Avast WEBforum

Business Products => Archive (Legacy) => Avast Business => Avast Server Protection => Topic started by: avastment on April 05, 2009, 09:20:37 PM

Title: 4.8 and windows firewall.
Post by: avastment on April 05, 2009, 09:20:37 PM
About 2 hours ago I was using AVG free for many years with Firefox.
Started having a problem with either Firefox, avg free or something else when clicking on a link after doing a search and coming up with first seeing link in address bar and before page loaded it switch to another link though it was an advertsing link.  to go to my choice link I had to click back button.
I did a AVG full scan yesterday and it only turned up 4 cookies which I deleted.
So I tried Malwarebytes and it turned these which I deleted.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.

then got to thinking after looking at Mozilla forum to switch to Avast.
I ran avast and after about 40 minutes no viruses nothing.
Prior to Avast I completly removed everything to do with AVG.

So I go to my windows firewall and see AVG files about 7 are all there and checked.  So I delete all of them.
Question is do I add all *.exe Avast files to Windows firewall with a check mark for each or which ones?

Oh and to get to this forum I was first redirected to some advertising site then had to hit back button to get here.

Title: Re: 4.8 and windows firewall.
Post by: avastment on April 05, 2009, 09:31:18 PM
I'm doing a little testing with my Google search bar.
If I type in cnet and hit return
there is cnet.com as top link.
so I click on it.

In search bar I see cnet.com and then address by it self changes to
http://www.newser.com/?utm_source=ask&utm_medium=cpc&utm_campaign=news
or this one in doing a search for avast home.
http://www.stopzilla.com/products/stopzilla/landing.do?aid=10192&cid=spyware

Why is this happening?

I'm going to try it now with my Yahoo search bar.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 05, 2009, 09:34:25 PM
same thing with Yahoo search.
I click link that looks authentic another advertising site pops up and then hitting back button either takes be to what I want or I can't exit out of site without closing it.
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 05, 2009, 09:40:17 PM
The windows (XP) firewall doesn't monitor outbound connections so you probably don't have to add any.

However the only files that require internet access are avast.setup (the avast update process), the ashWebSv.exe (web shield) and ashMaiSv.exe (the Internet Mail provider POP3/SMTP email scanner).

Based on those file references not being removed there may be other remnants - AVG8 Remover, download tool from here, http://www.grisoft.com/ww.download-tools (http://www.grisoft.com/ww.download-tools) there is a 32bit and 64 bit windows version, ensure you use the correct one.
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 05, 2009, 09:45:02 PM
same thing with Yahoo search.
I click link that looks authentic another advertising site pops up and then hitting back button either takes be to what I want or I can't exit out of site without closing it.

I would have though that MABM would have found this search hijack, but you could also try SAS - SUPERantispyware (http://www.superantispyware.com) On-Demand only in free version.

Try running MBAM and SAS from safe mode with your browsers closed.

Check this out, if the above don't resolve it.
- Firefox popping up ads and or google search redirects.
Please download GooredFix (http://jpshortstuff.247fixes.com/GooredFix.exe) and save it to your Desktop. - Double-click Goored.exe to run it. - Select 1. Find Goored (no fix) by typing 1 and pressing Enter. - A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). - Note: Do not run Option #2 yet.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 05, 2009, 10:04:44 PM
OK.  I've done a lot here and will have to leave soon it's like 1pm here in California. so later. 

I turned Windows firewall back on and added ashwebsv.exe and ashmaisv.exe however could not find avast.setup?

I downloaded that file to remove all of AVG and was not instructed to reboot so I went to next.

Goor

GooredFix v1.92 by jpshortstuff
Log created at 12:59 on 05/04/2009 running Option #1 (jaisen)
Firefox version 3.0.8 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

One last thing I tried to update AVAST and got this message

Information about current update:
Last encountered error: The package is broken.

Total time: 1:48

What should broken imply to me?

thanks.

Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 06, 2009, 12:03:16 AM
The avast.setup file used to be a temporary file created when the update proceeded, but it should be in the C:\Program Files\Alwil Software\Avast4\Setup folder.

OK, hopefully that has cleared any avg remnants, if any.

The Goored is clear as no suspect entries, so that is another down.

I would say just what it says some part of the update process is broken, this could be a partial install failure, which could be due to remnants of avg.

Try a repair of avast. Add Remove programs, select 'avast! Anti-Virus,' click the Change/Remove button and scroll down to Repair, click next and follow.

