MIME-Version: 1.0
Content-Type: multipart/related; boundary="----=_NextPart_01C8A58A.9D092030"

This document is a Single File Web Page, also known as a Web Archive file.  If you are seeing this message, your browser or editor doesn't support Web Archive files.  Please download a browser that supports Web Archive, such as Windows® Internet Explorer®.

------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity.htm
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"

<html xmlns:v=3D"urn:schemas-microsoft-com:vml"
xmlns:o=3D"urn:schemas-microsoft-com:office:office"
xmlns:w=3D"urn:schemas-microsoft-com:office:word"
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml"
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dus-ascii">
<meta name=3DProgId content=3DWord.Document>
<meta name=3DGenerator content=3D"Microsoft Word 12">
<meta name=3DOriginator content=3D"Microsoft Word 12">
<link rel=3DFile-List href=3D"MalwareIdentity_files/filelist.xml">
<!--[if gte mso 9]><xml>
 <o:DocumentProperties>
  <o:Author>xxx</o:Author>
  <o:LastAuthor>xxx</o:LastAuthor>
  <o:Revision>2</o:Revision>
  <o:TotalTime>145</o:TotalTime>
  <o:Created>2008-04-24T02:40:00Z</o:Created>
  <o:LastSaved>2008-04-24T02:40:00Z</o:LastSaved>
  <o:Pages>5</o:Pages>
  <o:Words>1494</o:Words>
  <o:Characters>8522</o:Characters>
  <o:Lines>71</o:Lines>
  <o:Paragraphs>19</o:Paragraphs>
  <o:CharactersWithSpaces>9997</o:CharactersWithSpaces>
  <o:Version>12.00</o:Version>
 </o:DocumentProperties>
</xml><![endif]-->
<link rel=3DdataStoreItem href=3D"MalwareIdentity_files/item0001.xml"
target=3D"MalwareIdentity_files/props0002.xml">
<link rel=3DthemeData href=3D"MalwareIdentity_files/themedata.thmx">
<link rel=3DcolorSchemeMapping href=3D"MalwareIdentity_files/colorschememap=
ping.xml">
<!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:TrackMoves>false</w:TrackMoves>
  <w:TrackFormatting/>
  <w:PunctuationKerning/>
  <w:DrawingGridHorizontalSpacing>5.5 pt</w:DrawingGridHorizontalSpacing>
  <w:DisplayHorizontalDrawingGridEvery>2</w:DisplayHorizontalDrawingGridEve=
ry>
  <w:ValidateAgainstSchemas/>
  <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
  <w:IgnoreMixedContent>false</w:IgnoreMixedContent>
  <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
  <w:DoNotPromoteQF/>
  <w:LidThemeOther>EN-US</w:LidThemeOther>
  <w:LidThemeAsian>X-NONE</w:LidThemeAsian>
  <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript>
  <w:Compatibility>
   <w:BreakWrappedTables/>
   <w:SnapToGridInCell/>
   <w:WrapTextWithPunct/>
   <w:UseAsianBreakRules/>
   <w:DontGrowAutofit/>
   <w:DontUseIndentAsNumberingTabStop/>
   <w:FELineBreak11/>
   <w:WW11IndentRules/>
   <w:DontAutofitConstrainedTables/>
   <w:AutofitLikeWW11/>
   <w:HangulWidthLikeWW11/>
   <w:UseNormalStyleForList/>
  </w:Compatibility>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
  <m:mathPr>
   <m:mathFont m:val=3D"Cambria Math"/>
   <m:brkBin m:val=3D"before"/>
   <m:brkBinSub m:val=3D"--"/>
   <m:smallFrac m:val=3D"off"/>
   <m:dispDef/>
   <m:lMargin m:val=3D"0"/>
   <m:rMargin m:val=3D"0"/>
   <m:defJc m:val=3D"centerGroup"/>
   <m:wrapIndent m:val=3D"1440"/>
   <m:intLim m:val=3D"subSup"/>
   <m:naryLim m:val=3D"undOvr"/>
  </m:mathPr></w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:LatentStyles DefLockedState=3D"false" DefUnhideWhenUsed=3D"true"
  DefSemiHidden=3D"true" DefQFormat=3D"false" DefPriority=3D"99"
  LatentStyleCount=3D"267">
  <w:LsdException Locked=3D"false" Priority=3D"0" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Normal"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"heading 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 7"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 8"/>
  <w:LsdException Locked=3D"false" Priority=3D"9" QFormat=3D"true" Name=3D"=
heading 9"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 7"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 8"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" Name=3D"toc 9"/>
  <w:LsdException Locked=3D"false" Priority=3D"35" QFormat=3D"true" Name=3D=
"caption"/>
  <w:LsdException Locked=3D"false" Priority=3D"10" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Title"/>
  <w:LsdException Locked=3D"false" Priority=3D"1" Name=3D"Default Paragraph=
 Font"/>
  <w:LsdException Locked=3D"false" Priority=3D"11" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtitle"/>
  <w:LsdException Locked=3D"false" Priority=3D"22" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Strong"/>
  <w:LsdException Locked=3D"false" Priority=3D"20" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Emphasis"/>
  <w:LsdException Locked=3D"false" Priority=3D"59" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Table Grid"/>
  <w:LsdException Locked=3D"false" UnhideWhenUsed=3D"false" Name=3D"Placeho=
lder Text"/>
  <w:LsdException Locked=3D"false" Priority=3D"1" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"No Spacing"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 1"/>
  <w:LsdException Locked=3D"false" UnhideWhenUsed=3D"false" Name=3D"Revisio=
n"/>
  <w:LsdException Locked=3D"false" Priority=3D"34" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"List Paragraph"/>
  <w:LsdException Locked=3D"false" Priority=3D"29" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Quote"/>
  <w:LsdException Locked=3D"false" Priority=3D"30" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Quote"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 1"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 2"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 3"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 4"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 5"/>
  <w:LsdException Locked=3D"false" Priority=3D"60" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Shading Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"61" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light List Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"62" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Light Grid Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"63" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 1 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"64" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Shading 2 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"65" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 1 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"66" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium List 2 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"67" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 1 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"68" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 2 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"69" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Medium Grid 3 Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"70" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Dark List Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"71" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Shading Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"72" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful List Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"73" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" Name=3D"Colorful Grid Accent 6"/>
  <w:LsdException Locked=3D"false" Priority=3D"19" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtle Emphasis"/>
  <w:LsdException Locked=3D"false" Priority=3D"21" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Emphasis"/>
  <w:LsdException Locked=3D"false" Priority=3D"31" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Subtle Reference"/>
  <w:LsdException Locked=3D"false" Priority=3D"32" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Intense Reference"/>
  <w:LsdException Locked=3D"false" Priority=3D"33" SemiHidden=3D"false"
   UnhideWhenUsed=3D"false" QFormat=3D"true" Name=3D"Book Title"/>
  <w:LsdException Locked=3D"false" Priority=3D"37" Name=3D"Bibliography"/>
  <w:LsdException Locked=3D"false" Priority=3D"39" QFormat=3D"true" Name=3D=
"TOC Heading"/>
 </w:LatentStyles>
</xml><![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;
	mso-font-charset:2;
	mso-generic-font-family:auto;
	mso-font-pitch:variable;
	mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1107304683 0 0 159 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin-top:0in;
	margin-right:0in;
	margin-bottom:10.0pt;
	margin-left:0in;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;
	text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-noshow:yes;
	mso-style-priority:99;
	color:purple;
	mso-themecolor:followedhyperlink;
	text-decoration:underline;
	text-underline:single;}
p.MsoNoSpacing, li.MsoNoSpacing, div.MsoNoSpacing
	{mso-style-priority:1;
	mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:"";
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
span.a1
	{mso-style-name:a1;
	mso-style-unhide:no;
	color:green;}
span.SpellE
	{mso-style-name:"";
	mso-spl-e:yes;}
span.GramE
	{mso-style-name:"";
	mso-gram-e:yes;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	mso-ascii-font-family:Calibri;
	mso-fareast-font-family:Calibri;
	mso-hansi-font-family:Calibri;}
@page Section1
	{size:8.5in 11.0in;
	margin:.5in .5in .5in .5in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
 /* List Definitions */
 @list l0
	{mso-list-id:44761541;
	mso-list-type:hybrid;
	mso-list-template-ids:-1117734480 1013058106 67698713 67698715 67698703 67=
698713 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:1.0in;
	text-indent:-.25in;}
@list l1
	{mso-list-id:633144754;
	mso-list-type:hybrid;
	mso-list-template-ids:2130745164 1429926920 67698691 67698693 67698689 676=
98691 67698693 67698689 67698691 67698693;}
@list l1:level1
	{mso-level-start-at:0;
	mso-level-number-format:bullet;
	mso-level-text:-;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:"Calibri","sans-serif";
	mso-fareast-font-family:Calibri;
	mso-bidi-font-family:"Times New Roman";}
@list l2
	{mso-list-id:1076509740;
	mso-list-type:hybrid;
	mso-list-template-ids:1016507042 67698703 67698713 67698715 67698703 67698=
713 67698715 67698703 67698713 67698715;}
@list l2:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l3
	{mso-list-id:1259486846;
	mso-list-type:hybrid;
	mso-list-template-ids:-1029541408 -606717024 67698713 67698715 67698703 67=
698713 67698715 67698703 67698713 67698715;}
@list l3:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
@list l4
	{mso-list-id:2100062129;
	mso-list-type:hybrid;
	mso-list-template-ids:-1644254102 1348772340 67698713 67698715 67698703 67=
698713 67698715 67698703 67698713 67698715;}
@list l4:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	margin-left:.75in;
	text-indent:-.25in;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Calibri","sans-serif";}
</style>
<![endif]--><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"2050"/>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1"/>
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple style=3D'tab-interval:.5in'>

<div class=3DSection1>

<p class=3DMsoNoSpacing><span class=3DGramE><b style=3D'mso-bidi-font-weigh=
t:normal'><span
style=3D'font-size:14.0pt'>Advanced malware identification techniques.</spa=
n></b></span><b
style=3D'mso-bidi-font-weight:normal'><span style=3D'font-size:14.0pt'><o:p=
></o:p></span></b></p>

<p class=3DMsoNoSpacing>March 2008</p>

<p class=3DMsoNoSpacing>By Chris Misztur <span style=3D'font-size:8.0pt'>[w=
ww.sync-io.net]</span></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing>Required Tools:</p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri'><span style=3D'mso-l=
ist:
Ignore'>1.<span style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Process Explorer <span style=3D'font-size:8.=
0pt'>[http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx]<o:p></=
o:p></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri'><span style=3D'mso-l=
ist:
Ignore'>2.<span style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span class=3DSpellE>Autoruns</span> <span
style=3D'font-size:8.0pt'>[http://technet.microsoft.com/en-us/sysinternals/=
bb963902.aspx]<o:p></o:p></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri'><span style=3D'mso-l=
ist:
Ignore'>3.<span style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]><span class=3DSpellE>ShellXView</span> <span
style=3D'font-size:8.0pt'>[http://www.nirsoft.net/utils/shexview.html]<o:p>=
</o:p></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri;colo=
r:windowtext'><span
style=3D'mso-list:Ignore'>4.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span></span><![endif]><span class=3DSpellE>Regcleaner</span=
> 4.3 <span
style=3D'font-size:8.0pt'>[</span><span class=3Da1><span style=3D'font-size=
:8.0pt;
mso-bidi-font-family:Arial;color:windowtext'>www.majorgeeks.com/download460=
.html]</span></span><span
class=3Da1><span style=3D'font-size:8.0pt;color:windowtext'><o:p></o:p></sp=
an></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri;colo=
r:windowtext'><span
style=3D'mso-list:Ignore'>5.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span></span><![endif]><span class=3DSpellE><span class=3Da1=
><span
style=3D'mso-bidi-font-family:Arial;color:windowtext'>Catchme</span></span>=
</span><span
class=3Da1><span style=3D'mso-bidi-font-family:Arial;color:windowtext'> </s=
pan></span><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Arial;color:=
windowtext'>[www.gmer.net/<b>catchme</b>.php]</span></span><span
class=3Da1><span style=3D'font-size:8.0pt;color:windowtext'><o:p></o:p></sp=
an></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri;colo=
r:windowtext'><span
style=3D'mso-list:Ignore'>6.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span></span><![endif]><span class=3Da1><span style=3D'mso-b=
idi-font-family:
Arial;color:windowtext'>Streams </span></span><span class=3Da1><span
style=3D'font-size:8.0pt;mso-bidi-font-family:Arial;color:windowtext'>[http=
://www.microsoft.com/technet/sysinternals/FileAndDisk/Streams.mspx]</span><=
/span><span
class=3Da1><span style=3D'font-size:8.0pt;color:windowtext'><o:p></o:p></sp=
an></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri;colo=
r:windowtext'><span
style=3D'mso-list:Ignore'>7.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span></span><![endif]><span class=3DSpellE><span class=3Da1=
><span
style=3D'color:windowtext'>Hijackthis</span></span></span><span class=3Da1>=
<span
style=3D'font-size:8.0pt;color:windowtext'> [http://www.majorgeeks.com/down=
load3155.html]<o:p></o:p></span></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in;text-indent:-.25in;mso-li=
st:l2 level1 lfo2'><![if !supportLists]><span
class=3Da1><span style=3D'font-size:8.0pt;mso-bidi-font-family:Calibri;colo=
r:windowtext'><span
style=3D'mso-list:Ignore'>8.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span></span><![endif]><span class=3Da1><span style=3D'color=
:windowtext'>LSPFIX
</span></span><span class=3Da1><span style=3D'font-size:8.0pt;color:windowt=
ext'>[http://www.majorgeeks.com/download4180.html]<o:p></o:p></span></span>=
</p>

<p class=3DMsoNoSpacing><span class=3Da1><span style=3D'font-size:8.0pt;mso=
-bidi-font-family:
Arial;color:windowtext'><o:p>&nbsp;</o:p></span></span></p>

<p class=3DMsoNoSpacing><span class=3Da1><span style=3D'font-size:8.0pt;mso=
-bidi-font-family:
Arial;color:windowtext'><span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>All
above tools are available at [http://www.sync-io.net/Dl]</span></span><span
style=3D'font-size:8.0pt;mso-bidi-font-family:Arial'><o:p></o:p></span></p>

<p class=3DMsoNoSpacing><span style=3D'font-size:8.0pt'><o:p>&nbsp;</o:p></=
span></p>

<p class=3DMsoNoSpacing><span style=3D'font-size:12.0pt'>Symptoms:<o:p></o:=
p></span></p>

<p class=3DMsoNoSpacing><span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </s=
pan>Surfing
the web is slow, computer performance in general is slow, constant pop ups
advertising software or notifying user that their computer has been infecte=
d.</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><span style=3D'font-size:12.0pt'>Causes:<o:p></o:p>=
</span></p>

<p class=3DMsoNoSpacing><span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </s=
pan>User
has downloaded and ran a malicious piece of code without knowing it.</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><span style=3D'font-size:12.0pt'>Resolution:<o:p></=
o:p></span></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in'><span style=3D'font-size=
:10.0pt'>Before
proceeding you may want to investigate whether you can use System Restore to
restore your computer to a point in time prior to the infection.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>To determine if your system restore
points have not been infected contact chris@sync-io.net.<o:p></o:p></span><=
/p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in'><b style=3D'mso-bidi-fon=
t-weight:
normal'><span style=3D'font-size:9.0pt;color:#00B050'><o:p>&nbsp;</o:p></sp=
an></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.5in'><b style=3D'mso-bidi-fon=
t-weight:
normal'><span style=3D'font-size:9.0pt;color:#00B050'>Any items modified/re=
moved during
this procedure will act as a guide to identifying the malicious software.<o=
:p></o:p></span></b></p>

<p class=3DMsoNoSpacing><span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </s=
pan></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>1.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Kill unwanted processes using task ma=
nager
to regain some control over computer.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in;text-indent:-1.0in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span
class=3DGramE>Run Windows Task Manager and sort the running Processes by Us=
er
Name.</span><span style=3D'mso-spacerun:yes'>&nbsp; </span>Start off by end=
ing
the processes under which Windows is currently logged in under.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>If you do now know whether a proce=
ss is
safe or not, you can try <span class=3DSpellE>Googling</span> the process or
using <a href=3D"http://www.file.net">www.file.net</a> or <a
href=3D"http://www.processlibrary.com">www.processlibrary.com</a> to help y=
ou
make a determination. <span style=3D'mso-spacerun:yes'>&nbsp;&nbsp;</span>N=
ow
check out the running processes of other users.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>If you see anything questionable,
attempt to end it.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Repeat this
procedure with Process Explorer.<span style=3D'mso-spacerun:yes'>&nbsp;
</span>End any RUNDLL32 processes.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in;text-indent:-1.0in'><o:p=
>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>PROCESS NAME ENDED<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>USERNAME</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNormal style=3D'margin-left:148.5pt'>___________________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>_________________</p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>2.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Remove start-up entries using MSCONFI=
G and <span
class=3DSpellE>Autoruns</span>.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in;text-indent:-.25in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>Under
START/Run&#8230; type in MSCONFIG and press OK.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>In the System Configuration Utility
select the Services tab and check the &#8216;Hide All Microsoft Services&#8=
217;
box.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>Scroll through the=
 list
of checked services and uncheck anything questionable.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Next, select the Startup tab.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Again go though the list of Startup
Items and uncheck anything questionable.<span
style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>If you&#8217;re not sure, Go=
ogle
it!<span style=3D'mso-spacerun:yes'>&nbsp; </span>If you receive an access =
denied
error or some sort, make a note of what you unchecked that threw the
error.<span style=3D'mso-spacerun:yes'>&nbsp; </span>This is just another a=
ttempt
by the malware to hide itself.<span style=3D'mso-spacerun:yes'>&nbsp; </spa=
n><span
class=3DGramE>Note that after making any changes in the System Configuration
Utility, a message box will be shown when you reboot your computer.</span><=
span
style=3D'mso-spacerun:yes'>&nbsp; </span>This is normal.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in;text-indent:-.25in'><o:p=
>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>SERVICE
NAME DISABLED<span style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp; </span><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>MANUFACTURER</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><o:p>=
&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>STARTUP
ITEM DISABLED<span style=3D'mso-tab-count:3'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>COMMAND
</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNormal style=3D'margin-left:1.75in;text-indent:-1.75in'><span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>___________=
_______________<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>________=
_______________</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in;text-indent:-.25in'><o:p=
>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in'>Run <span class=3DSpell=
E>Autoruns</span>.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>This procedure applies to all list=
ed
tabs.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Here you are looking for
entries with publishers other than Microsoft.<span
style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>If you find entries with emp=
ty or
questionable publishers, either uncheck them or delete them.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Also look for entries where the Im=
age
Path column is marked &#8216;File not found<span class=3DGramE>:&#8230;</sp=
an>&#8217;.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>These can be safely deleted.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Be careful when deleting unknown
publishers from the Drivers section.<span style=3D'mso-spacerun:yes'>&nbsp;
</span>Unless your computer uses biometric or advanced authentication metho=
ds,
the LSA Providers tab should only contain Microsoft entries.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>The Boot Execute tab should only c=
ontain
an &#8216;Auto Check Utility&#8217; entry.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>TAB NAME<span style=3D'ms=
o-tab-count:
3'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>ENTRY
NAME<span style=3D'mso-tab-count:3'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; </span>PUBLISHER</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp; </span>_____________________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.0in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>3.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Remove unwanted shell extensions from
Windows Explorer.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in;text-indent:-1.25in'><s=
pan
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>Run
<span class=3DSpellE>ShellExView</span> and sort by Company Name.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Search for any empty or questionab=
le
entries, select them and press F7 to disable them from loading with Windows=
.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in;text-indent:-1.25in'><o=
:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>EXTENSION NAME DISABLED<sp=
an
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p; </span>COMPANY
NAME</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNormal style=3D'margin-left:2.0in'>__________________________=
_<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span=
>______________________</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in;text-indent:-1.25in'><o=
:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>4.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Attempt to find any hidden files or
registry entries.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing><span style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp; </span>Run
<span class=3DSpellE>catchme</span>.<span style=3D'mso-spacerun:yes'>&nbsp;
</span>Note any finds below.</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>ENTRY<span style=3D'mso-=
tab-count:
5'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp; </span>PROCESS/SERVICE/AUTOSTART/FILE</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNormal style=3D'margin-left:117.0pt'>________________________=
__<span
style=3D'mso-tab-count:2'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; </span>___________________</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><span style=3D'mso-bidi-font-family:Ca=
libri'><span
style=3D'mso-list:Ignore'>5.<span style=3D'font:7.0pt "Times New Roman"'>&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span></span><![endif]>Attempt to find any alternate streams.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Extract Streams.exe to=
 your
desktop.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Open a command promp=
t.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>In the command prompt type &#8216;=
<span
class=3DSpellE>cd</span> desktop&#8217; and press enter.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Type &#8216;streams &#8211;s %<span
class=3DSpellE>systemdrive</span>%\ &gt; stream.log&#8217; and press enter.=
<span
style=3D'mso-spacerun:yes'>&nbsp; </span>After the command finishes open st=
ream.log
and note any files with streams other than <span class=3DSpellE>Zone.Identi=
fier</span>:$DATA.</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>FILENAME<span style=3D'ms=
o-tab-count:
4'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; </span>STREAM
FOUND</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
___<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
___<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
___<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
___<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
___<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________________</p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>6.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Examine your web browser&#8217;s load=
ed
extensions and add-ons.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Go through the list of=
 your
browser&#8217;s add-ons and ActiveX controls and remove or disable them.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>ADDON/ACTIVEX NAME<span
style=3D'mso-tab-count:4'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
_______</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
_______</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
_______</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
_______</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_________________________=
_______</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Start Process Explorer=
 and
press CTRL+D.<span style=3D'mso-spacerun:yes'>&nbsp; </span>The lower pane =
is now
showing any loaded DLLs.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Sele=
ct IEXPLORE.EXE
(or the infected browser binary) and sort the lower pane by Company Name.<s=
pan
style=3D'mso-spacerun:yes'>&nbsp; </span>Look for any empty or questionable
entries and mark them below.<span style=3D'mso-spacerun:yes'>&nbsp; </span>=
*.dat,
*.nls, *.so files are usually not harmful.<span style=3D'mso-spacerun:yes'>=
&nbsp;
</span>The harmful file types hear are *.<span class=3DSpellE>dll</span>.<s=
pan
style=3D'mso-spacerun:yes'>&nbsp; </span>Location of the file is retrieved =
by
scrolling over the name of the file.</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>NAME<span style=3D'mso-ta=
b-count:
3'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>LOCATION<span
style=3D'mso-tab-count:4'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span>COMPANY</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNormal style=3D'margin-left:1.25in'>_______________<span
style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span>__________________________=
__
<span style=3D'mso-tab-count:1'>&nbsp;&nbsp;&nbsp; </span>_________________=
__________</p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Scan your computer wit=
h <span
class=3DSpellE>Hijackthis</span>.<span style=3D'mso-spacerun:yes'>&nbsp; </=
span>To
obtain help with your output, post it on a <span class=3DSpellE>Hijackthis<=
/span>
forum.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>7.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Remove unwanted software manually or =
with
the help of 3<sup>rd</sup> party tools.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Before continuing, res=
tart
your computer and repeat steps 1 through 6 again.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>You may have already solved your p=
roblem.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Test your computer by surfing the =
web
for 10-15 minutes.<span style=3D'mso-spacerun:yes'>&nbsp; </span>If the pro=
blem
is still occurring, repeating the previous steps will reveal very important
information.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Compare your not=
es to
see what entries were recreated or duplicated after you restarted your
computer.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Identify these entr=
ies by
<span class=3DSpellE>Googling</span> them to reveal the identity of your
infection.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Once you have corr=
elated
your finds with a malicious software name you can Google for &#8216;Remove
Guide for Trojan XXX&#8217;.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Companies such as Syma=
ntec
provide tools for removing specific malicious code.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Also there are many users who have=
 had
the same problem as you and guides have already been created.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Note that some software will still=
 be
visible in Control Panel \ Add/Remove Programs.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Using the uninstall feature of the=
se
products is usually not effective. To remove the entry from Add/Remove Prog=
rams
use <span class=3DSpellE>RegCleaner</span> 4.3.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>If you attempt to delete any files=
 and
you receive errors such as access denied or file in use then you will have =
to
boot your computer into the <span class=3DSpellE>Windowx</span> Repair Cons=
ole
and use the DELETE command from there.<span style=3D'mso-spacerun:yes'>&nbs=
p;
</span>You can also try running LSPFIX to determine if your TCP/IP stack has
been hijacked.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Some malware c=
hooses
to insert itself into the Winsock (API used for communicating between IE and
the TCP/IP stack).</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>8.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Protect your computer from opportunis=
tic
re-infection.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Destroy your System Re=
store
points by turning off System Restore, reboot your computer, and turn System
Restore back on.<span style=3D'mso-spacerun:yes'>&nbsp;&nbsp; </span>Use the
Windows Disk Cleanup utility to remove any traces of temporary files.<span
style=3D'mso-spacerun:yes'>&nbsp; </span>Run <span class=3DSpellE>Regcleane=
r</span>
4.3 and perform a registry clean up.<span style=3D'mso-spacerun:yes'>&nbsp;
</span>Run &#8216;SFC /<span class=3DSpellE>scannow</span>&#8217; to valida=
te
your Windows system files.<span style=3D'mso-spacerun:yes'>&nbsp; </span>Al=
ways
protect your Windows logins with passwords and create Windows login accounts
with least privilege for the less educated users.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:.75in;text-indent:-.25in;mso-l=
ist:
l4 level1 lfo3'><![if !supportLists]><b style=3D'mso-bidi-font-weight:norma=
l'><span
style=3D'mso-bidi-font-family:Calibri'><span style=3D'mso-list:Ignore'>9.<s=
pan
style=3D'font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 </span></span></span></b><![endif]><b
style=3D'mso-bidi-font-weight:normal'>Keep it updated.<o:p></o:p></b></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'>Make sure your Windows=
 Updates
are current and use <span class=3DSpellE>Secunia&#8217;s</span> free Softwa=
re
Inspector <span style=3D'font-size:8.0pt'>[www.secunia.com]</span> to deter=
mine
what applications are out of date on your computer.</p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing style=3D'margin-left:1.25in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><o:p>&nbsp;</o:p></p>

<p class=3DMsoNoSpacing><span style=3D'color:#D9D9D9'>Editions<o:p></o:p></=
span></p>

<p class=3DMsoNoSpacing><span style=3D'color:#D9D9D9'>1<sup>st</sup>.March =
2008<o:p></o:p></span></p>

<p class=3DMsoNoSpacing><span style=3D'color:#D9D9D9'>2<sup>nd</sup>.April =
2008<o:p></o:p></span></p>

</div>

</body>

</html>

------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity_files/item0001.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml

<b:Sources xmlns:b=3D"http://schemas.openxmlformats.org/officeDocument/2006=
/bibliography" xmlns=3D"http://schemas.openxmlformats.org/officeDocument/20=
06/bibliography" SelectedStyle=3D"\APA.XSL" StyleName=3D"APA"/>
------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity_files/props0002.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml

<?xml version=3D"1.0" encoding=3D"UTF-8" standalone=3D"no"?>
<ds:datastoreItem ds:itemID=3D"{E6815EB8-03A9-40C5-B7EA-AF123AF2FB3A}" xmln=
s:ds=3D"http://schemas.openxmlformats.org/officeDocument/2006/customXml"><d=
s:schemaRefs><ds:schemaRef ds:uri=3D"http://schemas.openxmlformats.org/offi=
ceDocument/2006/bibliography"/></ds:schemaRefs></ds:datastoreItem>
------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity_files/themedata.thmx
Content-Transfer-Encoding: base64
Content-Type: application/vnd.ms-officetheme

UEsDBBQABgAIAAAAIQCCirwT+gAAABwCAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbKyRy2rDMBBF
94X+g9C22HK6KKXYzqJJd30s0g8Y5LEtao+ENAnJ33fsuFC6CC10IxBizpl7Va6P46AOGJPzVOlV
XmiFZH3jqKv0++4pu9cqMVADgyes9AmTXtfXV+XuFDApmaZU6Z45PBiTbI8jpNwHJHlpfRyB5Ro7
E8B+QIfmtijujPXESJzxxNB1+SoLRNegeoPILzCKx7Cg8Pv5DCSAmAtYq8czYVqi0hDC4CywRDAH
an7oM9+2zmLj7X4UaT6DF9jNBDO/XGD1P+ov5wZb2A+stkfp4lx/xCH9LdtSay6Tc/7Uu5AuGC6X
t7Rh5r+tPwEAAP//AwBQSwMEFAAGAAgAAAAhAKXWp+fAAAAANgEAAAsAAABfcmVscy8ucmVsc4SP
z2rDMAyH74W9g9F9UdLDGCV2L6WQQy+jfQDhKH9oIhvbG+vbT8cGCrsIhKTv96k9/q6L+eGU5yAW
mqoGw+JDP8to4XY9v3+CyYWkpyUIW3hwhqN727VfvFDRozzNMRulSLYwlRIPiNlPvFKuQmTRyRDS
SkXbNGIkf6eRcV/XH5ieGeA2TNP1FlLXN2Cuj6jJ/7PDMMyeT8F/ryzlRQRuN5RMaeRioagv41O9
kKhlqtQe0LW4+db9AQAA//8DAFBLAwQUAAYACAAAACEAa3mWFoMAAACKAAAAHAAAAHRoZW1lL3Ro
ZW1lL3RoZW1lTWFuYWdlci54bWwMzE0KwyAQQOF9oXeQ2TdjuyhFYrLLrrv2AEOcGkHHoNKf29fl
44M3zt8U1ZtLDVksnAcNimXNLoi38Hwspxuo2kgcxSxs4ccV5ul4GMm0jRPfSchzUX0j1ZCFrbXd
INa1K9Uh7yzdXrkkaj2LR1fo0/cp4kXrKyYKAjj9AQAA//8DAFBLAwQUAAYACAAAACEAlrWt4pYG
AABQGwAAFgAAAHRoZW1lL3RoZW1lL3RoZW1lMS54bWzsWU9v2zYUvw/YdyB0b2MndhoHdYrYsZst
TRvEboceaYmW2FCiQNJJfRva44ABw7phhxXYbYdhW4EW2KX7NNk6bB3Qr7BHUpLFWF6SNtiKrT4k
Evnj+/8eH6mr1+7HDB0SISlP2l79cs1DJPF5QJOw7d0e9i+teUgqnASY8YS0vSmR3rWN99+7itdV
RGKCYH0i13Hbi5RK15eWpA/DWF7mKUlgbsxFjBW8inApEPgI6MZsablWW12KMU08lOAYyN4aj6lP
0FCT9DZy4j0Gr4mSesBnYqBJE2eFwQYHdY2QU9llAh1i1vaAT8CPhuS+8hDDUsFE26uZn7e0cXUJ
r2eLmFqwtrSub37ZumxBcLBseIpwVDCt9xutK1sFfQNgah7X6/W6vXpBzwCw74OmVpYyzUZ/rd7J
aZZA9nGedrfWrDVcfIn+ypzMrU6n02xlsliiBmQfG3P4tdpqY3PZwRuQxTfn8I3OZre76uANyOJX
5/D9K63Vhos3oIjR5GAOrR3a72fUC8iYs+1K+BrA12oZfIaCaCiiS7MY80QtirUY3+OiDwANZFjR
BKlpSsbYhyju4ngkKNYM8DrBpRk75Mu5Ic0LSV/QVLW9D1MMGTGj9+r596+eP0XHD54dP/jp+OHD
4wc/WkLOqm2chOVVL7/97M/HH6M/nn7z8tEX1XhZxv/6wye//Px5NRDSZybOiy+f/PbsyYuvPv39
u0cV8E2BR2X4kMZEopvkCO3zGBQzVnElJyNxvhXDCNPyis0klDjBmksF/Z6KHPTNKWaZdxw5OsS1
4B0B5aMKeH1yzxF4EImJohWcd6LYAe5yzjpcVFphR/MqmXk4ScJq5mJSxu1jfFjFu4sTx7+9SQp1
Mw9LR/FuRBwx9xhOFA5JQhTSc/yAkArt7lLq2HWX+oJLPlboLkUdTCtNMqQjJ5pmi7ZpDH6ZVukM
/nZss3sHdTir0nqLHLpIyArMKoQfEuaY8TqeKBxXkRzimJUNfgOrqErIwVT4ZVxPKvB0SBhHvYBI
WbXmlgB9S07fwVCxKt2+y6axixSKHlTRvIE5LyO3+EE3wnFahR3QJCpjP5AHEKIY7XFVBd/lbobo
d/ADTha6+w4ljrtPrwa3aeiINAsQPTMR2pdQqp0KHNPk78oxo1CPbQxcXDmGAvji68cVkfW2FuJN
2JOqMmH7RPldhDtZdLtcBPTtr7lbeJLsEQjz+Y3nXcl9V3K9/3zJXZTPZy20s9oKZVf3DbYpNi1y
vLBDHlPGBmrKyA1pmmQJ+0TQh0G9zpwOSXFiSiN4zOq6gwsFNmuQ4OojqqJBhFNosOueJhLKjHQo
UcolHOzMcCVtjYcmXdljYVMfGGw9kFjt8sAOr+jh/FxQkDG7TWgOnzmjFU3grMxWrmREQe3XYVbX
Qp2ZW92IZkqdw61QGXw4rxoMFtaEBgRB2wJWXoXzuWYNBxPMSKDtbvfe3C3GCxfpIhnhgGQ+0nrP
+6hunJTHirkJgNip8JE+5J1itRK3lib7BtzO4qQyu8YCdrn33sRLeQTPvKTz9kQ6sqScnCxBR22v
1VxuesjHadsbw5kWHuMUvC51z4dZCBdDvhI27E9NZpPlM2+2csXcJKjDNYW1+5zCTh1IhVRbWEY2
NMxUFgIs0Zys/MtNMOtFKWAj/TWkWFmDYPjXpAA7uq4l4zHxVdnZpRFtO/ualVI+UUQMouAIjdhE
7GNwvw5V0CegEq4mTEXQL3CPpq1tptzinCVd+fbK4Ow4ZmmEs3KrUzTPZAs3eVzIYN5K4oFulbIb
5c6vikn5C1KlHMb/M1X0fgI3BSuB9oAP17gCI52vbY8LFXGoQmlE/b6AxsHUDogWuIuFaQgquEw2
/wU51P9tzlkaJq3hwKf2aYgEhf1IRYKQPShLJvpOIVbP9i5LkmWETESVxJWpFXtEDgkb6hq4qvd2
D0UQ6qaaZGXA4E7Gn/ueZdAo1E1OOd+cGlLsvTYH/unOxyYzKOXWYdPQ5PYvRKzYVe16szzfe8uK
6IlZm9XIswKYlbaCVpb2rynCObdaW7HmNF5u5sKBF+c1hsGiIUrhvgfpP7D/UeEz+2VCb6hDvg+1
FcGHBk0Mwgai+pJtPJAukHZwBI2THbTBpElZ02atk7ZavllfcKdb8D1hbC3ZWfx9TmMXzZnLzsnF
izR2ZmHH1nZsoanBsydTFIbG+UHGOMZ80ip/deKje+DoLbjfnzAlTTDBNyWBofUcmDyA5LcczdKN
vwAAAP//AwBQSwMEFAAGAAgAAAAhAA3RkJ+2AAAAGwEAACcAAAB0aGVtZS90aGVtZS9fcmVscy90
aGVtZU1hbmFnZXIueG1sLnJlbHOEj00KwjAUhPeCdwhvb9O6EJEm3YjQrdQDhOQ1DTY/JFHs7Q2u
LAguh2G+mWm7l53JE2My3jFoqhoIOumVcZrBbbjsjkBSFk6J2TtksGCCjm837RVnkUsoTSYkUigu
MZhyDidKk5zQilT5gK44o49W5CKjpkHIu9BI93V9oPGbAXzFJL1iEHvVABmWUJr/s/04GolnLx8W
Xf5RQXPZhQUoosbM4CObqkwEylu6usTfAAAA//8DAFBLAQItABQABgAIAAAAIQCCirwT+gAAABwC
AAATAAAAAAAAAAAAAAAAAAAAAABbQ29udGVudF9UeXBlc10ueG1sUEsBAi0AFAAGAAgAAAAhAKXW
p+fAAAAANgEAAAsAAAAAAAAAAAAAAAAAKwEAAF9yZWxzLy5yZWxzUEsBAi0AFAAGAAgAAAAhAGt5
lhaDAAAAigAAABwAAAAAAAAAAAAAAAAAFAIAAHRoZW1lL3RoZW1lL3RoZW1lTWFuYWdlci54bWxQ
SwECLQAUAAYACAAAACEAlrWt4pYGAABQGwAAFgAAAAAAAAAAAAAAAADRAgAAdGhlbWUvdGhlbWUv
dGhlbWUxLnhtbFBLAQItABQABgAIAAAAIQAN0ZCftgAAABsBAAAnAAAAAAAAAAAAAAAAAJsJAAB0
aGVtZS90aGVtZS9fcmVscy90aGVtZU1hbmFnZXIueG1sLnJlbHNQSwUGAAAAAAUABQBdAQAAlgoA
AAAA

------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity_files/colorschememapping.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml

<?xml version=3D"1.0" encoding=3D"UTF-8" standalone=3D"yes"?>
<a:clrMap xmlns:a=3D"http://schemas.openxmlformats.org/drawingml/2006/main"=
 bg1=3D"lt1" tx1=3D"dk1" bg2=3D"lt2" tx2=3D"dk2" accent1=3D"accent1" accent=
2=3D"accent2" accent3=3D"accent3" accent4=3D"accent4" accent5=3D"accent5" a=
ccent6=3D"accent6" hlink=3D"hlink" folHlink=3D"folHlink"/>
------=_NextPart_01C8A58A.9D092030
Content-Location: file:///C:/D11BB2F9/MalwareIdentity_files/filelist.xml
Content-Transfer-Encoding: quoted-printable
Content-Type: text/xml; charset="utf-8"

<xml xmlns:o=3D"urn:schemas-microsoft-com:office:office">
 <o:MainFile HRef=3D"../MalwareIdentity.htm"/>
 <o:File HRef=3D"item0001.xml"/>
 <o:File HRef=3D"props0002.xml"/>
 <o:File HRef=3D"themedata.thmx"/>
 <o:File HRef=3D"colorschememapping.xml"/>
 <o:File HRef=3D"filelist.xml"/>
</xml>
------=_NextPart_01C8A58A.9D092030--
