INFECTED: http://stanclous.telecomchicago.com/b --> DNS: stanclous.telecomchicago.com (stanclous.telecomchicago.com) / 31.210.96.155 checking domain: www.geoffwhite.ws --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 141.8.225.80 checking domain: www.glodyne.com --> seems to be INFECTED: http://ramaila.inboccaproductions.com/imghover --> DNS: ramaila.inboccaproductions.com (ramaila.inboccaproductions.com) / 31.210.96.156 checking domain: www.golden-champion.com --> seems to be INFECTED: http://updude.glsfinancials.com/pview --> DNS: updude.glsfinancials.com (updude.glsfinancials.com) / 85.17.25.202 checking domain: www.greenfieldadvisorsltd.com --> seems to be INFECTED: http://moutsiouna.iretarpg.com/url --> DNS: moutsiouna.iretarpg.com (moutsiouna.iretarpg.com) / 185.53.177.9 checking domain: www.griotcalendar.org --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 185.53.179.19 checking domain: www.gswsftp01.com --> seems to be INFECTED: http://parallag.bmemkitchens.com/b/ss/cnn-adbp-intl/1/H.24.1/s0929995991119 --> DNS: parallag.bmemkitchens.com (parallag.bmemkitchens.com) / 69.43.160.163 checking domain: www.healthnews8at8.com --> seems to be INFECTED: http://youjizzboy.autoserviceevent.com/fpc.pl --> DNS: youjizzboy.autoserviceevent.com (youjizzboy.autoserviceevent.com) / 31.210.96.157 checking domain: www.highsport.se --> seems to be INFECTED: http://udomchum.telecommichigan.com/t.gif --> DNS: udomchum.telecommichigan.com (udomchum.telecommichigan.com) / 31.210.96.155 checking domain: www.highwaterbrewing.com --> seems to be INFECTED: http://tirtawijaya.mrsstyleseeker.com/__utm.gif --> DNS: tirtawijaya.mrsstyleseeker.com (tirtawijaya.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.holidayinn-mulhouse.com --> seems to be INFECTED: http://hunton.valentinesalesevent.com/b --> DNS: hunton.valentinesalesevent.com (hunton.valentinesalesevent.com) / 31.210.96.156 checking domain: www.hospitalesangeles.com --> seems to be INFECTED: http://crdoba.hartford-capital.com/api/getCount2.php --> DNS: crdoba.hartford-capital.com (crdoba.hartford-capital.com) / 31.210.96.155 checking domain: www.hostal3soles.com --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 185.53.178.7 checking domain: www.hostpix.de --> seems to be INFECTED: http://xlau.kalkanturqouise.com/__utm.gif --> DNS: xlau.kalkanturqouise.com (xlau.kalkanturqouise.com) / failed: Name or service not known. checking domain: www.hummel-print.biz --> seems to be INFECTED: http://58385.pballgames.com/url --> DNS: 58385.pballgames.com (58385.pballgames.com) / 91.207.4.51 checking domain: www.hutano.com --> seems to be INFECTED: http://vocken.panjiaying.com/url --> DNS: vocken.panjiaying.com (vocken.panjiaying.com) / 31.210.96.156 checking domain: www.iagu.org --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: www.ijerd.com --> seems to be INFECTED: http://verzeroli.outbreakm3dia.com/t.gif --> DNS: verzeroli.outbreakm3dia.com (verzeroli.outbreakm3dia.com) / 185.2.66.16 checking domain: www.ilovethefingerlakes.com --> seems to be INFECTED: http://ailinn.automotiveservicesavings.com/if --> DNS: ailinn.automotiveservicesavings.com (ailinn.automotiveservicesavings.com) / 31.210.96.157 checking domain: www.information-international.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: www.innisicss.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.inteki.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: www.jailbreak-ps3.com --> seems to be INFECTED: http://trolleeroy.ancestorworshippublishing.com/__utm.gif --> DNS: trolleeroy.ancestorworshippublishing.com (trolleeroy.ancestorworshippublishing.com) / 31.210.96.158 checking domain: www.jalba.gr --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: www.jawa-club.at --> seems to be INFECTED: http://matinisi.nitplus.com/servlet/ajrotator/126371/0/vj --> DNS: matinisi.nitplus.com (matinisi.nitplus.com) / 31.210.96.156 checking domain: www.jcs3.com --> seems to be INFECTED: http://linita.golfnewsmontana.com/__utm.gif --> DNS: linita.golfnewsmontana.com (linita.golfnewsmontana.com) / 31.210.96.157 checking domain: www.jollybeach.net --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.9 checking domain: www.jonaswelsch.com --> seems to be INFECTED: http://forcea.glisinc.com/webpagethumbnail --> DNS: forcea.glisinc.com (forcea.glisinc.com) / failed: Name or service not known. checking domain: www.jordanbad.de --> seems to be INFECTED: http://facuri.chelseyfatula.com/pview --> DNS: facuri.chelseyfatula.com (facuri.chelseyfatula.com) / 185.53.177.13 checking domain: www.jornalfarroupilha.com.br --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.jornalocaminho.com.br --> seems to be INFECTED: http://gramelis.newyorkmascot.com/b --> DNS: gramelis.newyorkmascot.com (gramelis.newyorkmascot.com) / failed: Name or service not known. checking domain: www.jpot.com.sg --> seems to be INFECTED: http://maturkanic.girlsgoneglamis.com/__utm.gif --> DNS: maturkanic.girlsgoneglamis.com (maturkanic.girlsgoneglamis.com) / failed: Name or service not known. checking domain: www.jtcomms.com --> seems to be INFECTED: http://solichana.telecommichigan.com/safe_image.php --> DNS: solichana.telecommichigan.com (solichana.telecommichigan.com) / 31.210.96.155 checking domain: www.karavelle.com.br --> seems to be INFECTED: http://britts.oharvest.net/__utm.gif --> DNS: britts.oharvest.net (britts.oharvest.net) / 31.210.96.156 checking domain: www.kbhbrandmuseum.dk --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: www.keepcalm.com.br --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: www.kgpagolf.com --> seems to be INFECTED: http://namdarian.sellitandforgetittoday.com/__utm.gif --> DNS: namdarian.sellitandforgetittoday.com (namdarian.sellitandforgetittoday.com) / 31.210.96.156 checking domain: www.klanglos-studio.de --> seems to be INFECTED: http://camplong.barbeveragesnv.com/__utm.gif --> DNS: camplong.barbeveragesnv.com (camplong.barbeveragesnv.com) / failed: Name or service not known. checking domain: www.klaumonforma.com.br --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: www.klokast.se --> seems to be INFECTED: http://reportedtechniques.org/cgi-bin/r.cgi --> DNS: reportedtechniques.org (reportedtechniques.org) / 5.61.39.56 checking domain: www.koreanmartialarts.com --> seems to be INFECTED: http://xpod.gryphonaz.com/_xhr/ugccomments/ --> DNS: xpod.gryphonaz.com (xpod.gryphonaz.com) / 31.210.96.157 checking domain: www.kuriren.net --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.kyalasushi.com --> seems to be INFECTED: http://vesman.autoserviceevent.com/webpagethumbnail --> DNS: vesman.autoserviceevent.com (vesman.autoserviceevent.com) / 31.210.96.157 checking domain: www.leisurelanespa.com --> seems to be INFECTED: http://thehunt.newcarsat.com/a/8883/14611/30747-15.js --> DNS: thehunt.newcarsat.com (thehunt.newcarsat.com) / 31.210.96.157 checking domain: www.levin.com.br --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 64.74.223.30 checking domain: www.lipika.com --> seems to be INFECTED: http://malamut.revolverindy.com/pview --> DNS: malamut.revolverindy.com (malamut.revolverindy.com) / failed: Name or service not known. checking domain: www.listalapiazza.it --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.191, 208.73.210.212, 208.73.211.199, / checking domain: www.little-moon-aussies.com --> seems to be INFECTED: http://jahren.prestigehonda.net/fpc.pl --> DNS: jahren.prestigehonda.net (jahren.prestigehonda.net) / 31.210.96.157 checking domain: www.livre-etre-bien.com --> seems to be INFECTED: http://nedou.kidstryingtopayforcollege.com/b --> DNS: nedou.kidstryingtopayforcollege.com (nedou.kidstryingtopayforcollege.com) / 81.92.219.61 checking domain: www.log-in-verlag.de --> seems to be INFECTED: http://wcameron.powerplaycreative.com/pview --> DNS: wcameron.powerplaycreative.com (wcameron.powerplaycreative.com) / 31.210.96.158 checking domain: www.lovethisgirl.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.91 checking domain: www.loxsavvy.com.au --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 69.43.161.177 checking domain: www.maquinaslitograficas.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.200, 208.73.210.214, 208.73.211.178, / checking domain: www.mayer.com.ro --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: www.mazus-art.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 103.224.182.250 checking domain: www.medical-swiss.com --> seems to be INFECTED: http://zulainis.theinvisatread.com/url --> DNS: zulainis.theinvisatread.com (zulainis.theinvisatread.com) / 185.53.178.6 checking domain: www.meredithbrooks.com --> seems to be INFECTED: http://35903.flatblastard.com/url --> DNS: 35903.flatblastard.com (35903.flatblastard.com) / 91.207.4.51 checking domain: www.microforme.com --> seems to be INFECTED: http://suryoko.hitodeki.com/api/getCount2.php --> DNS: suryoko.hitodeki.com (suryoko.hitodeki.com) / failed: Name or service not known. checking domain: www.mind-body-soul.de --> seems to be INFECTED: http://timp.automotiveservicesavings.com/widgets/tweet_button.html --> DNS: timp.automotiveservicesavings.com (timp.automotiveservicesavings.com) / 31.210.96.157 checking domain: www.miniaturesupplier.com --> seems to be INFECTED: http://koumparou.mwhiteman.com/t.gif --> DNS: koumparou.mwhiteman.com (koumparou.mwhiteman.com) / 31.210.96.155 checking domain: www.mintfinancial.com.au --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.mitsuadvclub.net --> seems to be INFECTED: http://loardy.exquisiteclasscenter.com/url --> DNS: loardy.exquisiteclasscenter.com (loardy.exquisiteclasscenter.com) / 178.211.33.203 checking domain: www.modellfly.no --> seems to be INFECTED: http://gtracking.org/cgi-bin/r.cgi --> DNS: gtracking.org (gtracking.org) / 141.8.224.239 checking domain: www.moebel-direkt.net --> seems to be INFECTED: http://reset.com/fpc.pl --> DNS: reset.com (reset.com) / 54.243.32.25, 54.225.167.121, 2406:da00:ff00::36e1:a779, / checking domain: www.monah.us --> seems to be INFECTED: http://kukuljac.concretevibration.com/delivery/lg.php --> DNS: kukuljac.concretevibration.com (kukuljac.concretevibration.com) / 31.210.96.158 checking domain: www.movingtransfer.com --> seems to be INFECTED: http://taiugac.vehicleservicediscount.com/openx/www/delivery/lg.php --> DNS: taiugac.vehicleservicediscount.com (taiugac.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.mrlatinomagazine.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.msm.mc --> seems to be INFECTED: http://poserio.thecaregrouppc.net/delivery/lg.php --> DNS: poserio.thecaregrouppc.net (poserio.thecaregrouppc.net) / 81.92.219.62 checking domain: www.my-hebrew-programs.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.mywoom.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.nccdirect.com --> seems to be INFECTED: http://kulingoski.golfnewspennsylvania.com/new2/www/delivery/lg.php --> DNS: kulingoski.golfnewspennsylvania.com (kulingoski.golfnewspennsylvania.com) / 31.210.96.157 checking domain: www.neonconcursos.com.br --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.newsflash.org --> seems to be INFECTED: http://srse.techsupportauction.com/1pix.gif --> DNS: srse.techsupportauction.com (srse.techsupportauction.com) / failed: Name or service not known. checking domain: www.nicholas-williams.com --> seems to be INFECTED: http://mildworm.thecinema6.com/ps/ifr --> DNS: mildworm.thecinema6.com (mildworm.thecinema6.com) / 31.210.96.156 checking domain: www.norweger-in-not.de --> seems to be INFECTED: http://godhy.gayilluminati.com/openx/www/delivery/lg.php --> DNS: godhy.gayilluminati.com (godhy.gayilluminati.com) / failed: Name or service not known. checking domain: www.nqsacademy.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.nwd-ly.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.200, 208.73.210.214, 208.73.211.178, / checking domain: www.oo5.com --> seems to be INFECTED: http://uglyugly.savedalyfield.com/s --> DNS: uglyugly.savedalyfield.com (uglyugly.savedalyfield.com) / 31.210.96.157 checking domain: www.osbycentralservice.se --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 69.43.161.177 checking domain: www.padraoeditorial.com.br --> seems to be INFECTED: http://iamprotectedfrom.net/cgi-bin/r.cgi --> DNS: iamprotectedfrom.net (iamprotectedfrom.net) / 185.53.179.9 checking domain: www.painphysicianjournal.com --> seems to be INFECTED: http://brinning.automotiveeventregistration.com/new2/www/delivery/lg.php --> DNS: brinning.automotiveeventregistration.com (brinning.automotiveeventregistration.com) / 31.210.96.157 checking domain: www.pearlscorniche.com --> seems to be INFECTED: http://gamecomes.org/cgi-bin/r.cgi --> DNS: gamecomes.org (gamecomes.org) / 185.53.177.9 checking domain: www.pearlsindiatour.com --> seems to be INFECTED: http://underbuild.net/cgi-bin/r.cgi --> DNS: underbuild.net (underbuild.net) / 184.172.106.42 checking domain: www.perstererfineart.com --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: www.pfotenranch.de --> seems to be INFECTED: http://zaquitsha.vetsingreensboro.com/imghover --> DNS: zaquitsha.vetsingreensboro.com (zaquitsha.vetsingreensboro.com) / 185.53.179.6 checking domain: www.pino-travel.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.pixled.pl --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.planet-pulse.com --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: www.pmg.kncity.info --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.praxpetroleum.com --> seems to be INFECTED: http://kumasegawa.themorningjoker.com/openx/www/delivery/spc.php --> DNS: kumasegawa.themorningjoker.com (kumasegawa.themorningjoker.com) / 31.210.96.158 checking domain: www.prestigegym.com --> seems to be INFECTED: http://tippetts.prestigehonda.net/delivery/lg.php --> DNS: tippetts.prestigehonda.net (tippetts.prestigehonda.net) / 31.210.96.157 checking domain: www.proreha.net --> seems to be INFECTED: http://wedcheel.gliscentrifugal.com/delivery/lg.php --> DNS: wedcheel.gliscentrifugal.com (wedcheel.gliscentrifugal.com) / 31.210.96.155 checking domain: www.psicoterapeutas.org --> seems to be INFECTED: http://pantakit.powerplaycreative.com/imghover --> DNS: pantakit.powerplaycreative.com (pantakit.powerplaycreative.com) / 31.210.96.158 checking domain: www.quintadamainha.com --> seems to be INFECTED: http://limpiado.autoeventregistration.com/pview --> DNS: limpiado.autoeventregistration.com (limpiado.autoeventregistration.com) / 31.210.96.157 checking domain: www.rac-italia.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.radiogurbeti.com --> seems to be INFECTED: http://sonagara.slyforkfarm.com/b/ss/jobsdb-prd-id/1/H.23.6/s21023602889073 --> DNS: sonagara.slyforkfarm.com (sonagara.slyforkfarm.com) / 141.8.224.93 checking domain: www.rdm.hr --> seems to be INFECTED: http://40934.azdiscus.com/url --> DNS: 40934.azdiscus.com (40934.azdiscus.com) / 178.211.33.203 checking domain: www.rebo-rohstoffe.de --> seems to be INFECTED: http://argles.autoeventregistration.com/b --> DNS: argles.autoeventregistration.com (argles.autoeventregistration.com) / 31.210.96.157 checking domain: www.recrutam.ro --> seems to be INFECTED: http://dambalang.vehicleexchangeprogram.com/imghover --> DNS: dambalang.vehicleexchangeprogram.com (dambalang.vehicleexchangeprogram.com) / 31.210.96.157 checking domain: www.resistantculture.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.retrosheet.org --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.210.212, 208.73.211.199, 208.73.211.191, / checking domain: www.rgjassociation.info --> seems to be INFECTED: http://weedx.fubarpaintball.com/json --> DNS: weedx.fubarpaintball.com (weedx.fubarpaintball.com) / 31.210.96.156 checking domain: www.rich.co.ke --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: www.rollershop.de --> seems to be INFECTED: http://yinpou.aredietsok.com/b/ss/wbextextibrd,wbglobalext/1/G.9p2/s5601663509823 --> DNS: yinpou.aredietsok.com (yinpou.aredietsok.com) / 31.210.96.158 checking domain: www.rotoconcept.com --> seems to be INFECTED: http://mius.autoserviceevent.com/pview --> DNS: mius.autoserviceevent.com (mius.autoserviceevent.com) / 31.210.96.157 checking domain: www.royalbambi.de --> seems to be INFECTED: http://yukusai.emergencyvetdanvilleva.com/st --> DNS: yukusai.emergencyvetdanvilleva.com (yukusai.emergencyvetdanvilleva.com) / failed: Name or service not known. checking domain: www.royaltyautoplaza.com --> seems to be INFECTED: http://peppen.studiosylverline.com/_xhr/ugccomments/ --> DNS: peppen.studiosylverline.com (peppen.studiosylverline.com) / 31.210.96.157 checking domain: www.sandiegoinsidertours.com --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 69.43.161.177 checking domain: www.santuariodalapa.pt --> seems to be INFECTED: http://tixon.theafternoonjoker.com/b --> DNS: tixon.theafternoonjoker.com (tixon.theafternoonjoker.com) / 31.210.96.158 checking domain: www.sasgroup.pl --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 208.73.211.194, 208.73.211.199, 208.73.211.191, / checking domain: www.scantexas.com --> seems to be INFECTED: http://titasic.vehicleservicediscount.com/delivery/ajs.php --> DNS: titasic.vehicleservicediscount.com (titasic.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.scga.at --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.200, 208.73.210.214, 208.73.211.178, / checking domain: www.sculpture1940.com --> seems to be INFECTED: http://pizzaexperience.internet1495.com/imghover --> DNS: pizzaexperience.internet1495.com (pizzaexperience.internet1495.com) / 178.211.33.203 checking domain: www.sdfbd.org --> seems to be INFECTED: http://handsexual.com/cgi-bin/r.cgi --> DNS: handsexual.com (handsexual.com) / 141.8.225.77 checking domain: www.secondhandoptik.de --> seems to be INFECTED: http://whiff.newcarsat.com/imgres --> DNS: whiff.newcarsat.com (whiff.newcarsat.com) / 31.210.96.157 checking domain: www.siacgroup.com --> seems to be INFECTED: http://51078.azdiscus.com/url --> DNS: 51078.azdiscus.com (51078.azdiscus.com) / 178.211.33.203 checking domain: www.signagewidgets.com --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: www.singaporeparties.com.sg --> seems to be INFECTED: http://rothermich.freelifelinegovernmentphone.com/getSegment.php --> DNS: rothermich.freelifelinegovernmentphone.com (rothermich.freelifelinegovernmentphone.com) / 141.8.224.235 checking domain: www.skleprower.pl --> seems to be INFECTED: http://twiceseparate.com/cgi-bin/r.cgi --> DNS: twiceseparate.com (twiceseparate.com) / 184.172.106.42 checking domain: www.sportstoursinternational.co.uk --> seems to be INFECTED: http://tripplett.z-sat.com/__utm.gif --> DNS: tripplett.z-sat.com (tripplett.z-sat.com) / 31.210.96.158 checking domain: www.sreinc.net --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.177.9 checking domain: www.sri.cmu.ac.th --> seems to be INFECTED: http://twansha.yourcakedecoratingclass.com/__utm.gif --> DNS: twansha.yourcakedecoratingclass.com (twansha.yourcakedecoratingclass.com) / 31.210.96.158 checking domain: www.ssdrivingschooltampa.com --> seems to be INFECTED: http://quirarte.dealerholidayevent.com/new2/www/delivery/lg.php --> DNS: quirarte.dealerholidayevent.com (quirarte.dealerholidayevent.com) / 31.210.96.157 checking domain: www.stublla.net --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 199.59.243.120 checking domain: www.successinteaching.info --> seems to be INFECTED: http://protechere.com/cgi-bin/r.cgi --> DNS: protechere.com (protechere.com) / 69.43.161.177 checking domain: www.superpass.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 66.135.47.125 checking domain: www.systemcv.com.br --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.tailormadegolftours.com --> seems to be INFECTED: http://zivarous.vehicleexchangeprogram.com/iu --> DNS: zivarous.vehicleexchangeprogram.com (zivarous.vehicleexchangeprogram.com) / failed: No address associated with hostname. checking domain: www.televideoproductions.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 185.53.177.6 checking domain: www.temsa-nord.de --> seems to be INFECTED: http://dayfa.myredhomingpidgeon.com/__utm.gif --> DNS: dayfa.myredhomingpidgeon.com (dayfa.myredhomingpidgeon.com) / 69.43.160.163 checking domain: www.texcon.net --> seems to be INFECTED: http://gharavi.dealerholidayevent.com/b/ss/microncrucialusprod/1/H.9-pdvu-2/s64260921978464 --> DNS: gharavi.dealerholidayevent.com (gharavi.dealerholidayevent.com) / 31.210.96.157 checking domain: www.thehalfking.com --> seems to be INFECTED: http://flexwala.golfironworks.com/t.gif --> DNS: flexwala.golfironworks.com (flexwala.golfironworks.com) / 31.210.96.155 checking domain: www.thepatientsspeak.org --> seems to be INFECTED: http://twiceseparate.com/cgi-bin/r.cgi --> DNS: twiceseparate.com (twiceseparate.com) / 184.172.106.42 checking domain: www.therapiehyperbare.com --> seems to be INFECTED: http://tagipur.mrsstyleseeker.com/st --> DNS: tagipur.mrsstyleseeker.com (tagipur.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.theresastouchdayspa.ca --> seems to be INFECTED: http://prunotto.newcarsat.com/statapi/stat/add --> DNS: prunotto.newcarsat.com (prunotto.newcarsat.com) / 31.210.96.157 checking domain: www.thestampspot.com.au --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.214, 208.73.210.217, 208.73.211.178, / checking domain: www.timfirth.com --> seems to be INFECTED: http://holdpoker.ancestorworshippublishing.com/pingjs/ --> DNS: holdpoker.ancestorworshippublishing.com (holdpoker.ancestorworshippublishing.com) / 31.210.96.158 checking domain: www.tintasluxor.com.br --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 141.8.224.25 checking domain: www.tri-tex.net --> seems to be INFECTED: http://vicrant.newworldheroes.com/plugins/like.php --> DNS: vicrant.newworldheroes.com (vicrant.newworldheroes.com) / failed: No address associated with hostname. checking domain: www.tubtimsiam.com --> seems to be INFECTED: http://abew.whonose.com/fpc.pl --> DNS: abew.whonose.com (abew.whonose.com) / 178.211.33.203 checking domain: www.tumbadack.se --> seems to be INFECTED: http://alflo.autoserviceevent.com/gadgets/ifr --> DNS: alflo.autoserviceevent.com (alflo.autoserviceevent.com) / 31.210.96.157 checking domain: www.tunefreak.org --> seems to be INFECTED: http://wawabeh.williamsfp.com/delivery/lg.php --> DNS: wawabeh.williamsfp.com (wawabeh.williamsfp.com) / failed: Name or service not known. checking domain: www.turbo-mixer.de --> seems to be INFECTED: http://schmakel.strongpsychic.com/t.gif --> DNS: schmakel.strongpsychic.com (schmakel.strongpsychic.com) / 31.210.96.155 checking domain: www.turkescortbayanlar.com --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.243.120 checking domain: www.ucamb.org --> seems to be INFECTED: http://smittendorf.2cuonline.com/imgres --> DNS: smittendorf.2cuonline.com (smittendorf.2cuonline.com) / 31.210.96.155 checking domain: www.unitedmgtii.com --> seems to be INFECTED: http://petel.golfnewstennessee.com/delivery/lg.php --> DNS: petel.golfnewstennessee.com (petel.golfnewstennessee.com) / 31.210.96.157 checking domain: www.vantetoys.com --> seems to be INFECTED: http://witnest.sciconsultinggroup.com/__utm.gif --> DNS: witnest.sciconsultinggroup.com (witnest.sciconsultinggroup.com) / 81.92.219.60 checking domain: www.veterinarkliniken.se --> seems to be INFECTED: http://dutytraditional.net/cgi-bin/r.cgi --> DNS: dutytraditional.net (dutytraditional.net) / 5.61.39.56 checking domain: www.vfbhermsdorf.de --> seems to be INFECTED: http://hinouchi.greatserviceforless.com/__utm.gif --> DNS: hinouchi.greatserviceforless.com (hinouchi.greatserviceforless.com) / 31.210.96.157 checking domain: www.vidvanern.se --> seems to be INFECTED: http://usnai.restoremystuff.com/1pix.gif --> DNS: usnai.restoremystuff.com (usnai.restoremystuff.com) / 31.210.96.156 checking domain: www.vitaminbude.de --> seems to be INFECTED: http://karepii.dealerholidayevent.com/__utm.gif --> DNS: karepii.dealerholidayevent.com (karepii.dealerholidayevent.com) / 31.210.96.157 checking domain: www.wallyontheweb.com --> seems to be INFECTED: http://ichinohe.casabodamia.com/b --> DNS: ichinohe.casabodamia.com (ichinohe.casabodamia.com) / 141.8.224.169 checking domain: www.wcgconline.net --> seems to be INFECTED: http://keniisha.realdealpsychic.com/__utm.gif --> DNS: keniisha.realdealpsychic.com (keniisha.realdealpsychic.com) / 31.210.96.155 checking domain: www.welte.de --> seems to be INFECTED: http://ikhuichi.ahtcna.com/pview --> DNS: ikhuichi.ahtcna.com (ikhuichi.ahtcna.com) / 31.210.96.158 checking domain: www.wheelsacademy.com --> seems to be INFECTED: http://gadbaw.sunshinerealtyone.com/__utm.gif --> DNS: gadbaw.sunshinerealtyone.com (gadbaw.sunshinerealtyone.com) / failed: Name or service not known. checking domain: www.wmc.kylos.pl --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.wonderwhistle.co.uk --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.73.211.97 checking domain: www.wordgod.com.tw --> seems to be INFECTED: http://sahmari.theafternoonjoker.com/servlet/ajrotator/132868/0/vj --> DNS: sahmari.theafternoonjoker.com (sahmari.theafternoonjoker.com) / 31.210.96.158 checking domain: www.wronashouseofviolins.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 72.52.4.120 checking domain: www.xn--espaodoesporte-jjb.com.br --> seems to be INFECTED: http://underbuild.net/cgi-bin/r.cgi --> DNS: underbuild.net (underbuild.net) / 185.2.66.16 checking domain: www.yoderscountrymarket.com --> seems to be INFECTED: http://vaiduriam.vehicleexchangeprogram.com/url --> DNS: vaiduriam.vehicleexchangeprogram.com (vaiduriam.vehicleexchangeprogram.com) / 31.210.96.157 checking domain: www.zoeblitzer-natursteine.de --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 185.53.178.7 checking domain: zarov.com.br --> seems to be INFECTED: http://upanesh.kemperfitness.com/openx/www/delivery/spc.php --> DNS: upanesh.kemperfitness.com (upanesh.kemperfitness.com) / 81.92.219.60 date finished: Sun Mar 29 12:38:25 PDT 2015