PC infected ...HELP...HJT log here

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alternate, May 6, 2011.

  1. alternate

    alternate Private E-2

    Can somebody help me...Got infected after watching some porn I believe:cry
    HJT log:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 4:10:54 PM, on 5/6/2011
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.17055)
    Boot mode: Normal


    [EDIT] By chaslang: Inline HJT log removed. Required cleaning process not followed. [/EDIT]
     
    Last edited by a moderator: May 6, 2011
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.


    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. alternate

    alternate Private E-2

    I'm trying to do the steps of the guide ...but it is a difficult task...I was able to run the Superantispyware free edition...After it was finished I tried to reboot the machine but it hangs in there and I have to manually press the power button until it shuts off..after the harmful items were quarantined and removed I'm now unable to open any file .EXE so I can't do much...I'm typing this from my laptop..any ideas on how to repair this problem?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe boot mode and see if you can run MGtools. Even if it does not seem to run, after running it try the below.

    1. Bring up Task Manager by pressing CTRL-ALT-DEL. Then click File, New Task (Run...) and enter the below into the box and click OK. Note this assumes that your boot drive is drive C. If it is not drive C, change the letter accordingly.
      • C:\MGtools\fixfa.bat
      • Then see if you can run EXE files.
    2. If the above does not help, go to the below website:
    3. If the above still did not help, try this.
      • Download the below fEXEfix file to your Desktop. Once saved on your Desktop, Right click on it and select Install
      • Then see if you can run EXE files.
    Let me know which one of the above work for you ( that is if you were able to get any of them to work ).
     
  5. alternate

    alternate Private E-2

    Disregard my last post...After hours and hours of work I've managed to complete all the steps of the read and run me first.
    Looks like I'm still infected the same way ,,,it looked fine right after the steps but slowly my computer got redirects, hangs and other annoying stuff..MGtools gave me 15logs..I cant attach all of them in 1 post...here's first part of the logs
     

    Attached Files:

  6. alternate

    alternate Private E-2

    I can't copy and paste all the logs...the connection resets here, tell me which ones you need to see...I have ran scans on my other guest user account and no malaware was detected.
    here's more logs attached
     

    Attached Files:

  7. alternate

    alternate Private E-2

    part 3:
     

    Attached Files:

  8. alternate

    alternate Private E-2

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6518

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 7.0.5730.13

    5/7/2011 12:05:58 AM
    mbam-log-2011-05-07 (00-05-58).txt

    Scan type: Quick scan
    Objects scanned: 188664
    Time elapsed: 15 minute(s), 44 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 4
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\snk.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\snk.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\snk.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\exefile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("C:\Documents and Settings\Administrator\Local Settings\Application Data\snk.exe" -a "%1" %*) Good: ("%1" %*) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not supposed to copy and paste. You are supposed to attach them like this. The MBAM log was incorrectly posted inline.

    You need to attach the proper log from MGtools. The only file we asked you to attach from it is the C:\MGlogs.zip file. You should not be posting anything from inside the MGtools folder unless we ask you to do so.
     
  10. alternate

    alternate Private E-2

    sorry...here we go again...The computer is in much better shape but it still redirects webpages and seem to crash occasionally or just hangs in there for a long time..sometimes is difficult to change account users (it freezes) and yesterday I had to shut down using the power button cos it froze on me when try to just shut off via windows
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run TDSSKiller per the below instructions and attach the log afterwards.

    TDSSkiller - How to run


    Also tell me how things are working after a reboot.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After attaching the log from TDSSkiller, continue on with the below.

    Uninstall the below software:
    Conduit Engine

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. alternate

    alternate Private E-2

    During combo fix a message showed about my master boot sector being infected..when i rebooted the machine now I cannot get to windows splash screen anymore...Just a prompt line flashing on a black screen!!
     
  14. alternate

    alternate Private E-2

    During combo fix a message showed about my master boot sector being infected..when i rebooted the machine now I cannot get to windows splash screen anymore...Just a prompt line flashing on a black screen!! I had problems in the past with the mup.sys file...and had to use a hiren cd to fix these problems...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked you to attach the log from TDSSKiller first and then continue.
    • Did you run TDSSKiller? If so, what did it find and did you reboot after running it?
    • Can you boot in safe mode?
    • Do you have your Window Boot CD? If not, what version of Hiren's CD do you have?
     
  16. alternate

    alternate Private E-2

    If I can recall correctly TDSKiller detected some malware and rebooted leaving a log...after that I ran combofix with that script and then the message about the master boot sector being infected and just pass the motherboard logo and then get stuck...can't access safe mode..only F2 (setup) or F12 (boot menu). Don't have Windows boot disk and my Hirens cd is version 11.1 but it doesnt look like is being accessed when loaded on my cd-rom drive even with the proper configurations in BIOS...just to let you know I have spare PCs available if we need to slave the problematic HD( i just dont know how to slave it)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But why didn't you attach it as requetsed.


    Are you sure that it is a bootable CD? try it on another PC and see if it can be booted? If you cannot boot this CD in your PC and it is a bootable CD then it would seem you either have hardware issues with your DVD/CD player or your BIOS settings may not be what you think.

    You would have to get instructions in the Hardware Forum for this and it you would have to state what kind of drives in both PCs ( SATA or IDE ). Also you may not need to slave it, you may be able to just put it in as a secondary drive on a secondary interface. The problem is that I'm not sure what to do with it. It may be that you will just want to try to use Hiren's to fix the MBR but make sure to fix the problem drive and not the drive from the good PC.


    One thing that would also be interesting to check for on the problem drive is to see if the C:\Windows\system32\drivers\atapi.sys file exists or not.
     
  18. alternate

    alternate Private E-2

    I dont know if it would matter much if we had posted the TDS killer log because I would go ahead with it after the post and it would screw me the same way....
    I believe the whole problem was the infection message on my MBR by combofix.
    My hirens cd boots from other machines...my BIOS looks like correct. Right now it is as follows:
    DeLL dimension 3000 series
    DRIVE CONFIG:
    drive diskette-not installed
    primary master drive:Hard drive
    primary slave drive:OFF
    second master drive:cd-rom device
    second slave drive: cd-rom device
    IDE drive UDMA:eek:n

    HARD DISK SEQUENCE:
    1.System BIOS boot devices
    2. USB device

    BOOT SEQUENCE:1.IDE cd-rom device (checked)
    2.HArd disk drive c: (checked)

    I tried to copy the contents of the hirens cd to a USB sd card and changed BIOS to boot from USB device first but it didnt work either.

    I'm not sure which F12 boot menu to choose:
    1.normal.
    2 primary master drive
    3.hard disk drive C:
    4.IDE cd rom device
    5.USB flash device
    6.system set up
    7.IDE drive diagnostics
    8.boot to utility partition

    I suggested attaching my HD in other machine to maybe copy a healthy MBR (or any missing files)from another machine to my problematic one...is that possible?

    ARE those MBR problems due to disabling disk emulators with defogger? or setting MSconfig to normal start up? (it was selective start up before)

    Can you check if there are any step by step instructions on HARDWARE forum on how to attached my HD as a secondary drive? ...I'm just afraid to boot the hirens cd to my healthy computer instead of the problematic.
    And on the hirens cd 11.1 which tool do I use to fix MBR?

    Thanks
     
  19. alternate

    alternate Private E-2

    UPDATE: after some research I've managed to boot the Hirens cd on my problematic PC...(it was turning off the legacy device support on BIOS)...
    Now which tool do I use to repair MBR?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!


    This is for an older version of Hiren's CD but I would think the menus are still the same. Hopefully the problem is really with your MBR and this fixes it.
     
  21. alternate

    alternate Private E-2

    IT FIXED IT FIXED IT FIXED!!!!
    now do you want to post any logs from my sickened PC?
     
  22. alternate

    alternate Private E-2

    OMG...Combofix is preparing to run again when windows was loaded...I dont like that at all!! what do i do?
     
  23. alternate

    alternate Private E-2

    Coudn't stop combofix...it rebooted ok ...log created but I can't post it...No internet connection now...Tried to repair the connection manually but no luck...
     
  24. alternate

    alternate Private E-2

    Internet back in shape...I used winsockxpfix. I believe we need to clean up now all those tools that we've downloaded right...but before lemme attach some logs.
    Note TDSkiller was logged before the MBR problem , the combofix log was just now after everything was back to normal
     
  25. alternate

    alternate Private E-2

    here's the logs
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the followup MGlogs.zip file that I requested in my last fix, but let's do another fix first and this time remember to attach all the logs I ask for. ;)


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it:
    Code:
    KILLALL::
    
    RenV::
    c:\program files\Adobe\Reader 10.0\Reader\Reader_sl .exe
    c:\program files\Analog Devices\Core\smax4pnp .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager .exe
    c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility .exe
    c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard .exe
    c:\program files\Common Files\Ahead\Lib\NeroCheck .exe
    c:\program files\Common Files\Ahead\Lib\NMBgMonitor .exe
    c:\program files\Common Files\Java\Java Update\jusched .exe
    c:\program files\CyberLink\PowerDVD9\PDVD9Serv .exe
    c:\program files\CyberLink\PowerDVD9\Language\Language .exe
    c:\program files\DivX\DivX Plus Web Player\DDmService .exe
    c:\program files\DivX\DivX Update\DivXUpdate .exe
    c:\program files\iTunes\iTunesHelper .exe
     
    FileLook::
    c:\windows\system32\alleg42.dll
    c:\windows\system32\itlpfw32.dll
    C:\Qoobox\Quarantine\C\WINDOWS\system32\alleg42.dll.vir
    C:\Qoobox\Quarantine\C\WINDOWS\system32\itlpfw32.dll.vir
    
    File::
    c:\docume~1\NETWOR~1\LOCALS~1\APPLIC~1\trxaqyjiq.exe
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "trxaqyjiq"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  27. alternate

    alternate Private E-2

    Just to let you know I have a logmein account...just do not think the remote access is virus-related,:)
    Logs attached below.Thanks
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better. We just need to restore one file that was mistakenly removed by ComboFix.



    Now we need to use ComboFix to DeQuarantine some files that it should not have removed.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named C:\DeQuarantine_log.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\DeQuarantine_log.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  29. alternate

    alternate Private E-2

    Done....I have some suspicious that my computer had a shorter start up time right after fixing the MBR and right before the combofix suggested yesterday
    This one here:
    KILLALL::

    RenV::
    c:\program files\Adobe\Reader 10.0\Reader\Reader_sl .exe
    c:\program files\Analog Devices\Core\smax4pnp .exe
    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
    c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager .exe
    c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility .exe
    c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard .exe
    c:\program files\Common Files\Ahead\Lib\NeroCheck .exe
    c:\program files\Common Files\Ahead\Lib\NMBgMonitor .exe
    c:\program files\Common Files\Java\Java Update\jusched .exe
    c:\program files\CyberLink\PowerDVD9\PDVD9Serv .exe
    c:\program files\CyberLink\PowerDVD9\Language\Language .exe
    c:\program files\DivX\DivX Plus Web Player\DDmService .exe
    c:\program files\DivX\DivX Update\DivXUpdate .exe
    c:\program files\iTunes\iTunesHelper .exe

    FileLook::
    c:\windows\system32\alleg42.dll
    c:\windows\system32\itlpfw32.dll
    C:\Qoobox\Quarantine\C\WINDOWS\system32\alleg42.dll.vir
    C:\Qoobox\Quarantine\C\WINDOWS\system32\itlpfw32.dll.vir

    File::
    c:\docume~1\NETWOR~1\LOCALS~1\APPLIC~1\trxaqyjiq.exe

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "trxaqyjiq"=-

    The boot up time is perfect but the computer somehow lags too long before I can open up Firefox and lags again when loading my default home page...Maybe thats because of the Antivir antivirus???
    After those lags it goes pretty smoothly and quickly when using the internet or other programs...Maybe its just an impression...but yesterday was quicker.
    thanks for all your help
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't have an explanation for that because this fix would not have increased startup time. If anything, it could have improved it since you had infected startup entries that were removed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  31. alternate

    alternate Private E-2

    Everything is back to normal..I thank you and really appreciated all your help!!!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds