malware removal - I don't its name!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mgbinnewhaw, Aug 23, 2007.

  1. mgbinnewhaw

    mgbinnewhaw Private E-2

    Like a good boy I thought I would follow the procedure as spelled out and I looked at Read and Run me before posting details of my problem, but came up against another major obstacle. I don't know what sort of malware is afflicting my PC, never mind its name!!

    Since I believe I have malware of some sort, I should be grateful if someone would tell me whether it is essential to Read and Run me before taking the next step. If yes, how the hell can I find out the name of the malware on my PC?

    mgb
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We don't need to know the name of the malware ...just run the steps in the Read and Run First and then attach the requested logs....it is the only way for us to see what is happening on your computer.:)
     
  3. mgbinnewhaw

    mgbinnewhaw Private E-2

    OK, I followed the procedure specified in GetRunKey and ShowNew and attach the two resulting text files.

    I'm not sure whether it is relevant at this stage, but my problem is a very, very, very, slow responding PC - particularly after a restart and my desktop is displayed. I have to wait at least 10mins. before I can open, for example ZoneAlarm or Opera. Once they are open the response variies from slooow to veeery slooow.:confused

    I might add, I reformatted my HD and re-installed XP Pro 1 week ago because of the same (sort of) problem.

    I really hope someone can help!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the logs from Counterspy, BitDefender (online scan), PandaActiveScan, and HJT.

    Slow performance is not always a result of malware, but often it is programs that may conflict with other programs ...esp in regard to the setting that you may have with ZoneAlarm.
     
    Last edited by a moderator: Aug 25, 2007
  5. mgbinnewhaw

    mgbinnewhaw Private E-2

    Hello TimW,

    Thanks very much for your interest.

    When I try to run BitDefender online scan from Opera, I get a message saying I need to download IE 7 which I already have installed. I then cannot proceed further than the page telling me to download IE 7. When I try to run BiutDefender online scan from IE 7, I see a message that IE internet security may be blocking BitDefender. Since I ran an online BitDef scan before I reformatted my HD and re-installed XP Pro 3 or 4 weeks ago, I gave up and ran an online Panda Totalscan (which incidentally took about 12hrs. to complete instead of the 1hr. indicated on the download page).

    I attach the TotalScan log instead of BitDef and what there is of CounterSpy. In a second post I attach ActiveScan and HJT log files.

    Having noted there looks like no serious malware is present on my PC and noting your observation about program clashes, I now suspect that in fact ZoneAlarm will prove to be the culprit. It appears that I downloaded ZoneAlarm on 8/8/07 and the first thing I noticed after that was some or all BitDef modules were turned off. Also some shield or service in both programs was disabled at one time or another.

    mgb
     
  6. mgbinnewhaw

    mgbinnewhaw Private E-2

    Follow-up to previous post

    As for the HJT file renaming, I am confused about which HJT file I should rename - is it the .exe or the .log? I attach the log file (analysethis.log) created after I renamed the .exe.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did exactly what was directed with renaming HJT.:)

    You may wish to totally uninstall ZoneAlarm and see if you are still having problems.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  8. mgbinnewhaw

    mgbinnewhaw Private E-2

    May I relate, in a couple of paragraphs, the events of the last few hours, in case they are relevant?

    I uninstalled ZoneAlarm anyway because I read in the procedures elsewhere in these forums that the author recommended only the firewall, not the suite that is offered by default on the download site. Actually locating the firewall only required careful looking!

    I also downloaded a-squared Free, as suggeasted in the same forum, and found to my extreme frustration that I had lost the ability to connect to the Internet with Opera or IE7. So I tried to uninstall a-squared Free and the Deleting process froze and nothing short killing the thing freed it. I finally managed to delete ZoneAlarm suite, although the Add or Remove screen is frozen open and showing ZoneAlarm in the list of programs. I presume ZoneAlarm is gone because I saw a pop-up showing Deleting files.

    However, at least I restored my internet connection. I would mention that I have resolved to download nothing that is not a link from a Major Geeks forum or a manufacter's site!

    Now to your last post.

    The obvious reply to your implied question is I am still sinking slowly further into the mire, although your suggestion to eliminate ZoneAlarm was a good one!

    Excuse my ignorance, but what do I do with the following?:
    Also, what do I select? The above quote and then what? - paste it somewhere?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Then check the box next to:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    Then click fix....and exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You did not attach them.

    After doing the above .....
    Attach new logs for:
    ShowNew
    GetRun
    HJT
     
  10. mgbinnewhaw

    mgbinnewhaw Private E-2

    Please ignore the last perfect example of opening mouth before engaging brain (or in this case, opening eyes).:eek:
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL .....happens to the best of us.

    Check CCleaner under tools to see if you can uninstall thru that.
     
  12. mgbinnewhaw

    mgbinnewhaw Private E-2

    I tried CCCleaner to no avail, but you'll never believe that all I had to do was right-click the minimzed file icon in the taskbar - and Add or Remove was gone and so is ZoneAlarm!!:eek:

    I ran HJT, put a tick in the specified box, and HJT froze (not responding) even at the fifth attempt.

    As another indication of the slowness of my PC, I accessed this forum at between 90 B/s and 1.2KB/s!

    Sorry about the ommision of the TotalScan and CounterSpy logs, but in any event TotalScan indicated 3 cookies and CounterSpy "nothing to declare", as you will see this time.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach new logs for:
    ShowNew
    GetRun
    HJT
     
  14. mgbinnewhaw

    mgbinnewhaw Private E-2

    Finally got HJT to behave as it should on scan only, just after I ran it with a report. I really do attach it as a second post. This post has the three logs you requested in your last post.
     

    Attached Files:

  15. mgbinnewhaw

    mgbinnewhaw Private E-2

    I ran HJT scan only - this time I "fixed" the item specified, but when I ran Fixme.reg, the Registry Editor showed an error message saying "the specified file is not a registry script. You can only import binmary registry files".

    On a completely different subject, I seem to be doing or not doing something with regard to attachments. I look at my previous post below and do not see the three attachments I put with it. I saw them in Preview, so I know they were attached when I hit Submit. To attach a file, I click Manage Attachments, then Choose, select the file(s), click Upload, and there the file is below the message text. I may preview my post, and then hit Submit. The message arrives without the attachnent(s)!!!? Any suggestions?
     
  16. mgbinnewhaw

    mgbinnewhaw Private E-2

    Another withdrawal of question. This time about attachments in my last post - I have just seen the answer!!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your first run of HJT was correctly renamed:C:\Program Files\HijackThis\Analyse.exe

    This last run shows it running twice and without being renamed:
    C:\Program Files\HijackThis\HijackThis.exe
    C:\Program Files\HijackThis\HijackThis.exe

    This is not fixed:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    This is still running as a service:
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe

    C:\Program Files\a-squared Free\a2service.exe
    Didn't you attempt to uninstall this?

    Now download the attached chodefix.zip file (see the bottom of this message) to your Desktop or someplace else you will be able to find it. The extract the two files from it. Then double click on the chodefix.bat file. This will try to fix some of the damage caused by the Chode infection that you have. You should see a message like the below when it finishes (in about 3 seconds).
    Press any key to continue . . .
    Tell me if you see this message or not or if you get an error message instead. No matter what happens just continue on to the next steps.
    Attached Files http://forums.majorgeeks.com/images/attach/zip.gif chodefix.zip (131.3 KB, 42 views)

    After running ..please do the steps in the previous post ...both the HJT fix and the registry patch.

    Attach new logs for:
    ShowNew
    GetRun
    HJT ---again, renamed.
     
    Last edited by a moderator: Aug 29, 2007
  18. mgbinnewhaw

    mgbinnewhaw Private E-2

    I'm afraid I'm :confused by this - how can two files of the same details reside in the same directory? I attach two screen shots which are the basis of my understanding of the state of HJT and the (name) change you requested. Doesn't the attached screen shot confirm that?

    Yes I did, but when the deletion hung-up, I desisted and some time later I over-wrote it with a fresh download after it was clear that a-squared Free was not concerned in my problem.

    I am about to do the chodefix.
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Look at your last HJT log attachment .....

    Let me know how the system is running and what problems you are still having.
     
  20. mgbinnewhaw

    mgbinnewhaw Private E-2

    I ran HJT but R0 was already set to ......Start Page = http://www.ask.com without my ticking anything (see my previous post for HJT listing).

    When I ran fixme.reg I saw the same error message as before i.e. ...not a binary file (see attached file).
     

    Attached Files:

  21. mgbinnewhaw

    mgbinnewhaw Private E-2

    Sorry about the apparent confusion of my last post - crossed posts, I think.

    There is evidently something fundemental about log files that I do not understand.:) - but I'll forget about that for now.

    My PC is definitively running faster than a week ago, but things are still not normal, for example:
    1. a STOPzilla Alert pop-up, entitled Spyware Alert, cannot be removed/deleted. The message says STOPzilla has deleted and blocked the infection named System Policies.DisableRegistryTools. I am offered the choice of scan and remove now Yes/No, but the pop-up is frozen. It disappears immediately I try to take a screen shot of it, but returns immediately I close the PrintScreen utility. I'll try a reboot when I close this browser.
    2. opening a file from a desktop icon takes a minimum of 15 seconds, which is ridiculously slow for a 2,8GHz PC with 1G of RAM which was about 10 times faster (very subjectively) a few weeks ago.
    3. BitDefender is being disabled by something or other (no other firewall is installed/enabled except Windows Defender which is enabled only when BitDef is disabled).
     
  22. mgbinnewhaw

    mgbinnewhaw Private E-2

    Just an addendum to the present state of my PC.

    An hour after my last post and after a reboot I saw another STOPzilla pop-up (see attached screen shot). I deleted all and the pop-up went away. However, when I tried to logon to e-mail I could not. However, I was still able to access this forum thanks to Opera's tabs (I just love this browser) and from here I checked and find I can now connect to my on-line mailbox.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now let me get this straight.....You are running BitDefender, StopZilla and a-Squared? As well as Spybot, Trojan Hunter, Ad-Aware, Ad-watch, and
    C:\Program Files\SpywareDetector
    You did not tell me the results of running the Chode Fix....although I am beginning to think that most of your problems are coming from
    A) Having more than one anti-virus program running
    B) Running dubious software.

    Download and Install RogueRemover Free

    Run RogueRemover and select Scan and the program will walk you through the remaining steps.

    You should work thru the below link:
    * How to Protect yourself from malware!.

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    IMPORTANT: Do NOT run any other options until you are asked to do so!
    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.
    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT

    How are things working now?
     
  24. mgbinnewhaw

    mgbinnewhaw Private E-2

    First of all may I say that I really, really appreciate the time and effort you are putting into solving my problem:clap:clap:clap:clap - I couldn't be more satisfied if I were paying $300/hr. yet you do this for me and others free!!!
    I feel sure I thus express the sentiment of all the strangers you have helped over the years. As we say in French "Chapeau".

    Back to business:)
    When I ran chodefix I saw exactly as you described (as an aside, I was asked to hit the F5 key.....etc./.. to see the effect with the last line of hit any key to continue which is bloody silly because hitting anything causes the DOS window to disappear without showing anything!!) Incidentally, it took a lot longer than 3 secs. to start and run - about 15-20 is my guess.

    I ran HJT renamed to analyse.exe and saved the log file hijackthis30_08_07 which I attach. The fixme.reg file gave the same result as before (not a binary file).

    I attachFetNew to a second post hereafter.
     

    Attached Files:

  25. mgbinnewhaw

    mgbinnewhaw Private E-2

    I attach the file shownew.txt.

    .

    I trust my last post answers the point about Chode Fix.
    As for my installed programs, you are quite correct in your implied supposition that I was "suckered" into scanning and downloading Spyware Detector but when I was presented with approx. 350 threats by Spyware Detector, I realized it was a "con" because I had just run STOPzilla, and Trojan Hunter, in addition to having BitDef Intertnet Security suite running, all of which showed no threats. I have now deleted it.

    On the question of resident anti-malware programs am I not correct in thinking that they are non-operational until I run them? Just like Notepad, for example?

    The programs I consider as being my major protection are indeed:
    1. BitDef as my firewall, with anti-virus and anti-spyware modules active,
    2. STOPzilla as anti-spyware,
    3. asquaredfree as a supplement to BitDef or STOPzilla, (not yet quite clear about what this does):)
    4. TrojanHunter as my anti-trojan protection.

    Any other anti-malware programs are:
    ....either part of my attempt to decide "what does this do? will it protect me? and from what?"
    ....or part of my increasing toolbox of diagnostic tools (which I will put in a sandbox if their presence in a Windows directory ....causes problems).

    I will follow the How to Protect yourself from malware! link tomorrow.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The F5 key was supposed to be hit within Windows Explorer not the command prompt window.


    You did not attach it.
     
  27. mgbinnewhaw

    mgbinnewhaw Private E-2

    Where does it say that? Am I supposed to guess?

    The file is now attached.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The message that you get from ChodeFix.bat includes the below text.

    It is referring to two things related to Windows Explorer. You can either click the F5 key to do a refresh which is standard in almost all programs written for Windows or you can just select refresh in Windows Explorer.
     
  29. mgbinnewhaw

    mgbinnewhaw Private E-2

    Dear, oh dear, oh dear. Is this going to develop into a pi**ing contest? I really don't give a s**t about F5 and seeing the effect. But the fact remains that in addition to

    You forgot to mention that "the message that you get from ChodeFix.bat" also includes

    and the natural reaction is to hit F5. Just as one's finger is descending the eye sees the last line, but too late and the screen is gone! Which is no more than mildly irritating (since I don't give a sh*t about seeing the effect, as I said above) and gave rise to my observation that it is a bloody silly way to run the country. I still think so, but would not hold it against the programmer. As my penultimate post shows I have the greatest respect and admiration for the experts who run this forum, but they are liable to minor cockups like the rest of us.
     
  30. abri

    abri MajorGeek

    Hi Mgbinnewhaw,
    I'm convinced after many years on the internet, that no set of instructions yet written will ever be understood by all of the people all of the time. Too many variables involved. :)
    abri
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anything that is malware related at this time.

    However, I would like you to :
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Then post back (after removing one of your anti-virus programs) and tell me how things are running ...:)
     
  32. mgbinnewhaw

    mgbinnewhaw Private E-2

    Hello abri,

    As a user-document technical author of many years standing I have to disagree with you about all the people all the time, but when the text is written by a programmer I would agree with you wholeheartedly.:D

    Please do not take this as a provocation - I repeat what I said before about my respect for you experts (in computing but not necessarily in authoring):)
     
  33. mgbinnewhaw

    mgbinnewhaw Private E-2

    I cannot find this program - I can find many programs to uninstall SmitfraudFix but not one to install it!! The name S!Ri is rejected by Opera as having invalid characters in it.

    Can you provide more details?
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  35. mgbinnewhaw

    mgbinnewhaw Private E-2

    I ran AtfCleaner and timed the opening of 3 or 4 programs. Each one took at least 1min 45secs to open - Opera took at least 3mins. to open 7 or 8 tabs. So the answer to how how things are running is - sloooooow.

    Unfortunately, you didn't reply to my question:
    so I don't know exactly what to keep and what to delete.
     
  36. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As long as you only have one "active" anti-virus running you are good. Sorry if I confused you (sometimes its my normal state of mind :)) .....One other thing to try is to disconnect from the internet and totally disable all protection ( the entire BitDefender Suite) and see how things run ....time wise.
     
  37. mgbinnewhaw

    mgbinnewhaw Private E-2

    Tried it, but no difference in opening time of the same 4 applications as previously timed and mentioned.

    I attach the log file.

    Done part 1 and attach the log file. I'll do part 2 tomorrow (it's now 01:45 and I'm almost too tired to type correctly).:)
     

    Attached Files:

  38. mgbinnewhaw

    mgbinnewhaw Private E-2

    The bloody attachment thing foiled me again! Here is the missing log file.
     

    Attached Files:

  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rogue remover should have helped .....the smitfraud log (2nd part) I would like to see ...did you try uninstalling/disabling BitDefender Suite and seeing how fast/slow things opened?
     
  40. mgbinnewhaw

    mgbinnewhaw Private E-2

    Sorry about the break in service - family affairs occupied my time.
    I could not get the bloody thing to boot into safe mode, despite rebooting 7 or 8 times and hitting F8 until I nearly broke my finger in frustration. I cannot understand this because I rebooted in Safe Mode a month ago when I reformatted and re-installed XP. So I ran SmitfraudFix in normal mode - I hope this doesn't invalidate the run.

    I attach the three log files.
     

    Attached Files:

  41. mgbinnewhaw

    mgbinnewhaw Private E-2

    I forgot to mention that opening any application or Windows file takes about 2mins. minimum. So this PC is now slower than my first Commodore!!
     
  42. mgbinnewhaw

    mgbinnewhaw Private E-2

    Do you mean smitfraud run in Safe Mode?

    By the way, I am using a Logitech keyboard which defaults on start-up to media mode for the F1 through F12 keys (as I discovered after my great frustration trying to accept Windows EULA). Can you say whether there is any other (than this crap default) reason for F8 not performing its function?:(
    Yes, I disabled BitDef and came off-line and it made no difference at all.
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    NOTE: Running this utility will reset your HOSTS file to it's original state!

    Please download HOSTER and then follow the below steps.
    • Unzip HOSTER to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program.
    Starting in Safe Mode

    See if the above will get you into safe mode.
     
  44. mgbinnewhaw

    mgbinnewhaw Private E-2

    Did that and got this:
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Find this file: (XP systems)
    C:\Windows\system32\Drivers\ETC\HOSTS file

    To open and view the HOSTS file to doublecheck for bad entries, left button double click on the HOSTS file. A message will appear saying Windows can't open the file. Check the circle at the bottom entitled:

    Select the program from a list.

    Now click OK. In the next window....Scroll down in programs until you see Notepad and select it and click OK.

    If you see this line below the header info:

    127.0.0.1 localhost ---> tell me what is there.

    If it is still full of sites:
    Rename the file HOSTS to HOSTS.OLD. (a fresh new HOSTS file will be created when you restart Windows). Later you can delete the HOSTS.OLD file when things are back to normal.

    Where you able to get into safe mode with the link I posted?
     
  46. mgbinnewhaw

    mgbinnewhaw Private E-2

    It is full of host names - I'l rename it after I send this message.

    Two things happened after Hoster couldn't open the host file:

    1.When I rebooted I still couldn't get into Safe Mode, but I saw an error message from I think CounterSpy saying it had blocked an attempt to open the Host file.

    2.I rebooted this morning and, lo and behold, I got into Safe Mode!! However when I tried to run Smitfraudfix, it kept telling me to unzip all the files when they were already unzipped!! So I haven't yet managed to run Smitfraudfix in Safe Mode.
     
  47. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use add/remove programs to uninstall Counterspy.

    After resetting the host files....

    Let me know what happens.
     
  48. mgbinnewhaw

    mgbinnewhaw Private E-2

    I couldn't rename the Hosts file because "it is being used by another file or person". Does that mean I have to stop all the processes with host in their title? Or could I simply move the file to another HD?
    Is this in Safe Mode?
     
  49. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Close your browser ...all of the fixes should be done with administrative rights. Make sure all anti-virus and anti-spyware is not running.

    If you still cant do it....remove it with Avenger.

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt



    Yes ...that was for safe mode.
     
  50. mgbinnewhaw

    mgbinnewhaw Private E-2

    Sorry, am I being obtuse, but if I still can't do what?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds