The file you claim to have known about, claim to have submitted to anti-
virus sites, the file named "obatssrsghde.exe" was a marker inserted
into Stuarts batch file you stole from him, it was is a KEY that proves
you're a thief:
For those that don't know, Stuart inserted the obatssrsghde.exe marker
into his batch file to prove, to the community, that PCBUTTS1 / The Real
Truth MVP is actually a lying thief, and PCBUTTS admitted in his own
post that he created the marker and claimed to know what it was - even
claimed to have submitted the malware to anti-virus vendors, but the
joke was on him, Stuart told everyone in the community about it BEFORE
it appeared in PCBUTTS1 download.... There is no actual file named
obatssrsghde.exe in the malware community, it was a ruse.
The key is in the spelling:
obatssrsghde.exe
pcbuttsthief
If you change (add) 1 character to each letter you will see that
"obatssrsghde" is actually the marker "pcbuttsthief" - proving that
PCBUTTS1 is a thief.
Are there other markers - YES, does PCBUTTS1 know about them - know,
they've been there for a long time, but this is the most obvious one.
Face it Chris/PCBUTTS1/TRT, you've exposed yourself in public.
--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
spam9...@rrohio.com (remove 999 for proper email address)
"Stuart told everyone in the community about it BEFORE
it appeared in PCBUTTS1 download.... There is no actual file named
obatssrsghde.exe in the malware community, it was a ruse."
I'd like to know more about "the malware community"
May I join it, please?
If so ............ how?
TIA
--
Dave
LOL - I should have stated ANTI-MALWARE community, sorry.
BD, based on your posts and the information you post, I don't think you
could garner an invite, at least not for several more years.
| In article <#IgrJUWD...@TK2MSFTNGP02.phx.gbl>,
| Boate...@hotmail.co.uk says...
>> Leythos - you said ............
>> "Stuart told everyone in the community about it BEFORE
>> it appeared in PCBUTTS1 download.... There is no actual file named
>> obatssrsghde.exe in the malware community, it was a ruse."
>> I'd like to know more about "the malware community"
>> May I join it, please?
>> If so ............ how?
>> TIA
| LOL - I should have stated ANTI-MALWARE community, sorry.
| BD, based on your posts and the information you post, I don't think you
| could garner an invite, at least not for several more years.
BoaterDave would *never* garner an invite nor past any stage of vetting.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
"Leythos" <spam9...@rrohio.com> wrote in message
news:MPG.24d52d8cd...@us.news.astraweb.com
Did you say "Bass"?
Sounds a bit fishy to me! lol
--
Dave
gur ebg pbqr jnf yrnxrq gb fghneg nsgre guvf enaqbz svyr anzr fubjrq hc. V
sbhaq vg vebavp
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"Leythos" <spam9...@rrohio.com> wrote in message
news:MPG.24d52d8cd...@us.news.astraweb.com...
>
> BoaterDave would *never* garner an invite nor past any stage of
> vetting.
lol, I seen a veteran vet! I seen a veterinarian vet! But I ain't
never seen a BUTTS vet!
(ya gotta remember the right tune for that)
Besides, I doubt he knows what the word means anyway.
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"Leythos" <spam9...@rrohio.com> wrote in message
news:MPG.24d52d8cd...@us.news.astraweb.com...
>
Well, not a single person will download your pirated code now that
Well, not a single person will download your pirated code now that
I know this is serious business, but the entertainment value in stuffing
a sock in PCButts' piehole is just precious.
"Leythos" <spam9...@rrohio.com> wrote in message
news:MPG.24d52d8cd...@us.news.astraweb.com...
>
Don't you realize what just happened?
There are no further lies you can concoct that will undo the mess you're
in now.
...of course you will continue anyway...as it may be pathological thing.
(as for me, there's too little popcorn left for me to endure many
further acts or curtain calls)
"The Real Truth MVP" <t...@void.com> wrote in message
news:xNadnQxvdJF_4_bX...@giganews.com...
--
Peter
Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
"Leythos" <spam9...@rrohio.com> wrote in message
news:MPG.24d52d8cd...@us.news.astraweb.com...
>
http://www.internetinspiration.co.uk/downloads/roguefix_2.248.bat
http://www.pcbutts1.com/downloads/Remove-itSA.zip
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"Twayne" <nob...@devnull.spamcop.net> wrote in message
news:O4ssqEXD...@TK2MSFTNGP05.phx.gbl...
http://www.internetinspiration.co.uk/downloads/roguefix_2.248.bat
http://www.pcbutts1.com/downloads/Remove-itSA.zip
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"FromTheRafters" <erratic @nomail.afraid.org> wrote in message
news:%23pk$RuYDKH...@TK2MSFTNGP03.phx.gbl...
http://www.internetinspiration.co.uk/downloads/roguefix_2.248.bat
http://www.pcbutts1.com/downloads/Remove-itSA.zip
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"Peter Foldes" <ok...@hotmail.com> wrote in message
news:eond6iZD...@TK2MSFTNGP04.phx.gbl...
Well, not a single person will download your pirated code now that
people and corporations
need to keep the malware
definitions up to date so
there is no theft involved.
frankly, I don't know why
microsoft doesn't block
your ip address.
you're a god damn game
player and this newsgroup
can do without your irrelevant
threads - liarthos.
--
db���`�...�><)))�>
DatabaseBen, Retired Professional
- Systems Analyst
- Database Developer
- Accountancy
- Veteran of the Armed Forces
- Microsoft Partner
- @hotmail.com
~~~~~~~~~~"share the nirvana" - dbZen
>
>
"Leythos" <spam9...@rrohio.com> wrote in message news:MPG.24d551929...@us.news.astraweb.com...
| I disagree.
| people and corporations
| need to keep the malware
| definitions up to date so
| there is no theft involved.
| frankly, I don't know why
| microsoft doesn't block
| your ip address.
| you're a god damn game
| player and this newsgroup
| can do without your irrelevant
| threads - liarthos.
Nothing Leythos has posted is untrue. While the wording of his post could be better, it
is accurate.
There certainly WAS theft involved and I was in on the setup to cause Butts to indict
himself.
This had NOTHING to do with "...need to keep the malware definitions up to date..."
This had everything to do with catching Butts in his lies by setting him up like a bowling
pin.
Stuart Saunders wrote RogueFix and Butts has been plagiarizing ever since I recomended its
trial in a posted reply I made in an Alt Usenet group.
Stuart created a subsection of code to detect and remove a bogus file named
"obatssrsghde.exe". The subsection was bogus was inserted ONLY to show that Butts is
plagiarizing RogueFix for Remove-It.
Stuart notified trusted people and the anti malware community of the existence of the
"obatssrsghde.exe" maker and the key to its decoding. That key is drop the .EXE of
"obatssrsghde.exe" and you get "obatssrsghde". Now shift each character +1 to get the
string "pcbuttsthief".
The thread is here...
http://groups.google.com/group/alt.comp.virus/browse_thread/thread/819e6742cabb25a3?hl=en#
It is long but all is in that thread.
In summation...
Either way this thread proves "he" is is a liar.
1. "Coded string to reveal 'pcbuttsthief' "
It is a fact that Stuart injected a subsection into RogueFix that was fake to begin with
and included detection for something that never existed. That was a file called
"obatssrsghde.exe" and it was NOT a year ago as historical copies of BOTH RogueFix and
Remove-It show when it was added. We also have Stuart providing this information to
trusted individuals and sharing it with the anti malware community such as there was a
base of persons who knew about the string and is decryption.
2. "Sample submission called "obatssrsghde.exe" "
Butts strongly stated that he had created a subsection of a script that would detect a
file
known to be "obatssrsghde.exe". At first he would not give us details on what malware or
malware family the detection of "obatssrsghde.exe" belongs to. Later he provided
information
in the form of text and includes a URL for Virus Total and a URL for Prevx.
The URL for Virus Total (VT) shows the MD5 value of this file and what the AV vendors
detect the file as as well as providing the Prevx URL he posted. Included with this
information he states he provided the 'sample' to the various anti malware vendors which
included Malware Bytes.
From the MD5 value an employee of Malware Bytes is able to track down the file submitted
and examine it and the information Butts provided in the Remove-It script and in the
thread does not jive with the reality of the submitted sample.
From the MD5 value I contact VT and I obtain the sample and provide the information this
has to do with busting PCBUTTs1. VT employee is well acquainted with history and facts
surroundind Butts and sends me the sample as
"7f6f82967ab768bd3b7aa6ee40249686d0ecbc50944ed9548953e3a3e8a75bcb" stored in a password
protected 7z archive file indicating both it would be a pleasure to Bust Butts as well as
the following text...
it arrived twice, sent by the same person:
file name: obatssrsghde.exe
date.....: 2009/07/21 03:40
source...: US, Anonymous, id 1340019
file name: roxio_downloaded_from_Demonoid.co
date.....: 2009/07/21 03:34
source...: US, Anonymous, id 1340019
I debunked the idea of the file named "obatssrsghde.exe" by taking a chinese spy binary
and creating a VT report. Then renaming said spy file to "obatssrsghde.exe" and
resubmitting it. Thus replicating what Butts did. Examining what VT sent me as the FIRST
submission a file named "roxio_downloaded_from_Demonoid.co" and then renaming it and
resubmitting it to VT as "obatssrsghde.exe".
Examinination of the file sent to me from VT yields that it is a NOT a resultant file but
really a trojan dropper with the following information...
- Registry additions
HKLM\SOFTWARE\Microsoft\Active Setup\Data
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\UpdateNf
- Created files
C:\WINDOWS\system32\api32.dll
C:\WINDOWS\system32\avwav3.dll
C:\WINDOWS\system32\raidmg.dll
C:\WINDOWS\system32\updatenf.dll
Strings:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.9.0.8) Gecko/2009032609
Firefox/3.0.8
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
User-Agent: LimeWire/5.1.2 X-Locale-Pref: en X-Requeries: false X-Version: 4.9
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\UpdateNf
GNUTELLA/0.6 200 OK X-Ultrapeer: True X-Ultrapeer-Needed: True
aniraws.com/bootstrap/skulls.php
grantgalitz.com/Beacon/gwc.php
gwc.mitigated.net/gwc.php
gwc.ak-electron.eu:12050
gwc.eod.cc/skulls.php
Suffix= downloaded from Demonoid.com
The string "downloaded from Demonoid.com" found in the binary matches what Butts first
submitted to VT as "roxio_downloaded_from_Demonoid.co".
Remove-It subsection has lines for "obatssrsghde.exe" but Remove-It has ZERO lines for the
above DLLs or Registry modifications and it would be presumed that IFF Butts had the
ability to analyze this malware he would not only target the malware dropper but the
dropped files and Registry modifications as well. Additionally he stated that when he
obtained the file there were zero detections for it on VT and later the anti malware
vendors starting detecting the malware thanks to his submisson. This is contradicted by
the first VT report for "roxio_downloaded_from_Demonoid.co" received @ 2009/07/21 03:34
and "obatssrsghde.exe" recived 7 minutes later and examination of who detects what and the
respective anti virus libraries showing detection took place long before Butts submitted
"roxio_downloaded_from_Demonoid.co".
----
Summation:
Thus we have a contradiction.
On the one hand you have Butts statements the he put "obatssrsghde.exe" in Remove-It
because he found it was malicious.
On the otherhand he states that he placed "obatssrsghde.exe" as his OWN marker over a year
ago.
In either case he contradicts himself and in both cases the statements are debunked as
nothing but lies.
gur ebg pbqr jnf yrnxrq gb fghneg nsgre guvf enaqbz svyr anzr fubjrq hc. V
sbhaq vg vebavp
Translation:
The rot code was leaked to Stuart after this random file name showed up. I
found it ironic
That ROT code is all over my Remove-it software. I sent Stuart an email last
year after I added that file name apparently he could not figure it out
until now. That inserted code was one way how I was able to prove ownership
of my files after you trolls filed bogus DMCA complaints against me in your
futile attempts at trying to shut me down. So you see Stuart knew nothing
about that file until I told him about it. Stuart the real thief has played
you for a fool and then once again your obsession with me has made you a
bigger fool. Just face it Spammer I am better then you and always will be,
you will NEVER be able to best me because everything I do is legit and I
don't lie. I keep everything and have records of everything I do. I have
beat 2 DMCA complaints because of the truth and you can't stand it. I've
been around a lot longer then you and that thief Stuart and I am going
nowhere.
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
*WARNING* Do NOT follow any advice given by the people listed below.
They do NOT have the expertise or knowledge to fix your issue. Do not waste
your time.
David H Lipman, Malke, PA Bear, Beauregard T. Shagnasty, Leythos.
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:OrB0fFhD...@TK2MSFTNGP03.phx.gbl...
The code did not appear in your hacked file UNTIL AFTER IT WAS ADDED TO
STUARTS FILE THAT YOU STOLE.
You've exposed yourself as the PIRATE/THIEF we all have said you are.
I hope that some of the people that I have maligned so perfidiously can find
in their hearts to forgive me. I will try to provide full compensation to
them when I have regained my health.
--
The Real Truth http://pcbutts1-therenotruth.blogspot.com/
*WARNING* Many public-spirited and knowledgeable people freely give their
time to this newsgroup. You would do well to follow any advice given by
the people listed below. They may have the expertise to fix your issue. You
will not be wasting your time.
David H Lipman, Malke, PA Bear, Ken Blake, John John, Mike Hall, Patrick
Keenan, Ron Badour, Brian A, Peter Foldes, Shenan Stanley, TaurArian, Bruce
Hagen, Leonard Grey, Daave, Bruce Chambers, SC Tom, Elmo, Lem, Kelly, Uwe
Sieber, Pegasus and many more.
"Peter Foldes" <ok...@hotmail.com> wrote in message
news:eond6iZD...@TK2MSFTNGP04.phx.gbl...
=================
From: "The Real Truth MAP" <t...@void.com>
<snip>
X-Newsreader: Microsoft Windows Live Mail 14.0.8050.1202
X-MimeOLE: Produced By Microsoft MimeOLE V14.0.8050.1202
Message-ID: <O5sRE2jD...@TK2MSFTNGP02.phx.gbl>
Newsgroups:
microsoft.public.security.virus,microsoft.public.windowsxp.general
NNTP-Posting-Host: host86-154-71-224.range86-154.btcentralplus.com
86.154.71.224
<snip>
=================
When did Paddy move to the UK?
PS: Whoever you are, you're running an outdated & buggy version of WLMail.
The Real Truth MAP wrote:
> I am so sorry. I must apologise to this newsgroup and the whole world for
> my disgraceful postings. When I have completed my treatment I promise
> never
> to pollute Usenet with my drivel again. If I should relapse and post here
> in the meantime please forgive me and ignore my ranting. I beg you to
> never,
> ever download anything from http://www.ms-mvp.org/ as I was mentally ill
> when I created this site and I put many unforgivable things there.
>
> I hope that some of the people that I have maligned so perfidiously can
> find
> in their hearts to forgive me. I will try to provide full compensation to
> them when I have regained my health.
>
>
--
Peter
Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.
"The Real Truth MAP" <t...@void.com> wrote in message
news:O5sRE2jD...@TK2MSFTNGP02.phx.gbl...
Yes, because you can trust that you didn't insert that post with a
date of july 2008 when your pre-dated over a year. Yeah. Trustable.
Yeah, whatever ;-)
And man, did I write that comment above poorly.
'Yes, because you can trust that you didn't insert that post with a
date of July 2008 when the first post on your blog is predated by over
a year. Yeah, totally trustable there.'
English. It's fundamental.
Twayne
"The Real Truth MAP" <t...@void.com> wrote in message
news:O5sRE2jD...@TK2MSFTNGP02.phx.gbl
> I am so sorry. I must apologise to this newsgroup and the whole
> world for my disgraceful postings. When I have completed my
> treatment I promise never to pollute Usenet with my drivel again. If
> I should relapse and post here in the meantime please forgive me and
> ignore my ranting. I beg you to never, ever download anything from
> http://www.ms-mvp.org/ as I was mentally ill when I created this site
> and I put many unforgivable things there.
> I hope that some of the people that I have maligned so perfidiously
> can find in their hearts to forgive me. I will try to provide full
> compensation to them when I have regained my health.
>
>
SC Tom
"Twayne" <nob...@devnull.spamcop.net> wrote in message
news:etZf1xuD...@TK2MSFTNGP05.phx.gbl...
"SC Tom" wrote:
> I have some ocean-front property in Arizona I'm looking to unload cheap :-)
>
> SC Tom
You must have bought it from George:
http://www.youtube.com/watch?v=NwVHOl4-Ndw
and more games.
--
db���`�...�><)))�>
DatabaseBen, Retired Professional
- Systems Analyst
- Database Developer
- Accountancy
- Veteran of the Armed Forces
- Microsoft Partner
- @hotmail.com
~~~~~~~~~~"share the nirvana" - dbZen
>
>
"The Real Truth MAP" <t...@void.com> wrote in message news:O5sRE2jD...@TK2MSFTNGP02.phx.gbl...
A wasted mind is a terrible thing.