<?xml version="1.0" encoding="iso-8859-1" ?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<!--
	This feed generated for Anonymous	More info at http://naklon.info/rss/about.htm
	Customized and Ported for CastleCops
-->
  <title>CastleCops Recent Posts</title>
  <generator>RSS Feed 2.2.1</generator>
  <link rel="alternate" type="text/html"
   href="http://www.castlecops.com/"/>
  <modified>2008-05-12T02:49:28Z</modified>
  <entry>
    <title mode="escaped">Malware Listserv :: MD5...: 0558d855b2c7842b831adc2a3bde0ff2</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088499.html#1088499"/>
    <dc:creator>tetak</dc:creator>
    <dc:subject>Malware Listserv</dc:subject>
    <author>
		<name>tetak</name>
    </author>
    <id>http://www.castlecops.com/postp1088499.html#1088499</id>
    <issued>2008-05-12T02:48:40Z</issued>
    <modified>2008-05-12T02:48:40Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
	Subject: MD5...: 0558d855b2c7842b831adc2a3bde0ff2&lt;br /&gt;Posted: Mon May 12, 2008 2:48 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	MediaTubeCodec_ver1.234.0.exe
&lt;br /&gt;

&lt;br /&gt;
AhnLab-V3 2008.5.10.0 2008.05.10 - 
&lt;br /&gt;
AntiVir 7.8.0.17 2008.05.11 - 
&lt;br /&gt;
Authentium 4.93.8 2008.05.11 - 
&lt;br /&gt;
Avast 4.8.1169.0 2008.05.11 - 
&lt;br /&gt;
AVG 7.5.0.516 2008.05.11 - 
&lt;br /&gt;
BitDefender 7.2 2008.05.08 - 
&lt;br /&gt;
CAT-QuickHeal 9.50 2008.05.10 (Suspicious) - DNAScan 
&lt;br /&gt;
ClamAV 0.92.1 2008.05.11 - 
&lt;br /&gt;
DrWeb 4.44.0.09170 2008.05.10 - 
&lt;br /&gt;
eSafe 7.0.15.0 2008.05.09 Suspicious File 
&lt;br /&gt;
eTrust-Vet 31.4.5772 2008.05.09 - 
&lt;br /&gt;
Ewido 4.0 2008.05.11 - 
&lt;br /&gt;
F-Prot 4.4.2.54 2008.05.12 - 
&lt;br /&gt;
F-Secure 6.70.13260.0 2008.05.12 Trojan-Downloader.Win32.Zlob.myf 
&lt;br /&gt;
Fortinet 3.14.0.0 2008.05.11 - 
&lt;br /&gt;
Ikarus T3.1.1.26.0 2008.05.12 Trojan.Win32.Tibs.G 
&lt;br /&gt;
Kaspersky 7.0.0.125 2008.05.12 Trojan-Downloader.Win32.Zlob.myf 
&lt;br /&gt;
McAfee 5292 2008.05.10 - 
&lt;br /&gt;
Microsoft 1.3408 2008.05.12 Trojan:Win32/Tibs.gen!G 
&lt;br /&gt;
NOD32v2 3091 2008.05.12 - 
&lt;br /&gt;
Norman 5.80.02 2008.05.09 - 
&lt;br /&gt;
Panda 9.0.0.4 2008.05.11 - 
&lt;br /&gt;
Prevx1 V2 2008.05.12 Malware Dropper 
&lt;br /&gt;
Rising 20.43.62.00 2008.05.11 - 
&lt;br /&gt;
Sophos 4.29.0 2008.05.11 Mal/EncPk-CG 
&lt;br /&gt;
Sunbelt 3.0.1097.0 2008.05.07 - 
&lt;br /&gt;
Symantec 10 2008.05.12 - 
&lt;br /&gt;
TheHacker 6.2.92.307 2008.05.11 - 
&lt;br /&gt;
VBA32 3.12.6.5 2008.05.12 suspected of Downloader.Zlob.8 
&lt;br /&gt;
VirusBuster 4.3.26:9 2008.05.11 - 
&lt;br /&gt;
Webwasher-Gateway 6.6.2 2008.05.11 Win32.Malware.gen (suspicious) 
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
Additional information 
&lt;br /&gt;
File size: 125952 bytes 
&lt;br /&gt;
MD5...: 0558d855b2c7842b831adc2a3bde0ff2&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Unknown Files :: RE: poorly detected malware</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088498.html#1088498"/>
    <dc:creator>tetak</dc:creator>
    <dc:subject>Unknown Files</dc:subject>
    <author>
		<name>tetak</name>
    </author>
    <id>http://www.castlecops.com/postp1088498.html#1088498</id>
    <issued>2008-05-12T02:47:17Z</issued>
    <modified>2008-05-12T02:47:17Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:47 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	I've added the files to the malware listserv.&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-size: 14px; line-height: normal&quot;&gt;Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
&lt;br /&gt;

&lt;br /&gt;
Download it for free from &lt;a href=&quot;http://www.microsoft.com/athome/security/spyware/software/default.mspx&quot;&gt;http://www.microsoft.com/athome/security/spyware/software/default.mspx&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Malware Listserv :: MD5...: 9e9d72893711d4b00fb002f7a443c9b5 AtnvrsInstall.exe</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088497.html#1088497"/>
    <dc:creator>tetak</dc:creator>
    <dc:subject>Malware Listserv</dc:subject>
    <author>
		<name>tetak</name>
    </author>
    <id>http://www.castlecops.com/postp1088497.html#1088497</id>
    <issued>2008-05-12T02:47:00Z</issued>
    <modified>2008-05-12T02:47:00Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
	Subject: MD5...: 9e9d72893711d4b00fb002f7a443c9b5 AtnvrsInstall.exe&lt;br /&gt;Posted: Mon May 12, 2008 2:47 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	AtnvrsInstall.exe
&lt;br /&gt;

&lt;br /&gt;
AhnLab-V3 2008.5.10.0 2008.05.10 - 
&lt;br /&gt;
AntiVir 7.8.0.17 2008.05.11 SPR/Dldr.FraudLoad.AR.1 
&lt;br /&gt;
Authentium 4.93.8 2008.05.11 - 
&lt;br /&gt;
Avast 4.8.1169.0 2008.05.11 - 
&lt;br /&gt;
AVG 7.5.0.516 2008.05.11 Downloader.Purityscan.BA 
&lt;br /&gt;
BitDefender 7.2 2008.05.08 - 
&lt;br /&gt;
CAT-QuickHeal 9.50 2008.05.10 - 
&lt;br /&gt;
ClamAV 0.92.1 2008.05.11 - 
&lt;br /&gt;
DrWeb 4.44.0.09170 2008.05.10 - 
&lt;br /&gt;
eSafe 7.0.15.0 2008.05.09 suspicious Trojan/Worm 
&lt;br /&gt;
eTrust-Vet 31.4.5772 2008.05.09 - 
&lt;br /&gt;
Ewido 4.0 2008.05.11 - 
&lt;br /&gt;
F-Prot 4.4.2.54 2008.05.12 - 
&lt;br /&gt;
F-Secure 6.70.13260.0 2008.05.12 - 
&lt;br /&gt;
Fortinet 3.14.0.0 2008.05.11 - 
&lt;br /&gt;
Ikarus T3.1.1.26.0 2008.05.12 - 
&lt;br /&gt;
Kaspersky 7.0.0.125 2008.05.12 not-a-virus:Downloader.Win32.FraudLoad.ar 
&lt;br /&gt;
McAfee 5292 2008.05.10 - 
&lt;br /&gt;
Microsoft 1.3408 2008.05.12 - 
&lt;br /&gt;
NOD32v2 3091 2008.05.12 - 
&lt;br /&gt;
Norman 5.80.02 2008.05.09 - 
&lt;br /&gt;
Panda 9.0.0.4 2008.05.11 - 
&lt;br /&gt;
Prevx1 V2 2008.05.12 Malicious Software 
&lt;br /&gt;
Rising 20.43.62.00 2008.05.11 - 
&lt;br /&gt;
Sophos 4.29.0 2008.05.11 - 
&lt;br /&gt;
Sunbelt 3.0.1097.0 2008.05.07 - 
&lt;br /&gt;
Symantec 10 2008.05.12 - 
&lt;br /&gt;
TheHacker 6.2.92.307 2008.05.11 - 
&lt;br /&gt;
VBA32 3.12.6.5 2008.05.12 Downloader.Win32.FraudLoad.ar 
&lt;br /&gt;
VirusBuster 4.3.26:9 2008.05.11 - 
&lt;br /&gt;
Webwasher-Gateway 6.6.2 2008.05.11 Riskware.Dldr.FraudLoad.AR.1 
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
Additional information 
&lt;br /&gt;
File size: 56080 bytes 
&lt;br /&gt;
MD5...: 9e9d72893711d4b00fb002f7a443c9b5&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: file backup</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088496.html#1088496"/>
    <dc:creator>Arenlor</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>Arenlor</name>
    </author>
    <id>http://www.castlecops.com/postp1088496.html#1088496</id>
    <issued>2008-05-12T02:36:15Z</issued>
    <modified>2008-05-12T02:36:15Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=156063&quot; target=&quot;_blank&quot;&gt;Arenlor&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:36 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Depends on the files you need backed up. My mom has a 4G flash thumb drive that I use to back up all her files.&lt;br /&gt;_________________&lt;br /&gt;Who is this General Fault and why is he trying to read my HDD?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: Err, just got this today...</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088495.html#1088495"/>
    <dc:creator>Arenlor</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>Arenlor</name>
    </author>
    <id>http://www.castlecops.com/postp1088495.html#1088495</id>
    <issued>2008-05-12T02:34:17Z</issued>
    <modified>2008-05-12T02:34:17Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=156063&quot; target=&quot;_blank&quot;&gt;Arenlor&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:34 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	That specific trojan is coming up a lot recently, seems to be false positives. I'm beginning to wonder if AVG hasn't gone rogue on us. Can you tell me if all the ports from zone alarm were on TCP Port 2869? Also could you look to see what ports they are coming in on to see if they are sequential? It seems someone may just be trying to hack any comcast users they can. This may be something from comcast though. Or if you have an open wireless network someone could be trying to use that to gain access. Or if it's an open network they may be using a P2P client and it's trying to find the right computer. Anyway I suggest using the &lt;a href=&quot;http://wiki.castlecops.com/MRP&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;MRP&lt;/a&gt;&lt;br /&gt;_________________&lt;br /&gt;Who is this General Fault and why is he trying to read my HDD?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Windows Vista and Longhorn :: RE: Hmm damn vista</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088494.html#1088494"/>
    <dc:creator>Anonymous</dc:creator>
    <dc:subject>Windows Vista and Longhorn</dc:subject>
    <author>
		<name>Anonymous</name>
    </author>
    <id>http://www.castlecops.com/postp1088494.html#1088494</id>
    <issued>2008-05-12T02:24:48Z</issued>
    <modified>2008-05-12T02:24:48Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=1&quot; target=&quot;_blank&quot;&gt;Anonymous&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:24 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	so from toshibas web site or windows??? what drivers?                        &lt;img src=&quot;http://isc2.castlecops.com/icon_rolleyes.gif&quot; alt=&quot;Rolling Eyes&quot; border=&quot;0&quot; /&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: C:\Windows\System32\drivers\core.cache.dsk</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088493.html#1088493"/>
    <dc:creator>Arenlor</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>Arenlor</name>
    </author>
    <id>http://www.castlecops.com/postp1088493.html#1088493</id>
    <issued>2008-05-12T02:24:34Z</issued>
    <modified>2008-05-12T02:24:34Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=156063&quot; target=&quot;_blank&quot;&gt;Arenlor&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:24 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Please follow the &lt;a href=&quot;http://wiki.castlecops.com/MRP&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;MRP&lt;/a&gt;.&lt;br /&gt;_________________&lt;br /&gt;Who is this General Fault and why is he trying to read my HDD?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: C:\Windows\System32\drivers\core.cache.dsk</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088492.html#1088492"/>
    <dc:creator>mrrockford</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>mrrockford</name>
    </author>
    <id>http://www.castlecops.com/postp1088492.html#1088492</id>
    <issued>2008-05-12T02:24:17Z</issued>
    <modified>2008-05-12T02:24:17Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=54812&quot; target=&quot;_blank&quot;&gt;mrrockford&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:24 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Howdy,
&lt;br /&gt;

&lt;br /&gt;
Please click &lt;a href=&quot;http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&amp;gt;&amp;gt;&amp;gt;Here&amp;lt;&amp;lt;&amp;lt;&lt;/span&gt;&lt;/a&gt; to download the latest version of HijackThis to your desktop.
&lt;br /&gt;

&lt;br /&gt;
Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
&lt;br /&gt;

&lt;br /&gt;
It will be installed by default here: C:\Program Files\Trend Micro\HijackThis
&lt;br /&gt;

&lt;br /&gt;
A shortcut to the application will also be placed on your Desktop.
&lt;br /&gt;

&lt;br /&gt;
The program will open automatically after installation.
&lt;br /&gt;

&lt;br /&gt;
You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
&lt;br /&gt;

&lt;br /&gt;
Close all other windows except HijackThis.
&lt;br /&gt;

&lt;br /&gt;
Click on &amp;quot;&lt;span style=&quot;font-weight: bold&quot;&gt;Do a system scan and save a logfile&lt;/span&gt;&amp;quot; When the log pops up in Notepad, copy and paste that file in a new thread in this &lt;a href=&quot;http://www.castlecops.com/f67-Trend_Micro_HijackThis_Logs.html&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt; forum&lt;/a&gt;. (Click on the Format menu, and uncheck Word Wrap, Ctrl+A to highlight everything in the log, Ctrl+C to copy it to your clipboard. In your new thread, position the cursor and press Ctrl+V to paste it.)
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Do NOT have HijackThis fix anything yet.&lt;/span&gt; Most of what it finds will be harmless or even required.&lt;br /&gt;_________________&lt;br /&gt;&quot;Anyone who considers protocol unimportant has never dealt with a cat.&quot;
&lt;br /&gt;

&lt;br /&gt;
L. Long&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: what is this????</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088491.html#1088491"/>
    <dc:creator>Arenlor</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>Arenlor</name>
    </author>
    <id>http://www.castlecops.com/postp1088491.html#1088491</id>
    <issued>2008-05-12T02:20:25Z</issued>
    <modified>2008-05-12T02:20:25Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=156063&quot; target=&quot;_blank&quot;&gt;Arenlor&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:20 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	I'm thinking these are either a bunch of FPs or you should all follow the &lt;a href=&quot;http://wiki.castlecops.com/MRP&quot;  target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;MRP&lt;/a&gt; and get HijackTHis help.&lt;br /&gt;_________________&lt;br /&gt;Who is this General Fault and why is he trying to read my HDD?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: what is this????</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088490.html#1088490"/>
    <dc:creator>shadowmistress</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>shadowmistress</name>
    </author>
    <id>http://www.castlecops.com/postp1088490.html#1088490</id>
    <issued>2008-05-12T02:10:00Z</issued>
    <modified>2008-05-12T02:10:00Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=190295&quot; target=&quot;_blank&quot;&gt;shadowmistress&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:10 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	My AVG 8 on XP also found something!
&lt;br /&gt;
Yesterday it found it in a Flock Photobucket Uploader exe and today it's in my System Vol Folder, A0250523.exe, which I believe is the Adobe Reader exe I just updated (or an older version?)...
&lt;br /&gt;

&lt;br /&gt;
What is this thing? What should I do? Please help!&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: Hijacked!</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088489.html#1088489"/>
    <dc:creator>taxxin</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>taxxin</name>
    </author>
    <id>http://www.castlecops.com/postp1088489.html#1088489</id>
    <issued>2008-05-12T02:09:20Z</issued>
    <modified>2008-05-12T02:09:20Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=190294&quot; target=&quot;_blank&quot;&gt;taxxin&lt;/a&gt;&lt;br /&gt;
	Subject: Hijacked!&lt;br /&gt;Posted: Mon May 12, 2008 2:09 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	HiJackThis Log:
&lt;br /&gt;

&lt;br /&gt;
Logfile of Trend Micro HijackThis v2.0.2
&lt;br /&gt;
Scan saved at 9:01:39 PM, on 5/11/2008
&lt;br /&gt;
Platform: Windows XP SP2 (WinNT 5.01.2600)
&lt;br /&gt;
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
&lt;br /&gt;
Boot mode: Normal
&lt;br /&gt;

&lt;br /&gt;
Running processes:
&lt;br /&gt;
C:\WINDOWS\System32\smss.exe
&lt;br /&gt;
C:\WINDOWS\system32\winlogon.exe
&lt;br /&gt;
C:\WINDOWS\system32\services.exe
&lt;br /&gt;
C:\WINDOWS\system32\lsass.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\WINDOWS\System32\svchost.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
&lt;br /&gt;
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
&lt;br /&gt;
C:\Program Files\Alwil Software\Avast4\ashServ.exe
&lt;br /&gt;
C:\WINDOWS\system32\brsvc01a.exe
&lt;br /&gt;
C:\WINDOWS\system32\brss01a.exe
&lt;br /&gt;
C:\WINDOWS\system32\spoolsv.exe
&lt;br /&gt;
C:\WINDOWS\system32\DVDRAMSV.exe
&lt;br /&gt;
C:\WINDOWS\b2new.exe
&lt;br /&gt;
C:\WINDOWS\system32\nvsvc32.exe
&lt;br /&gt;
C:\WINDOWS\system32\PnkBstrA.exe
&lt;br /&gt;
C:\WINDOWS\System32\snmp.exe
&lt;br /&gt;
C:\WINDOWS\System32\svchost.exe
&lt;br /&gt;
C:\WINDOWS\system32\MsPMSPSv.exe
&lt;br /&gt;
C:\WINDOWS\system32\svchost.exe
&lt;br /&gt;
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
&lt;br /&gt;
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
&lt;br /&gt;
C:\WINDOWS\system32\wmsdkns.exe
&lt;br /&gt;
C:\WINDOWS\Explorer.EXE
&lt;br /&gt;
C:\WINDOWS\SOUNDMAN.EXE
&lt;br /&gt;
C:\WINDOWS\system32\LVCOMSX.EXE
&lt;br /&gt;
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
&lt;br /&gt;
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
&lt;br /&gt;
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
&lt;br /&gt;
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
&lt;br /&gt;
C:\WINDOWS\system32\CTHELPER.EXE
&lt;br /&gt;
C:\WINDOWS\system32\regsvr32.exe
&lt;br /&gt;
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\RAMASST.exe
&lt;br /&gt;
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
&lt;br /&gt;
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
&lt;br /&gt;

&lt;br /&gt;
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
&lt;br /&gt;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
&lt;br /&gt;
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
&lt;br /&gt;
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\REAL\TOOLBAR\REALBAR.DLL
&lt;br /&gt;
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINDOWS\system32\urqRJYqo.dll
&lt;br /&gt;
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
&lt;br /&gt;
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
&lt;br /&gt;
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\REAL\TOOLBAR\REALBAR.DLL
&lt;br /&gt;
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
&lt;br /&gt;
O4 - HKLM\..\Run: [IMJPMIG8.1] &amp;quot;C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE&amp;quot; /Spoil /RemAdvDef /Migration32
&lt;br /&gt;
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
&lt;br /&gt;
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
&lt;br /&gt;
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
&lt;br /&gt;
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
&lt;br /&gt;
O4 - HKLM\..\Run: [SSBkgdUpdate] &amp;quot;C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe&amp;quot; -Embedding -boot
&lt;br /&gt;
O4 - HKLM\..\Run: [PaperPort PTD] &amp;quot;C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [IndexSearch] &amp;quot;C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [PPort11reminder] &amp;quot;C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe&amp;quot; -r &amp;quot;C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
&lt;br /&gt;
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
&lt;br /&gt;
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
&lt;br /&gt;
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
&lt;br /&gt;
O4 - HKLM\..\Run: [Jet Detection] &amp;quot;C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe&amp;quot;
&lt;br /&gt;
O4 - HKLM\..\Run: [QuickTime Task] &amp;quot;C:\Program Files\QuickTime\qttask.exe&amp;quot; -atboottime
&lt;br /&gt;
O4 - HKUS\S-1-5-21-299502267-1993962763-725345543-1004\..\Run: [LogitechSoftwareUpdate] &amp;quot;C:\Program Files\Logitech\Video\ManifestEngine.exe&amp;quot; boot (User 'smcconnell1')
&lt;br /&gt;
O4 - HKUS\S-1-5-21-299502267-1993962763-725345543-1004\..\Run: [H/PC Connection Agent] &amp;quot;C:\Program Files\Microsoft ActiveSync\wcescomm.exe&amp;quot; (User 'smcconnell1')
&lt;br /&gt;
O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'SYSTEM')
&lt;br /&gt;
O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User 'Default user')
&lt;br /&gt;
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
&lt;br /&gt;
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\SYSTEM32\RAMASST.exe
&lt;br /&gt;
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
&lt;br /&gt;
O9 - Extra button: Acez.com - Download Free Screen Savers - {88E50F1D-4790-4C6B-BEE3-D54E46B6EEF6} - C:\WINDOWS\acezlink.htm
&lt;br /&gt;
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - &lt;a href=&quot;http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196915030609&quot;&gt;http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196915030609&lt;/a&gt;
&lt;br /&gt;
O20 - Winlogon Notify: urqRJYqo - C:\WINDOWS\SYSTEM32\urqRJYqo.dll
&lt;br /&gt;
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
&lt;br /&gt;
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
&lt;br /&gt;
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
&lt;br /&gt;
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
&lt;br /&gt;
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
&lt;br /&gt;
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
&lt;br /&gt;
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
&lt;br /&gt;
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
&lt;br /&gt;
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\b2new.exe
&lt;br /&gt;
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
&lt;br /&gt;
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
&lt;br /&gt;

&lt;br /&gt;
--
&lt;br /&gt;
End of file - 7069 bytes
&lt;br /&gt;

&lt;br /&gt;
Have made several attempts to get all the malicious items, but obviously I am missing a key component.
&lt;br /&gt;

&lt;br /&gt;
taxxin&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: Disable the safe mode/system recovery popup on xp?</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088488.html#1088488"/>
    <dc:creator>Arenlor</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>Arenlor</name>
    </author>
    <id>http://www.castlecops.com/postp1088488.html#1088488</id>
    <issued>2008-05-12T02:08:08Z</issued>
    <modified>2008-05-12T02:08:08Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=156063&quot; target=&quot;_blank&quot;&gt;Arenlor&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:08 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	I know I do, but I just wondered if it's removable, it'd be nice to do on the systems I'm in charge of since I always just disable system restore and rarely use safe mode even.&lt;br /&gt;_________________&lt;br /&gt;Who is this General Fault and why is he trying to read my HDD?&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: IE severe Slowdown and weird Bonjour folder</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088486.html#1088486"/>
    <dc:creator>markamus</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>markamus</name>
    </author>
    <id>http://www.castlecops.com/postp1088486.html#1088486</id>
    <issued>2008-05-12T02:06:58Z</issued>
    <modified>2008-05-12T02:06:58Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=59597&quot; target=&quot;_blank&quot;&gt;markamus&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:06 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	That scan isn't showing me what I'm looking for. Let's try one more.
&lt;br /&gt;

&lt;br /&gt;
Please download &lt;a href=&quot;http://download.sysinternals.com/Files/RootkitRevealer.zip&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: purple&quot;&gt;Rootkit Revealer&lt;/span&gt;&lt;/span&gt;&lt;/a&gt; (link is at the very bottom of the page)&lt;ul&gt; &lt;li&gt;Unzip it to your desktop. &lt;li&gt;Open the rootkitrevealer folder and double-click &lt;span style=&quot;font-weight: bold&quot;&gt;rootkitrevealer.exe&lt;/span&gt; &lt;li&gt;Click the &lt;span style=&quot;font-weight: bold&quot;&gt;Scan&lt;/span&gt; button (bottom right) &lt;li&gt;It may take a while to scan (don't do anything while it's running) &lt;li&gt;When it's done, go up to &lt;span style=&quot;font-weight: bold&quot;&gt;File &amp;gt; Save&lt;/span&gt;. Choose to save it to your desktop. &lt;li&gt;Open &lt;span style=&quot;font-weight: bold&quot;&gt;rootkitrevealer.txt&lt;/span&gt; on your desktop and copy the entire contents and paste them here. &lt;/ul&gt; &lt;span style=&quot;color: #FF0000&quot;&gt;** NOTE ** &lt;/span&gt;Before performing a scan it is recommended to do the following.
&lt;br /&gt;

&lt;br /&gt;
   1. Physically unplug the cable from the PC to the internet connection.
&lt;br /&gt;
   2. Close down All Scheduling/Updating + Running Background tasks etc.
&lt;br /&gt;
   3. Launch and run the program.
&lt;br /&gt;
   4. While it is scanning DO NOT use your computer at ALL until the scan has been completed.
&lt;br /&gt;
   5. Save your Log File, and then Enable those things you closed down, or Reboot, and ONLY then Reconnect to the Internet. 
&lt;br /&gt;

&lt;br /&gt;
This will ensure you have a simpler and clearer log file to analyze.
&lt;br /&gt;

&lt;br /&gt;
Post back with the results of the Rootkit Revealer scan along with a fresh HijackThis log and again, an update on how the PC is running.
&lt;br /&gt;

&lt;br /&gt;
Thanks,
&lt;br /&gt;

&lt;br /&gt;
markamus&lt;br /&gt;_________________&lt;br /&gt;&lt;a href=&quot;http://www.uniteagainstmalware.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;UNITE&lt;/a&gt; and &lt;a href=&quot;http://asap.maddoktor2.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;ASAP&lt;/a&gt; member&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: file backup</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088485.html#1088485"/>
    <dc:creator>luke9511</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>luke9511</name>
    </author>
    <id>http://www.castlecops.com/postp1088485.html#1088485</id>
    <issued>2008-05-12T02:03:34Z</issued>
    <modified>2008-05-12T02:03:34Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=15833&quot; target=&quot;_blank&quot;&gt;luke9511&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 2:03 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;pwillener wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;That depends on each user's situation. I personally use &lt;a href=&quot;http://www.acronis.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Acronis True Image&lt;/a&gt; to make an image copy of all my partitions to a second HD.&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;only problem is i dont have a hard drive big enough for that&lt;br /&gt;_________________&lt;br /&gt;my computer specs:
&lt;br /&gt;
Compaq Presario SR1650NX
&lt;br /&gt;
Processer:AMD Athlon 64 3500+ 2.2ghz
&lt;br /&gt;
RAM:2gig's
&lt;br /&gt;
Video:ATI Radeon X1600 Pro 512mb PCI-E Graphics
&lt;br /&gt;
Hard Drive:250gig
&lt;br /&gt;
Drives:DVD+RW and CD-ROM&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">SIRT Reports :: [SIRT#173201] Botnet, Canadian Pharmacy on gschildday.com</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088484.html#1088484"/>
    <dc:creator>newangels</dc:creator>
    <dc:subject>SIRT Reports</dc:subject>
    <author>
		<name>newangels</name>
    </author>
    <id>http://www.castlecops.com/postp1088484.html#1088484</id>
    <issued>2008-05-12T02:00:40Z</issued>
    <modified>2008-05-12T02:00:40Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=179731&quot; target=&quot;_blank&quot;&gt;newangels&lt;/a&gt;&lt;br /&gt;
	Subject: [SIRT#173201] Botnet, Canadian Pharmacy on gschildday.com&lt;br /&gt;Posted: Mon May 12, 2008 2:00 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Spam Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Botnet_Canadian_Pharmacy_spam173201.html&quot;&gt;http://www.castlecops.com/Botnet_Canadian_Pharmacy_spam173201.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed spam.IP Converted: 123.111.50.177
&lt;br /&gt;

&lt;br /&gt;
dword = 2070885041
&lt;br /&gt;
hex1 = 0x7b6f32b1
&lt;br /&gt;
hex2 = 0x7b.0x6f.0x32.0xb1
&lt;br /&gt;
oct = 0173.0157.062.0261
&lt;br /&gt;
View CIDR AS9318 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=9318&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=9318&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;9318 | KR | apnic | 1998-06-03 | HANARO-AS Hanaro Telecom Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS9318:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: kr
&lt;br /&gt;
Responsible Domain: hananet.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@hananet.net&quot;&gt;abuse@hananet.net&lt;/a&gt;
&lt;br /&gt;
Criminal Evidence
&lt;br /&gt;

&lt;br /&gt;
     ** REDIRECTOR **
&lt;br /&gt;

&lt;br /&gt;
This site is using redirections to access a hidden criminal site
&lt;br /&gt;
See the Spam Wiki entry at &lt;a href=&quot;http://www.spamtrackers.eu/wiki/index.php?title=Registrations&quot;&gt;http://www.spamtrackers.eu/wiki/index.php?title=Registrations&lt;/a&gt;
&lt;br /&gt;
or from China: &lt;a href=&quot;http://www.spamtrackers.hk/wiki/index.php?title=Registrations&quot;&gt;http://www.spamtrackers.hk/wiki/index.php?title=Registrations&lt;/a&gt;
&lt;br /&gt;
See the McAfee Site Advisor information at &lt;a href=&quot;http://siteadvisor.com/sites/gschildday.com&quot;&gt;http://siteadvisor.com/sites/gschildday.com&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; XIN NET TECHNOLOGY CORPORATION  aka SINO-I.COM
&lt;br /&gt;
REGISTRATION OF THE WEB SITE: gschildday.com
&lt;br /&gt;
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; XIN NET TECHNOLOGY CORPORATION  aka SINO-I.COM
&lt;br /&gt;
REGISTRATION OF THE NAME SERVERS
&lt;br /&gt;
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
&lt;br /&gt;
 Primary DNS:  ns1.fopns.com  58.242.152.80
&lt;br /&gt;
  Secondary DNS:  ns2.fopns.com  221.122.64.14
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
ACTION: To suspend these name servers successfully, follow these steps.
&lt;br /&gt;
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
&lt;br /&gt;
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt;This Is a Botnet Using 6 Illegally hijacked Machines.
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
     ** TARGET SITE **
&lt;br /&gt;

&lt;br /&gt;
See the Spam Wiki entry at &lt;a href=&quot;http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Pharmacy&quot;&gt;http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Pharmacy&lt;/a&gt;
&lt;br /&gt;
or from China: &lt;a href=&quot;http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Pharmacy&quot;&gt;http://www.spamtrackers.hk/wiki/index.php?title=Canadian_Pharmacy&lt;/a&gt;
&lt;br /&gt;
See the McAfee Site Advisor information at &lt;a href=&quot;http://siteadvisor.com/sites/prettydesert.com&quot;&gt;http://siteadvisor.com/sites/prettydesert.com&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; XIN NET TECHNOLOGY CORPORATION  aka SINO-I.COM
&lt;br /&gt;
REGISTRATION OF THE WEB SITE: prettydesert.com
&lt;br /&gt;
ACTION: To suspend this criminal site which breaks your terms of service, set the domain status to clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; XIN NET TECHNOLOGY CORPORATION  aka SINO-I.COM
&lt;br /&gt;

&lt;br /&gt;
REGISTRATION OF THE NAME SERVERS
&lt;br /&gt;
These name servers are registered by criminals to resolve only illegal web sites. This breaks your terms of service. You can safely suspend them:
&lt;br /&gt;
Name Server.......... ns4.guprovider.com
&lt;br /&gt;
  Name Server.......... ns3.guprovider.com
&lt;br /&gt;
  Name Server.......... ns2.guprovider.com
&lt;br /&gt;
  Name Server.......... ns1.guprovider.com
&lt;br /&gt;

&lt;br /&gt;
ACTION: To suspend these name servers successfully, follow these steps.
&lt;br /&gt;
1. set the ns Address records to a non-routable address, such as 127.0.0.1 or 61.61.61.61.
&lt;br /&gt;
2. Set the domain status to clientUpdateProhibited, clientTransferProhibited, clientDeleteProhibited, and clientHold
&lt;br /&gt;

&lt;br /&gt;

&lt;br /&gt;
&amp;gt; &lt;a href=&quot;mailto:abuse@hananet.net&quot;&gt;abuse@hananet.net&lt;/a&gt;
&lt;br /&gt;
IP ADDRESS OF HOST: 123.111.50.177
&lt;br /&gt;

&lt;br /&gt;
The IP address of this criminal site is within your allocated address space.
&lt;br /&gt;
ACTION:  Black-hole the route to this address to prevent further criminal activity&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://byt.gschildday.com&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: RE: file backup</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088483.html#1088483"/>
    <dc:creator>pwillener</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>pwillener</name>
    </author>
    <id>http://www.castlecops.com/postp1088483.html#1088483</id>
    <issued>2008-05-12T01:59:09Z</issued>
    <modified>2008-05-12T01:59:09Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=158434&quot; target=&quot;_blank&quot;&gt;pwillener&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:59 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	That depends on each user's situation. I personally use &lt;a href=&quot;http://www.acronis.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;Acronis True Image&lt;/a&gt; to make an image copy of all my partitions to a second HD.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">General Computer Problems :: Err, just got this today...</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088482.html#1088482"/>
    <dc:creator>ayim</dc:creator>
    <dc:subject>General Computer Problems</dc:subject>
    <author>
		<name>ayim</name>
    </author>
    <id>http://www.castlecops.com/postp1088482.html#1088482</id>
    <issued>2008-05-12T01:51:50Z</issued>
    <modified>2008-05-12T01:51:50Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=190292&quot; target=&quot;_blank&quot;&gt;ayim&lt;/a&gt;&lt;br /&gt;
	Subject: Err, just got this today...&lt;br /&gt;Posted: Mon May 12, 2008 1:51 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Right, so I was just using the computer normally then out of the blue these Zone Alarm pop-up's started coming up ( i had like 44 before but I restarted my computer )
&lt;br /&gt;
&lt;a href=&quot;http://img186.imageshack.us/img186/3536/05112008214351kv3.png&quot;&gt;http://img186.imageshack.us/img186/3536/05112008214351kv3.png&lt;/a&gt; &lt;a href=&quot;http://img186.imageshack.us/img186/402/05112008214356mq9.png&quot;&gt;http://img186.imageshack.us/img186/402/05112008214356mq9.png&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;
then shortly after my AVG Antivirus found a &amp;quot;Trojan Horse generic10.vpd&amp;quot; in an Uninstall.exe of C:\Program Files\YAMB\, I healed it and thought that was the problem but I keep getting the popups from zone alarm, is someone scanning my ports trying to hack me or what x.X
&lt;br /&gt;

&lt;br /&gt;
(Oh, and I also had YAMB on my computer for like 2 years... don't see how it turns into a virus now)&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Security :: RE: Malware - Hundreds of thousands of SQL injections</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088480.html#1088480"/>
    <dc:creator>AplusWebMaster</dc:creator>
    <dc:subject>Security</dc:subject>
    <author>
		<name>AplusWebMaster</name>
    </author>
    <id>http://www.castlecops.com/postp1088480.html#1088480</id>
    <issued>2008-05-12T01:42:30Z</issued>
    <modified>2008-05-12T01:42:30Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=38620&quot; target=&quot;_blank&quot;&gt;AplusWebMaster&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:42 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	FYI...
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Mass File Injection Attack&lt;/span&gt;
&lt;br /&gt;
- &lt;a href=&quot;http://isc.sans.org/diary.html?storyid=4405&quot;&gt;http://isc.sans.org/diary.html?storyid=4405&lt;/a&gt;
&lt;br /&gt;
Last Updated: 2008-05-11 21:48:56 UTC - &amp;quot;We received a report... this afternoon about a couple of URLs containing a &lt;span style=&quot;text-decoration: underline&quot;&gt;malicious JavaScript that pulls down a file associated with Zlob&lt;/span&gt;.  If you do a google search for these two URLs, you get &lt;span style=&quot;text-decoration: underline&quot;&gt;about 400,000 sites that have a call to this Javascript file included in them now&lt;/span&gt;.  The major portion of the sites seem to be running phpBB forum software.
&lt;br /&gt;
If you have a proxy server that logs outbound web traffic at your site, you might want to look for connection attempts to these two sites.  Internal clients that have connected may need some cleanup work. Another preventive step would be to &lt;span style=&quot;text-decoration: underline&quot;&gt;blacklist these two URLs&lt;/span&gt;.
&lt;br /&gt;

&lt;br /&gt;
hxxp ://free .hostpinoy .info /f.js
&lt;br /&gt;
hxxp ://xprmn4u.info /f .js  &amp;quot;
&lt;br /&gt;

&lt;br /&gt;
 &lt;img src=&quot;http://isc2.castlecops.com/icon_eek.gif&quot; alt=&quot;Shocked&quot; border=&quot;0&quot; /&gt;&lt;br /&gt;_________________&lt;br /&gt;&lt;a href=&quot;http://www.apluswebmaster.net/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;AplusWebMaster&lt;/a&gt; 
&lt;br /&gt;
~ Are you &lt;a href=&quot;http://update.microsoft.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;up to date&lt;/a&gt; or vulnerable to &lt;span style=&quot;text-decoration: underline&quot;&gt;Hackers&lt;/span&gt;? ...or &lt;span style=&quot;text-decoration: underline&quot;&gt;both&lt;/span&gt;?
&lt;br /&gt;
Be wise, like a &lt;a href=&quot;http://getfirefox.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;fox&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Politics :: RE: Meet Ozymandias, All Ye Mighty</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088479.html#1088479"/>
    <dc:creator>alanstancliff</dc:creator>
    <dc:subject>Politics</dc:subject>
    <author>
		<name>alanstancliff</name>
    </author>
    <id>http://www.castlecops.com/postp1088479.html#1088479</id>
    <issued>2008-05-12T01:40:13Z</issued>
    <modified>2008-05-12T01:40:13Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=159210&quot; target=&quot;_blank&quot;&gt;alanstancliff&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:40 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;JoAnnCQ wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;Hi Alan,
&lt;br /&gt;

&lt;br /&gt;
I hope Your Wife had a nice Mother's Day.  
&lt;br /&gt;

&lt;br /&gt;
&amp;amp; I really like Bob Dylan's Words.  Like this one, &lt;span style=&quot;font-style: italic&quot;&gt;With God on Our Side:&lt;/span&gt;
&lt;br /&gt;

&lt;br /&gt;
&lt;a href=&quot;http://www.bobdylan.com/moderntimes/songs/withgod.html&quot;&gt;http://www.bobdylan.com/moderntimes/songs/withgod.html&lt;/a&gt;
&lt;br /&gt;

&lt;br /&gt;
Somehow His Words are &lt;span style=&quot;font-style: italic&quot;&gt;always relevant &lt;/span&gt;(&amp;amp; I dunno how He does that either?)  To me they are anyway or how?&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;
&lt;br /&gt;
===========
&lt;br /&gt;
And a happy and blessed mother's day to you, too, and all the women here. Even those who are not mothers, just your being half the human race means so much to me.
&lt;br /&gt;

&lt;br /&gt;
The women in my life have always brought earthiness and groundedness to me and have helped me be a better man.&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-size: 15px; line-height: normal&quot;&gt;Regards,
&lt;br /&gt;

&lt;br /&gt;
Alan
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;a href=&quot;http://www.alanstancliff.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;My Web Site, Blog, Music, Art&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Anti-Virus Updates :: RE: F-Secure® Updates</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088478.html#1088478"/>
    <dc:creator>roddy32</dc:creator>
    <dc:subject>Anti-Virus Updates</dc:subject>
    <author>
		<name>roddy32</name>
    </author>
    <id>http://www.castlecops.com/postp1088478.html#1088478</id>
    <issued>2008-05-12T01:34:01Z</issued>
    <modified>2008-05-12T01:34:01Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=114811&quot; target=&quot;_blank&quot;&gt;roddy32&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:34 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;span style=&quot;font-weight: bold&quot;&gt;Latest Definition Updates:&lt;/span&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;May 11, 2008 / 23:00:11 (GMT+2)  &lt;/span&gt;
&lt;br /&gt;
F-Secure Anti-Virus detects Exploit:W32/AdobeReader.K with this update. 
&lt;br /&gt;
&lt;a href=&quot;http://www.f-secure.com/download-purchase/updates.shtml&quot;&gt;http://www.f-secure.com/download-purchase/updates.shtml&lt;/a&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.f-secure.com/v-descs/_new.shtml&quot;&gt;http://www.f-secure.com/v-descs/_new.shtml&lt;/a&gt;&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;&lt;span style=&quot;font-size: 9px; line-height: normal&quot;&gt;Microsoft MVP - Windows Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Anti-Virus Updates :: RE: NOD32 updates</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088477.html#1088477"/>
    <dc:creator>roddy32</dc:creator>
    <dc:subject>Anti-Virus Updates</dc:subject>
    <author>
		<name>roddy32</name>
    </author>
    <id>http://www.castlecops.com/postp1088477.html#1088477</id>
    <issued>2008-05-12T01:29:13Z</issued>
    <modified>2008-05-12T01:29:13Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=114811&quot; target=&quot;_blank&quot;&gt;roddy32&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:29 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;Update 3091 (20080512)&lt;/span&gt;
&lt;br /&gt;
2008-05-12 03:03&lt;/span&gt;
&lt;br /&gt;
BAT/KillWin.DG, INF/Autorun, Win32/Autoit.AG (2), Win32/Sality.NAK (2)
&lt;br /&gt;
&lt;a href=&quot;http://www.eset.eu/podpora/aktualizacia-3091?lng=en&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;http://www.eset.eu/podpora/aktualizacia-3091?lng=en&lt;/a&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.eset.eu/support/update-xy1&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;http://www.eset.eu/support/update-xy1&lt;/a&gt;&lt;br /&gt;_________________&lt;br /&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;&lt;span style=&quot;color: blue&quot;&gt;&lt;span style=&quot;font-size: 9px; line-height: normal&quot;&gt;Microsoft MVP - Windows Security&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: Infected PC, scans aren't fixing it  Please advise - Win ME</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088475.html#1088475"/>
    <dc:creator>Trekkie</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>Trekkie</name>
    </author>
    <id>http://www.castlecops.com/postp1088475.html#1088475</id>
    <issued>2008-05-12T01:11:41Z</issued>
    <modified>2008-05-12T01:11:41Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=188976&quot; target=&quot;_blank&quot;&gt;Trekkie&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:11 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	-********
&lt;br /&gt;
May 11, Sunday 
&lt;br /&gt;

&lt;br /&gt;
Hello, AbuIbrahim – Here’s May 11 update.
&lt;br /&gt;

&lt;br /&gt;
  &lt;span style=&quot;font-weight: bold&quot;&gt;Quote: &lt;/span&gt;Please reboot into safe mode, &lt;span style=&quot;font-weight: bold&quot;&gt;if you still see multiple windows opening up&lt;/span&gt;, then please do a hijackthis scan while in safe mode then copy and paste the results.
&lt;br /&gt;

&lt;br /&gt;
1) AbuIbrahim, I rebooted into safe mode and didn’t get the multiple windows, restarted in normal mode.
&lt;br /&gt;

&lt;br /&gt;
Quote:  …If you still have a &lt;span style=&quot;font-weight: bold&quot;&gt;copy of the file flash9d.ocx, then move that file &lt;/span&gt;to the following folder: 
&lt;br /&gt;
C:\Windows\System\Macromed\Flash\
&lt;br /&gt;

&lt;br /&gt;
2) I moved a copy of the file flash9d.ocx from my desktop folder to C:\Windows\System\Macromed\Flash\ , so now that folder contains 3 different ocx files.  See screen shot posted today of current Flash folder contents.  
&lt;br /&gt;

&lt;br /&gt;
After moving flash9d.ocx file to Flash, I restarted IE and was able to use browser, but the sound hasn’t returned to my PC.
&lt;br /&gt;
I also went through questions on Windows ME Sound Troubleshooter in Help &amp;amp; Support of my PC -- that didn't help.
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;What do you think I should try next &lt;/span&gt;– &lt;span style=&quot;font-weight: bold&quot;&gt;the adobe link &lt;/span&gt;http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_19166&amp;amp;sliceId=1&amp;quot;] 
&lt;br /&gt;
 &lt;span style=&quot;font-weight: bold&quot;&gt;then the microsft kb link &lt;/span&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;308366”?
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Do you think I should  run the  “uninstall ActiveX.exe” &lt;/span&gt;that’s in the  C:\Windows\System\Macromed\Flash  folder?
&lt;br /&gt;

&lt;br /&gt;
Thank you for your time, AbuIbrahim.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Politics :: RE: Meet Ozymandias, All Ye Mighty</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088474.html#1088474"/>
    <dc:creator>JoAnnCQ</dc:creator>
    <dc:subject>Politics</dc:subject>
    <author>
		<name>JoAnnCQ</name>
    </author>
    <id>http://www.castlecops.com/postp1088474.html#1088474</id>
    <issued>2008-05-12T01:04:43Z</issued>
    <modified>2008-05-12T01:04:43Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=122386&quot; target=&quot;_blank&quot;&gt;JoAnnCQ&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:04 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	&lt;span style=&quot;color: blue&quot;&gt;The Little Black Boy
&lt;br /&gt;

&lt;br /&gt;
My mother bore me in the southern wild,
&lt;br /&gt;
And I am black, but O! my soul is white;
&lt;br /&gt;
White as an angel is the English child,
&lt;br /&gt;
But I am black as if bereav'd of light.
&lt;br /&gt;

&lt;br /&gt;
My mother taught me underneath a tree
&lt;br /&gt;
And sitting down before the heat of day,
&lt;br /&gt;
She took me on her lap and kissed me,
&lt;br /&gt;
And pointing in the east began to say:
&lt;br /&gt;

&lt;br /&gt;
Look on the rising sun: there God does live
&lt;br /&gt;
And gives his light, and gives his heat away:
&lt;br /&gt;
And flowers and trees and beasts and men receive
&lt;br /&gt;
Comfort in the morning, joy in the noon day.
&lt;br /&gt;

&lt;br /&gt;
And we are put on earth a little space,
&lt;br /&gt;
That we may learn to bear the beams of love:
&lt;br /&gt;
And these black bodies and this sunburnt face
&lt;br /&gt;
Is but a cloud, and like a shady grove:
&lt;br /&gt;

&lt;br /&gt;
For when our souls have learn'd the heat to bear
&lt;br /&gt;
The cloud will vanish; we shall hear his voice,
&lt;br /&gt;
Saying: Come out from the grove, my love &amp;amp; care,
&lt;br /&gt;
And round my golden tent like lambs rejoice.
&lt;br /&gt;

&lt;br /&gt;
Thus did my mother say and kissed me:
&lt;br /&gt;
And thus I say to little English boy;
&lt;br /&gt;
When I from black and he from white cloud free,
&lt;br /&gt;
And round the tent of God like lambs we joy,
&lt;br /&gt;

&lt;br /&gt;
I'll shade him from the heat, till he can bear
&lt;br /&gt;
To lean in joy upon our father's knee:
&lt;br /&gt;
And then I'll stand and stroke his silver hair,
&lt;br /&gt;
And be like him and he will then love me.
&lt;br /&gt;

&lt;br /&gt;
-William Blake 
&lt;br /&gt;
Songs of Innocence &amp;amp; Experience 
&lt;br /&gt;

&lt;br /&gt;
(I really like that one but it makes me sad too)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Security :: TrojanHunter by Mischel</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088473.html#1088473"/>
    <dc:creator>sherrymyra</dc:creator>
    <dc:subject>Security</dc:subject>
    <author>
		<name>sherrymyra</name>
    </author>
    <id>http://www.castlecops.com/postp1088473.html#1088473</id>
    <issued>2008-05-12T01:03:26Z</issued>
    <modified>2008-05-12T01:03:26Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=149844&quot; target=&quot;_blank&quot;&gt;sherrymyra&lt;/a&gt;&lt;br /&gt;
	Subject: TrojanHunter by Mischel&lt;br /&gt;Posted: Mon May 12, 2008 1:03 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Does anyone know anything about this program?  Good or bad?  I'm looking for a trojan hunter free or otherwise.  I had used Trend Micro but for some reason I can't get it to work now.&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
  <entry>
    <title mode="escaped">Trend Micro HijackThis Logs :: RE: IE severe Slowdown and weird Bonjour folder</title>
    <link rel="alternate" type="text/html"
     href="http://www.castlecops.com/postp1088472.html#1088472"/>
    <dc:creator>lobofonseca</dc:creator>
    <dc:subject>Trend Micro HijackThis Logs</dc:subject>
    <author>
		<name>lobofonseca</name>
    </author>
    <id>http://www.castlecops.com/postp1088472.html#1088472</id>
    <issued>2008-05-12T01:02:12Z</issued>
    <modified>2008-05-12T01:02:12Z</modified>
	<content type="text/html" mode="escaped">Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=140849&quot; target=&quot;_blank&quot;&gt;lobofonseca&lt;/a&gt;&lt;br /&gt;
	Posted: Mon May 12, 2008 1:02 am (GMT 0)&lt;br /&gt;&lt;br /&gt;&lt;span class="postbody"&gt;
	Markamus, here's the log. Thanks!
&lt;br /&gt;

&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;Scanning Report&lt;/span&gt;
&lt;br /&gt;
Sunday, May 11, 2008 21:18:03 - 21:59:09
&lt;br /&gt;

&lt;br /&gt;
Computer name: GABRIEL-82D84F0 
&lt;br /&gt;
Scanning type: Scan system for malware, rootkits 
&lt;br /&gt;
Target: C:\ 
&lt;br /&gt;
Result: 3 malware found
&lt;br /&gt;
Monitor.Win32.PKRPoker (spyware) 
&lt;br /&gt;
System 
&lt;br /&gt;
RiskTool.Win32.Reboot (spyware) 
&lt;br /&gt;
System 
&lt;br /&gt;
Tracking Cookie (spyware) 
&lt;br /&gt;
System 
&lt;br /&gt;
Statistics
&lt;br /&gt;
Scanned:
&lt;br /&gt;
Files: 45005 
&lt;br /&gt;
System: 4075 
&lt;br /&gt;
Not scanned: 8 
&lt;br /&gt;
Actions:
&lt;br /&gt;
Disinfected: 0 
&lt;br /&gt;
Renamed: 0 
&lt;br /&gt;
Deleted: 0 
&lt;br /&gt;
None: 3 
&lt;br /&gt;
Submitted: 0 
&lt;br /&gt;
Files not scanned:
&lt;br /&gt;
C:\HIBERFIL.SYS 
&lt;br /&gt;
C:\PAGEFILE.SYS 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\CONFIG\SAM 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE 
&lt;br /&gt;
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM 
&lt;br /&gt;
Options
&lt;br /&gt;
Scanning engines:
&lt;br /&gt;
F-Secure USS: 2.30.0 
&lt;br /&gt;
F-Secure Hydra: 2.8.8110, 2008-05-12 
&lt;br /&gt;
F-Secure AVP: 7.0.171, 2008-05-12 
&lt;br /&gt;
F-Secure Pegasus: 1.20.0, 2008-02-28 
&lt;br /&gt;
F-Secure Blacklight: 1.0.68 
&lt;br /&gt;
Scanning options:
&lt;br /&gt;
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR 
&lt;br /&gt;
Use Advanced heuristics&lt;/span&gt;&lt;br /&gt;
	</content>
  </entry>
</feed>
<!-- Page generation time: 0.1852s  - GZIP disabled -->