<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7500876854249784659</id><updated>2011-08-11T17:20:41.476+02:00</updated><category term='account lockout'/><category term='rootkit detection'/><category term='outlook'/><category term='malware protection'/><category term='iframes'/><category term='vulnerability assessment'/><category term='myths and facts'/><category term='active directory'/><category term='RMS'/><category term='antivirus comparison'/><category term='malware removal'/><category term='conficker/Downadup/kido'/><title type='text'>AbuIbrahim12's Security Journal</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>31</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-232343919628878370</id><published>2010-11-09T03:33:00.003+02:00</published><updated>2010-11-13T13:58:44.256+02:00</updated><title type='text'>What We Can Learn From Science Regarding Industry-Sponsored Testing of Security Products</title><content type='html'>Robert Cialdini, a Psychology professor at Arizona State University, stated his top-notch book, Influence Science and Practice:&lt;br /&gt;&lt;blockquote style="font-weight: bold; font-family: arial;"&gt;"Take the case of the medical controversy surrounding the safety of calcium-channel blockers, a class of drugs for heart disease. One study discovered that 100 percent of the scientists who found and published results supportive of the drugs had received prior support (free trips, research funding, or employment) from the pharmaceutical companies; but only 37 percent of those critical of the drugs had received any such prior support. "&lt;/blockquote&gt;His statement was based on a scientific paper published in The New England Journal of Medicine in 1998. Details of the research can be found here:&lt;br /&gt;&lt;a href="http://www.nejm.org/doi/full/10.1056/NEJM199801083380206"&gt;Conflict of Interest in the Debate over Calcium-Channel Antagonists&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Wow, these results are staggering. 37% of doctors were critical of a particular form of drug. But when some form of support is involved all doctors became in favor of such drug. This and other related research cited at the end of this article scientifically proves (at least from a psychology and medicine perspective) that industry-supported evaluation or testing of security related products such as antiviruses, IPS's, etc. have an influence on the quality and outcomes of their results.&lt;br /&gt;&lt;br /&gt;Examples of such type of research studies in the security industry are:&lt;br /&gt;1. Symantec funded an antivirus testing by PassMark: &lt;a href="http://www.passmark.com/ftp/antivirus_11-performance-testing-ed2.pdf"&gt;Consumer Antivirus Performance Benchmarks&lt;/a&gt;&lt;br /&gt;2. Symantec sponsored another antivirus evaluation by Dennis Technology Labs: &lt;a href="http://www.dennistechnologylabs.com/reports/s/a-m/symantec/DTL_PCVP2011_SYMC.pdf"&gt;PC Anti-Virus Protection 2011&lt;/a&gt;&lt;br /&gt;3. &lt;del&gt;Trend Micro sponsored an antivirus testing by NSS Labs:&lt;/del&gt;(debatable) &lt;a href="http://trendmicro.mediaroom.com/index.php?s=43&amp;amp;item=749"&gt;http://trendmicro.mediaroom.com/index.php?s=43&amp;amp;item=749&lt;/a&gt;&lt;br /&gt;4. Microsoft sponsored two NSS Labs tests for comparing the security of IE8 with other  browsers:&lt;br /&gt;&lt;a href="http://arstechnica.com/microsoft/news/2009/08/microsoft-sponsors-two-nss-reports-ie8-is-the-most-secure.ars"&gt;http://arstechnica.com/microsoft/news/2009/08/microsoft-sponsors-two-nss-reports-ie8-is-the-most-secure.ars&lt;/a&gt;&lt;br /&gt;5. Trend-Micro commissioned West Coast Labs Anti-Spam comparison tests: &lt;a href="http://it.trendmicro.com/imperia/md/content/uk/whitepaper/wp06_wclantispamrpt_090317us.pdf"&gt;http://it.trendmicro.com/imperia/md/content/uk/whitepaper/wp06_wclantispamrpt_090317us.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The results of these studies are not surprising. Symantec was ranked  first by Dennis Technology Labs and PassMark. &lt;del&gt;Trend Micro was ranked first by NSS Labs.&lt;/del&gt; IE8 was shown to be far superior than its peers according to NSS Labs. Trend Micro topped the antispam comparison tests by West Coast Labs.&lt;br /&gt;&lt;br /&gt;The reason I am blogging this, is because I have come across a lot of CIO's and security experts who still believe and take into granted the results published by such kind of studies. Its even a pity to see security gurus from notable organizations such as SANS fall into this and cite these results.&lt;br /&gt;&lt;br /&gt;For more information please see:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Study: Industry-Sponsored Research Yields Favorable Results a Majority of the Time: &lt;a href="http://www.doctorpundit.com/index.php/2010/08/03/study-industry-sponsored-research-yields-favorable-results-a-majority-of-the-time"&gt;http://www.doctorpundit.com/index.php/2010/08/03/study-industry-sponsored-research-yields-favorable-results-a-majority-of-the-time&lt;/a&gt;&lt;/li&gt;&lt;li&gt;The uncertainty principle and industry-sponsored research: &lt;a href="http://www.ncbi.nlm.nih.gov/pubmed/10968436"&gt;http://www.ncbi.nlm.nih.gov/pubmed/10968436&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Pharmaceutical industry sponsorship and research outcome and quality: systematic review &lt;a href="http://www.bmj.com/content/326/7400/1167.full"&gt;http://www.bmj.com/content/326/7400/1167.full&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Source of funding and outcome of clinical trials  - Journal of General Internal Medicine &lt;a href="http://www.springerlink.com/content/r654521305u8547k/"&gt;http://www.springerlink.com/content/r654521305u8547k/&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-232343919628878370?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/232343919628878370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/11/what-we-can-learn-from-science.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/232343919628878370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/232343919628878370'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/11/what-we-can-learn-from-science.html' title='What We Can Learn From Science Regarding Industry-Sponsored Testing of Security Products'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-1703861739474877971</id><published>2010-11-02T08:21:00.002+02:00</published><updated>2010-11-02T08:44:07.416+02:00</updated><title type='text'>2010 Cairo Security Camp</title><content type='html'>I gave off a presentation at the 2010 Cairo Security Camp at Cairo, Egypt about 2 months ago.  The event was held at Nile University Smart Village. My presentation was on rootkits detection and removal. I have also talked about ADS and MBR infections.&lt;br /&gt;All praise to God, according to the &lt;a href="http://www.bluekaizen.org/event0-evaluation.php"&gt;attendees evaluation&lt;/a&gt;, I was voted as both, the most liked speaker, and best event topic.&lt;br /&gt;&lt;a id="publishButton" class="cssButton" target=""&gt;&lt;div class="cssButtonOuter"&gt;&lt;div class="cssButtonMiddle"&gt;&lt;div class="cssButtonInner"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-1703861739474877971?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/1703861739474877971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/11/2010-cairo-security-camp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1703861739474877971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1703861739474877971'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/11/2010-cairo-security-camp.html' title='2010 Cairo Security Camp'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-8002303614858658574</id><published>2010-10-06T20:10:00.003+02:00</published><updated>2010-10-06T21:45:54.642+02:00</updated><title type='text'>New Features Added to Startups@Ease</title><content type='html'>I have made a complete re-design of the user interface of Startups@Ease. I have also included two new additional features to help reduce unnecessary software from running every time the computer restarts, which are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;1. Installed third party services:&lt;/span&gt; Services are a type of startups that starts running in the background even before you log into the computer. There is a lot of unwanted services that comes bundled with some of the software you may have installed. Additionaly, these unwanted services may exist from pre-installed software whenever you buy a new computer. You can go through the Q&amp;amp;A wizard to see which of these services that are actively running in your computer that you do not want by clicking on the '&lt;span style="font-weight: bold;"&gt;Installed Services&lt;/span&gt;' button.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;2. Services that are part of the Windows operating system&lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;:&lt;/span&gt; Windows come with a large amount of services that start automatically and actively run in the background. Most of these services are very important for the the OS to function properly. However, there are few default Windows services that are not essential to the OS and are not always needed to be actively running. Based on how you use your computer, you can determine which of these unnecessary services that you may need by going through a questionnaire that can be accessed by the '&lt;span style="font-weight: bold;"&gt;Windows Services&lt;/span&gt;' button.&lt;br /&gt;&lt;br /&gt;If you have bought a new computer and you have used Startups@Ease, it will be a shame that the tool has not significantly boosted your computer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mVuWlEoAXhc/TKzF3JQqfzI/AAAAAAAAACU/69KpgbfKyB0/s1600/newlook.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 127px;" src="http://1.bp.blogspot.com/_mVuWlEoAXhc/TKzF3JQqfzI/AAAAAAAAACU/69KpgbfKyB0/s400/newlook.jpg" alt="" id="BLOGGER_PHOTO_ID_5525008394046046002" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-8002303614858658574?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/8002303614858658574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/10/new-features-added-to-startupsease.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8002303614858658574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8002303614858658574'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/10/new-features-added-to-startupsease.html' title='New Features Added to Startups@Ease'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mVuWlEoAXhc/TKzF3JQqfzI/AAAAAAAAACU/69KpgbfKyB0/s72-c/newlook.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-8434252206227704439</id><published>2010-08-29T15:30:00.002+02:00</published><updated>2010-08-29T15:43:41.350+02:00</updated><title type='text'>Startups@Ease Now Supports 64-bit Windows</title><content type='html'>I have re-written the code for Startups@Ease and now it supports both 32-bit and 64-bit operating systems using the same executable.&lt;br /&gt;The tool is automatically compatible with Windows XP 32-bit, Vista 32-bit, 7  32-bit, server 2003 32-bit, server 2008 32-bit, Vista 64-bit, 7  64-bit and server 2008 64-bit.&lt;br /&gt;As for Windows XP 64-bit and server 2003 64-bit, you will need to download and install this &lt;a href="http://support.microsoft.com/kb/942589"&gt;hotfix&lt;/a&gt; before running this tool. The hotfix would allow 32-bit applications to access the 64-bit locations native to the operating system. Without the hotfix, the tool will not function properly.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-8434252206227704439?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/8434252206227704439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/startupsease-now-supports-64-bit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8434252206227704439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8434252206227704439'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/startupsease-now-supports-64-bit.html' title='Startups@Ease Now Supports 64-bit Windows'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-6784045969687339882</id><published>2010-08-20T13:59:00.006+02:00</published><updated>2010-08-20T15:48:39.982+02:00</updated><title type='text'>Startups@Ease has Been Released</title><content type='html'>I finally launched a freeware tool called &lt;a href="http://www.startupsatease.com/" target="_blank"&gt;Startups@Ease&lt;/a&gt; that I have been developing in the past few months. The program is mainly designed to help non-geeks to manage unwanted startups in their computers. When executed, the program searches for unnecessary startups and then displays them as a series of questions and (yes/no) answers to the user. These questions are phrased such a way that non-technically sophisticated users can understand and be able to make a judgment whether they actually need the unnecessary startups or not. &lt;o:p&gt;&lt;/o:p&gt;  &lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;The tool does NOT delete or&lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt; uninstall any of your programs.&lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt; All of the startup programs that appear in the Q&amp;amp;A wizard can&lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt; be accessed either through the &lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;start menu or from the control &lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;panel. In addition, the tool &lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;automatically creates backups of any programs it has disabled &lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;from startups.&lt;br /&gt;&lt;br /&gt;The tool is available here: &lt;a href="http://www.startupsatease.com/" target="_blank"&gt;http://www.startupsatease.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;To use the program, click the begin button as in the image &lt;/span&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;below: &lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mVuWlEoAXhc/TG6CdjwOktI/AAAAAAAAAB0/65QEAbGzt-U/s1600/main.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 327px; height: 400px;" src="http://1.bp.blogspot.com/_mVuWlEoAXhc/TG6CdjwOktI/AAAAAAAAAB0/65QEAbGzt-U/s400/main.png" alt="" id="BLOGGER_PHOTO_ID_5507482838646035154" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;If an unnecessary startup is found, a wizard will pop-up similar to the image below. However, the questions posted will vary from one computer to another.&lt;br /&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mVuWlEoAXhc/TG6FBZ2aH3I/AAAAAAAAAB8/B8nA0SPbB7s/s1600/wizard.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 384px;" src="http://4.bp.blogspot.com/_mVuWlEoAXhc/TG6FBZ2aH3I/AAAAAAAAAB8/B8nA0SPbB7s/s400/wizard.png" alt="" id="BLOGGER_PHOTO_ID_5507485653486149490" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Once, the wizard is complete a page will pop-up which contains a review for all of  the selected answers for each question. At this page, select the confirm button and then you will need to restart your computer.The program does not enforce a restart and does not have the option to perform a restart. Hence, users should perform the restart at their own will from the start menu.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-6784045969687339882?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/6784045969687339882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/startupsease-has-been-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6784045969687339882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6784045969687339882'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/startupsease-has-been-released.html' title='Startups@Ease has Been Released'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mVuWlEoAXhc/TG6CdjwOktI/AAAAAAAAAB0/65QEAbGzt-U/s72-c/main.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-1771439644689883725</id><published>2010-08-07T19:45:00.004+03:00</published><updated>2010-08-10T06:02:01.253+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='myths and facts'/><category scheme='http://www.blogger.com/atom/ns#' term='account lockout'/><title type='text'>Is an Account Lockout Policy Really Worth It</title><content type='html'>I strongly agree with Jesper Johansson and Steve Riley with their point of view on account lockouts in which they have mentioned in the book that they have published many years ago, &lt;a href="http://www.amazon.com/Protect-Your-Windows-Network-Perimeter/dp/0321336437"&gt;&lt;span id="btAsinTitle"&gt;Protect Your Windows Network: From Perimeter to Data&lt;/span&gt;&lt;/a&gt;. Here is a transcript of what they have written in page 344:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;The authors consider that account lockout not only provides no positive security value, but actually decreases security. As we showed earlier, only really poor passwords can be guessed successfully. Thus, the real problem if a guessing attack succeeds is really poor passwords not lack of account lockout. Turning on account lockout does not make the passwords any stronger, and a sophisticated attacker will tailor the attack to work around any account lockout settings. Hence the claim that it provides no security value.&lt;br /&gt;&lt;br /&gt;Worse than not doing any good, however, is the fact that account lockout is harmful. It can obviously be used by an attacker in a very easy denial-of-service attack to lock out every single account on the system, rendering the system unusable. Now consider if this were to happen to your Web server it would not be much of a "server" any longer. Moreover, it is highly likely that the account lockout settings are tripped accidentally. For example, almost all vulnerability scanners will trip account lockout settings, resulting in entire data centers being disabled. Finally, even if there is a timeout to the lockout, users will generally call the help desk when their account no longer works.&lt;br /&gt;....&lt;br /&gt;&lt;/blockquote&gt;The authors then continue to describe the futility of account lockouts from a risk management point of view. Even though, the reasons that they have provided more than 5 years ago are fairly convincing, today there is a far more important reason why you need to disable account lockout across your network. A large amount of malware today perform dictionary attacks to break account passwords. The most notorious among them, is the conficker worm which has affected tens of millions of computer last year and is still a problematic infection today.&lt;br /&gt;&lt;br /&gt;Earlier last year, I was called to assist in an emergency downadup outbreak at a financial institute. What was found is that despite only less than 4% of the machines were affected, it was these 4% that caused a major downtime to the whole business and thousands of employees were not able to get any work done because they cannot log on their machines. The reason was very simple, these small percentage of downadup-ridden machines tried to guess the passwords of every other machine across the network. The institute had to disable the account lockout policy&lt;br /&gt;in order for the business to start functioning again and employees getting back to work. Thanks to account lockout, the institute suffered financially  more from this harmful policy more then the mere existence of the malware itself.&lt;br /&gt;&lt;br /&gt;I greatly advise that the risk management team of every company that has a windows network to revisit the account lockout policy. Instead, I do recommend that failed logon attempts are logged and a warning message such as an email is sent to notify network administrators after a certain amount of failed logons have been attempted.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-1771439644689883725?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/1771439644689883725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/on-issue-of-account-lockout.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1771439644689883725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1771439644689883725'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/08/on-issue-of-account-lockout.html' title='Is an Account Lockout Policy Really Worth It'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-1165276031454728734</id><published>2010-05-26T16:12:00.006+03:00</published><updated>2010-05-28T14:48:52.837+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='myths and facts'/><category scheme='http://www.blogger.com/atom/ns#' term='vulnerability assessment'/><title type='text'>Existance of Malware = Vulnerable to Targeted Attacks</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CUsers%5CAbdo%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CUsers%5CAbdo%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CUsers%5CAbdo%5CAppData%5CLocal%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;ZH-TW&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;    &lt;w:usefelayout/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:PMingLiU; 	panose-1:2 2 5 0 0 0 0 0 0 0; 	mso-font-alt:新細明體; 	mso-font-charset:136; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611969 684719354 22 0 1048577 0;} @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-520092929 1073786111 9 0 415 0;} @font-face 	{font-family:"\@PMingLiU"; 	panose-1:2 2 5 0 0 0 0 0 0 0; 	mso-font-charset:136; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611969 684719354 22 0 1048577 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:PMingLiU; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p 	{mso-style-noshow:yes; 	mso-style-priority:99; 	mso-margin-top-alt:auto; 	margin-right:0in; 	mso-margin-bottom-alt:auto; 	margin-left:0in; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:PMingLiU; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;I have came across a couple of companies that tend to focus most of their security strategy in trying to mitigate targeted attacks on their  network and given little attention in protecting their businesses from malware (automated attacks) other than a &lt;a href="http://www.information-age.com/channels/security-and-continuity/features/306456/antivirus-vendors-fighting-a-losing-battle.thtml"&gt;futile reliance&lt;/a&gt; on an updated antivirus. It is true that the impact of targeted attacks on a company is far more greater than existence of automated or commercially spread malware,  for an example some computer got infected with a Zlob trojan. However, if your security vendor's management console reported a single existance of a malware file in any computer in your network, then sadly, the fact is, your business is an easy target of a potential targetted attack regardless of all the security measures or security software/hardware at your business has put in place. With exception to viruses, the existence of malware in the form of a worm, bot, trojan, exploit, rootkit, keylogger, backdoor, spyware, adware, etc. are all indicators that your business is unprotected against spear attacks.&lt;br /&gt;&lt;br /&gt;The reason for this is that targeted attacks use the same techniques as malware to compromise a system but at a more complex level. If it's the purpose of information theft, financial theft, espionage or whatever reason, a professional hacker would attempt to gain access of a business resource either through a vulnerability or by social engineering. Since both techniques are also used by malware, we can compare by examples how targeted attacks and malware utilize these techniques as a vector for accessibility.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;code&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/code&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;1. Social Engineering:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt; &lt;/span&gt;- malware would send a generic &lt;span style=""&gt; &lt;/span&gt;email that would try to influence any user with no particular target. The email may entice the user to download the malicious file by promising them to see the dancing monkeys, celebrities, clothless people, fake news, etc. At worst case, the email may try to add a little genuinity by saying 'from the IT department'. &lt;span style=""&gt; &lt;/span&gt;The &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=storm%20worm%20e-mail%20social%20engineering&amp;amp;um=1&amp;amp;ie=UTF-8&amp;amp;sa=N&amp;amp;tab=iw"&gt;Storm worm&lt;/a&gt; bot and &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=waledac+email+social+engineering&amp;amp;aq=f&amp;amp;aqi=&amp;amp;aql=&amp;amp;oq=&amp;amp;gs_rfai="&gt;Waledac&lt;/a&gt; emails are excellent examples of a typical malware type social engineering. &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;- In contrast, in a targeted attack, the social engineering tactic is a lot more sophisticated. The bad guys will try to collect as much information about their targets, for example through &lt;a href="http://www.theaustralian.com.au/news/nation/social-networking-sites-key-to-net-attacks/story-e6frg6nf-1225856142092"&gt;social-networking sites&lt;/a&gt;.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;The socially-engineered email may likely indicate a target name, such as "Dear Alice", indicate a spoofed source, such as "Bob, IT Manager". &lt;span style=""&gt; &lt;/span&gt;In fact, the recent attack on Google from Chine was mainly accomplished by &lt;a href="http://www.itproportal.com/security/news/article/2010/1/27/google-hackers-used-social-engineering-tricks-carry-out-attacks/"&gt;social engineering&lt;/a&gt;: &lt;/p&gt;  &lt;p style="margin-left: 0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;McAfee’s Chief Technology Officer George Kurtz announced that the hackers used complex social engineering techniques and advanced reconnaissance techniques to specifically target those individuals which had access to sensitive company information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Explaining the tactic used, Kurtz mentioned “Speaking generically, we're seeing a lot more targeted attacks where people focus on [employees with] the highest set of privileges, and then work backwards, gaining access to secondary parties to get to the primary source.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 9pt; line-height: 115%; font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: black;"&gt;Read more: &lt;a href="http://www.itproportal.com/security/news/article/2010/1/27/google-hackers-used-social-engineering-tricks-carry-out-attacks/#ixzz0pDqjEPBR"&gt;http://www.itproportal.com/security/news/article/2010/1/27/google-hackers-used-social-engineering-tricks-carry-out-attacks/#ixzz0pDqjEPBR&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;2. Vulnerabilities:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;- malware would usually exploit operating system or browser vulnerabilities after patch's are released. &lt;span style=""&gt; &lt;/span&gt;For example, the conficker worm tries to spread from one computer to another using an OS vulnerability. Another example, is a variant of the storm worm exploits a vulnerability in internet explorer for drive-by downloads. At some cases malware may sometimes exploit vulnerabilities in flash, java and adobe reader.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;- In a targeted attack, the bad guys would try to exploit vulnerabilities that has been publicly disclosed in virtually every type of software you may have, including winzip, quick time, real player, silverlight, etc.. That is why it is important to have a software such as Secunia PSI to ensure that all your software is up to date. At some cases, the bad guys would exploit a vulnerability before a patch is released or at rare cases, not known of before. This has happened in the recent &lt;span style=""&gt; &lt;/span&gt;hydraq attack as reported here:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;http://www.computerworld.com/s/article/9144938/Microsoft_confirms_IE_zero_day_behind_Google_attack&lt;br /&gt;&lt;br /&gt;In conclusion, as a testbench to assess the security of your network, check if there is any reported malware in any computer in your business. Understand how the malware infected the machine such as email, drive-by downloads, vulnerability, social engineering, etc. and then implement counter measures in order to prevent such malware to re-exist in your business. If your business cannot protect all of your computers from malware infections then definitely your network is vulnerable to an unsophisticated targeted attack. Perhaps your business could be or have been compromised and you may not even know it.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-1165276031454728734?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/1165276031454728734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/05/existance-of-malware-vulnerable-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1165276031454728734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1165276031454728734'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/05/existance-of-malware-vulnerable-to.html' title='Existance of Malware = Vulnerable to Targeted Attacks'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-6246522591392042936</id><published>2010-05-26T15:24:00.006+03:00</published><updated>2010-07-04T07:25:48.547+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='myths and facts'/><title type='text'>Internal Vs. External Attacks Myth</title><content type='html'>After encountering a lot of IT representatives from different companies, I am surprised to find that the majority of them still believe that most of the security breaches originate from inside the company.&lt;br /&gt;Michael Kassner has written an excellent article, definitely worth reading, at the &lt;a href="http://blogs.techrepublic.com.com/security/?p=1606"&gt;Tech Republic&lt;/a&gt; last year on why such a belief no longer applies today. Kassner references the   &lt;a title="csi 2008" href="http://i.cmpnet.com/v2.gocsi.com/pdf/CSIsurvey2008.pdf" target="_blank"&gt;CSI/FBI Computer Crime and Security Survey &lt;/a&gt;&lt;em&gt;&lt;/em&gt;which asks organizations to estimate the percentage of internal attacks they  encountered. The results of survey is displayed in the following graph:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://i.techrepublic.com.com/blogs/2008a.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 449px; height: 188px;" src="http://i.techrepublic.com.com/blogs/2008a.jpg" alt="" border="0" /&gt;&lt;/a&gt;After doing some statistical analysis, the estimated overall average of security breaches that originate from internal attacks is less than &lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold;"&gt;16%&lt;/span&gt;&lt;/span&gt;. The difference is overwhelmingly significant that likely any margin of error such as the "different point of view" 's in Kassner's article would still have little effect in proving contrary beliefs.&lt;br /&gt;Hence, allocating your IT security budget of your organization can be calculated by a simple risk management formula. Let,&lt;br /&gt;E = the average financial impact including losses that may result due to an external attack on your organization. The impact may include financial or information thefts, reputation, loss of productivity, recovery, etc.&lt;br /&gt;I =   the average financial impact including losses that may result due to an  internal attack on your organization.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mVuWlEoAXhc/S_0dPQ2kMQI/AAAAAAAAABs/9r1XggyvKY4/s1600/eq1.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 451px; height: 36px;" src="http://1.bp.blogspot.com/_mVuWlEoAXhc/S_0dPQ2kMQI/AAAAAAAAABs/9r1XggyvKY4/s400/eq1.png" alt="" id="BLOGGER_PHOTO_ID_5475564870011465986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Further readings:&lt;br /&gt;&lt;a href="http://www.pcworld.com/businesscenter/article/147098/insider_threat_exaggerated_study_says_.html"&gt;http://www.pcworld.com/businesscenter/article/147098/insider_threat_exaggerated_study_says_.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-6246522591392042936?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/6246522591392042936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/05/internal-vs-external-attacks-myth.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6246522591392042936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6246522591392042936'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/05/internal-vs-external-attacks-myth.html' title='Internal Vs. External Attacks Myth'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mVuWlEoAXhc/S_0dPQ2kMQI/AAAAAAAAABs/9r1XggyvKY4/s72-c/eq1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-3865607146645973109</id><published>2010-04-11T22:21:00.002+02:00</published><updated>2010-04-11T22:29:44.577+02:00</updated><title type='text'>The Myth of Patch Management</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-520092929 1073786111 9 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:0in; 	margin-left:.5in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:256983714; 	mso-list-type:hybrid; 	mso-list-template-ids:1009419280 -1134636268 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;} @list l0:level1 	{mso-level-start-at:0; 	mso-level-number-format:bullet; 	mso-level-text:-; 	mso-level-tab-stop:none; 	mso-level-number-position:left; 	margin-left:.75in; 	text-indent:-.25in; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:Arial; 	mso-ansi-font-style:italic;} @list l0:level2 	{mso-level-tab-stop:1.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level3 	{mso-level-tab-stop:1.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level4 	{mso-level-tab-stop:2.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level5 	{mso-level-tab-stop:2.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level6 	{mso-level-tab-stop:3.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level7 	{mso-level-tab-stop:3.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level8 	{mso-level-tab-stop:4.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level9 	{mso-level-tab-stop:4.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;From an old video recording of a security session held at Technet:&lt;a href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=991"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;a href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=991"&gt;http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=991&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;i&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;“The Air Force had an environment where they standardized &lt;missingword&gt;, based on a limited number of server build and client build using images and vhd files.. and then they allow them to make another decision. They did a risk assessment of patch delays and came to the following conclusion...&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;i&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;If we delay installation of a patch because we have to test it, then there is a time window between patch download date and install date, of when their machines are vulnerable to attack…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;i&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;and their risk assessment concluded, that getting attacked in that time window, is much more likely than immediately installing the patch and see if an application breaks. That was their risk assessment. So they have done what I have been begging people to do for years. They have turned their patch management over to Microsoft (outsourced it to us). When we issue a patch, they install it right away.”&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoListParagraph" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;span style=""&gt;-&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;      &lt;span style="font-weight: bold;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style="font-weight: bold;" dir="LTR"&gt;&lt;/span&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;span style="font-weight: bold;"&gt;Steve Riley&lt;/span&gt;,  Former Senior Security Strategist - Microsoft Trustworthy Computing&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;Book author of "Protect Your Windows Network, from Perimeter to Data"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;However, there is one point I would disagree with the Air Force. Newly released operating system service packs and IE versions must  be tested in a  business environments first regardless how small or large the business is, and if there is a testing team or not. At the same time, I do not recommend delaying installing those updates. I have seen security experts who test the new service pack updates even for their home environment.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Note: Steve Riley is now with Amazon Cloud Computing. He can be found here: &lt;a href="http://stvrly.wordpress.com/"&gt;http://stvrly.wordpress.com/&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;span style="color: rgb(31, 73, 125);"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-3865607146645973109?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/3865607146645973109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/04/myth-of-patch-management.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3865607146645973109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3865607146645973109'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/04/myth-of-patch-management.html' title='The Myth of Patch Management'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-4661457963296911948</id><published>2010-04-11T18:32:00.004+02:00</published><updated>2010-04-11T22:20:27.425+02:00</updated><title type='text'>Barnes &amp; Noble Sucks! The Rogue Online Bookstore.</title><content type='html'>A very close friend of mine was ordering books online and I asked him to order 2 books (a business book and a windows security book) with him since I couldnt find them in the bookstores in my region. He noticed that the shipping options at Barnes &amp;amp; Noble were very attractive compared to other major online stores. In addition we had a discount coupon. So he decided to try it out and little we did know that the experience we were about to get was extremely horrible.&lt;br /&gt;&lt;br /&gt;During the order the discount coupon was accepted and clearly indicated that $xx was successfully deducted from our total purchase. Everything seems great and placed our order. A day later we received a notification that our order is being shipped. The next day, my friend received an unexpected email from B&amp;amp;N and that's where several problems started to appear.&lt;br /&gt;&lt;br /&gt;He received a no-reply email that one books in the order has been canceled without any justification:&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-520092929 1073786111 9 0 415 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	color:black;} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:#003399; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style=";font-family:&amp;quot;;font-size:10pt;color:black;"   &gt;&lt;blockquote&gt;We apologize, but despite our efforts, we weren't able to fulfill some or all of the items in your order, as noted below. These items have been canceled from your order.&lt;br /&gt;&lt;br /&gt;We apologize for any inconvenience this has caused and look forward to your next visit to Come back and visit anytime at &lt;a href="http://www.bn.com/"&gt;http://www.bn.com&lt;/a&gt;. &lt;/blockquote&gt; &lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;/span&gt;I am not sure why they canceled the shipment of one of the books. I doubt it is availability issues, since all the books we ordered clearly indicated on their website that they are in stock. Anyhow, when my friend reviewed his paypal account, he found that the new B&amp;amp;N transaction charged far more than the total order details on B&amp;amp;N site. There was a clear inconsistency between what they charged for and what they display in thier total purchase details.&lt;br /&gt;We decided to do some calculations and found that the price difference equals to all the discounts that he was entitled to including the members discount. Nevertheless, my friend contacted them to clarify with them why an item was canceled and why they charged more than the B&amp;amp;N account indicates. Four business days has passed and they have not responded. My friend will call them tomorrow morning to straighten things with them. At worst case, we will likely cancel all purchases with them.&lt;br /&gt;&lt;br /&gt;In summary, B&amp;amp;N sucks because:&lt;br /&gt;1. They cancel items in the order without justification or warning&lt;br /&gt;2. They charge more than the total shipment price that they display to you on their website and via email without notification or consent&lt;br /&gt;3. They show that your discount coupons are in use, but once they cancel one of the items without your consent, all your discounts will go as well without your notice.&lt;br /&gt;4. They do not respond to 'customer care' emails.&lt;br /&gt;&lt;br /&gt;Personally, I will stick to Amazon as I have been always been doing, despite their pricy international shipment options. I have purchased over a $1000 worth of books from Amazon, and I am completely satisfied with their excellent and transparent service.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-4661457963296911948?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/4661457963296911948/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/04/barnes-noble-sucks-rogue-online.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4661457963296911948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4661457963296911948'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/04/barnes-noble-sucks-rogue-online.html' title='Barnes &amp; Noble Sucks! The Rogue Online Bookstore.'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-4488468843210333122</id><published>2010-02-28T13:23:00.004+02:00</published><updated>2010-02-28T14:32:55.699+02:00</updated><title type='text'>Beware of Fake Alerts and Antiviruses When Google Searching the recent Chile Earthquake</title><content type='html'>Symantec issued a security response in a &lt;a href="http://www.symantec.com/connect/blogs/massive-earthquake-chile-leads-surge-rogue-antivirus"&gt;blog posting&lt;/a&gt; yesterday stating the following:&lt;br /&gt;&lt;p style="text-align: left;"&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p style="text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;A &lt;a href="http://news.bbc.co.uk/2/hi/americas/8540289.stm" jquery1267354008296="60"&gt;massive earthquake struck near the Chilean city of  Concepcion&lt;/a&gt; in the early hours of the morning of February 27th, 2010. The &lt;a href="http://www.prh.noaa.gov/ptwc/?region=1&amp;amp;id=pacific.2010.02.27.104329" jquery1267354008296="61"&gt;quake measuring 8.8&lt;/a&gt; on the Richter scale was  considerably stronger than the one that recently caused widespread destruction  on the island of Haiti. Fortunately, despite the size of this latest quake, so  far there has been few reported casualties. The quake occurred near the coast  and &lt;a href="http://www.prh.noaa.gov/ptwc/messages/pacific/2010/pacific.2010.02.27.144553.txt" jquery1267354008296="62"&gt;tsumani warnings&lt;/a&gt; were issued for many countries  bordering on the Pacific ocean. Unfortunately as with any major news event,  miscreants are not slow to pounce when such opportunities arise to further their  aims. &lt;/span&gt;&lt;/p&gt;&lt;div style="text-align: left;"&gt; &lt;/div&gt;&lt;p style="text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;Search engine results returned for terms such as “Chile Earthquake” are being  poisoned to lead users to rogue antivirus web sites.&lt;/span&gt;&lt;/p&gt;&lt;p style="text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;.....&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p style="text-align: left;"&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.symantec.com/connect/blogs/massive-earthquake-chile-leads-surge-rogue-antivirus"&gt;http://www.symantec.com/connect/blogs/massive-earthquake-chile-leads-surge-rogue-antivirus&lt;/a&gt;&lt;/p&gt;&lt;p&gt;For further investigation and curiosity, I changed the keywords a little and to my surprise the rogue antivirus webpages are appearing on the first google search page.&lt;/p&gt;&lt;p&gt;Any combination of keywords such as &lt;span style="font-style: italic;"&gt;tsunami&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;santiago&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;chile&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;earthquake&lt;/span&gt;, &lt;span style="font-style: italic;"&gt;pictures&lt;/span&gt;, etc. would display poisoned search results on google. Many of the results appear to be compromised legitimate websites. A small sample of such websites include the following (enter at your own risk):&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;hxxp://papeteriengrosshandel.ch/pap.php?q=santiago-earthquake&lt;br /&gt;hxxp://jashburn.org/pot.php?sell=santiago%20earthquake&lt;br /&gt;hxxp://borderchorders.org/fjn.php?m=santiago%20chile&lt;br /&gt;hxxp://2009.v3lingyue.com/ydx.php?t=santiago%20chile&lt;br /&gt;hxxp://www.cyprusbestcompanies.com/phocadownload/ddo.php?q=usgs+chile+earthquake&lt;br /&gt;hxxp://www.pennbrew.com/index2.php?p=chile-earthquake&lt;br /&gt;hxxp://joaap.org/wuw.php?do=chile%20earthquake%20facts&lt;br /&gt;hxxp://addsisli.org/jxz.php?page=chile%20earthquake%201960%20facts&lt;br /&gt;hxxp://hnhmp.com/xvauhiqo/earthquake23049.php&lt;br /&gt;hxxp://neuromodfound.org/jvv.php?do=chile%20earthquake%202009&lt;br /&gt;hxxp://chinadowntown.com/chi.php?q=chile-tsunami-2010&lt;br /&gt;hxxp://www.nudeyrudey.co.nz/nud.php?q=chile-earthquake-1960&lt;br /&gt;hxxp://bannerdesigns.co.za/ban.php?q=chile-earthquake-1960&lt;br /&gt;hxxp://sbk.com.pl/njenh/sokzp.php?tsunamis-earthquake&lt;br /&gt;hxxp://www.justlite.com/xaftk/gzlk.php?earthquake-tsunami-photos&lt;br /&gt;hxxp://ymc.kr/gjux/fsa.php?california-earthquake-tsunami-possibility&lt;br /&gt;hxxp://theperfumeseller.com/the.php?q=chile-quake-map&lt;br /&gt;hxxp://cpbusa.com/cbp.php?q=earthquake-chile&lt;br /&gt;hxxp://www.mindmakers.nl/26omall/14.php?q=earthquake+worksheeta&lt;br /&gt;hxxp://n.clanstar.org/ykopo.php?c=pictures-of-earthquake-in-chile&lt;br /&gt;hxxp://12a1nhc.com/bxg.php?do=chile%20earthquake%201960%20pictures&lt;br /&gt;hxxp://refinedwebdesigns.com/zgu.php?go=chile%20earthquake%201960%20pictures&lt;br /&gt;hxxp://files.liamfiddler.com/xsy.php?o=earthquake-in-chile-today&lt;br /&gt;hxxp://10500bcfilms.com/ttx.php?in=chile%20earthquake%202010&lt;br /&gt;hxxp://diamond-virgin.net/fdz.php?p=chile%208.8%20earthquake&lt;br /&gt;hxxp://jaredunderwood.com.au/yhy.php?f=recent-earthquake-chile&lt;/p&gt;&lt;p&gt;Each of the above pages would direct users to the following sites which would display fake antivirus alerts:&lt;/p&gt;&lt;p&gt;hxxp://188.124.5.159/index.html&lt;br /&gt;hxxp://188.72.246.99/index.html&lt;/p&gt;&lt;p&gt;hxxp://you22tube.com/?id=103&amp;amp;ids=cb7c54&amp;amp;d=1&amp;amp;s=2&lt;br /&gt;hxxp://www1.dotout-forscan-get.in&lt;br /&gt;hxxp://www1.dotoutfor-scanget.in/&lt;br /&gt;hxxp://www1.letfastscanand-cure.in/&lt;br /&gt;hxxp://www1.dotwin-to-scan-get.in/&lt;br /&gt;hxxp://www1.dotwintoscan-get.in/&lt;br /&gt;hxxp://www1.setfast-scan-and-cure.in&lt;br /&gt;hxxp://scan1.run-spyware-a0.com&lt;br /&gt;hxxp://www1.let-fast-scanandcure.in/&lt;/p&gt;&lt;p&gt;Some of the sites include a payload for unpatched browsers. Additionaly, clicking anywhere on the site would prompt an unwary user to download the installation file for the rogue antivirus.&lt;/p&gt;&lt;p&gt;So far, I have picked up three different variants of malware files from the above pages. Two of the malicious files were reported to MMPC. The third variant was somwhat blocked in my machine.&lt;/p&gt;&lt;p&gt;The first file is currently detected by 11 out of 41 security vendors as shown here: &lt;a href="http://www.virustotal.com/analisis/fabca4efdaf5c89d36e153637fbe92bc130f62812d6261833b073a23240260c8-1267321093"&gt;http://www.virustotal.com/analisis/fabca4efdaf5c89d36e153637fbe92bc130f62812d6261833b073a23240260c8-1267321093&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The second file is detected by only 6 out of 41 security vendors: &lt;a href="http://www.virustotal.com/analisis/6120d00068c7e9c15c664ca0aefbbea6a5e97c589074007635bfffad8ef49e9f-1267350125"&gt;http://www.virustotal.com/analisis/6120d00068c7e9c15c664ca0aefbbea6a5e97c589074007635bfffad8ef49e9f-1267350125&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;All of the above urls have been submitted to malwareurl.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-4488468843210333122?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/4488468843210333122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/02/beware-of-fake-alerts-and-antiviruses.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4488468843210333122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4488468843210333122'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/02/beware-of-fake-alerts-and-antiviruses.html' title='Beware of Fake Alerts and Antiviruses When Google Searching the recent Chile Earthquake'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-205160542581815600</id><published>2010-01-13T16:48:00.002+02:00</published><updated>2010-01-13T17:00:37.592+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware protection'/><category scheme='http://www.blogger.com/atom/ns#' term='iframes'/><title type='text'>The Dangers of Iframe</title><content type='html'>This is old news but something worth blogging about.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;An estimated 5.8 million pages belonging to 640,000 websites were infected with  code designed to launch malware attacks on visitors, according to a report  released Tuesday.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;An estimated 54.8 percent of the attacks observed by Dasient involved malicious  javascript that was injected into compromised sites. iFrames that silently  redirected users to malicious sites came in second at 37.1. Dasient has  cataloged more than 72,000 unique malware infections involving websites.&lt;/span&gt;&lt;/blockquote&gt;Full article from the Register:&lt;a href="http://www.theregister.co.uk/2009/10/27/mass_website_compromises_spike/"&gt; Mass web infections spike to 6 million pages&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The number of legitimate Websites being hacked to host &lt;/span&gt;&lt;a style="font-style: italic;" href="http://www.pcworld.com/businesscenter/article/165029/malwares_newest_threat_fake_urls.html?tk=rel_news" target="_blank"&gt;malware &lt;/a&gt;&lt;span style="font-style: italic;"&gt;has hit startling highs in recent days, new figures  from MessageLabs have revealed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Data taken from the days between May 4 and 8 showed that 84.6 percent of  Websites blocked by the company &lt;/span&gt;&lt;a style="font-style: italic;" href="http://www.pcworld.com/article/162662/are_you_infected_a_smart_and_simple_test.html?tk=rel_news" target="_blank"&gt;for hosting malicious content &lt;/a&gt;&lt;span style="font-style: italic;"&gt;were 'well-established' domains  that have been around for a year or more.&lt;/span&gt;&lt;/blockquote&gt;Full article from PCWorld: &lt;a href="http://www.pcworld.com/businesscenter/article/165014/most_attacks_come_from_legit_but_hijacked_sites.html"&gt;Most Attacks Come from Legit but Hijacked Sites&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Iframe attacks, being a largescale threat is relatively new. In the  past, we used to tell people to surf the internet safely by not to searching or  browsing suspicious websites, porn, cracks, free music/lyrics/movies, gambling,  etc.. Then came along safe search add-ons such as mywot and siteadvisor which  would greatly help people avoid questionable and unsafe sites. However, the  threat webscape today has changed as the bad guys are moving into different  tactics. With the appearance of iframe attacks, the borderline that  distinguishes black and white sites might  no longer be useful. The problem is  that the sites that we completely trust can be vector of getting our  computers infected. Browser security software such web access protection (used  by antiviruses and firewalls) and reputation rating in these cases will no  longer work here. It will protect user from being infected from black sites, but  not from the white sites. Also, there is no way to tell if a legitimate site  contains an iframe unless we look at its page source, since iframes may oftenly  not change the sites appearance or functionality.&lt;br /&gt;&lt;br /&gt;In my opinion the only way  to be protected from a trusted site that happens to have a malicious iframe is  disabling iframes altogether.&lt;br /&gt;For details on how to disable iframes on Internet Explorer, please see:&lt;br /&gt;&lt;a href="http://antivirus.about.com/od/securitytips/ht/ieiframe.htm"&gt;http://antivirus.about.com/od/securitytips/ht/ieiframe.htm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-205160542581815600?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/205160542581815600/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2010/01/dangers-of-iframe.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/205160542581815600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/205160542581815600'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2010/01/dangers-of-iframe.html' title='The Dangers of Iframe'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-6453254421910363979</id><published>2009-12-13T17:22:00.007+02:00</published><updated>2010-01-13T09:56:30.522+02:00</updated><title type='text'>How to tell if an unknown file is a legitimate or a malware file</title><content type='html'>This article is intended mainly for HJT helpers and trainees. Prior knowledge and expertise of the windows OS is required. None of the steps below are 100% accurate. You will need to use multiple steps in this guide order to be able to end up with a confident conclusion.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="Edit-Time-Data" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_editdata.mso"&gt;&lt;!--[if !mso]&gt; &lt;style&gt; v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} &lt;/style&gt; &lt;![endif]--&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves&gt;false&lt;/w:TrackMoves&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step 1&lt;/span&gt;&lt;/b&gt;. there are 4 rules of thumb in which you can immediately know within seconds that the unknown file &lt;span style=""&gt; &lt;/span&gt;is a malware file:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;1) The name of the file or folder is randomly generated or makes absolutely no sense. These type of files would typically display zero results in search engines.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Ex: c:\&lt;span style="color:red;"&gt;p0sdn8flqy.exe &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;2) The malware uses a name that is similar to the name of a legitimate file (commonly windows file) within the same folder.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Ex: legitimate = c:\windows\system32\lsass.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;         &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;malware = C"\windows\system32\&lt;span style="color:red;"&gt;lsasss.exe&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;3) The malware uses the exact name of a legitimate file, commonly a windows file but in another folder.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Ex: legitimate = C:\windows\explorer.exe&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;         &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;malware&lt;span style=""&gt;  &lt;/span&gt;= c:\windows\system32\&lt;span style="color:red;"&gt;explorer.exe&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;4) The malware uses a name that are commonly only used by malware. Ex. startup file names with controversial words somewhere within its name, the names of celebrities, the use of non-alphanumeric characters, or white spaces.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;Ex: c:\windows\system32\&lt;span style="color:red;"&gt;crack.dll&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step 2. &lt;a name='more'&gt;&lt;/a&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt; &lt;/span&gt;Searching the file name or CLSID on &lt;a href="http://www.systemlookup.com/"&gt;www.systemlookup.com&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step 3&lt;/span&gt;&lt;/b&gt;. Using google search for file name, service name, md5 and CLSID. &lt;a href="http://www.uniteagainstmalware.com/schools.php"&gt;UNITE schools&lt;/a&gt; provide an excellent guide on how to use google to identify malware files in diagnostic logs. You will need to join a school to access the guides.&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt;"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step 4&lt;/span&gt;&lt;/b&gt;. Below &lt;span style=""&gt;is a list of websites where you can upload and scan individual files to make sure that they are safe or not:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=""&gt;&lt;a href="http://virscan.org/"&gt;&lt;span style="color:blue;"&gt;http://virscan.org/&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=""&gt;&lt;a href="http://www.virustotal.com/en/indexf.html"&gt;&lt;span style="color:blue;"&gt;http://www.virustotal.com/en/indexf.html&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=""&gt;&lt;a href="http://virusscan.jotti.org/"&gt;&lt;span style="color:blue;"&gt;http://virusscan.jotti.org/&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=""&gt;&lt;a href="http://scanner.virus.org/"&gt;&lt;span style="color:blue;"&gt;http://scanner.virus.org/&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;However, no detections from the antimalware scanners, does not necessarily mean that the file could be safe.. The file could be new malware released to the wild. On the other hand, due to false positives, a legitimate file could be possibly detected by 5 or less antimalware scanners.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step5&lt;/span&gt;&lt;/b&gt;. Disassembling the file and check for hints within the strings of the file. This step would require a bit of an expertise. One simple way to distinguish a legitimate file from a malware is to look for keywords, IP addresses or a web url. The strings would also provide hints on the file functionality and behavior. Most dissassemblers have features to populate the strings in the file.  Examples are &lt;a href="http://www.spybotupdates.biz/files/filealyz-2.0.0.10.exe#hash%28md5:F50A8FA1893DA43CFC4B5557B285D298%29"&gt;Filealyzer 2&lt;/a&gt; and &lt;a href="http://www.heaventools.com/overview.htm"&gt;PE-Explorer&lt;/a&gt;.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;To demonstrate using a dissembler in analyzing a legitimate file, I randomly chose a strange file name that had no description from the drivers folder:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;C:\windows\system32\drivers\&lt;span style="color: rgb(23, 54, 93);"&gt;wssbtr1f.sys&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;A screenshot of the list of strings is shown below:&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mVuWlEoAXhc/SyUHFPrzUcI/AAAAAAAAABc/CHDLaiywmxM/s1600-h/wssbtr1f.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 253px;" src="http://3.bp.blogspot.com/_mVuWlEoAXhc/SyUHFPrzUcI/AAAAAAAAABc/CHDLaiywmxM/s400/wssbtr1f.jpg" alt="" id="BLOGGER_PHOTO_ID_5414741913673880002" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;At one place of the results, it is somewhat related to hardware card. Could be either a PCMCIA or a memory card. Another place it mentions a Bluetooth device. Based on the results, we can conclude that this file is related to a Bluetooth card which is exactly what I have. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;On the other hand, the string results of a malware file would populate malware-related keywords, urls or IP addresses. Example below is the strings list of a P2P worm. This worm uses keywords as shown in the screenshot as a social engineering tactic for attracting new victims.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mVuWlEoAXhc/SyUIS_RfmUI/AAAAAAAAABk/Ofh8xMJFea0/s1600-h/bad22.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 251px;" src="http://2.bp.blogspot.com/_mVuWlEoAXhc/SyUIS_RfmUI/AAAAAAAAABk/Ofh8xMJFea0/s400/bad22.JPG" alt="" id="BLOGGER_PHOTO_ID_5414743249298364738" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Also a file with an .scr extension is an executable. So having a file named AVI.scr or MP4.scr would definitely indicate suspicious behavior.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt;Step 6.&lt;/span&gt;&lt;/b&gt;&lt;span style="line-height: 115%;font-size:12pt;" &gt; &lt;/span&gt;Running the unknown file in a test machine or in a virtual environment and analyze the file and network behaviour. Analysis can be done with a combination of regshot, procmon, netstat, wireshark, tcpview and/or dirmon. However, since most people do not have a test machine or a VM, you can upload the unknown file to an online malware analyzer such as &lt;a href="http://sunbeltsecurity.com/Submit.aspx?type=cwsandbox&amp;amp;cs=A41CD150B37359889A553671CBFD2360"&gt;Sunbeltlabs&lt;/a&gt; &lt;span style=""&gt; &lt;/span&gt;and &lt;a href="http://www.threatexpert.com/"&gt;ThreatExpert&lt;/a&gt;. Within minutes or hours, the online malware analyzer would provide a report that includes; file/folders created, windows registry modifications, network traffic and system modifications. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-6453254421910363979?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/6453254421910363979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/12/how-to-tell-if-unknown-file-is.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6453254421910363979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6453254421910363979'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/12/how-to-tell-if-unknown-file-is.html' title='How to tell if an unknown file is a legitimate or a malware file'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mVuWlEoAXhc/SyUHFPrzUcI/AAAAAAAAABc/CHDLaiywmxM/s72-c/wssbtr1f.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-8890174735921298447</id><published>2009-11-29T10:03:00.002+02:00</published><updated>2009-11-29T14:48:34.098+02:00</updated><title type='text'>Virmansec Event Success!</title><content type='html'>Elhamdulilah, the presentation I gave on conficker at the Microsoft Innovation Center, Riyadh was a success.&lt;br /&gt;&lt;br /&gt;The presentation can be downloaded from here:&lt;br /&gt;&lt;a href="http://staff.kfupm.edu.sa/coe/shafei/downadup.zip"&gt;http://staff.kfupm.edu.sa/coe/shafei/downadup.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The powerpoint slides is mostly pictures and it may not be of much benefit to those who havent attended. However, a lot of the technical information has already been mentioned here this blog. The presentation style was inspired by the best presentation gurus such as:&lt;br /&gt;- bio/intro and overall structure as by&lt;a href="http://www.presentationzen.com/"&gt; Garr Reynolds&lt;/a&gt;&lt;br /&gt;- slides and graphics as by &lt;a href="http://en.wikipedia.org/wiki/Dick_Hardt"&gt;Dick Hardt&lt;/a&gt; and &lt;a href="http://www.sethgodin.com/sg/"&gt;Seth Godin&lt;/a&gt;&lt;br /&gt;- speaking freely as by &lt;a href="http://www.guykawasaki.com/"&gt;Guy Kawasaki&lt;/a&gt;&lt;br /&gt;- walking freely as by &lt;a href="http://stvrly.wordpress.com/"&gt;Steve Riley&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Running the powerpoint will be a bit heavy on a windows OS.  had to optimize my operating system in order for it to run smoothly on a projector with completely no lag. This is what I have done to have a lag-free presentation:&lt;br /&gt;1. Disabled all real-time protection tools including firewall. (assuming you are not connected to the internet)&lt;br /&gt;2. Disabled automatic updates&lt;br /&gt;3. Disabled Task Scheduler via services mmc&lt;br /&gt;4. Disabled screensaver, and all power saving options.&lt;br /&gt;5. Disabled wireless connection and all related processes. (left bluetooth on for my bluetooth mouse/pointer)&lt;br /&gt;6. Disabled all unneccessary processes. In my task manager I had a total of 28 processes left running on an XP machine. I preferred not to disable other OS processes because I had to run a  demo on the same machine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-8890174735921298447?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/8890174735921298447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/virmansec-event-success.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8890174735921298447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8890174735921298447'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/virmansec-event-success.html' title='Virmansec Event Success!'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-467931529175483886</id><published>2009-11-04T11:32:00.002+02:00</published><updated>2009-11-04T14:25:52.830+02:00</updated><title type='text'>Conficker Presentation at Riyadh</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.omnilore.org/images/BetterPresentations.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 250px; height: 181px;" src="http://www.omnilore.org/images/BetterPresentations.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;God willing, I will be doing a presentation at the Microsoft Innovation Center on fighting the Conficker worm. This a highly technical presentation mainly targeted towards enterprise environments.  The presentation includes live demos on infected machines. Microsoft Corporation (MSFT), Virmansec and R-Tech will be sponsoring the event.&lt;br /&gt;The presentation covers all possible techniques in detecting and removing conficker for enterprises.&lt;br /&gt;&lt;br /&gt;Attendance and registration is for free. Snacks and refreshments are also for free. If you are in Riyadh, please take the time to read and register for the event here:&lt;br /&gt;&lt;a href="http://www.eventbrite.com/event/472252520"&gt;http://www.eventbrite.com/event/472252520&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Advanced knowledge about windows NT operating systems and active directory is a must.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-467931529175483886?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/467931529175483886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/conficker-presentation-at-riyadh.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/467931529175483886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/467931529175483886'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/conficker-presentation-at-riyadh.html' title='Conficker Presentation at Riyadh'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-6158963944764797874</id><published>2009-11-02T16:18:00.003+02:00</published><updated>2009-11-03T12:06:34.036+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RMS'/><title type='text'>Server 2008 RMS Installation Problem</title><content type='html'>I spent a few days trying to implement a simulation environment to test windows Rights Management Services and some third-party plugins on a server 2008 native. Every time I attempt to install RMS 2008 I was confronted with the following error message:&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p style="font-weight: bold;" class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote style="color: rgb(255, 0, 0);"&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;&lt;span style="font-size:130%;"&gt; Error: Attempt to configure Active Directory Rights Management Server failed. An error was encountered while trying to provision AD RMS. Remove and re-install AD RMS to attempt provisioning again.&lt;/span&gt;&lt;/p&gt;  &lt;/blockquote&gt;&lt;br /&gt;Despite uninstall/reinstalling the RMS service several times and verifying all the pre-requisites the error message still popped-up. I have followed every single line mentioned in the &lt;a href="http://www.microsoft.com/DOWNLOADS/details.aspx?familyid=A0EA7CD0-7DE7-43A5-B1F9-B4CC679CECB3&amp;amp;displaylang=en"&gt;microsoft guide&lt;/a&gt; but yet the error re-appeared. There were absolutely no log files or events to explain the acause of the error. Also I couldnt find any solution on the internet that worked.&lt;br /&gt;Almost giving up, my partner and I resorted to an unexpected solution..... changing the AD domain name.&lt;br /&gt;RMS 2008 seemed to distaste single lettered domain names such as A.com and B.com that we initially tried to use.  This was a bit strange since RMS 2003 worked fine using these same test domain names.&lt;br /&gt;&lt;br /&gt;So after the changing the domain name to demo.com seemed to work with us in getting rid of the mysterious error message.&lt;br /&gt;&lt;br /&gt;With courtesy of Samer Alotaiby.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-6158963944764797874?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/6158963944764797874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/server-2008-rms-installation-problem.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6158963944764797874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6158963944764797874'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/11/server-2008-rms-installation-problem.html' title='Server 2008 RMS Installation Problem'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-3960174737332662768</id><published>2009-10-21T17:11:00.003+02:00</published><updated>2009-10-21T17:16:36.644+02:00</updated><title type='text'>3,200 Reported Account Hijacking on Facebook,Twitter</title><content type='html'>&lt;blockquote style="font-style: italic;"&gt;If you're on Facebook, Twitter or any other social networking site, you could be the next victim.&lt;br /&gt; That's because more cyberthieves are targeting increasingly popular social networking sites that provide a gold mine of personal information, according to the FBI. Since 2006, nearly 3,200 account hijacking cases have been reported to the Internet Crime Complaint Center, a partnership between the FBI, the National White Collar Crime Center and the Bureau of Justice Assistance&lt;/blockquote&gt;Continue reading:&lt;br /&gt;&lt;a href="http://edition.cnn.com/2009/CRIME/10/19/social.networking.crimes/index.html?iref=mpstoryview"&gt;http://edition.cnn.com/2009/CRIME/10/19/social.networking.crimes/index.html?iref=mpstoryview&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the article:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;blockquote&gt;&lt;b&gt;How to protect yourself against social media scams: &lt;/b&gt;&lt;br /&gt;- Change your passwords frequently&lt;br /&gt;- Adjust Web site privacy settings&lt;br /&gt;- Be selective when adding friends&lt;br /&gt;- Limit access to your profile to contacts you trust&lt;br /&gt;- Disable options such as photo sharing&lt;br /&gt;- Be careful what you click on&lt;br /&gt;- Familiarize yourself with the security and privacy settings&lt;br /&gt;- Learn how to report a compromised account&lt;br /&gt;- Use security software that updates automatically&lt;br /&gt;&lt;br /&gt;(Information provided by FBI and Internet security experts)&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-3960174737332662768?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/3960174737332662768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/3200-reported-account-hijacking-on.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3960174737332662768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3960174737332662768'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/3200-reported-account-hijacking-on.html' title='3,200 Reported Account Hijacking on Facebook,Twitter'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-538798438580714221</id><published>2009-10-21T05:00:00.002+02:00</published><updated>2009-10-21T05:04:12.370+02:00</updated><title type='text'>New Variant of Total Security Locks up Applications on Infected PC's</title><content type='html'>&lt;blockquote style="font-style: italic;"&gt;A new variant of scareware has been detected that not only inundates&lt;br /&gt;users with exhortations to purchase phony antivirus software called&lt;br /&gt;"Total Security 2009," but that also locks users out of nearly all&lt;br /&gt;applications until they purchase the disreputable product.  Once their&lt;br /&gt;PCs are infected with the malware, the only program users can open is&lt;br /&gt;Internet Explorer, so they can navigate to the site and make a purchase.&lt;/blockquote&gt;&lt;br /&gt;More:&lt;br /&gt;&lt;a href="http://blogs.usatoday.com/technologylive/2009/10/new-twist-on-scareware-locks-up-your-pc.html"&gt;http://blogs.usatoday.com/technologylive/2009/10/new-twist-on-scareware-locks-up-your-pc.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pcworld.com/article/173765/a_rogue_demands_a_ransom.html"&gt;http://www.pcworld.com/article/173765/a_rogue_demands_a_ransom.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-538798438580714221?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/538798438580714221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/new-variant-of-total-security-locks-up.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/538798438580714221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/538798438580714221'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/new-variant-of-total-security-locks-up.html' title='New Variant of Total Security Locks up Applications on Infected PC&apos;s'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-3180661386385381690</id><published>2009-10-17T14:46:00.005+02:00</published><updated>2009-10-18T11:56:09.871+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='active directory'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker/Downadup/kido'/><title type='text'>Removing Conficker/Downadup from Your Network Using Active Directory</title><content type='html'>A couple of security companies have provided some neat freeware tools for network administrators to cleanup the downadup worm within their business networks. Some examples of these tools are:&lt;br /&gt;1. &lt;a href="http://support.kaspersky.com/faq/?qid=208279973"&gt;Kaspersky Administration kit &lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://www.bdtools.net/"&gt;Bitdefender Network Removal Tool&lt;/a&gt;&lt;br /&gt;3. &lt;a href="https://secure.sophos.com/products/free-tools/conficker-removal-tool-network/download/"&gt;Sophos Conficker Network Cleanup Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;These tools provide an automated deployment and disinfection for multiple computers at once.&lt;br /&gt;&lt;br /&gt;However, I was called to an enterprise client who was suffering from a Downadup outbreak last May. The client had approximately 4000 computers across 6-8 domains. There was one problem though; since the network tools were not provided by the antivirus vendor they had installed, the client was not comfortable to install any third-party software on their servers. Luckily, they were ok with using the tiny, fast and silent Kaspersky kk.exe program. Now, I had to figure out to run this tool across all the infected machines for each domain.  This is how I did it:&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;First, in each domain I copied the kk.exe into a shared folder. The shared folder could be on any server such as a file server. The accessibility of the shared folder was to &lt;span style="font-weight: bold; font-style: italic;"&gt;everyone&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Second, I created a batch script that can deployed via the active directory:&lt;br /&gt;&lt;blockquote style="font-family: courier new;"&gt;@ECHO OFF&lt;br /&gt;:: batch file made by AbuIbrahim12, Microsoft MVP&lt;br /&gt;:: downadup/kido/conficker/conflicker removal tool&lt;br /&gt;:: restores windows services, removes added policies&lt;br /&gt;color 1F&lt;br /&gt;copy \\{serverName}&lt;servername&gt;\&lt;sharedfolder&gt;{sharedFolder}\kk.exe c:\kk.exe&lt;br /&gt;cd \&lt;br /&gt;start kk.exe -s -x -l C:\VirusReport.txt&lt;br /&gt;sc config wscsvc start= auto&lt;br /&gt;sc config winDefend start= auto&lt;br /&gt;sc config wuauserv start= auto&lt;br /&gt;sc config BITS start= auto&lt;br /&gt;sc config ERSvc start= auto&lt;br /&gt;sc config WerSvc start= auto&lt;br /&gt;sc start wscsvc&lt;br /&gt;sc start WinDefend&lt;br /&gt;sc start wuauserv&lt;br /&gt;sc start BITS&lt;br /&gt;sc start ERSvc&lt;br /&gt;sc start WerSvc &lt;/sharedfolder&gt;&lt;/servername&gt;&lt;/blockquote&gt;Third, I went to the domain controller for every domain and done the following:&lt;br /&gt;Active Directory Users and Computer -&gt; right-click domain name (or 'Users') in the left pane and select &lt;span style="font-weight: bold;"&gt;Properties &lt;/span&gt;-&gt; &lt;span style="font-weight: bold;"&gt;Group Policy&lt;/span&gt; tab -&gt; &lt;span style="font-weight: bold;"&gt;new &lt;/span&gt;-&gt; name the new policy to 'Downadup Script' -&gt; &lt;span style="font-weight: bold;"&gt;edit &lt;/span&gt;-&gt; you can now create either a startup script or a logon script. I prefer using the logon script as not everyone would reboot their computers and there could be some computers that the business would not like to have rebooted.&lt;br /&gt;The logon script can be created as follows:&lt;br /&gt;User Configuration -&gt; Windows Settings -&gt; Scripts -&gt; double-click &lt;span style="font-weight: bold;"&gt;Logon &lt;/span&gt;in the right pane -&gt; Show files -&gt; record the location of the logon folder -&gt; copy and paste the batch file into the logon folder -&gt; close the logon folder -&gt; &lt;span style="font-weight: bold;"&gt;Add &lt;/span&gt;-&gt; browse to the logon folder and add the batch file -&gt; &lt;span style="font-weight: bold;"&gt;ok&lt;/span&gt; -&gt; &lt;span style="font-weight: bold;"&gt;ok &lt;/span&gt;-&gt; close the group policy editor -&gt; &lt;span style="font-weight: bold;"&gt;Apply &lt;/span&gt;&lt;br /&gt;open the command prompt and then type:&lt;span style="font-weight: bold;"&gt; gpupdate /force&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now depending on the severity of the issue, you may want to ask the employees to immediately logoff/logon from/to their machines or at some time later. My client decided to wait until the next day when employees logon into thier machines in the morning. The script would run kk.exe completely unnoticeable in the background with completely no disruption to employee activities as it disinfects the worm-ridden machines.&lt;br /&gt;After 3 days, the 4000 machines were downadup free and the logon script was removed from the active directory.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-3180661386385381690?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/3180661386385381690/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/removing-confickerdownadup-from-your.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3180661386385381690'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3180661386385381690'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/10/removing-confickerdownadup-from-your.html' title='Removing Conficker/Downadup from Your Network Using Active Directory'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-6822593855610846749</id><published>2009-09-26T12:33:00.003+02:00</published><updated>2009-09-26T13:00:45.070+02:00</updated><title type='text'>Investigating New Trends of Rogue Antiviruses - Part 2</title><content type='html'>Besides the randomly named sites that host the rogue antivirus pages, I have also noticed a huge amount of legitimate sites that have been compromised to direct traffic to the rogue antivirus domains.&lt;br /&gt;&lt;br /&gt;Each compromised website contains a folder with a 5 lettered randomly generated name. The folder also contains another randomly generated folder of the same length that contains hundreds of computer generated infected php web pages.&lt;br /&gt;&lt;br /&gt;Examples of the folders found on compromised legitimate sites that I have discovered via google are:&lt;br /&gt;http://kingofthecageskennels.com/hoabe/sueno/&lt;br /&gt;http://trd3tv.net/qiqut/aejpc/&lt;br /&gt;http://markingsstudio.com/ppplc/iyiux/&lt;br /&gt;http://internationalharpmuseum.org/keaeb/qrdaw/&lt;br /&gt;http://romania-ti.com/steuf/sgqrm/&lt;br /&gt;http://bizbuilderswa.org/pmrum/bpakx/&lt;br /&gt;http://mrantasi.com/ljglc/mjqrl/&lt;br /&gt;http://amerilao.org/grano/kpsxm/&lt;br /&gt;http://appliancerepair.tv/bseul/ewsyo/s&lt;br /&gt;http://susancastor.org/czpmf/dihbl/&lt;br /&gt;http://deartes.net/qesbr/sieme/&lt;br /&gt;http://ffseguros.net/zwwzo/ommil/&lt;br /&gt;http://eventsregister.net/cbuga/dykdb/&lt;br /&gt;http://giaitri8x.net/bdrmh/bhusp/&lt;br /&gt;http://alu-vene.com/eiika/zeypc/&lt;br /&gt;http://streetmedia.us/iktdl/ytzcq/&lt;br /&gt;http://butteredhost.com/iwyiw/xdbhc/&lt;br /&gt;http://leadershipsummit.net/tyird/yeirh/&lt;br /&gt;http://vogelrentalproperties.ca/iljqu/daogi/&lt;br /&gt;http://punk-designs.com/uaiyx/tkuif/&lt;br /&gt;http://guard-door.info/fqrna/nyhlh/&lt;br /&gt;http://mortgagecapitalrealty.com/cyzle/ubpnr/&lt;br /&gt;http://endoscopyspecialists.com/kescd/drwiy/&lt;br /&gt;http://californiahistoricalsociety.org/ieeci/skelr&lt;br /&gt;http://uriellaw.com/ilrxb/dxixr&lt;br /&gt;http://elrealsabordecuba.com/lyxei/uolqe/&lt;br /&gt;http://karpovthewreckedtrain.com/epjfw/htgbs/&lt;br /&gt;http://moto-osat.com/npkcg/zuzfj&lt;br /&gt;http://swanjoy.com/ewyqi/fopzi/&lt;br /&gt;http://stevericks.net/yuyrz/tbrdw/&lt;br /&gt;http://costumeoriental.com/lwicu/nghep/&lt;br /&gt;http://kfgroup.net/nbfep/biqni/&lt;br /&gt;http://otroma.com/omhig/flwbi&lt;br /&gt;http://bilikbahasa.com/nsege/olgyf/&lt;br /&gt;http://catasticbritz.com/imgjx/ekquz&lt;br /&gt;http://tomspencerbassin.com/pcuwz/sbous&lt;br /&gt;http://puijonsrknuoret.net/exhcy/sirfa/&lt;br /&gt;http://caflasvegas.org/zeaen/ifpkl/&lt;br /&gt;http://energizardelvalle.com/xisfe/esixm/&lt;br /&gt;&lt;br /&gt;Examples of infected php pages taken from one of the above sites:&lt;br /&gt;http://kingofthecageskennels.com/hoabe/sueno/survivors.php&lt;br /&gt;http://trd3tv.net/qiqut/aejpc/pomegranate.php&lt;br /&gt;&lt;br /&gt;The list of compromised sites continue to grow every hour.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-6822593855610846749?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/6822593855610846749/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/investigating-new-trends-of-rogue_26.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6822593855610846749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/6822593855610846749'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/investigating-new-trends-of-rogue_26.html' title='Investigating New Trends of Rogue Antiviruses - Part 2'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-617397801869283964</id><published>2009-09-26T11:26:00.005+02:00</published><updated>2009-09-26T12:33:16.530+02:00</updated><title type='text'>Investigating New Trends of Rogue Antiviruses - Part 1</title><content type='html'>After being intrigued by the fact that my user name being used as keywords for developing malicious pages, I started investigating further the rogue antivirus pages the past two weeks whenever I had some free time.&lt;br /&gt;&lt;br /&gt;I currently found so far the following main webpages where a lot of infected web pages direct their traffic to:&lt;br /&gt;hxxp://fast-virus-scan7.com&lt;br /&gt;hxxp://myzonesecure.com&lt;br /&gt;hxxp://winfixscanner1.com&lt;br /&gt;hxxp://7removespyware.com&lt;br /&gt;hxxp://onlinesearch-protect.net&lt;br /&gt;hxxp://compurerthreats2.com&lt;br /&gt;hxxp://mytotalscanner.com&lt;br /&gt;hxxp://mytotalscanner17.com&lt;br /&gt;hxxp://mytotalscanner17.com/scan2/video2.php?pid=111&lt;br /&gt;hxxp://protectyourpc-now1.com/pr.cgi?id=2739&lt;br /&gt;hxxp://best-scanpc.net/disk/?code=934&lt;br /&gt;hxxp://check-threats-online.com&lt;br /&gt;&lt;br /&gt;The following domains which are likely bot generated sites that redirects  traffic to the above malware sites:&lt;br /&gt;jntscxwv.cc&lt;br /&gt;hibqeidh.cc&lt;br /&gt;gmfcmdt.cc&lt;br /&gt;ppsjucknp.cc&lt;br /&gt;cqmilpkl.cc&lt;br /&gt;fymhizm.cc&lt;br /&gt;ockdtsahp.cc&lt;br /&gt;srpantlq.cc&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;(Most links are now expired)&lt;br /&gt;&lt;br /&gt;Another variant of Rogue Antiviruses called Antivirus Plus are hosted in the following domains&lt;br /&gt;&lt;cite&gt;ihaerxi.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ikaocy.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;iqevun.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ijobuaw.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;iqoysab.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;iniegox.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;inejayf.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ihouvi.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ilipyw.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ikyadeh.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ilyocij.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ikorate.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ijobuaw.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ijuoxe.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;idoafy.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ikuaxge.cn&lt;br /&gt;&lt;/cite&gt;&lt;cite&gt;ifueme.cn&lt;br /&gt;&lt;/cite&gt;gowyti.cn&lt;br /&gt;&lt;br /&gt;Beware, most of these links are still active.&lt;br /&gt;&lt;cite&gt;&lt;br /&gt;&lt;/cite&gt;The malicious executable files that are hosted on these websites have already been reported to the Microsoft Malware Protection Center. I would like to thank MS for their quick response and creating definitions for all of the submitted samples.&lt;br /&gt;&lt;br /&gt;Information about the malware hosted on these sites are documented here:&lt;br /&gt;&lt;a id="ctl00_pageContent_contentCenter_ctl00_submissionFileGrid_ctl04_HyperLinkThreats" title="TrojanDownloader:Win32/Renos" href="http://www.blogger.com/Threat/Encyclopedia/Entry.aspx?ThreatId=-2147396242"&gt;TrojanDownloader:Win32.Renos&lt;/a&gt;&lt;br /&gt;&lt;a id="ctl00_pageContent_contentCenter_ctl00_submissionFileGrid_ctl04_HyperLinkThreats" title="Trojan:Win32/FakeXPA" href="http://www.blogger.com/Threat/Encyclopedia/Entry.aspx?ThreatId=-2147356977"&gt;Trojan:Win32/FakeXPA&lt;/a&gt;&lt;br /&gt;&lt;a id="ctl00_pageContent_contentCenter_ctl00_submissionFileGrid_ctl05_HyperLinkThreats" title="Trojan:Win32/Yektel.A" href="http://www.blogger.com/Threat/Encyclopedia/Entry.aspx?ThreatId=-2147359504"&gt;Trojan:Win32/Yektel.A&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-617397801869283964?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/617397801869283964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/investigating-new-trends-of-rogue.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/617397801869283964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/617397801869283964'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/investigating-new-trends-of-rogue.html' title='Investigating New Trends of Rogue Antiviruses - Part 1'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-5697519048029796766</id><published>2009-09-06T09:55:00.009+02:00</published><updated>2009-09-15T10:29:22.370+02:00</updated><title type='text'>New Smitfraud Variant</title><content type='html'>I was searching my username today on google and I found a malicious site that uses my username as keywords. The malicious pages includes the following urls:&lt;br /&gt;hxxp://q84.isutv.com/wap715-abuibrahim12.html&lt;br /&gt;hxxp://ps51.isutv.com/wap565-abuibrahim12.html&lt;br /&gt;hxxp://ps51.isutv.com/wap84-cherrytoons.html&lt;br /&gt;hxxp://q84.isutv.com/wap363-query-letter.html&lt;br /&gt;hxxp://ps51.isutv.com/wap780-whippedwomen.html&lt;br /&gt;hxxp://ps51.isutv.com/wap293-dr-emma-starr.html&lt;br /&gt;hxxp://q84.isutv.com/wap561-bnz.html&lt;br /&gt;hxxp://q84.isutv.com/wap895-dmaiv.html&lt;br /&gt;hxxp://q84.isutv.com/wap632-unesco.html&lt;br /&gt;&lt;br /&gt;Each of the pages would redirect you tothe following  rogue antivirus pages:&lt;br /&gt;hxxp://best-virus-scanner4.com/scan1/?pid=111&amp;amp;engine=pHT3zjjyMjE2Mi4xMzEuMjQmdGltZT0xMjUuMIEMPAZO&lt;br /&gt;hxxp://fast-virus-scan9.com/scan1/?pid=111&amp;amp;engine=pHT22jzyMjE2Mi4xMzEuMjQmdGltZT0xMjUuMkEMPAlO&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mVuWlEoAXhc/SqN-C-rEZGI/AAAAAAAAAAo/gAeqo89N2iY/s1600-h/smitfraud.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 413px; height: 306px;" src="http://1.bp.blogspot.com/_mVuWlEoAXhc/SqN-C-rEZGI/AAAAAAAAAAo/gAeqo89N2iY/s320/smitfraud.jpg" alt="" id="BLOGGER_PHOTO_ID_5378280969658983522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The web page displays a classic fake explorer page giving an impression that your hard-disk partitions are being scanned and malware was found in the computer.&lt;br /&gt;Clicking anywhere around the page, will prompt you download a new trojan named Antivirus_111.exe which at the time I write this blog entry has no detections by any antivirus.&lt;br /&gt;&lt;br /&gt;The file when uploaded on VirusTotal, produced the following results:&lt;a name='more'&gt;&lt;/a&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File Antivirus_21_1_.exe received on 2009.09.06 07:48:07 (UTC)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;a-squared&lt;/td&gt;&lt;td&gt;4.5.0.24&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;5.0.0.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;7.9.1.8&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antiy-AVL&lt;/td&gt;&lt;td&gt;2.0.3.7&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;5.1.2.4&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;4.8.1351.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;8.5.0.409&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;7.2&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;10.00&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;0.94.1&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Comodo&lt;/td&gt;&lt;td&gt;2204&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td style="color: red;"&gt;Heur.Packed.Unknown&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;5.0.0.12182&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;7.0.17.0&lt;/td&gt;&lt;td&gt;2009.09.03&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;31.6.6721&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;4.5.1.85&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;8.0.14470.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;3.120.0.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;19&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;T3.1.1.72.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jiangmin&lt;/td&gt;&lt;td&gt;11.0.800&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;K7AntiVirus&lt;/td&gt;&lt;td&gt;7.10.837&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;7.0.0.125&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;6.8.5&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;1.5005&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32&lt;/td&gt;&lt;td&gt;4399&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;6.01.09&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;nProtect&lt;/td&gt;&lt;td&gt;2009.1.8.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;10.0.2.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PCTools&lt;/td&gt;&lt;td&gt;4.4.2.0&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx&lt;/td&gt;&lt;td&gt;3.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;21.45.14.00&lt;/td&gt;&lt;td&gt;2009.09.01&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;4.45.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;3.2.1858.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;1.4.4.12&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;6.3.4.3.396&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;8.950.0.1094&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;3.12.10.10&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;2009.9.4.1919&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;4.6.5.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;Additional information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File size: 167424 bytes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;MD5   : 3aeef8ccec46822d91c97ed92f8a4af2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA1  : 9e310ffad459fe3a10544d6ee78403a3b382891d&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA256: b2d842f4ebf1561429a0d84929ceeda2c7c5a7f850c2fd66ac4fa2ea6b6d6f15&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/b2d842f4ebf1561429a0d84929ceeda2c7c5a7f850c2fd66ac4fa2ea6b6d6f15-1252223287"&gt;http://www.virustotal.com/analisis/b2d842f4ebf1561429a0d84929ceeda2c7c5a7f850c2fd66ac4fa2ea6b6d6f15-1252223287&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Upon executing the file, the following gui appears:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_mVuWlEoAXhc/SqOndEKQBVI/AAAAAAAAAAw/8-_8WiIwOLk/s1600-h/smit2.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 296px; height: 183px;" src="http://2.bp.blogspot.com/_mVuWlEoAXhc/SqOndEKQBVI/AAAAAAAAAAw/8-_8WiIwOLk/s320/smit2.JPG" alt="" id="BLOGGER_PHOTO_ID_5378326497785283922" border="0" /&gt;&lt;/a&gt;The program then automatically installs a fake antivirus called "Total Security":&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mVuWlEoAXhc/SqOoGobY2SI/AAAAAAAAAA4/pFmMnkO9_UI/s1600-h/smit4.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 336px; height: 260px;" src="http://4.bp.blogspot.com/_mVuWlEoAXhc/SqOoGobY2SI/AAAAAAAAAA4/pFmMnkO9_UI/s320/smit4.JPG" alt="" id="BLOGGER_PHOTO_ID_5378327211895478562" border="0" /&gt;&lt;/a&gt;The malware creates the following folders:&lt;br /&gt;c:\program files\common files\&lt;span style="font-weight: bold;"&gt;TSUninstall&lt;/span&gt;&lt;br /&gt;c:\program files\&lt;span style="font-weight: bold;"&gt;TS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It also creates the following file:&lt;br /&gt;C:\WINDOWS\system32\&lt;span style="font-weight: bold;"&gt;iehelpmod.dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The following registry keys have been added:&lt;br /&gt;&lt;br /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}]&lt;br /&gt;&amp;amp;IE Help - C:\WINDOWS\system32\iehelpmod.dll [2009-09-06 335360]&lt;br /&gt;&lt;br /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]&lt;br /&gt;"TS"=C:\Program Files\TS\tsc.exe [2009-09-06 1542176]&lt;br /&gt;&lt;br /&gt;[HKEY_USERS\S-1-5-21-725345543-484763869-1708537768-1003\Software\Microsoft\Windows\CurrentVersion\Uninstall\TS]&lt;br /&gt;&lt;br /&gt;If you attempt to uninstall the rogue antivirus, it will show up the following window in order to lure unwary users to purchase their fake product:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mVuWlEoAXhc/SqOr6q3H1HI/AAAAAAAAABA/57SP00jU8q4/s1600-h/SMITUNINST.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 239px;" src="http://3.bp.blogspot.com/_mVuWlEoAXhc/SqOr6q3H1HI/AAAAAAAAABA/57SP00jU8q4/s320/SMITUNINST.JPG" alt="" id="BLOGGER_PHOTO_ID_5378331404436755570" border="0" /&gt;&lt;/a&gt;I have uploaded the file C:\Program Files\TS\tsc.exe on virustotal which showed that Mcafee is the only antivirus that was able to detect it:&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File tsc.exe received on 2009.09.06 11:48:22 (UTC)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;a-squared&lt;/td&gt;&lt;td&gt;4.5.0.24&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;5.0.0.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;7.9.1.8&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td style="color: red;"&gt;TR/Crypt.ZPACK.Gen&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antiy-AVL&lt;/td&gt;&lt;td&gt;2.0.3.7&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;5.1.2.4&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;4.8.1351.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;8.5.0.409&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;7.2&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;10.00&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;0.94.1&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Comodo&lt;/td&gt;&lt;td&gt;2204&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;5.0.0.12182&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;7.0.17.0&lt;/td&gt;&lt;td&gt;2009.09.03&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;31.6.6721&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;4.5.1.85&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;8.0.14470.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;3.120.0.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;19&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;T3.1.1.72.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jiangmin&lt;/td&gt;&lt;td&gt;11.0.800&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;K7AntiVirus&lt;/td&gt;&lt;td&gt;7.10.837&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;7.0.0.125&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td style="color: red;"&gt;FakeAlert-HP&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td style="color: red;"&gt;FakeAlert-HP&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;6.8.5&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Crypt.ZPACK.Gen&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;1.5005&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32&lt;/td&gt;&lt;td&gt;4399&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;6.01.09&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;nProtect&lt;/td&gt;&lt;td&gt;2009.1.8.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;10.0.2.2&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PCTools&lt;/td&gt;&lt;td&gt;4.4.2.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx&lt;/td&gt;&lt;td&gt;3.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;21.45.14.00&lt;/td&gt;&lt;td&gt;2009.09.01&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;4.45.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;3.2.1858.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;1.4.4.12&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;6.3.4.3.396&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;8.950.0.1094&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;3.12.10.10&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;2009.9.4.1919&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;4.6.5.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;Additional information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File size: 1542176 bytes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;MD5...: 47f48d75791e9ff4831b0e4a553c5569&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA1..: 3a1f8a2186611e0c3bcf53cc650307dd5a6bbe82&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA256: a7173500bd783ef55d520cb4c9cdd235a250437e639ed589ac99855d65324b5f&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;ssdeep: 24576:L6x4SD2YP9PeJaSl2eiaQtXOstG0Bu/SCoIxFViKsSKlRZMXK:G4Si2Op2&lt;br /&gt;TaQtestpiUSaZ&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;http://www.virustotal.com/analisis/a7173500bd783ef55d520cb4c9cdd235a250437e639ed589ac99855d65324b5f-1252237702&lt;br /&gt;&lt;br /&gt;I have also uploaded the associated file &lt;span style="font-weight: bold;"&gt;iehelpmod.dll &lt;/span&gt;&lt;span&gt;on virustotal and no definitions have been created for this trojan yet:&lt;br /&gt;&lt;table border="1"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File iehelpmod.dll received on 2009.09.06 10:43:15 (UTC)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;a-squared&lt;/td&gt;&lt;td&gt;4.5.0.24&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;5.0.0.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;7.9.1.8&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antiy-AVL&lt;/td&gt;&lt;td&gt;2.0.3.7&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;5.1.2.4&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;4.8.1351.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;8.5.0.409&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;7.2&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;10.00&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;0.94.1&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Comodo&lt;/td&gt;&lt;td&gt;2204&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;5.0.0.12182&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;7.0.17.0&lt;/td&gt;&lt;td&gt;2009.09.03&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;31.6.6721&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;4.5.1.85&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;8.0.14470.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;3.120.0.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;19&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;T3.1.1.72.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jiangmin&lt;/td&gt;&lt;td&gt;11.0.800&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;K7AntiVirus&lt;/td&gt;&lt;td&gt;7.10.837&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;7.0.0.125&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;5732&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;6.8.5&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td style="color: red;"&gt;Heuristic.LooksLike.Trojan.FakeAntivirus.I&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;1.5005&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32&lt;/td&gt;&lt;td&gt;4399&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;6.01.09&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;nProtect&lt;/td&gt;&lt;td&gt;2009.1.8.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;10.0.2.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PCTools&lt;/td&gt;&lt;td&gt;4.4.2.0&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx&lt;/td&gt;&lt;td&gt;3.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;21.45.14.00&lt;/td&gt;&lt;td&gt;2009.09.01&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;4.45.0&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;3.2.1858.2&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;1.4.4.12&lt;/td&gt;&lt;td&gt;2009.09.06&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;6.3.4.3.396&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;8.950.0.1094&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;3.12.10.10&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;2009.9.4.1919&lt;/td&gt;&lt;td&gt;2009.09.04&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;4.6.5.0&lt;/td&gt;&lt;td&gt;2009.09.05&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;Additional information&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;File size: 335360 bytes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;MD5...: 5a07fb253ebefadd26d289ccab379a99&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA1..: 0b25e2c20b6e6b08df8f05267710f1ed9325dc32&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4"&gt;SHA256: 73ac8c99e02c5475a55434f574d1ceee0bec2c56e126578fb466fd6f5c6b2c7c&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If you ever get infected with VirusTotal, you can easily get rid of the pest by following these instructions:&lt;br /&gt;&lt;br /&gt;1. end process to tsc.exe in taskmgr&lt;br /&gt;2. close all browsers&lt;br /&gt;3. make sure to view hidden files, system files and extensions within folder options&lt;br /&gt;4. browse and delete the following folders:&lt;br /&gt;c:\program files\common files\&lt;span style="font-weight: bold;"&gt;TSUninstall&lt;/span&gt;&lt;br /&gt;c:\program files\&lt;span style="font-weight: bold;"&gt;TS&lt;br /&gt;&lt;/span&gt;&lt;span&gt;5. Run &lt;a href="http://free.antivirus.com/hijackthis/"&gt;Hijackthis, &lt;/a&gt;and select 'do a system scan only', and then place a checkmark beside each of these entries: &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;O2 - BHO: &amp;amp;IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;O4 - HKCU\..\Run: [TS] C:\Program Files\TS\tsc.exe&lt;/span&gt;&lt;br /&gt;6. Then restart the computer&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A. Elshafei&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-5697519048029796766?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/5697519048029796766/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/new-smitfraud-variant.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5697519048029796766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5697519048029796766'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/09/new-smitfraud-variant.html' title='New Smitfraud Variant'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mVuWlEoAXhc/SqN-C-rEZGI/AAAAAAAAAAo/gAeqo89N2iY/s72-c/smitfraud.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-8269033809524762128</id><published>2009-08-16T10:26:00.009+03:00</published><updated>2009-10-10T13:47:23.859+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='antivirus comparison'/><title type='text'>Which is the best antivirus out there?</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:12;"  &gt;   I have been asked this question almost everyday by friends, family, colleagues, businesses and a lot of people I bump to. As a security expert, I find this question is not that easy to answer. In  my opinion there is no best antivirus software. Each has its own advantages and disadvantages. Also, I tend not to rely on the various antivirus ratings/comparisons performed by third-party organisations and those found on the internet. Though they do repesent accurate results depending on what testbenches they use, but they do not represent an accurate picture of the overall performance/quality of an antivirus software.&lt;br /&gt;&lt;br /&gt;There is so much involved in evaluating an ativirus such as:&lt;br /&gt;1. Detection rates (which most antivirus ratings tend to focus on). For better accuracy, detection rates should depend on the latest or existing malware out there on the internet. It would be pointless to evaluate the detection rate of an antivirus and compare it others using extinct malware samples such as apropos rootkit or even worse using vius samples from the DOS era.&lt;br /&gt;2. Removal capabilities of active malware =&gt; an antivirus with a high detection rate does not necessarily mean that it is capable of removing the infection after it detects it. An antivirus would render useless if it is unable to clean or remove a virus it detects. I have seen this quite often with highly rated antiviruses.&lt;br /&gt;3. False positive considerations&lt;br /&gt;4. Memory and CPU resources and Scan times. People will refrain installing an antivirus if it will hog down thier systems regardless on how much you swear this is the best protection.&lt;br /&gt;5. Rootkit, ADS, MBR detection+removal&lt;br /&gt;6. Cleaning malware registry keys. A couple of antiviruses just remove virus files and leaves all associated registry items intact.&lt;br /&gt;7. For businesses: integration with exchange, SAP, sharepoint, file servers, etc. and whatever is required to meet business needs.&lt;br /&gt;8. Dealing with patched system files and file infectors.&lt;br /&gt;9. How quick an antivirus responds to new threats and zero-day malware.&lt;br /&gt;10. Customer experience with thier support system for either businesses or home (Not that important but worth mentioning).&lt;br /&gt;11. Robustness =&gt; ideally a malware should not cripple or disable the antivirus or tamper with any of its files.&lt;br /&gt;&lt;br /&gt;As a result, you will find the results from one antivirus ratings to another varies at a huge proportions. The top 10 in one rating could be among the last 10 in another rating. For example, NOD32 is rated 3rd best antivirus according to av-comparatives.org. But according, to mtc.sri.com, NOD32 was ranked last from among 30 antiviruses. In AV-test it is ranked 15th.&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;In my opinnion, &lt;a href="http://winnow.oitc.com/AntiVirusPerformance.html"&gt;&lt;span style="color:blue;"&gt;OITC &lt;/span&gt;&lt;/a&gt;ratings provides a better picture among all antivirus ratings. But yet I do not depend on its results to tell which is the best antivirus since it does not evaluate the other criteria I mentioned above such as removal capabilities.&lt;br /&gt;&lt;br /&gt;Anyhow, for those who still greatly beleive in the various antivirus ratings and depend on them on making thier business decisions, I have combined the ratings from the following trusted third-party comparison results:&lt;br /&gt;1. &lt;a href="http://mtc.sri.com/live_data/av_rankings/"&gt;&lt;span style="color:blue;"&gt;http://mtc.sri.com/live_data/av_rankings/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;2. &lt;a href="http://winnow.oitc.com/AntiVirusPerformance.html"&gt;&lt;span style="color:blue;"&gt;http://winnow.oitc.com/AntiVirusPerformance.html&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;3. &lt;a href="http://virusinfo.info/index.php?page=testseng"&gt;&lt;span style="color:blue;"&gt;http://virusinfo.info/index.php?page=testseng&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;4. &lt;a href="http://www.av-comparatives.org/"&gt;&lt;span style="color:blue;"&gt;http://www.av-comparatives.org/comparativesreviews/main-tests&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;5. &lt;a href="http://www.av-test.org/"&gt;&lt;span style="color:blue;"&gt;http://www.av-test.org/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The comparions were combined by averaging the rating from each site and then sorting the averages in an ascending order. Each ratings were given equal weights. Antiviruses that appeared only in a single rating were excluded. The results of averaging those 5 rankings are as follows:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;table class="MsoNormalTable" style="width: 186pt; margin-left: 4.65pt; border-collapse: collapse;" width="248" border="0" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style="height: 15pt;"&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: solid solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Antivir&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Ikarus, F-secure&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;3&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Kaspersky&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;4&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;trustport&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;5&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;escan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;6&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Microsoft&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;7&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Gdata&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;8&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Bitdefender&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;9&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Avg&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;10&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Sophos&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;11&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Secureweb&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;12&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;symantec&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;13&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;esafe&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;14&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;nod32&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;15&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Avast&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;16&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Norman&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;17&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;prevx&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;18&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;mcafee&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;19&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;panda&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;20&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;F-prot&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;21&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Authentuim, VBA32&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;22&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;CAT&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;23&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Trendmicro&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;24&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;DrWeb&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;25&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;k-7 computing&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;26&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;fortinet&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;27&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;ClamAV&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;28&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Ahnlab, Rising, Hacksoft&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;29&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;etrust&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;30&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;sunbelt&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="height: 15pt;"&gt;   &lt;td style="border-style: none solid solid; padding: 0in 5.4pt; width: 48pt; height: 15pt;" width="64" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; text-align: right; line-height: normal;" align="right"&gt;&lt;span style="color:black;"&gt;31&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border-style: none solid solid none; padding: 0in 5.4pt; width: 138pt; height: 15pt;" width="184" nowrap="nowrap" valign="bottom"&gt;   &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"&gt;&lt;span style="color:black;"&gt;Virusbuster&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:12;"  &gt;&lt;br /&gt;Again, I would not take these results as granted. Based on the results of the 5 ranking, Antivir is ranked first. Although Antivir has an impressive detection rates but it had a very bad shortcomming. It wasnt capable of cleaning infected system and legitimate files (file infectors such as Sality). Instead it gave an option of either quarantine or delete the infected system and legtimate files. If you choose either option, your system would be unbootable. Dr. Web on the other hand, is the best antivirus vendor to clean the infected files safely. Dr.Web is the only vendor I would recommend when dealing with file infectors. But yet Dr.Web has its own shortcommings.&lt;br /&gt;&lt;br /&gt;In conclusion, if you are a home user, go for a free antivirus such as AVG and Avira. If you are a corporation, what to select should depend mainly on your business needs. However, I would stay away from any of the security products mentioned &lt;a href="http://www.calendarofupdates.com/updates/index.php?act=calendar&amp;amp;cal_id=1&amp;amp;code=showevent&amp;amp;event_id=44516"&gt;&lt;span style="text-decoration: underline;"&gt;here&lt;/span&gt;&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-8269033809524762128?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/8269033809524762128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/08/which-is-best-antivirus-out-there.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8269033809524762128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8269033809524762128'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/08/which-is-best-antivirus-out-there.html' title='Which is the best antivirus out there?'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-4167208649357005060</id><published>2009-07-28T13:34:00.002+03:00</published><updated>2009-07-28T14:53:23.412+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker/Downadup/kido'/><title type='text'>The Best Freeware Tools to Detect and Remove the Conficker/Downadup/Kido worm</title><content type='html'>In my&lt;a href="http://abuibrahim12.blogspot.com/2009/07/how-to-remove-downadupconfickerkido.html"&gt; previous post&lt;/a&gt; I have talked about how to manually clean and remove the downadup worm. I wrote that article back in March, 2009 when new variants of downadup started to appear in which antivirus venders haven't yet developed definitions for. However, since mid-April I havent personally encountered any new or unique variants of downadup.  I started to do a quick evaluation of almost all the conflicker removal tools listed here:&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.html?storyid=5860"&gt;http://isc.sans.org/diary.html?storyid=5860&lt;/a&gt;&lt;br /&gt;The tests were made on infected live machines and networks. The results I have found are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;The best downadup detection tool:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Mcafee Conficker Detection Tool: &lt;a href="http://www.mcafee.com/us/enterprise/confickertest.html"&gt;http://www.mcafee.com/us/enterprise/confickertest.html&lt;/a&gt;&lt;br /&gt;This program ROCKS! The only two products from Mcafee that I would recommend every enterprise to have: Secureweb and Mcafee Conficker Detection Tool.&lt;br /&gt;The detection tool requires no installation, very easy to use and extremely fast. I have been using this tool since April after Mcafee fixed a bug in it. Every business that I have recommended the tool to them have highly praised it and love it so much.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;The best downadup removal tool:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have found that the &lt;a href="http://support.kaspersky.com/faq/?qid=208279973" target="_blank"&gt;kaspersky Kido Killer &lt;/a&gt; is the best so far. It requires no installation and no reboot for removal. It is very fast and effective. It has worked with different variants that I have come across offline. Sadly, when I tested the Bitdefender Conflicker removal tool (which I thought was good) on some machines, it did not succesfully remove one of the variants although it did detect it.&lt;br /&gt;&lt;br /&gt;KK.exe has some neat command line that not only removes the infection, it can also restore the windows services that were disabled (does not restore windefender and security center though), restores the display of hidden system files, disables autorun, restore safeboot keys and many more.&lt;br /&gt;&lt;br /&gt;I commonly use the following command line:&lt;br /&gt;&lt;b style="font-weight: bold;"&gt;kk.exe -j -a -x&lt;/b&gt;&lt;span style="font-weight: bold;"&gt; -l report.txt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Windefender and the windows Security center can then be restored by the following command lines:&lt;br /&gt;&lt;b&gt;sc config wscsvc start= auto&lt;br /&gt;sc config winDefend start= auto&lt;br /&gt;sc start wscsvc&lt;br /&gt;sc start WinDefend&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The worst tool I came across was Symantec Downadup removal tool. It took over 6 hours scanning and since I am impatient I gave up and had to abort it. I could not tell if it actually does detect or remove the worm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-4167208649357005060?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/4167208649357005060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/best-freeware-tools-to-detect-and.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4167208649357005060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/4167208649357005060'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/best-freeware-tools-to-detect-and.html' title='The Best Freeware Tools to Detect and Remove the Conficker/Downadup/Kido worm'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-3586596996852569996</id><published>2009-07-18T08:18:00.003+03:00</published><updated>2009-07-18T12:12:52.718+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker/Downadup/kido'/><title type='text'>How to Manually Remove the Downadup/Conficker/Kido Worm</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Tahoma; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:1627400839 -2147483648 8 0 66047 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:black; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: 15.6pt;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:85%;color:black;"   &gt;1. The quickest way to know if a Win 2k, 2k3, XP, Vista or 2k8 machine is infected regardless of the conflicker variant (even if it was a user-mode rookit - such rootikit only hides the dll file and its service key) , is by running this command-line:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost" /v netsvcs&lt;/span&gt;&lt;br /&gt;I use a batch file to do this. Based on the results, you can then detemine the randomly generated name of the windows service of the infection. e.g. abcde. It is usually found at the end of the list. If there is no randomly named service listed then most likely conficker is not there.&lt;br /&gt;&lt;br /&gt;Another quick way to determine if conficker exist, is by running gmer. The results of the quick scan that gmer runs when starting would show that &lt;span style="color: rgb(255, 0, 0);"&gt;C:\windows\system32\svchost.exe&lt;/span&gt; is hidden and highlighted in red. But at the end, you will need to know the service name associated with conficker by going through the netsvcs list.&lt;br /&gt;&lt;br /&gt;2. End process of the svchost.exe associated with netsvc, by using tasklist /svc and taskkill pid&lt;br /&gt;&lt;br /&gt;3. Browse to the following registry key:&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\&lt;span style="font-style: italic;"&gt;abcde&lt;/span&gt;&lt;br /&gt;You may not view the contents of the key since the permissions were removed by the infection.&lt;br /&gt;right-click the abcde key &gt; permission &gt; add &gt; everyone &gt; select full control &gt; ok &gt; F5 to refresh &gt; go to the parameters key and take not the path of the dll&lt;br /&gt;e.g. c:\windows\system32\&lt;span style="font-style: italic;"&gt;wxyz.dll&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;4. Use &lt;a href="http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe"&gt;fixpolicies.exe&lt;/a&gt; to reset policies that were added by the worm, such as disabling viewing system files.&lt;br /&gt;&lt;br /&gt;5. Look for the dll file located at C:\windows\system32\&lt;br /&gt;right-click the dll file &gt; properties &gt; uncheck read-only &gt; ok &gt; then delete the file. If the file cannot be deleted try stopping the service first.&lt;br /&gt;In case you cannot find the file, you will need to use gmer and browse for the file from the files tab. Then use the delete button on the right.&lt;br /&gt;&lt;br /&gt;6. Use the following command-line to delete the service:&lt;br /&gt;&lt;b&gt;sc delete abcde&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;7. Reboot the computer&lt;br /&gt;&lt;br /&gt;8. You can create a batch file to restore the following windows services:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="background: rgb(204, 204, 204) none repeat scroll 0% 0%; margin-bottom: 0.65pt; line-height: 15.6pt; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;"&gt;&lt;span style=";font-family:&amp;quot;;font-size:85%;color:black;"   &gt;sc config wscsvc start= auto&lt;br /&gt;sc config winDefend start= auto&lt;br /&gt;sc config wuauserv start= auto&lt;br /&gt;sc config BITS start= auto&lt;br /&gt;sc config ERSvc start= auto&lt;br /&gt;sc config WerSvc start= auto&lt;br /&gt;sc start wscsvc&lt;br /&gt;sc start WinDefend&lt;br /&gt;sc start wuauserv&lt;br /&gt;sc start BITS&lt;br /&gt;sc start ERSvc&lt;br /&gt;sc start WerSvc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:85%;color:black;"   &gt;&lt;br /&gt;9. Finally, make sure the machines has the latest recommended updates from microsoft:&lt;br /&gt;&lt;a href="http://windowsupdate.microsoft.com/" target="_blank"&gt;http://windowsupdate.microsoft.com&lt;/a&gt;&lt;br /&gt;The most important is that kb958644 is installed.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;A. Elshafei  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-3586596996852569996?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/3586596996852569996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/how-to-remove-downadupconfickerkido.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3586596996852569996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/3586596996852569996'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/how-to-remove-downadupconfickerkido.html' title='How to Manually Remove the Downadup/Conficker/Kido Worm'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-7853478033874960563</id><published>2009-07-11T16:56:00.002+03:00</published><updated>2009-07-11T17:06:12.319+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit detection'/><title type='text'>Detecting and Removing Rootkits in a Nutshell</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Publisher.Document"&gt;&lt;meta name="Generator" content="Microsoft Publisher 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if !mso]&gt; &lt;style&gt; v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} b\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} &lt;/style&gt; &lt;![endif]--&gt;&lt;!--[if pub]&gt;&lt;xml&gt;  &lt;b:publication type="OplPub" oty="68" oh="256"&gt;   &lt;b:ohprintblock priv="30E"&gt;281&lt;/b:OhPrintBlock&gt;   &lt;b:dptlpagedimensions type="OplPt" priv="1211"&gt;    &lt;b:xl priv="104"&gt;7560000&lt;/b:Xl&gt;    &lt;b:yl priv="204"&gt;10692000&lt;/b:Yl&gt;   &lt;/b:DptlPageDimensions&gt;   &lt;b:ohgallery priv="180E"&gt;259&lt;/b:OhGallery&gt;   &lt;b:ohfancyborders priv="190E"&gt;261&lt;/b:OhFancyBorders&gt;   &lt;b:ohcaptions priv="1A0E"&gt;257&lt;/b:OhCaptions&gt;   &lt;b:ohquilldoc priv="200E"&gt;276&lt;/b:OhQuillDoc&gt;   &lt;b:ohmailmergedata priv="210E"&gt;262&lt;/b:OhMailMergeData&gt;   &lt;b:ohcolorscheme priv="220E"&gt;279&lt;/b:OhColorScheme&gt;   &lt;b:dwnextuniqueoid priv="2304"&gt;1&lt;/b:DwNextUniqueOid&gt;   &lt;b:identguid priv="2A07"&gt;0``````````````````````&lt;/b:IdentGUID&gt;   &lt;b:dpgspecial priv="2C03"&gt;5&lt;/b:DpgSpecial&gt;   &lt;b:ctimesedited priv="3C04"&gt;1&lt;/b:CTimesEdited&gt;   &lt;b:nudefaultunitsex priv="4104"&gt;0&lt;/b:NuDefaultUnitsEx&gt;   &lt;b:ohimpositionengine priv="440E"&gt;285&lt;/b:OhImpositionEngine&gt;  &lt;/b:Publication&gt;  &lt;b:printerinfo type="OplPrb" oty="75" oh="281"&gt;   &lt;b:ohcolorsepblock priv="30E"&gt;282&lt;/b:OhColorSepBlock&gt;   &lt;b:opmoutsideprintmode priv="B04"&gt;1&lt;/b:OpmOutsidePrintMode&gt;   &lt;b:finitcomplete priv="1400"&gt;False&lt;/b:FInitComplete&gt;   &lt;b:dpix priv="2203"&gt;0&lt;/b:DpiX&gt;   &lt;b:dpiy priv="2303"&gt;0&lt;/b:DpiY&gt;   &lt;b:dxloverlap priv="2404"&gt;0&lt;/b:DxlOverlap&gt;   &lt;b:dyloverlap priv="2504"&gt;0&lt;/b:DylOverlap&gt;  &lt;/b:PrinterInfo&gt;  &lt;b:colorseperationinfo type="OplCsb" oty="79" oh="282"&gt;   &lt;b:plates type="OplCsp" priv="214"&gt;    &lt;b:oplcsp type="OplCsp" priv="11"&gt;     &lt;b:ecpplate type="OplEcp" priv="213"&gt;      &lt;b:color priv="104"&gt;-1&lt;/b:Color&gt;     &lt;/b:EcpPlate&gt;    &lt;/b:OplCsp&gt;   &lt;/b:Plates&gt;   &lt;b:dzloverprintmost priv="304"&gt;304800&lt;/b:DzlOverprintMost&gt;   &lt;b:cproverprintmin priv="404"&gt;243&lt;/b:CprOverprintMin&gt;   &lt;b:fkeepawaytrap priv="700"&gt;True&lt;/b:FKeepawayTrap&gt;   &lt;b:cprtrapmin1 priv="904"&gt;128&lt;/b:CprTrapMin1&gt;   &lt;b:cprtrapmin2 priv="A04"&gt;77&lt;/b:CprTrapMin2&gt;   &lt;b:cprkeepawaymin priv="B04"&gt;255&lt;/b:CprKeepawayMin&gt;   &lt;b:dzltrap priv="C04"&gt;3175&lt;/b:DzlTrap&gt;   &lt;b:dzlindtrap priv="D04"&gt;3175&lt;/b:DzlIndTrap&gt;   &lt;b:pctcenterline priv="E04"&gt;70&lt;/b:PctCenterline&gt;   &lt;b:fmarksregistration priv="F00"&gt;True&lt;/b:FMarksRegistration&gt;   &lt;b:fmarksjob priv="1000"&gt;True&lt;/b:FMarksJob&gt;   &lt;b:fmarksdensity priv="1100"&gt;True&lt;/b:FMarksDensity&gt;   &lt;b:fmarkscolor priv="1200"&gt;True&lt;/b:FMarksColor&gt;   &lt;b:flinescreendefault priv="1300"&gt;True&lt;/b:FLineScreenDefault&gt;  &lt;/b:ColorSeperationInfo&gt;  &lt;b:textdocproperties type="OplDocq" oty="91" oh="276"&gt;   &lt;b:ohplcqsb priv="20E"&gt;278&lt;/b:OhPlcqsb&gt;   &lt;b:ecpsplitmenu type="OplEcp" priv="A13"&gt;    &lt;b:color&gt;134217728&lt;/b:Color&gt;   &lt;/b:EcpSplitMenu&gt;  &lt;/b:TextDocProperties&gt;  &lt;b:storyblock type="OplPlcQsb" oty="101" oh="278"&gt;   &lt;b:iqsbmax priv="104"&gt;1&lt;/b:IqsbMax&gt;   &lt;b:rgqsb type="OplQsb" priv="214"&gt;    &lt;b:oplqsb type="OplQsb" priv="11"&gt;     &lt;b:qsid priv="104"&gt;3&lt;/b:Qsid&gt;     &lt;b:tomfcopyfitbase priv="80B"&gt;-9999996.000000&lt;/b:TomfCopyfitBase&gt;     &lt;b:tomfcopyfitbase2 priv="90B"&gt;-9999996.000000&lt;/b:TomfCopyfitBase2&gt;    &lt;/b:OplQsb&gt;   &lt;/b:Rgqsb&gt;  &lt;/b:StoryBlock&gt;  &lt;b:colorscheme type="OplSccm" oty="92" oh="279"&gt;   &lt;b:cecp priv="104"&gt;8&lt;/b:Cecp&gt;   &lt;b:rgecp type="OplEcp" priv="214"&gt;    &lt;b:oplecp priv="F"&gt;Empty&lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="111"&gt;     &lt;b:color&gt;16711680&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="211"&gt;     &lt;b:color&gt;52479&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="311"&gt;     &lt;b:color&gt;26367&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="411"&gt;     &lt;b:color&gt;13421772&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="511"&gt;     &lt;b:color&gt;16737792&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="611"&gt;     &lt;b:color&gt;13382502&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;    &lt;b:oplecp type="OplEcp" priv="711"&gt;     &lt;b:color&gt;16777215&lt;/b:Color&gt;    &lt;/b:OplEcp&gt;   &lt;/b:Rgecp&gt;   &lt;b:szschemename priv="618"&gt;Bluebird&lt;/b:SzSchemeName&gt;  &lt;/b:ColorScheme&gt;  &lt;![if pub11]&gt;  &lt;![endif]&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if pub]&gt;&lt;xml&gt;  &lt;b:page type="OplPd" oty="67" oh="265"&gt;   &lt;b:ptlvorigin type="OplPt" priv="511"&gt;    &lt;b:xl&gt;22858575&lt;/b:Xl&gt;    &lt;b:yl&gt;22852950&lt;/b:Yl&gt;   &lt;/b:PtlvOrigin&gt;   &lt;b:oid priv="605"&gt;(`@`````````&lt;/b:Oid&gt;   &lt;b:ohoplwebpageprops priv="90E"&gt;266&lt;/b:OhoplWebPageProps&gt;   &lt;b:ohpdmaster priv="D0D"&gt;263&lt;/b:OhpdMaster&gt;   &lt;b:pgttype priv="1004"&gt;5&lt;/b:PgtType&gt;   &lt;b:ptlvoriginex type="OplPt" priv="1111"&gt;    &lt;b:xl&gt;110183775&lt;/b:Xl&gt;    &lt;b:yl&gt;110178150&lt;/b:Yl&gt;   &lt;/b:PtlvOriginEx&gt;  &lt;/b:Page&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */ @font-face 	{font-family:Georgia; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	panose-1:2 4 5 2 5 4 5 2 3 3; 	mso-font-signature:647 0 0 0 536871071 0;} @font-face 	{font-family:Arial; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	panose-1:2 11 6 4 2 2 2 2 2 4; 	mso-font-signature:31367 -2147483648 8 0 1073742335 -65536;} @font-face 	{font-family:"Times New Roman"; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	panose-1:2 2 6 3 5 4 5 2 3 4; 	mso-font-signature:31367 -2147483648 8 0 1073742335 -65536;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin-right:0pt; 	text-indent:0pt; 	margin-top:0pt; 	margin-bottom:0pt; 	text-align:left; 	font-family:"Times New Roman"; 	mso-default-font-family:"Times New Roman"; 	mso-ascii-font-family:"Times New Roman"; 	mso-latin-font-family:"Times New Roman"; 	mso-greek-font-family:"Times New Roman"; 	mso-cyrillic-font-family:"Times New Roman"; 	mso-armenian-font-family:Sylfaen; 	mso-hebrew-font-family:"Times New Roman"; 	mso-arabic-font-family:"Times New Roman"; 	mso-devanagari-font-family:Mangal; 	mso-bengali-font-family:Vrinda; 	mso-gurmukhi-font-family:Raavi; 	mso-oriya-font-family:Sandnya; 	mso-tamil-font-family:Latha; 	mso-telugu-font-family:Gautami; 	mso-kannada-font-family:Tunga; 	mso-malayalam-font-family:Kartika; 	mso-thai-font-family:"Angsana New"; 	mso-georgian-font-family:Sylfaen; 	mso-hangul-font-family:Batang; 	mso-kana-font-family:"MS Mincho"; 	mso-bopomofo-font-family:PMingLiU; 	mso-han-font-family:SimSun; 	mso-halfwidthkana-font-family:"MS Mincho"; 	mso-syriac-font-family:"Estrangelo Edessa"; 	mso-thaana-font-family:"MV Boli"; 	mso-latinext-font-family:"Times New Roman"; 	font-size:10.0pt; 	color:black; 	mso-font-kerning:14.0pt; 	mso-char-tracking:100%; 	mso-font-width:100%;} ol 	{margin-top:0in; 	margin-bottom:0in; 	margin-left:-2197in;} ul 	{margin-top:0in; 	margin-bottom:0in; 	margin-left:-2197in;} @page 	{mso-hyphenate:auto;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:shapedefaults ext="edit" spidmax="3075" fill="f" fillcolor="white [7]" strokecolor="black [0]"&gt;   &lt;v:fill color="white [7]" color2="white [7]" on="f"&gt;   &lt;v:stroke color="black [0]" color2="white [7]"&gt;    &lt;o:left ext="view" color="black [0]" color2="white [7]"&gt;    &lt;o:top ext="view" color="black [0]" color2="white [7]"&gt;    &lt;o:right ext="view" color="black [0]" color2="white [7]"&gt;    &lt;o:bottom ext="view" color="black [0]" color2="white [7]"&gt;    &lt;o:column ext="view" color="black [0]" color2="white [7]"&gt;   &lt;/v:stroke&gt;   &lt;v:shadow color="#ccc [4]"&gt;   &lt;v:textbox inset="2.88pt,2.88pt,2.88pt,2.88pt"&gt;   &lt;o:colormenu ext="edit" fillcolor="blue [1]" strokecolor="black [0]" shadowcolor="#ccc [4]"&gt;  &lt;/o:shapedefaults&gt;&lt;o:shapelayout ext="edit"&gt;   &lt;o:idmap ext="edit" data="1"&gt;  &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: Georgia; color: rgb(51, 51, 51);" lang="en-US"&gt;** FOR HJT HELPERS&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: Georgia; color: rgb(51, 51, 51);" lang="en-US"&gt;&lt;span style=""&gt;                 &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: Georgia; color: rgb(51, 51, 51);" lang="en-US"&gt;Categorizing the rootkit detection and removal method is solely based on my personal opinion. I will appreciate any feedback or reports of inaccuracies, fallacies, found in this article: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: Georgia; color: rgb(51, 51, 51);" lang="en-US"&gt;&lt;span style=""&gt;                 &lt;/span&gt;abuibrahim&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: Arial; color: rgb(51, 51, 51);" lang="en-US"&gt;&lt;span dir="ltr"&gt;&lt;/span&gt;0 &lt;/span&gt;&lt;span style="font-size: 9pt; font-family: Georgia; color: rgb(51, 51, 51);" lang="en-US"&gt;&lt;span style=""&gt;  &lt;/span&gt;AT&lt;span style=""&gt;    &lt;/span&gt;gmail&lt;span style=""&gt;    &lt;/span&gt;DOT&lt;span style=""&gt;    &lt;/span&gt;com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="" lang="en-US"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Georgia; 	panose-1:2 4 5 2 5 4 5 2 3 3; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman"; 	color:black; 	mso-font-kerning:14.0pt;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	mso-themecolor:hyperlink; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Important Guidelines Before Removing a Rootkit if a rootkit is found on a machine:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;  &lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;1. Backup all important data, emails, documents, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 27pt; text-indent: -27pt;"&gt;&lt;span style="font-family: Symbol; color: rgb(51, 51, 51);" lang="X-NONE"&gt;&lt;/span&gt;Þ &lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;this is just for safety measures. Removing a rootkit can cause system instability and a antirootkit software may sometimes remove a system file along with the rootkit. This step is particular important when using automatic tools for rooktit detections and removal.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Disconnect from the internet&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Close down All Scheduling/Updating + Running Background tasks etc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Disable real-time monitoring programs&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;5. When scanning for a rootkit, do not use the computer at all&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;6. Use 2 or more rootkit scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 27pt; text-indent: -27pt;"&gt;&lt;span style="font-family: Symbol; color: rgb(51, 51, 51);" lang="X-NONE"&gt;Þ&lt;/span&gt; &lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Never rely on the results of one anti-rootkit software. Rootkits uses different technologies for hiding and no single anti-rootkit can find all rookit techniques.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Methods of Detecting and Removing Rootkits:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Automatic Detection and Removal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Semi-automatic&lt;span style=""&gt;  &lt;/span&gt;Detection and Removal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Manual&lt;span style=""&gt;  &lt;/span&gt;Detection and Removal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Advanced&lt;span style=""&gt;  &lt;/span&gt;Detection and Removal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1) Automatic Detection and Removal:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Tools that automates the process of detecting a rootkit and removes them. Minimal skills are required to uses these tools.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Examples:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. F-secure online scan: &lt;a href="http://support.f-secure.com/enu/home/ols.shtml"&gt;http://support.f-secure.com/enu/home/ols.shtml&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. AVG antirootkit&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Trend-micro Rootkit Buster&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Panda Antirootkit&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;5. Avira Antirootkit&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;6. Mcafee Rootkit Detective&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;7. Sophos Antirootkit&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Disadvantage of using these Automated tools:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Highly unstable software. Have used it once at the rootkit revelations forum and it destroyed windows beyond repair&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Highly unpredicatable -&gt; they sometimes report that they remove a rootkit and they actually did nothing&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Highly unreliable -&gt; cannot find rootkits that use newer techniques.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;The automatic tools are good though if you are removing the most popular or classic rootkits such as pe386.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2) Semi-automatic Detection and Removal:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- For more experienced users&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- You will need to distinguish rootkits from false positives&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Such tools will highlight entries that are predicted to be rootkits. For example Icesword and GMER will highlight services and processes that are rootkits. RKunhooker will tag what are hidden.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Examples:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1.&lt;span style=""&gt;  &lt;/span&gt;GMER &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Icesword&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Rootkit Unhooker&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Darkspy&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;5. SVV&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;6. VICE&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;7. RootRepeal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Detection and Removal are split into two ways:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Rookits that use drivers (more common):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Two important indicators are: hidden service, and rootkit files. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Rootkit files can be found at processes list (ex. Icesword), SSDT list (ex Icesword), rootkit file scan (ex. GMER), rootkit file browsing (ex. Darkspy) or from the service image path in the registry.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Rootkit Removal steps:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step1: Stop or Disable Service&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step2: End executable process(s) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step3: Delete service and related files&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Rootkits that use inline hooking or DLL hooking such as Vanquish (less common):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- One important indicator: presence of a dll file&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;The dll file can be found by two ways: "Code Hook" scan using RKunhooker (recommended), the other way is doing a full file scan using GMER or any other anti-rootkit tool&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Note: GMER and Icesword do not automatically find these kind of rookits. Only when a full file scan is performed or rootkit file browsing, some hidden files may appear.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Also &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Removal steps:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step1: perform "Code Hook" scan using RKunhooker &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step2: highlight all entries related to culprit dll file and click 'unhook selected'&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step3: End executable related process(s) if applicable (ex. vanquish.exe)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Step4: Delete dll and related files&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;            &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;br /&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3) Manual Detection and Removal:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-family: Symbol; color: rgb(51, 51, 51);" lang="X-NONE"&gt;¨&lt;/span&gt; &lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; Manual Detection Tools:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. RootkitRevealer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Rootkit Hook Analyzer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Sysprot&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;For how to know if there is a rootkit present in the rootkitrevealer results: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://abuibrahim12.blogspot.com/2009/07/does-my-rootkitrevealer-log-show.html"&gt;http://abuibrahim12.blogspot.com/2009/07/does-my-rootkitrevealer-log-show.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;To know how to intepret rootkitrevealer logs:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://forum.sysinternals.com/forum_posts.asp?TID=2408&amp;amp;PN=1"&gt;http://forum.sysinternals.com/forum_posts.asp?TID=2408&amp;amp;PN=1&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;/span&gt;&lt;span style="font-family: Symbol; color: rgb(51, 51, 51);" lang="X-NONE"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-family: Symbol; color: rgb(51, 51, 51);" lang="X-NONE"&gt;¨&lt;/span&gt; &lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Manual Removal Methods:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Manually deleting files in safe mode &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;»&lt;/span&gt;&lt;span style=""&gt; given that the rootkit does not use SafeBoot keys to be hidden in safe mode as well&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. DOS commands&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;»&lt;/span&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;span style=""&gt;may or may not work. HackerDefender can be completely deactivated and cleaned up using this method&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;such as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Sc&lt;span style=""&gt;  &lt;/span&gt;stop&lt;span style=""&gt;  &lt;/span&gt;RKservice&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Sc&lt;span style=""&gt;  &lt;/span&gt;delete&lt;span style=""&gt;  &lt;/span&gt;RKservice&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Net &lt;span style=""&gt; &lt;/span&gt;stop&lt;span style=""&gt;  &lt;/span&gt;RKservice&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in;"&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;REG DELETE RKregpath&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Manual Removal Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Delete on reboot using killbox&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Avenger &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- Combofix&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;In combofix the &lt;span style=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: blue;"&gt;rootkit::&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; directive is not always needed. I found that &lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: blue;"&gt;file::&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;, &lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: blue;"&gt;driver::&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; and &lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: blue;"&gt;killall::&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; are enough with most rootkits I have encountered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4) Advanced Detection and Removal:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Slaving hard-drive to another computer and perform a normal anti-virus scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Using a Bootable CD-ROM such as BartPE and UBCD4Win&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. Offline file comparisons:&lt;span style=""&gt;  &lt;/span&gt;&lt;a href="http://abuibrahim12.blogspot.com/2009/07/detecting-rootkits-in-windows.html"&gt;http://abuibrahim12.blogspot.com/2009/07/detecting-rootkits-in-windows.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;MBR Rootkits:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- &lt;/span&gt;&lt;u&gt;&lt;span style=""&gt;Detection&lt;/span&gt;&lt;/u&gt;&lt;span style=""&gt;:&lt;span style=""&gt;  &lt;/span&gt;see &lt;a href="http://www2.gmer.net/mbr/"&gt;http://www2.gmer.net/mbr/&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;as you can observe the presence of the phrase: "&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Courier New&amp;quot;; color: rgb(51, 51, 51);"&gt;\Device\Harddisk0\DR0&lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;" any where in a GMER log is an indication of an MBR rootkit regardless of its variant. However, you may need to verify first that changes done to MBR is not perfomed by a legitimate application such as acronis.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;- &lt;/span&gt;&lt;u&gt;&lt;span style=""&gt;Removal&lt;/span&gt;&lt;/u&gt;&lt;span style=""&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;1. Windows Recovery Console:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Windows XP/2k: &lt;span style=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span style=""&gt;fixmbr&lt;/span&gt;&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Windows Vista:&lt;span style=""&gt;    &lt;/span&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;i&gt;&lt;span style=""&gt;bootrec.exe /fixmbr&lt;/span&gt;&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. Stealth MBR rootkit detector 0.2.2 by Gmer:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www2.gmer.net/mbr/mbr.exe"&gt;http://www2.gmer.net/mbr/mbr.exe&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. ESET Mebroot Remover:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.eset.cz/download/emebremover"&gt;http://www.eset.cz/download/emebremover&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;          &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Recommended readings:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.securityfocus.com/infocus/1850"&gt;http://www.securityfocus.com/infocus/1850&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://safecomputing.umn.edu/guides/scan_unhackme.html"&gt;http://safecomputing.umn.edu/guides/scan_unhackme.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.5starsupport.com/tutorial/rootkits.htm"&gt;http://www.5starsupport.com/tutorial/rootkits.htm&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.microsoft.com/technet/sysinternals/utilities/rootkitrevealer.html"&gt;http://www.microsoft.com/technet/sysinternals/utilities/rootkitrevealer.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;A. Elshafei&lt;/span&gt;&lt;/p&gt;  &lt;span style="" lang="en-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;p&gt;&lt;/p&gt;   &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-7853478033874960563?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/7853478033874960563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/detecting-and-removing-rootkits-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/7853478033874960563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/7853478033874960563'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/detecting-and-removing-rootkits-in.html' title='Detecting and Removing Rootkits in a Nutshell'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-5637602471572369495</id><published>2009-07-07T13:35:00.002+03:00</published><updated>2009-07-07T13:41:03.913+03:00</updated><title type='text'>Guidelines Before Responding to Hijackthis Logs</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Georgia; 	panose-1:2 4 5 2 5 4 5 2 3 3; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman"; 	color:black; 	mso-font-kerning:14.0pt;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:#0066FF; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;br /&gt;** FOR HJT HELPERS ONLY **&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;When replying to a hijackthis log either it is a practice log or a live log, you will need to do the following actions in order:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;1. The first thing is to make sure that hjt log posted is not an attachment. Do not open the log attachment. Ask the OP to copy and paste the logfile into a new post. A lot of forums have policies that the OP's should post the contents of the log file and not attach files unless requested to do so.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;2. If the user posted an unreadable log or one with spaces in between the entries, have them rescan with HijackThis and when notepad opens, go to "Format" and uncheck "Word Wrap." Otherwise this will waist a lot of time for helpers to read the logfile.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;3. Make sure:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- that hijackthis program used is the latest version &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- the log file is not cut-off (incomplete log)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- hijackthis is not running from a temporary folder&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- the date stamp of the log file is not more than a week old. You can ask the OP to post an updated logfile&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- the OP is authorized to remove files from the company PC &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;- the OP is not being helped at another forum for the &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;same&lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt; log&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Do not assist the OP at all if p2p programs are found within the log or mentioned anywhere by the OP. Request the OP to remove all the P2P programs before proceeding with the cleanup or advising any further instructions. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;         &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;5. If there is any hints from the OP posts/log, or doubt that the OP may not be using a legitimate windows copy, then ask the OP to download and run the MGA diagnostics tool from microsoft to verify that the windows copy is valid. The tool can be downloaded from here:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://download.microsoft.com/download/7/B/1/7B1C3ADA-723B-4CC8-8949-7250397FA9CD/MGADiag.exe"&gt;http://download.microsoft.com/download/7/B/1/7B1C3ADA-723B-4CC8-8949-7250397FA9CD/MGADiag.exe&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;If the windows copy is not legitimate, the thread should be locked immediately. The thread will also be locked if the OP has any cracks or warez to any other commercial software.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Hints of non-legitimate copies could be: wgatray.exe process is running. or If the OP has a very old service pack, like XP no-SP, XP SP1, Vista no-SP, Win 2k SP3. However, XP SP3 is relatively new so an OP with XP SP2 only should not raise an alarm. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;6. If two or more antivirus programs are found, then ask the OP to uninstall one of them. Two antivirus programs are enough to make the computer unusable. So ask the OP to do so before or within the same post when providing malware removal instructions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;         &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;7. If the OP is infected with a malware, then It is a good practice to double-check if the malware is a backdoor+password stealer. In this case you will have to inform the OP about the compromise and to change passwords, contact banks, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;For more information about this, please see: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=3251.msg8988;boardseen#new"&gt;http://spywarehammer.com/simplemachinesforum/index.php?topic=3251.msg8988;boardseen#new&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;8. If there is no firewall or anti-virus &lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=""&gt;and&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=""&gt; the OP does not have a serious infection. Then ask the OP to download, install, update and scan the computer before posting any removal instructions. However, if the OP has by definition a worm, a virus, backdoor, malicious keylogger, botnets, or an unknown malware that uses a service, then it is better to install the anti-virus after removing the malware. Viruses in particular are known to either disrupt, infect or delete anti-virus software especially if they aren't installed yet. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;         &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;9. If the OP has any of the protection programs listed &lt;/span&gt;&lt;/span&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=203.new#new"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span style=""&gt;here&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;, then ask the OP to temporarily disable the real time protection tools when providing instructions for malware removal. Once the malware is removed, remember to re-enable the protections tools. An exception to this is when the malware removal procedure is done in safe mode. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;         &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;10. Once all of the above is cleared, then you can post removal instructions in any form that is applicable, using online scans, manually deleting files, hijackthis fixes, combofix, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;   &lt;span style=""&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-5637602471572369495?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/5637602471572369495/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/guidelines-before-responding-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5637602471572369495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5637602471572369495'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/guidelines-before-responding-to.html' title='Guidelines Before Responding to Hijackthis Logs'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-1548052322901852067</id><published>2009-07-06T12:59:00.003+03:00</published><updated>2009-07-06T13:03:29.068+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware removal'/><title type='text'>Cleaning Up Malware... Manually!</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Georgia; 	panose-1:2 4 5 2 5 4 5 2 3 3; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman"; 	color:black; 	mso-font-kerning:14.0pt;} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:#0066FF; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;** FOR HJT TRAINEES AND BEGINNERS **&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;span style=""&gt;                &lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;After identifying the malware files either through an anti-malware scan or through helper tools, the next thing that comes to action is cleaning them from the system. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;Manual cleanup is divided into the following:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;1. Adware, PUP, foistware and bloatware: &lt;span style=""&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;use add/remove programs if applicable.&lt;span style=""&gt;  &lt;/span&gt;To check whether the unwanted program can be uninstalled, please see:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.bleepingcomputer.com/uninstall/"&gt;http://www.bleepingcomputer.com/uninstall/&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;2. File/Folder deletion: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;In safe mode, simply browse to the suspected files and then delete them. Make sure that the file extensions, hidden and system files are shown before locating the files. Stubborn files may require tools such as &lt;/span&gt;&lt;/span&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=153.0"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span style=""&gt;Killbox&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;, File Assassin, Unlocker, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;3. ADS: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;A third-party tool is needed. You can use Hijackthis ADS removal or LADS software. Make sure that the ADS process is not active before removal. To learn about Alternate Data Streams see this:&lt;span style=""&gt;  &lt;/span&gt;&lt;a href="http://www.bleepingcomputer.com/tutorials/tutorial25.html"&gt;http://www.bleepingcomputer.com/tutorials/tutorial25.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;4. Ending Processes:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; I am not fond of ending processes manually. The only time it is needed is when dealing with rootkits. Task manager always fails so a third-party tool is needed. You can use killbox, hijackthis mult-process killing, icesword, etc.. Hopefully, in safe mode you will not need to end processes. However, if in safe mode a process is active, it is then best to use combofix and other semi-automated tools while in normal mode.&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;5. Win Services: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;To remove a service, you will need to stop it first. Three ways to stop a service without any additional tool:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;a) using &lt;/span&gt;&lt;i&gt;&lt;span style=""&gt;services.msc &lt;/span&gt;&lt;/i&gt;&lt;span style=""&gt;(not recommended since malware may not be listed there)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;b) using &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;sc stop &lt;servicekeyname&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt;&lt;span style=""&gt;  &lt;/span&gt;dos command in windows XP/Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;c) using &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;net stop &lt;servicekeyname&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt;&lt;span style=""&gt;  &lt;/span&gt;dos command in windows 2K/XP/Vista&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Please note that a windows service key name is different than its "display name" and description. HJT helpers should be able to identify the service key names from the display names in hjt logs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;To delete a service, the two easiest ways:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;a) using &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;sc delete &lt;servicekeyname&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt;&lt;span style=""&gt;  &lt;/span&gt;dos command in windows XP/Vista. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;b) using hijackthis delete an NT service option at the misc. tools section.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;NOTE: There are some malware services that cannot be stopped manually. Only in this case, try deleting the service first and then reboot.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;6. Registry keys and entries:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; There are three different ways of deleting or changing an arbitrary (can be located anywhere) registry item without the aid of a third-party tool. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;a)&lt;/span&gt; &lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Using a gui interface through &lt;/span&gt;&lt;i&gt;&lt;span style=""&gt;regedit&lt;/span&gt;&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;b) &lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Using the command-line reg.exe such as &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;reg delete &lt;/span&gt;&lt;/b&gt;&lt;span style=""&gt;or &lt;/span&gt;&lt;b&gt;&lt;span style=""&gt;reg add&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.5in;"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;/span&gt;c) &lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Using scripts via .reg files&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;More information:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.bleepingcomputer.com/tutorials/tutorial44.html"&gt;http://www.bleepingcomputer.com/tutorials/tutorial44.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.bleepingcomputer.com/tutorials/tutorial74.html"&gt;http://www.bleepingcomputer.com/tutorials/tutorial74.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;7. LSP entries:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; a third-party tool is needed such as LSPfix&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://www.bleepingcomputer.com/tutorials/tutorial59.html"&gt;http://www.bleepingcomputer.com/tutorials/tutorial59.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;8. Infected host file:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; you can use mvp hosts to simply replace the bad host file with a much better one. see: &lt;a href="http://www.mvps.org/winhelp2002/hosts.htm"&gt;http://www.mvps.org/winhelp2002/hosts.htm&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;9. DLLs:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; if a dll file does not depend on the rundll32.exe, then it is preferred that they be unregistered before deletion. To unregister a dll, you can use the dos command:&lt;span style=""&gt;  &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;regsvr32&lt;span style=""&gt;    &lt;/span&gt;/u&lt;span style=""&gt;  &lt;/span&gt;&lt;path\baddllname.dll&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;10. R3 entries that cannot be removed by hijackthis: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;use Registrar Lite to delete the key&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;11. Registry with embedded nulls: &lt;span style=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;You will need to use tools such as regdelnull and &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.xs4all.nl/%7Efstaal01/swreg-us.html"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span style=""&gt;SWreg&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;. For more information about embedded nulls, please see:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb897446.aspx"&gt;http://technet.microsoft.com/en-us/sysinternals/bb897446.aspx&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;          &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;12. Infected System Restore files: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;Based on an old Microsoft KB article, it is best to turn off system restore. This&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;will clear up all restore files including the infected ones. Once the entire system is clear from malware by a thorough anti-virus scan, you can then turn on system restore and create a restore point.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=202.0"&gt;http://spywarehammer.com/simplemachinesforum/index.php?topic=202.0&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;13. Policies that have been added by Malware: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;download and run fixpolicies.exe from here:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;a href="http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe"&gt;http://downloads.malwareremoval.com/BillCastner/FixPolicies.exe&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;      &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;b&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;14. Rootkits and MBR infections: &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;please read &lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;Detecting and Removing Rootkits in a Nutshell&lt;/span&gt;&lt;/span&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;br /&gt;   &lt;p class="MsoNormal" style=""&gt;&lt;span style=""&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;A. Elshafei &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-1548052322901852067?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/1548052322901852067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/cleaning-up-malware-manually.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1548052322901852067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/1548052322901852067'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/cleaning-up-malware-manually.html' title='Cleaning Up Malware... Manually!'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-8754029877601348358</id><published>2009-07-05T11:49:00.001+03:00</published><updated>2009-07-05T11:55:26.620+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='outlook'/><title type='text'>How to Import Your Messages from .OST Files</title><content type='html'>The common technique to import messages from .ost files is by first using outlook to export your messages to a .pst file. Then you can import the .pst files directly using the import and export wizard. However, what would happen if you cannot export your ost mail to pst or never had a chance to do so. This is exactly what happened to one of my colleagues at work. His OS died all of a sudden fail due to unknown causes. Safe mode, System restore,  cd windows repair and repair install all didn't work.&lt;br /&gt;&lt;br /&gt;     Anyhow all his files were extracted from the hard-disk including his emails for a clean install. The outlook emails were in the form of pst and ost files. However, the ost file had all of his recent emails.  According to an&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:1; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:variable; 	mso-font-signature:0 0 0 0 0 0;} @font-face 	{font-family:Georgia; 	panose-1:2 4 5 2 5 4 5 2 3 3; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:647 0 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif"; 	mso-fareast-font-family:"Times New Roman"; 	color:black; 	mso-font-kerning:14.0pt;} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:#0066FF; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:Arial; 	mso-bidi-theme-font:minor-bidi;} .MsoPapDefault 	{mso-style-type:export-only; 	margin-bottom:10.0pt; 	line-height:115%;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin-top:0in; 	mso-para-margin-right:0in; 	mso-para-margin-bottom:10.0pt; 	mso-para-margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: 10pt; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; color: black;"&gt;&lt;a href="http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?dg=microsoft.public.outlook.installation&amp;amp;tid=aeee0549-a57e-4530-859c-fc591c073ef7&amp;amp;cat=&amp;amp;lang=&amp;amp;cr=&amp;amp;sloc=&amp;amp;p=1"&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;span style=""&gt;outlook MVP&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size: 9pt; font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; color: rgb(51, 51, 51);"&gt;&lt;span style=""&gt;,&lt;/span&gt;&lt;/span&gt; you cannot import an ost file. Others would recommend that you use a commercial tool to convert the ost file to a pst file.  I developed my own  technique which is far more simpler to import ost messages. It has worked like a charm for my colleague, so you will need to follow these instructions carefully:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;First&lt;/span&gt;, if you already have  set your exchange settings on MS Outlook and had already synchronized with the exchange server, then you will need to export all your current  messages to a pst file. Save this pst file in a safe location to be used afterwards.&lt;br /&gt;If you haven't setup your exchange settings yet, then you will need to do so. Try not to synchronize with the server yet. But incase you do need to synchronize with the server, then you will need to export any new messages that you received during synchronization to pst file so you will not lose them.&lt;br /&gt;NOTE: your current exchange settings should be exactly the same as the exchange settings you had for .ost file that you want to import.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Second&lt;/span&gt;, go to tools =&gt; account settings =&gt; data files =&gt; under file name, look for the outlook.ost file and take note of its full path.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Third&lt;/span&gt;, close outlook and then browse to the folder where the current ost file is located. Copy and paste this ost file in a safe place as a backup in case something goes wrong.  Place the ost file that you would like to backup into the same folder (the ost file that you would like to import should replace the current ost).  Make sure the name of the ost file is outlook.ost&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Fourth&lt;/span&gt;, open outlook and start synchronizing. If successfully, you should be able to restore your emails from the ost files. As for the messages that you already had in your outlook, they can be restored by using the import and export wizard to import the pst file you created and saved earlier.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A. Elshafei&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-8754029877601348358?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/8754029877601348358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/how-to-import-your-messages-from-ost.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8754029877601348358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/8754029877601348358'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/how-to-import-your-messages-from-ost.html' title='How to Import Your Messages from .OST Files'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-5978240526190843375</id><published>2009-07-04T13:59:00.001+03:00</published><updated>2009-07-04T14:08:11.187+03:00</updated><title type='text'>Does my RootkitRevealer log show a Rootkit?</title><content type='html'>Well there isn't much more to add on how to determine rootkits using rootkitrevealer. The authors of rootkitrevealer provide an excellent tutorial on how to use the tool: &lt;a href="http://www.sysinternals.com/Utilities/RootkitRevealer.html"&gt;http://www.sysinternals.com/Utilities/RootkitRevealer.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;But to keep things simple and succinct, here is a good tip on how to detect a rootkit regardless on how many discrepancies and unconfirmed false positives were found:&lt;br /&gt;&lt;br /&gt;Most rootkits register themselves as services in the windows registry. Therefore a rootkit exists if rootkitreveler finds one or more of the following entries:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\xxxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\xxxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\xxxx&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xxxx&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;where xxxx is an arbitrary service name given by the rootkit. So to make this clear, if you find any one of these entries in the rootkitrevealer results, then you have a rootkit. If you have none of these entries in your log then most likely you dont have a rootkit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7500876854249784659-5978240526190843375?l=abuibrahim12.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://abuibrahim12.blogspot.com/feeds/5978240526190843375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/does-my-rootkitrevealer-log-show.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5978240526190843375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7500876854249784659/posts/default/5978240526190843375'/><link rel='alternate' type='text/html' href='http://abuibrahim12.blogspot.com/2009/07/does-my-rootkitrevealer-log-show.html' title='Does my RootkitRevealer log show a Rootkit?'/><author><name>AbuIbrahim12</name><uri>http://www.blogger.com/profile/11442793884116122695</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7500876854249784659.post-4801618810771629828</id><published>2009-07-04T12:55:00.001+03:00</published><updated>2009-07-05T11:58:05.183+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit detection'/><title type='text'>Detecting Rootkits in Windows Millennium/98/95</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CAbdo2%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;AR-SA&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Ac
