suspect service

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by utente, Aug 23, 2008.

  1. utente

    utente Private E-2

    hi
    someone could help me?

    i ve found a strange error in the system event log
    Event Type: Error
    Event Source: Service Control Manager
    Event Category: None
    Event ID: 7022
    Date: 23/08/2008
    Time: 17.50.47
    User: N/A
    Computer: XXXXXXXXXXXX
    Description:
    The IxiqZBmXFNfTwX service hung on starting.

    so i take a look at the services and i found

    Service Name Authorization
    Display name IxiqZBmXFNfTwX
    Description zOAnZRigObPn
    Pathh to executable C:\WINNT\System32\svchost.exe -k Authorization
    Startup type Automatic
    Service status Starting

    OS is 2K SP4
    CPU is Celeron 1200

    i ve submitted svchost.exe to an on line verification tool and this is the result

    Scan taken on 23 Aug 2008 16:41:00 (GMT)
    A-Squared Found nothing
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    CPsecure Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    F-Secure Anti-Virus Found nothing
    Fortinet Found nothing
    Ikarus Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    Panda Antivirus Found nothing
    Sophos Antivirus Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing


    system has been scanned by Superantispyware, Malwarebytes, SpyBot s&D, Ikarus virus utilities, Kaspersky on line, Panda on line and results free of viruses

    thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    svchost.exe is not the problem. It is a valid Windows system file.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.




    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. utente

    utente Private E-2

    Ty chaslang,

    so i followed yr instructions as u can see some logs attached

    unfortunately:

    1) i didnt run Combofix because i can't find W2K installation CD to install Windows Console Manager and i m afraid of damage this PC running Combofix without installing that

    2) MGTools gave me the 16 bit MS-DOS Subsystem Error:
    c:\WINNT\system32\cmd.exe
    SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers. Virtual Device Driver format in the registr is invalid. Choose 'Close' to terminate the application.

    so i followed the instructions on
    http://support.microsoft.com/default.aspx?scid=KB;EN-US;q254914

    but i discovered with surprise the the key VirtualDeviceDrivers is totally missing! in
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\

    so i pressed 'Ignore' instead of 'Close' to the error window and some result of MGTools are in the attached log

    I also tried to start MGTools in safe mode but i ve found with horror that this computer shows a Blue Screen 07b in safe mode (and also in safe mode with command prompt), just after Mup.sys. Anyway this computer starts well in Normal mode

    3) i attach a Gmer log in the next post

    thank you again

    PS sorry for any bad english cause here is italy
     

    Attached Files:

  4. utente

    utente Private E-2

    this is gmer 1.0.14.14536 log
     

    Attached Files:

  5. utente

    utente Private E-2

    my antivirus Ikarus virus.utilities just now has found (and destoyed?) a virus:

    date/time: 25/08/2008 18.05.39
    filename: run2.vbs
    original path: c:\WINNT\
    filesize: 0.50 KB
    virusname: Trojan.VBS.TQK
    suggestion: saved & deleted
    signatureId: 18085417
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [MS Java virtual machine] javavm.exe
    O4 - HKLM\..\RunServices: [MS Java virtual machine] javavm.exe
    O16 - DPF: {439B6D3C-A359-4D73-8515-2AFE8CF90C08} -
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/11d84a80b82cf8c87105/netzip/RdxIE601_it.cab
    O23 - Service: Windows Genuine Advantage Registration Service (wgareg) - Unknown owner - C:\WINNT\system32\wgareg.exe (file missing)
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. utente

    utente Private E-2

    thanks a lot chaslang
    i hope now i'm malaware clean but unfortunately the strange service is still in the list of the services


    in addition i ve verified user profiles in the system properties windows and the list is very suspect:

    Name Size Type Modified
    Account Unknown 116150 KB Local 26/08/2008
    Account Unknown 3806004 KB Local 26/08/2008
    Account Unknown 3075 KB Local 26/08/2008
    FLI-HOME\Administrator 1880240 KB Local 26/08/2008

    The Computer Management application shows instead only these users

    Administrator
    Guest

    could be the 'account unknown' a login to different domains not avalaible at the moment (legacy LAN)? do that could be the reason why the details are not available at system properties? (as you can see on \Documents and Settings\ are listed various users)
     

    Attached Files:

  8. utente

    utente Private E-2

    I know that bumping the thread will retard the answer but i'm desperate!

    again another new virus found!

    date/time: 26/08/2008 23.10.14
    filename: Logo1_.exe
    original path: c:\WINNT\
    filesize: 88 KB
    virusname: Trojan-Spy.Win32.Delf.PG
    suggestion: Save & Delete
    signatureId: 315550


    help!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should not have posted since this only made it take longer to get an answer as we stated in the sticky thread.

    Your logs are all clean. The items in C:\Documents and Settings that I would question (but they are not malware) are the below two:
    Code:
    "C:\Documents and Settings\"
    00370595      26 Nov 2007              "00370595"
    FLI           22 Mar 2004              "fli"
    The others are normal. The above my be left over from deleted accounts. Either way they are not malware and have been there for quite some time. In fact the FLI one was created when the other normal accounts were created.

    Are you actually having any malware problems?
     
  10. utente

    utente Private E-2

    yes i know sorry

    00370595 and FLI are accounts that I created
    the others (Administrator, All Users, Default User, helpdesk) aren't.
    i suppose the first three are normal, but i don't remember the creation of helpdesk user and i d like to remove but i m not able to
    i often access to a corporate LAN with this computer maybe the company created that account

    yes every day some new virus i m becoming paranoic

    today Ikarus found this

    date/time: 27/08/2008 23.36.02
    filename: FireFoxUpdater.exe
    original path: c:\WINNT\
    filesize: 177.5 KB
    virusname: Trojan.Buzus.iij
    suggestion: Save & Delete
    signatureId: 267935

    and Sophos AV (that i just installed) discovered 8 istances of a virus named Mal/IFrame-F in some files in the cache of internet explorer such adserve.htm, chart.asp, and others

    PS in the while i ve disabled the suspect service
     
    Last edited: Aug 27, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware issue. I suggest that you post about it in the Software Forum.

    Perhaps it is coming in from other computers on your network. Also maybe you just need to get your PCs properly protected. That file was not in the last logs you attached.

    Did you uninstall Ikarus?
     
  12. utente

    utente Private E-2

    No. Do you suggest to unintalling it?
     
  13. utente

    utente Private E-2

    tried to follow your suggestion as in the sticky thread "How to protect yourself from malware!"

    this showed me other problems:

    1) Ikarus detect a virus named Win32.SuspectCrc in the setup of Comodo BOClean Anti-Malware

    date/time: 28/08/2008 17.30.57
    filename: CBO_Setup_4.27.exe
    original path: c:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\W7KVQDMX\
    filesize: 1816.37 KB
    virusname: Win32.SuspectCrc
    suggestion: deleted
    signatureId: 20841621

    2) so i installed Spyware Terminator but it's quite slowing computer performances

    3) i'm not able to do oher downloads even from majorgeeks.com after installing Online Armor Personal Firewall (free edition). maybe could you please suggest me some guidelines to correctly setup it?

    thank you very much
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The very first instructions in the READ & RUN ME stated that you must not have multiple antivirus programs installed so you should not have installed Sophos without having uninstall Ikarus first.

    And if Ikarus is finding malware in Comodo's BO Clean, it is just a false positive. Perhaps this is even more of a reason to uninstall it.

    How much RAM do you have in this PC and what is the processor speed. Online Armor may be too much for this PC to handle. Did you install the Web Security Guard toolbar with Spyware Terminator? You may want to try uninstalling this Crawler Toolbar.
     
  15. utente

    utente Private E-2

    ok i uninstalled it

    PC is Celeron 1200 RAM 376

    do you suggest another firewall?

    thanks for all
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is it? Ikarus? Sophos? Online Armor? Spyware Terminator? WebSecurity Guard?

    Very slow and very little RAM by todays standards. You will have to be careful which applications you use. As some are more resource hungry than others. You will have to do some experimenting to see what works best for your hardware.

    Yes! I would not use Online Armor on this PC.

    I also just noticed another item in your HJT log to fix. I will also give you some optionally items to fix which will free up some resources. You will have to reserach these optional items to see if you need any of them.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    FIX THESE THREE
    O4 - HKUS\.DEFAULT\..\Run: [MS Java virtual machine] javavm.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')

    Optionally fix the below which are really unecessary
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe


    Optionally fix the below after you determine if you use their features.
    O4 - HKLM\..\Run: [projselector] "C:\Program Files\Common Files\Roxio Shared\Project Selector\projselector.exe" -r
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - Global Startup: FotoStation Easy AutoLaunch.lnk = C:\Program Files\FotoStation Easy\FotoStation Easy AutoLaunch.exe


    After clicking Fix, exit HJT.
     
    Last edited: Aug 30, 2008
  17. utente

    utente Private E-2

    first of all thank you very very much for your close attention

    yes this is a sweet old machine but i need to use this for several reasons
    i changed Armor with Jetico that seems to be less resource consuming and it seems to work good even if i dont understand what to answer to the pop up windows concerning datagrams, inbound connections to 445 port and so on (i always allow them)

    i also did:
    1) cleared all the keys you showed me cause are reall unecessary

    O4 - HKUS\.DEFAULT\..\Run: [MS Java virtual machine] javavm.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')


    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe


    O4 - HKLM\..\Run: [projselector] "C:\Program Files\Common Files\Roxio Shared\Project Selector\projselector.exe" -r
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - Global Startup: FotoStation Easy AutoLaunch.lnk = C:\Program Files\FotoStation Easy\FotoStation Easy AutoLaunch.exe


    2) uninstall Sophos AV cause was a trial version near to the end and i stll use Ikarus

    3) unistall Web Security Guard with Crawler Toolbar as you suggested, but i noticed that still remains keys about Webcrawler in the analyze log. so i attach here a new Mgtools.log

    4) noticed the suspect service is still there, the Safe Boot still don't start and that there are a lot of errors in the event log (i only report once the errors - the last istance - but they are recurring very often):

    system log errors:
    4.a) Event Type: Error
    Event Source: Srv
    Event Category: None
    Event ID: 2012
    Date: 31/08/2008
    Time: 0.39.25
    User: N/A
    Computer: FLI-HOME
    Description:
    The server has encountered a network error.
    Data:
    0000: 00 00 04 00 01 00 54 00 ......T.
    0008: 00 00 00 00 dc 07 00 c0 ....Ü..À
    0010: 00 00 00 00 3d 02 00 c0 ....=..À
    0018: 00 00 00 00 00 00 00 00 ........
    0020: 00 00 00 00 00 00 00 00 ........
    0028: 57 09 00 00 W...


    4.b) Event Type: Warning
    Event Source: w32time
    Event Category: None
    Event ID: 54
    Date: 31/08/2008
    Time: 16.51.42
    User: N/A
    Computer: FLI-HOME
    Description:
    The Windows Time Service was not able to find a Domain Controller. A time and date update was not possible.
    Data:
    0000: e5 03 00 00 å...

    4.c)
    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10003
    Date: 31/08/2008
    Time: 17.18.30
    User: N/A
    Computer: FLI-HOME
    Description:
    Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion. The server is:
    {00020906-0000-0000-C000-000000000046}
    The user is Unavailable/Unavailable, SID=Unavailable.

    application log errors:
    4.d)

    Event Type: Error
    Event Source: Userenv
    Event Category: None
    Event ID: 1000
    Date: 31/08/2008
    Time: 1.43.56
    User: NT AUTHORITY\SYSTEM
    Computer: FLI-HOME
    Description:
    Windows cannot unload your registry file. If you have a roaming profile, your settings are not replicated. Contact your administrator.

    DETAIL - Access is denied. , Build number ((2195)).

    4.e)

    Event Type: Error
    Event Source: Perflib
    Event Category: None
    Event ID: 2002
    Date: 31/08/2008
    Time: 16.51.21
    User: N/A
    Computer: FLI-HOME
    Description:
    The open procedure for service "PerfDisk" in DLL "C:\WINNT\SYSTEM32\perfdisk.dll" has taken longer than the established wait time to complete. There may be a problem with this extensible counter or the service it is collecting data from or the system may have been very busy when this call was attempted.

    4.f)

    Event Type: Warning
    Event Source: PerfDisk
    Event Category: None
    Event ID: 2001
    Date: 30/08/2008
    Time: 2.21.55
    User: N/A
    Computer: FLI-HOME
    Description:
    Unable to read the disk performance information from the system. Disk performance counters must be enabled for at least one physical disk or logical volume in order for these counters to appear. Disk performance counters can be enabled by using the Hardware Device Manager property pages. Status code returned is data DWORD 0.
    Data:
    0000: 6f 10 00 00 o...

    security log:
    is totally empty
    (i controlled properties and they are set to log every event and to be stored for 7 days

    5) noticed in the Computer Management/System Tools/Shared Folders/Session two sessions without name or properties so i disconnected them. Concerned of that, I ve also tried - but unsuccesfully - to unshare ADMIN$ C$ and IPC$
     

    Attached Files:

    Last edited: Aug 31, 2008
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may wish to read this: http://www.petri.co.il/what's_port_445_in_w2k_xp_2003.htm

    You can just fix the below lines with analyse.exe:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327

    Try the below fix.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!




    You will have to work these problems in the Software Forum as they are not malware issues.
     
  19. utente

    utente Private E-2

    i ve successfully disabled netbios over tcp but i can t disable 445 port without being cutted off the corporate lan

    done

    done. seems work as usual. i ll verify if pc works on the corporate lan too. if it will not, there is a way to roll back?

    here are the logs and thanks
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger makes backups of what it removes and then there is also System Restore.
     
  21. utente

    utente Private E-2

    i'm very sorry for boring you again but the others AV doesn't show any problem but kaspersky online do

    please note that some week ago both Ikarus and a previous installation of Kaspersky reported that they have been cleaned the pst archive from Email-Worm.Win32.Wallon.a

    do you think it is a dangerous menace?
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to manually cleanup your Outlook folders to remove what Kasperky showed there unless you know what the fliarchive.pst file is and why it was named this way.

    The other detection is not a problem. Kaspersky is detecting your Ikarus quarantine folder which you should just empty.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  23. utente

    utente Private E-2

    ok but how can i do? i need of that Outlook archive and cannot delete it.

    ok thanks

    Not really but i noticed that if i dont block all datagrams and inbound connections a few minutes later i found sessions active and open files like PIPE\BROWSER (i dont know whats that)
    seems like i m heavy scanned from some other internet users and it s very annoying blocking all these connections

    i'll do
    thank you very very much
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then your best bet is to run Outlook and cleanup as much unnecessary mail from it as possible especially things with attachments that could be considered questionable by your virus scanner.

    Normal part of Windows.

    Your firewall is just doing its job of blocking things. You should not need to wrooky about blocking these once they are blocked and you tell it to always block them. Just make sure you are not blocking anything that would interfere with things you need to work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds