Firewall will not work

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tazman282, Feb 3, 2012.

  1. Tazman282

    Tazman282 Private E-2

    I had a virus/malware about three months ago, I thought I got rid of it but there are still some sort of files left. I have tried most everything to remove them and enable my firewall but nothing seems to work. Here are the logs of what I could perform tonight. I was unable to get the mgtools zip but it said that is performed everything but I can't find it. I also was unable to run combofix. I have done a full scan or malwarebytes and it finds nothing but when I do a security essentials scan it finds a file and then after quaranteen and reboot it is unable to start windows and has to use a restore point. When trying to start firewall here are the codes I get and the trojan SE finds.

    0x8007042c

    error 1068

    trojan:win64/sirefef.b
     

    Attached Files:

  2. Tazman282

    Tazman282 Private E-2

    Not sure how to get mgtools but here is the hijackthis from within that log, no zip file though.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    The log from MGtools is not in the MGtools folder. It is located at C:\MGlogs.zip and this is the file we need in order to help you.

    Also where are the logs from SUPERAntiSpyware and Malwarebytes?

    What exactly happened when you tried to run ComboFix?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also note your mentioned using Microsoft Security Essentials. You should not even have this installed as you already have Authentium AntiVirus5 installed. You need to uninstall one of these immediately
     
  5. Tazman282

    Tazman282 Private E-2

    Combofix says "System Shield" is running and I have no idea what that even is, everything is deactivated. Here are the other logs.

    I downloaded security essentials before and ran it in which it found something and Quarantined it but after reboot, windows wouldn't start and had to recover. I am not sure what Authentium AntiVirus5 is unless that is the instructed SuperAntispyware that was installed in the malware removal forum. Hope this is everything.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Tell it to run anyway. This is likely just a left over entry in windows security center that needs to be removed from your security programs that have been uninstalled.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on the C:\MGtools\FixWFW.bat file and select Run As Administrator. This will run very fast. Did it run okay or did you get any error messages?
     
  8. Tazman282

    Tazman282 Private E-2

    The .bat file ran quickly with no errors and the combofix says that it will run anyway with the system shield but then it doesn't do anything at all.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let't try a different method to get started without ComboFix.

    Now download The Avenger by Swandog46, and save it to your Desktop.



    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Feb 4, 2012
  10. Tazman282

    Tazman282 Private E-2

    The system has been running good overall, I did have to manually delete most of those files below 80% and the last one was in there but without the "pending" name in front so I left it. I will let you know that Iolo is the paid version of System Mechanic but I uninstalled it as instructed.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger did not run properly. Try all the instructions again, but this time use safe boot mode.

    Note that things under Registry values to delete: are not files!!!!! They are registry keys. Thus you should not be trying to manually removed them.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot.... one more thing I need you to do to fix another part of the Zero Access infection you have.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  13. Tazman282

    Tazman282 Private E-2

    Well I was trying to delete the registy with regedit, hope I didn't make things worse. In safemode it isn't running right either.

    Error: Could not open RunOnce key to register cleanup.
    Aborting execution! (error0: the operation completeed successfully)
     
  14. Tazman282

    Tazman282 Private E-2

    Successfully been added to registry.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then since some items have already been fixed, let's try the below fix instead.


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Users\David Dohring\AppData\Local\Temp

    Now empty your Recycle Bin!

    Now no matter what happens with all of the above, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. Tazman282

    Tazman282 Private E-2

    I am getting the same error and it is not offering a new text document or the reboot option, it states that there is nothing in que for reboot.

    All of a sudden my mouse is all over the place and highlighting and moving boxes on me. Not sure why, just letting you know.

    Also with Mgtools, this is the second time I have seen it but

    nslookup.exe - ordinal not found this ordinal 1108 could not be located in the dynamic link library WSOCK32.dll
     

    Attached Files:

  17. Tazman282

    Tazman282 Private E-2

    I wrote you back and it said something about moderator approval.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like the Zero Access infection as change some of your file and registry permissions. We need to eventually be able to use Avenger and or ComboFix to fully fix this. But for now, let's attempt to fix some permissions isses first.


    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.
    • Now after the reboot, please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor click File, Import.
      • Navigate your way to the C:\MGtools folder and locate the fixW7BFE.reg key and select it.
      • Then click the Open button and allow this to be added into your registry
    • Tell me what happend exactly. Like do you get any error messages or do you get a success message?
    • Do the same as above to import the below registry patches:
      • FixW7FW.reg
      • FixW7FWdrv.reg
    • Again tell me what happens.

    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    The above will not fix all of the problems. We still need to remove some malware files and registry entries, but we need to be able to get some of the tools to run inorder to do this.
     
  19. Tazman282

    Tazman282 Private E-2

    Cannot import “file” Error accessing the registry
    Cannot import “file” Error accessing the registry
    Cannot import “file” Not all data was successfully written to the registry. Some keys are open by the system or other processes.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay some of the fixes actually applied and some did not. Let's continue.

    Download OTL by Old Timer and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif

    Now shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.

    Code:
    :Files
    C:\ProgramData\0p04pj5k68p403
    C:\Windows\assembly\GAC_32\Desktop.ini
    C:\Windows\assembly\GAC_64\Desktop.ini
    C:\Windows\SysWOW64\vL4GicO.com.b
    C:\Users\David Dohring\AppData\Local\Temp\pgldauog.sys
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSSVC]
    "NextInstance"=dword:00000001
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSSVC\0000]
    "Service"="MpsSvc"
    "Legacy"=dword:00000001
    "ConfigFlags"=dword:00000000
    "Class"="LegacyDriver"
    "ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
    "DeviceDesc"="@%SystemRoot%\\system32\\FirewallAPI.dll,-23090"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV\0000]
    "ConfigFlags"=dword:00000020
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV\0000\Control]
    "ActiveService"="mpsdrv" 
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\subsystems]
    "Windows"=hex(2):25,53,79,73,74,65,6D,52,6F,6F,74,25,5C,73,\
    79,73,74,65,6D,33,32,5C,63,73,72,73,73,2E,65,78,65,20,4F,62,6A,65,63,\
    74,44,69,72,65,63,74,6F,72,79,3D,5C,57,69,6E,64,6F,77,73,20,53,68,61,\
    72,65,64,53,65,63,74,69,6F,6E,3D,31,30,32,34,2C,32,30,34,38,30,2C,37,\
    36,38,20,57,69,6E,64,6F,77,73,3D,4F,6E,20,53,75,62,53,79,73,74,65,6D,\
    54,79,70,65,3D,57,69,6E,64,6F,77,73,20,53,65,72,76,65,72,44,6C,6C,3D,\
    62,61,73,65,73,72,76,2C,31,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,6E,\
    73,72,76,3A,55,73,65,72,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,33,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,\
    6E,73,72,76,3A,43,6F,6E,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,32,20,53,65,72,76,65,72,44,6C,6C,3D,73,78,\
    73,73,72,76,2C,34,20,50,72,6F,66,69,6C,65,43,6F,6E,74,72,6F,6C,3D,4F,\
    66,66,20,4D,61,78,52,65,71,75,65,73,74,54,68,72,65,61,64,73,3D,31,36,\
    00
    [HKEY_LOCAL_MACHINE\system\controlset001\control\session manager\subsystems]
    "Windows"=hex(2):25,53,79,73,74,65,6D,52,6F,6F,74,25,5C,73,\
    79,73,74,65,6D,33,32,5C,63,73,72,73,73,2E,65,78,65,20,4F,62,6A,65,63,\
    74,44,69,72,65,63,74,6F,72,79,3D,5C,57,69,6E,64,6F,77,73,20,53,68,61,\
    72,65,64,53,65,63,74,69,6F,6E,3D,31,30,32,34,2C,32,30,34,38,30,2C,37,\
    36,38,20,57,69,6E,64,6F,77,73,3D,4F,6E,20,53,75,62,53,79,73,74,65,6D,\
    54,79,70,65,3D,57,69,6E,64,6F,77,73,20,53,65,72,76,65,72,44,6C,6C,3D,\
    62,61,73,65,73,72,76,2C,31,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,6E,\
    73,72,76,3A,55,73,65,72,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,33,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,\
    6E,73,72,76,3A,43,6F,6E,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,32,20,53,65,72,76,65,72,44,6C,6C,3D,73,78,\
    73,73,72,76,2C,34,20,50,72,6F,66,69,6C,65,43,6F,6E,74,72,6F,6C,3D,4F,\
    66,66,20,4D,61,78,52,65,71,75,65,73,74,54,68,72,65,61,64,73,3D,31,36,\
    00
    [HKEY_LOCAL_MACHINE\system\controlset002\control\session manager\subsystems]
    "Windows"=hex(2):25,53,79,73,74,65,6D,52,6F,6F,74,25,5C,73,\
    79,73,74,65,6D,33,32,5C,63,73,72,73,73,2E,65,78,65,20,4F,62,6A,65,63,\
    74,44,69,72,65,63,74,6F,72,79,3D,5C,57,69,6E,64,6F,77,73,20,53,68,61,\
    72,65,64,53,65,63,74,69,6F,6E,3D,31,30,32,34,2C,32,30,34,38,30,2C,37,\
    36,38,20,57,69,6E,64,6F,77,73,3D,4F,6E,20,53,75,62,53,79,73,74,65,6D,\
    54,79,70,65,3D,57,69,6E,64,6F,77,73,20,53,65,72,76,65,72,44,6C,6C,3D,\
    62,61,73,65,73,72,76,2C,31,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,6E,\
    73,72,76,3A,55,73,65,72,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,33,20,53,65,72,76,65,72,44,6C,6C,3D,77,69,\
    6E,73,72,76,3A,43,6F,6E,53,65,72,76,65,72,44,6C,6C,49,6E,69,74,69,61,\
    6C,69,7A,61,74,69,6F,6E,2C,32,20,53,65,72,76,65,72,44,6C,6C,3D,73,78,\
    73,73,72,76,2C,34,20,50,72,6F,66,69,6C,65,43,6F,6E,74,72,6F,6C,3D,4F,\
    66,66,20,4D,61,78,52,65,71,75,65,73,74,54,68,72,65,61,64,73,3D,31,36,\
    00 
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. Tazman282

    Tazman282 Private E-2

    seems good
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope! It may have only seemed that way. OTL did not fix most of what it said it fixed or they all came back plus some more. Also the Windows Firewall is still not working because the registry keys are still locked.

    Let's continue with the fixes. I want to try using in the below. If you cannot get ComboFix to run properly while in normal boot mode, please try booting into safe boot mode to repeat the fix.

    First we will manually change some registry key permissions.

    • Please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    Now follow the below instructions for changing permissions for various registry keys using Regedit.
    • First navigate to the below registry key and have it selected
      • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MpsSvc
    • Then right click on this key and select Permissions
    • Then on the Permissions for MpsSvc for click the Add button
    • In the Enter the object names to select box type Everyone and click the Check Names button which should cause the Everyone text to be approved and underlined
    • Then click the OK button which returns you to the Permissions for MpsSvc form
    • Make sure you select Everyone from the upper list, and then in the Permissions form Everyone box, select Full Control and see if it allows you to click the Apply button.
      • If you could Apply this then repeat the above for the below registry keys
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSSVC\0000
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV\0000
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSDRV\0000\Control
      • Even if you could not apply any of these, continue with the below instructions for any that had a problem
    • Click the Advanced button
    • On this Advanced... form, select the Owner tab.
    • On the Owner tab, do the next steps to add Everyone to owners and make Everyone the current owner
    • Click the Other users of groups... button
    • One the next form, in the Enter the object name to select box, type in Everyone and then click Check Names which will then verify that Everyone exists and will underline the text to show it was found
    • Then click OK
    • Then back on the Advanced Security Settings for "the key in question" form select Everyone and then click the Apply button. And then OK out of this form.
    • Now you should be back at the Permissions for Root form.
    • Select Everyone and see if you can now give Full Control by checking the box and clicking Apply.
    Now no matter what happen above, try the below steps anyway.
    • Please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor click File, Import.
    • Navigate your way to the C:\MGtools folder and locate the FixW7FWdrv.reg key and select it.
    • Then click the Open button and allow this to be added into your registry
    • Tell me what happend exactly. Like do you get any error messages or do you get a success message?
    • Now do the same as above to import the below registry patche:
      • FixW7FW.reg
    • Again tell me what happens.
    Now again no matter what happens above, continue on with below instructions and remember if ComboFix does not run in normal boot mode to immediately try running the fix in safe boot mode.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now whether ComboFix ran or not continue on with the below in normal boot mode.



    Now goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • the log from TDSSkiller
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. Tazman282

    Tazman282 Private E-2

    I was unable to find the
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MPSSVC\0000
    but did find all the others. The first part did not work and all gave an error message but worked using the second method via the advanced options.
    As far as the Regedit, the first one was imported successfully, but the second one was not, an error occured and said it was unable to add it.

    Combofix still didn't run in regular or safemode, still got same System security message.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try letting it run anyway? You need to ignore the message about System Shield if that is what you mean.
     
  25. Tazman282

    Tazman282 Private E-2

    Sorry I have been out of town the last few days, I have tried to run combofix everytime and it says that it is going to but then does nothing.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can boot your PC into the System Recovery Environment ( how to do this is explained down below. We will also need a flash drive with another tool loaded on it which we will use while in the System Recovery Environment.

    Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Now plug the flashdrive into the infected PC.

    Use one of the two options below to boot into the System Recovery Environment.


    Option 1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    Option 2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    After getting into the System Recovery Options menu you will see the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • Windows notepad should open
      • Under File menu select Open.
      • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type type e:\frst64 and press Enter
      • Note: Replace letter e with the drive letter of your flash drive.
    • The FSRT will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds