Morning Discussion
by Jeff "geedeck" Gondek, Feb 22, 2008 3:43am PSTHow is everyone doing this fine Friday? GDC is coming to a close, but we're still seeing some really great stuff out of it, such as exclusive footage of Fallen Empires and the announcement of Portal 2. Plus, you know you like some fresh video for the new God of War PSP game.
Lately with the release of Audiosurf, Shacker Aeg1x has been doing daily song challenges in the comments so be sure to check that out if the game floats your boat. People seem to like the question, so what are you playing this weekend?
Mortal Kombat 'Komplete' coming to PC
Xbox One rumors: confirmations and open questions
EA 'building titles for the Nintendo console'
Best of PSN collection coming in June for $40
Warhammer 40,000: Armageddon announced for PC and iOS



I've been in business fixing computers for eight years now so just a little qualification of myself. I fix roughly 6 to 7 computers per day and while a few don't have spyware the rest do. I don't format computers to fix them from spyware (weaksauce techs do) and I don't lose people's data. That being said feel free to share any other methods or tools in this thread and we can all grab the pitchforks and do battle.
First off you need a few software tools. You can download them from the interweb. There are of course other tools that work such as Process Explorer and Autoruns but this is what I use. I've also included a link to Super Antispyware which I don't use but my other techs like it.
HijackThis ( http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html )
Pocket Killbox (http://www.bleepingcomputer.com/files/killbox.php )
Hoster ( http://www.majorgeeks.com/Hoster_d4626.html )
Crap Cleaner (http://www.ccleaner.com/ )
Dial-A-Fix (http://wiki.djlizard.net/Dial-a-fix_beta#Mirrors.2Fdownload_locations.2C_and_articles )
NOD32 ( http://www.eset.com/download/free_trial_download_eav.php )
Rootkit Revealer ( http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx )
Avenger ( http://swandog46.geekstogo.com/avengernotes.htm )
Super Anti-Spyware ( http://www.superantispyware.com/download.html )
Ideally you want to run this in Safe Mode. To easily get there in Windows XP click Start – Run and type in MSCONFIG. Click on the Boot.ini tab and check off Safe Boot. If you want an Internet connection then put the radio button beside Network. In order to change it back you must remove the checkmark beside Safeboot. Vista is very similar but doesn't use radio buttons.
First thing I do now is open up Hoster and mark your Hosts file read-only. You may want to restore the original HOSTS files and then mark read-only.
Let’s move to Pocket Killbox shall we? This program does some great stuff. I initially use it for cleaning out the temp files. You can do this too by clicking on Tools and then Delete Temp Files. After that’s done go to the next step with HijackThis. Don’t close Killbox off just yet, you might need it later.
Next thing to do is to run HijackThis. This tool is dangerous but I’ll guide you through it. It lists all programs running in your computer good or bad. The latest version is 2.02 so make sure you have that one. The new HijackThis has a feature where you can upload the log and it'll give you an idea of what needs to be removed. I've tried this a couple of times on infected computers and while it found some of them it didn't remove them all so I wouldn't recommend this. Better would be to post the log in here for a Shacker to give you a better idea.
Click scan. You can safely remove all the 01’s since those are just homepage redirects and hijacks. The 02 ’s can all go also unless you recognize them. The only ones that I keep are the Google toolbar, MSN toolbar, or else Adobe Acrobat. The rest are usually bad. Again your computer may vary from the hundreds that I fix but I doubt it. The 03’s are the various toolbars installed. They only one I would keep is the c:\windows\system\msdxm.ocx one. The rest can go.
Here comes the big one, the 04’s. These are the programs that run when Windows starts up and the ones that are in the registry. I can’t list the ones that you should remove obviously so you have to be careful in removing them. I will list below the standard XP services and programs running on a default installation. This will give you a ground floor on where to start from. Of course installing other programs will change this list and you will have to decide whether or not you want that software from starting up everytime Windows boots. You cannot destroy a XP install by removing all of the 04's. So whatever you remove you can replace by either restoring the HijackThis entries or reinstalling the program.
For Vista I don't have the standard default ones that only show up in the Task Manager. There are different ones than listed below such as sidebar.exe and the like but they are pretty obvious. I would still keep a close eye out on ones that are misspelled or in the wrong location. Maybe someone else would like to post the list from Vista?
Explorer.exe
Spoolsv.exe
Svchost.exe (4 or 5 times!)
Taskmgr.exe (you’re using it)
Alg.exe
Lsass.exe
Services.exe
Winlogon.exe
Csrss.exe
Smss.exe
System
System Idle Process
Beware of spelling differences! They usually target the svchost.exe and make them look like scvhost.exe or something similar. Also beware of location. Services.exe does not run from the Program Files folder or anything else critical.
If you are unsure of anything else running you can always Google it and it will tell you. It doesn’t?? Well then delete it because 99.9234822% of the time if Google has not heard of it then you don’t need it.
Now be careful of the RunOnce folder because since you’ve been through the Add/Remove panel there may be some uninstallers that want to run next time Windows boots up. Hence the RunOnce part. Don’t remove them or else your work will be for naught.
Next section is usually the 09’s. These are just extra buttons in Explorer. You can leave them if you like or remove them. I’ve never seen hijackers hit these.
Next up to bat is the 10’s 11’s, these are always LSP or Winsock hijacks. HijackThis does not remove them by itself since it would break your internet connection. You need either the Winsock Fix from my site ( http://www.five-online.com/files/WinsockFix.exe ) or else HijackThis suggests the LSP fix from cexx.org ( http://cexx.org/lspfix.htm ).
We’re almost done the list. The next ones are the 16’s and these are all the stuff that IE has downloaded for you in your internet travels. You will see baddies in here like XXX toolbar and the like. You can tell which ones are bad and good by looking at the website on the right hand side. If it’s something you like then keep it.
If the above hasn’t helped you then you missed something in the 04 section of HijackThis, check it again. If you’re absolutely positively sure then you may have a .dll hijack which are pretty retarded but solvable. You need to boot into Safe Mode and turn on your hidden system files.
Go to your C:\Windows\System32 folder and sort by Date Modified. You can move all .dll’s created recently to a folder on your Desktop. Reboot normally and keep an eye on your computer. If it complains of any missing .dll’s then don’t worry. It might be the spyware asking. Usually they are randomally named .dll’s so they are pretty identifiable.
The other tools listed above like Rootkit Revealer and Avenger should only be used if the above process failed.
Rootkit Revealer is pretty straightforward. It just lets you know if there's anything hidden from the Windows API. There are legit entries in this when you scan. Usually you're looking for recent stuff either from a few days ago or a few weeks. It can't remove them for you but it's a good tool to identify what path you need to take to remove them.
The other one is Avenger. This is a much more powerful tool than Killbox and can do quite a lot of things. I would suggest that if you need to use this tool you read and then re-read the webpage linked above. I use it for more complex file removal problems. It's fully scriptable so use it carefully.
Once you've done this then there's only a reboot waiting. Once you reboot NOD32 should be run through a full system scan.
Now this concludes our stay at the spyware hotel. But wait, how did I get infected redfive? Well most commonly is the porn sites but I’ve had people swear up and down that they didn’t go there (lol, husband). The second most common ones is from updating your codec software with infected software. Just stick to VLC and everything will be fine. How can I prevent this from happening again? Seriously install Firefox ( http://www.mozilla.com/en-US/ ). I could go on with how to make IE bulletproof but I’m not. Suck it and install Firefox ( http://www.mozilla.com/en-US/ ). Did I mention to install Firefox yet ( http://www.mozilla.com/en-US/ )?
Updated February 23, 2008
Thread Truncated. Click to see all 108 replies.
Thread Truncated. Click to see all 16 replies.
I wonder if TF2's downward trend continues, will valve keep dedicating so much effort with new maps/unlockables? Will they try to address the reasons people seem to be leaving the game in droves, though it seems like just adding a new map wont help, as there was no real effect on that graph when CP_Badlands was released.
Perhaps a bigger change? I know people will bitch at me for saying this, but if the game had been more like TFC I think it would still have decent numbers. Real team fortress gameplay is unique, with different capture methods, more gameplay choices and better balance for the attackers. TF2 just feels stale already. I already know whats going to happen on each CP map and where the battles will be. Nothing changes, there are no surprises.
Thread Truncated. Click to see all 177 replies.
Thread Truncated. Click to see all 165 replies.
if you aren't playing yet, you should sign up http://ikariam.org and join us on the Epsilon server. It's lots of fun.
Also, someone trade me something for crystals please.
Thread Truncated. Click to see all 603 replies.
Ok, yes, I am Still Alive.
Its been a hard week for your dauntless commissioner. I have been battling the evil inside, and with the help of some heavy duty modern pharmaceuticals I appear to be finally winning. At least my temperature is down to Double Digits now. Despite my Critical Condition this week, the Captains managed to schedule some matches! Good Job Captains! As soon as I have server info, I'll let you know. If the matches that arent yet scheduled get a time & date, I'll let you know.
Zero Loss Braket 3rd round
Heroes of Kvatch vs. Louis Kemp Seafood Co. - ????
The Fighting Mongooses vs. OGC - ????
One Loss Braket 2nd round
Strum un Drang vs. ))<>(( - Sunday Feb 24 @ 6pm Pacific - Server: TBD
Team Philly Blunts vs. NastyJack's JO Buddies - Sunday Feb 24 @ 6pm Pacific - Server: TBD
Viral Agents vs. Shack Rangers - ????
Critical Tits! vs. PRESS F10 - Thursday Feb 28 @ 7pm Pacific - Server: TBD
Thread Truncated. Click to see all 60 replies.
http://epicslut.ytmnd.com/
Thread Truncated. Click to see all 68 replies.
It was a great show! He was in good voice (just doesn't have the upper register for "Still Alive" tho), and the crowd was super live. A little too live sometimes -- "hey I'm going to shout something witty!" etc. -- but mainly just fun. Lots of singing, including of course "all we wanna do is grargle bargh".
I was kinda skeptical about what he would do in a live show, but it had good pacing, guest artists ... the song selection was surprise-free, but his delivery was spot-on. I guess it helps to be in a big friendly sort-of-drunk crowd but he got a lot of laughs out of me with songs I've heard many times already. I'd probably even go see him again with the same material (but need some new stuff in the pipeline for after that).
Show ended with him and some bloggers playing Rock Band, including Leo Laporte who managed to fail them out of the song at 99% complete. Boo.
Oh actually that wasn't the last-last song; he finished with a sing-along on "First of May".
So... yeah. Good times. Sleepy now.
Thread Truncated. Click to see all 7 replies.
Last week, I posted a fix for the spoiler tag so you could expand replies by clicking a spoiler twice, and Maarten put it into the live Shack javascript. ( http://www.shacknews.com/laryn.x?id=16270350 ) Looks like a couple of people have found a bug in the new code:
http://www.shacknews.com/laryn.x?id=16322029#itemanchor_16322029
http://www.shacknews.com/laryn.x?id=16294452#itemanchor_16294452
This should be broken (can't click it): congratulations, you have won the game
Fix in reply (I'll be sending this to Maarten).
Thread Truncated. Click to see all 16 replies.
Been using it for years now and I think I'd like to try something new / different / better....
Thread Truncated. Click to see all 21 replies.
A few simple rules:
* The winner gets to nominate the next track.
* We're going to stick with free music to make things simple. This can be shacker made songs, game music, songs available for free (in downloadable form) on an artist's website, etc. Just make sure you include a link so everyone can grab the song. I recommend the audio section on www.newgrounds.com if you don't know where to start.
* It's probably simplest if we restrict everything to the Elite cars for now. Maybe we could have a Pro category as well if there's demand for it.
* When posting your score note your audiosurf username, score and car type. Use ThomW's gamewith.us to keep track of shackers usernames: http://shackers.gamewith.us/finder/audiosurf
Yesterday's winner was Felraiser with 99059 points on Chaoz Fantasy by ParagonX9 ( http://www.newgrounds.com/audio/listen/85046 ). He's nominated ModeSelektor 2 by Modeselektor which is free to download here: http://www.last.fm/music/Modeselektor/_/ModeSelektor+2?autostart
You can keep track of the scores here: http://www.audio-surf.com/gamesite_fetchscores.php?league=2&aname=Modeselektor&sname=ModeSelektor%202
Good luck!
Also remember to check out Matt Burris's www.audiosurfboard.com for videos. If you're owning up the track try recording it with fraps so everyone can see how you do it :D
Thread Truncated. Click to see all 8 replies.
who wants to see diary of the dead at the angelika on monday???
Thread Truncated. Click to see all 5 replies.
Thread Truncated. Click to see all 34 replies.
Thread Truncated. Click to see all 27 replies.
I propose we call it I-Game from now on so that it gets harder for people searching for the other word to find us.
We need a private forum like we had for O-Game where we can discuss strats, trades, etc.
If you are a shacker and you play, let RMR know where you are and what resources you have, in lieu of having a webapp that we update ourselves (hint hint).
We need an IRC Channel so NFXFSX can post porn and tell us how much his life sucks, and so that we can all pick on Galadriel.
Trade with other shackers! Find one close and trade resource for resource. We need more crystal - if you are sitting on some, help a fellow shacker out!
Thread Truncated. Click to see all 243 replies.
... in reply ...
Thread Truncated. Click to see all 82 replies.
Thread Truncated. Click to see all 57 replies.
As most of you tf players know, tf2.hackedbychinese.com / Shacknews Chicago has been tracking stats. Its been generating daily awards on who has done the best of what - here are a few of note:
Backstab Kills: omnova (51 Most backstab kills)
Captures Blocked: [VA]Warmaker (11 captures blocked)
Dominator: project13 (16 dominations)
Flags Captured: omnova (2 flags captured)
Flags Defended: Havoc (4 flags defended)
Headshot Kills: DOOManiac (64 Most headshot kills)
Kill Assists - Medic: Felraiser (NJOB) (101 medic kill assists)
Points Captured: Rosewood (24 points captured)
Thread Truncated. Click to see all 4 replies.
Lately I've had inclinations to look beyond WoW and see what other games are being played. Any suggestions?
Thread Truncated. Click to see all 10 replies.
I just converted a .vob to DIVX with Dr. Divx with the intention of streaming it to my 360. However, the video doesn't show up from my 360. It converted it to a .divx file rather than an AVI. Should that matter? I thought it was all just Divx format?
Thread Truncated. Click to see all 18 replies.
http://www.shacknews.com/shackmeet/events.x?id=4555
March 15th (3 weeks away!)
My fiancée Miresse and I are throwing a Shackmeet to celebreate the release of Super Smash Brothers Brawl. dahanese is helping organize this shindig to make sure it will be awesome.
It's in Novato which is about 25 minutes north of San Francisco. I have plenty of floor room to crash and you're welcome to if you want to drink all night.
There will be a large TV, Smash Brothers, plenty of seating and lots and lots of booze. I think Smash Brothers even has a tournament mode where you can have any number of players play in a ladder, which could be awesome. I also have a full Rock Band set so that's something to do if we get bored of Smash Brothers.
Clicky and sign up:
http://www.shacknews.com/shackmeet/events.x?id=4555
Thread Truncated. Click to see all 6 replies.
IP: nero.shackbattles.com:27960
RA3 1.76
Punkbuster is disabled so no need to install it.
No password for now but I expect Rydogg will put one since there was some pro that came earlier today to blow our fun.
You need the q3 1.32 patch available here
http://fileshack.com/file.x/1290/Quake+3+Arena+1.32+Windows+Point+Release
and the latest Rocket Arena 3 mod available here
http://www.fileshack.com/file.x?fid=3547
I am going in. Nobody is there right now.
Thread Truncated. Click to see all 109 replies.