If that doesn't work try, uninstall, reboot, install, reboot.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 02:01:35 AM
I found avast.setup where you said it would be and where it was had I opened all file extensions in setup dll.  It along with 3 other AV files are checked in windows firewall.

I uninstalled, restarted, installed, restarted using same Reg # and it appears as I have to once again do a scan.  However I thought let me see if I can update and tried and got same package broken report. I put some * in one location to hide my name.


Below is from log.

05.04.2009 16:54:13 general: Started: 05.04.2009, 16:54:13
05.04.2009 16:54:13 general: Running setup_av_pro-537 (1335)
05.04.2009 16:54:13 system: Operating system: WindowsXP ver 5.1, build 2600, sp 3.0 [Service Pack 3]
05.04.2009 16:54:13 system: Memory: 26% load. Phys:1545268/2096360K free, Page:3611660/4038308K free, Virt:2069356/2097024K free
05.04.2009 16:54:13 system: Computer WinName: INSPIRON
05.04.2009 16:54:13 system: Windows Net User: INSPIRON\jaisen
05.04.2009 16:54:13 general: Cmdline: /downloadpkgs /noreboot /updatevps /silent /progress 
05.04.2009 16:54:13 general: DldSrc set to inet
05.04.2009 16:54:13 general: Operation set to INST_OP_UPDATE_GET_PACKAGES
05.04.2009 16:54:13 general: Old version: 537 (1335)
05.04.2009 16:54:13 registry: Deleted registry: Software\Alwil Software\Avast\4.0\UpdateReady
05.04.2009 16:54:14 system: Using temp: C:\DOCUME~1\******~1\LOCALS~1\Temp\_av_proI.tm~a01748 (28474M free)
05.04.2009 16:54:14 general: SGW32P::CheckIfInstalled set m_bAlreadyInstalled to 1
05.04.2009 16:54:14 internet: SYNCER: Agent=Syncer/4.80 (av_pro-1335;p)
05.04.2009 16:54:14 system: Computer DnsName: INSPIRON
05.04.2009 16:54:14 system: Computer Ip Addr: 75.213.117.185
05.04.2009 16:54:14 system: Installed in: C:\Program Files\Alwil Software\Avast4 (28474M free)
05.04.2009 16:54:14 internet: SYNCER: Type: use IE settings
05.04.2009 16:54:14 internet: SYNCER: Auth: another authentication, use WinInet
05.04.2009 16:54:14 package: Part prg_av_pro-537 is installed
05.04.2009 16:54:14 package: Part vps-9031900 is installed
05.04.2009 16:54:14 package: Part news-4e is installed
05.04.2009 16:54:14 package: Part setup_av_pro-537 is installed
05.04.2009 16:54:14 package: Part jrog-e0 is installed
05.04.2009 16:54:14 general: Old version: 537 (1335)
05.04.2009 16:54:14 general: GUID: 3f90d82e-dfd9-47d8-942f-f5c585aa60d7
05.04.2009 16:54:14 general: Server definition(s) loaded for 'main': 229 (maintenance:0)
05.04.2009 16:54:14 general: SelectCurrent: selected server 'Download730 AVAST Server' from 'main'
05.04.2009 16:54:14 internet: SYNCER: Type: use IE settings
05.04.2009 16:54:14 internet: SYNCER: Auth: another authentication, use WinInet
05.04.2009 16:54:14 general: Entered SetupProcessPro::Do( INST_OP_UPDATE_GET_PACKAGES )
05.04.2009 16:54:14 general: Entered SetupProcessWin32Avast::Do( INST_OP_UPDATE_GET_PACKAGES )
05.04.2009 16:54:14 general: Entered SetupProcessWin32::Do( INST_OP_UPDATE_GET_PACKAGES )
05.04.2009 16:54:14 general: Entered SetupProcess::Do( INST_OP_UPDATE_GET_PACKAGES )
05.04.2009 16:54:14 general: progress thread start
05.04.2009 16:54:14 internet: SYNCER: Agent=Syncer/4.80 (av_pro-1335;f)
05.04.2009 16:54:36 internet: Used server: http://download730.avast.com/iavs4x
05.04.2009 16:54:36 package: Download servers.def, servers.def.vpu failed with error 0x20000011.
05.04.2009 16:54:51 internet: Used server: http://download730.avast.com/iavs4x
05.04.2009 16:55:12 internet: Used server: http://download730.avast.com/iavs4x
05.04.2009 16:55:12 file: GetFileWithRetry: servers.def downloaded .
05.04.2009 16:55:12 file: GetNewerStampedFile:DSA_FileVerify(C:\DOCUME~1\******~1\LOCALS~1\Temp\_av_proI.tm~a01748\onefile), error: 0x2000000B
05.04.2009 16:55:12 package: Tried to download servers.def but failed with error 0x20000011.
05.04.2009 16:55:12 package: LoadAllDefs failed 0x20000011
05.04.2009 16:55:12 general: Err:The package is broken
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 02:25:53 AM
i read this in a forum though it did not help.

I'm on UM175 VZ broadband did below tried to update and got package broken.

Oh, I typed into yahoo search bar broken avast package and was taken to an advertising site and I had to click back to get to below Avast form question and answer.

Had the same problem Package broken etc. etc... , found in settings > update connections> a tick box that said "My Computer is permanently connected to the Internet" since I am on dsl I figure to click that  ..... and lo and behold no more Broken packages
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 06, 2009, 02:46:48 AM
Thanks for the update (excuse the pun) glad that you now have it sorted.

Welcome to the forums.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 05:14:13 AM
I don't have it fixed.

"Had the same problem Package broken etc. etc... , found in settings > update connections> a tick box that said "My Computer is permanently connected to the Internet" since I am on dsl I figure to click that  ..... and lo and behold no more Broken packages"

above is from some one else in this form and I tried it.  Did not work.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 08:07:01 AM
"Had the same problem Package broken etc. etc... , found in settings > update connections> a tick box that said "My Computer is permanently connected to the Internet" since I am on dsl I figure to click that  ..... and lo and behold no more Broken packages"

There is more to above than what it says.  This is from another forum user.
What is missing is
yes click on update connections,and click computer is permanently connected to internet.
I am using a UM175 VZ modem which I guess is permanently connected to internet when I turn my computer on
However,  You have to click on proxy box
and click direct connection option.

This allowed me to update not only virus but Avast program too.   Oh so easy.
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 06, 2009, 02:48:41 PM
You never did say if you ran the avg8 uninstall tool I gave the link for ?

What your modem if isn't an issue it is the type of connection, broadband, DSL or Cable are all permanent connections, Dial-up is blatantly obvious so if you aren't using that then you are permanently connected.

Your proxy setting is by default set to 'Auto Detect (use Internet Explorer settings),' this for the most part is fine foe the greatest majority, but for some it doesn't (why I don't know). You seem to have been one of the unfortunate few and Changing it to no proxy has worked.

Now! you are sorted ;D
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 04:11:48 PM
I used avgremove you suggested to me.  AVG is gone.

As for being sorted and being a user of Avast for less than 24 hours I have a suggestion or two.

So last night, it is now Monday morning, I thought why not do a VRDB thing.  So I click start and you i ball went around, around, around and kept going for about 35 minutes when it got to be like really late so I stopped it.
Suggestion 1 would be some sort of moving bar showing progress in percent or numbers or something with time remaining or something or an automatic shutdown of my computer.
Suggestion 2 are skins.  They could better in colors, boxes, white spaces. 

and lastly I still have problem with google and yahoo search bars being a new term for me Hijacked.  There are others with this problem and no real answer other than doing a Hijack test, copying log and posting it for someone else to look at. 
There has to be another way.
Title: Re: 4.8 and windows firewall.
Post by: Lisandro on April 06, 2009, 04:24:07 PM
avastment, both VRDB and skins will be dropped in next avast version. The first, due to lack of usage nowadays.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 04:38:46 PM
you got back to me too soon. 

I found a skin I like.

Lite -on.

I sent below to Firefox form 20 minutes ago.

I'm using firefox 3.08.
I type in say Mozillazine into Firefox search bar, click enter, see a top link to Mozillazine web site and then I click to get to Mozillazine,
then in address bar I see firefox URL and then like moments, split moments late I am taken to an advertising site like Stopzilla or something like it and have to hit back button to get to Mozillzine web site.

Question is it my fault for using Firefox or a Firefox responsibility to keep "hijacking software out of Firefox search bar?

It would be like if I bought a Pizza and someone having to do with providing Pizza was adding peanuts to it and I'm allergic to peanuts.
Whose job is it to find out where those peanuts were added to my pizza?

Like am I suppose to take my Pizza to another store for it to be analyzed before I eat it?

Something or someone is Hijacking Firefox's search bar.
I would think Firefox would like to know why someone or something is messing with Firefox's search bar.

Please find a fix.

Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 07:46:15 PM
Avast
I'm going to help you fix this hijacking problem when using search bar in Mozilla Firefox and I know nothing about hijacking, virus or malware.

You can type
about:cache?device=disk
into address bar of Firefox and it will bring up firefox Cache.

I did it in my recent cache and found these files.

I see something though it might be nothing.
some of these expiration dates are 1969 and if I am not mistaken 1969 was a while ago and those are sites I have been directed to from where I wanted to go.

Couldn't there be some way to find where in registry they dates are coming from or at least block site links with expiration dates that have come and gone a long time ago?



 Key: http://media.lavasoft.com/img/boxes_segmentation_mid.gif
     Data size: 173 bytes
   Fetch count: 1
 Last modified: 2009-04-06 09:10:37
       Expires: 2009-04-26 18:31:32

           Key: http://www.greattranslators.com/images/logo_continental.gif
     Data size: 5629 bytes
   Fetch count: 1
 Last modified: 2009-04-06 10:36:38
       Expires: 2009-04-24 10:29:16

           Key: id=49da3b48&uri=http://safebrowsing.clients.google.com/safebrowsing/downloads?client=navclient-auto-ffox&appver=3.0.8&pver=2.2&wrkey=AKEgNiuPTBFCGH8zTprF1cyaBJYFoPktu-u2QcZmUcEHkRXaUnd5LGa8VdsKIiqVlAzb-LXPINHqDVDhIUT8xJnzwjzu-Y3_BA==
     Data size: 472 bytes
   Fetch count: 1
 Last modified: 2009-04-06 10:29:37
       Expires: 1969-12-31 16:00:00

           Key: http://static.trialpay.com/js/t/?p=tp&tpr=243783
     Data size: 4386 bytes
   Fetch count: 1
 Last modified: 2009-04-06 09:11:28
       Expires: 2009-04-06 10:11:23

           Key: http://www.trialpay.com/checkout/?c=10507bf&tid=9ahI9ha
     Data size: 25992 bytes
   Fetch count: 1
 Last modified: 2009-04-06 09:11:27
       Expires: 1969-12-31 16:00:00
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 06, 2009, 08:31:32 PM
Firefox is less prone to these search hijackings than IE by a long way. There is however no way to establish who is responsible as for it to get established the use would normally have to have accepted the addition of something.

The problem being there are some toolbars that the user might feel helps them when in fact they only help the originator, you might well get some other unknown gifts that pay for your free toolbar. Personally I don't allow any toolbars to install and I take care of what add-ons I install, usually sourced at the Mozilla site.

If you haven't already got the NoScript add-on for firefox I suggest you do.

The safebrowsing is a security tool that blocks access to known malicious sites.

As for trialpay.com (this you can google if you can get past any redirects) is often used by software manufactures as a means of getting something for free, so there may be some payment involved, could be marketing information gathered or targeted adverts based on browsing, etc. http://www.trialpay.com/about/ (http://www.trialpay.com/about/).

Typing about:cache?device=disk into firefox address basr gives a blank page on my system.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 06, 2009, 09:14:00 PM
OK I added noscript to FF.

One other thing I noticed
I can't open my regedit file by going to
start
run and typing in
regedit
nothing happens.

I found a site suggesting I could possibly make some changes.  And yes I have gone into registry before this time trying this from another forum

It is VERY IMPORTANT that you learn how to examine your system for potential
problems as well as using 'fixit' programme such as AdAware or Spybot.

Check your startup folder and MSCONFIG (startup tab).  You can also check
the following registry keys and edit as appropriate (if you have experience
with same).

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce






Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 06, 2009, 10:01:59 PM
This and other areas are commonly blocked to prevent easy removal of malware.

You may find that regedit.exe has been intercepted and there is a way round that find regedit.exe, in my XP Pro it is in the Windows folder, copy it and paste it into another temporary folder, rename it to regedit.com, you will get a warning, it is OK.

Now if there are two files one with a file type of .exe and another .com the .com one takes precedence so by running the regedit.com that should allow you to open the registry for editing. This is a temporary measure to allow you to edit the registry if needs be and not a permanent solution.

http://www.taskmanagerfix.com/enable-disabled-regedit (http://www.taskmanagerfix.com/enable-disabled-regedit)
Or
http://www.pchell.com/support/registryeditordisabled.shtml (http://www.pchell.com/support/registryeditordisabled.shtml)
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 07, 2009, 01:51:50 AM
David,
I may have found a cure and trust me I know very little about computers you can tell by my questions.

Let me test it for a day or so.

Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 07, 2009, 02:51:31 AM
OK, fingers crossed ;D
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 08, 2009, 05:22:26 PM
I went to regedit not from run / command .  Had to download a shortcut to regedit to open it.
did a search for mshta.exe
then had to look very carefully for "%1"%* coming after mshta.exe.
if it was any different than above I had to modify it to above and then delete entry.
It was only in one place.  I either restarted or not, can' remember and did some searching.
I've done a lot of searching since in Firefox search bar using google and Yahoo and so far no hijacking to Advertising links.  none.
Also downloaded NoScript and at first it was annoying but now I kind of think it is doing things to help me.
my CPU and internet connection are fast.  So I am happy.
I will work on regedit problem from run command.  thanks.
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 08, 2009, 06:26:14 PM
You're welcome.

NoScript whilst a bit of a pain at first it doesn't take long to build up permissions for your favourite sites, provided you trust the site (though it is possibly that it could be hacked, but you then have the web shield also).

You can export your noscript whitelist so you have a copy so you don't have to start from scratch if you have to reinstall firefox or the add-on at any time; just import the saved whitelist into your new installation, etc. and no need to have to allow all those you already did.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 08, 2009, 10:10:42 PM
creating a folder on desktop
going to windows folder
finding regedit.exe
copy to new desktop folder
rename it regedit.com
will not allow me to open regedit
or trying run command regedit.exe or regedit.com.
However this does works from desktop
"C:\Program Files\Safer Networking\RegAlyzer\RegAlyzer.exe"
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 08, 2009, 10:15:38 PM
If you place regedit.com in C:\ as in the desktop you would have to enter the full path into the run command for it to find and run regedit.com

Use the windows Start, Run and copy and paste c:\regedit.com and click OK.

If you are using Vista you are going to have to jump through some hoops first. right click on wherever you have regedit.com and select Run As now you would select administrator and you have to enter the password.
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 09, 2009, 12:23:26 AM
David,

I found this. 

http://www.raylanddelosreyes.com/how-to-restore-regedit-taskmanager-ang-msconfig-using-vbscript/

Downloaded restore.vbs file.  it ran then I went to enter regedit in run / open nothing happened.
I shut down, had lunch rebooted, tried again and it worked.
I can enter regedit in open box and regedit opens.

another question.  should this file be in registry? after doing registry search for mshta

@C:\WINDOWS\system32\mshta.exe,-6412
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 09, 2009, 01:04:52 AM
I honestly don't know, but it appears to be a legitimate file name, though that doesn't mean it isn't a) infected or b) in the wrong location (mine is in the system32 folder). I have no idea why there would be an @ character before the path.

http://www.liutilities.com/products/wintaskspro/processlibrary/mshta/ (http://www.liutilities.com/products/wintaskspro/processlibrary/mshta/)

Why were you doing a search for mshta.exe in the registry anyway ?

There are many registry entries for mshta.exe in mine, none with -6412 though most end in ,1
Title: Re: 4.8 and windows firewall.
Post by: avastment on April 09, 2009, 07:15:22 AM
This all started when I had a problem with clicking in google or yahoo search box in Firefox and hijacked to another site after clicking on some link and seeing URL appear in URL box and a second later be hijacked to a advertising site.

I tried to find forum I found information, so I could show you link that explained to search for mshta.exe with an ending other than "%1" %* in registry

I found one with "%1"*
so I changed it to "%1" %*
then deleted whole line.

Either I rebooted or again went to google search bar in Firefox and what do you know I was able to go to a site from results from yahoo or google without going to an advertising site.

Never mind about -6412 ending.  So far my CPU and connection speeds are find and no problems.


Title: Re: 4.8 and windows firewall.
Post by: avastment on April 09, 2009, 07:29:40 AM
I found link about mshta.exe

and I did delete all of them if I found them in list shown in below link and everything seems to be fine with my computer.

http://www.exterminate-it.com/malpedia/file/mshta.exe
Title: Re: 4.8 and windows firewall.
Post by: DavidR on April 09, 2009, 03:04:50 PM
You have to find more than just one link you have to consider the other legitimate links for that file name or you could end up doing some serious damage.

Add to that this site is rated dangerous by WOT (web of trust), http://www.mywot.com/en/scorecard/exterminate-it.com (http://www.mywot.com/en/scorecard/exterminate-it.com), so you have to exercise due care in where you get your information from.