Archive for the ‘Computer’ Category

My New Toy

I finally got my new laptop this week :) . Well, it’s not really mine, it’s my office’s. Last month when I was still on leave my boss told me to search for a new laptop since my old HP is already out of date. Later I told her that my choice was either HP Pavilion dv4-1532TX Moonlight White or HP Pavilion dm3-1028TX.

It should have been ready on the first day I came back to work two weeks ago if our new IT guy just approved one of my choices. Instead he told our GA department to hold and waited until I came because he wanted to talk to me first.

Later he told me the specs of those two laptops were too high for legal department. But I said those laptops were within $1,100 budget. He said he had a list of cheaper laptop with the same or lesser specs. WTF! I told him if that was the case, then my boss shouldn’t bother to call me during my leave on the first place. Just bought any laptop they wanted and surprised me later!

HP Pavilion dv4-1532TX Moonlight White

My new HP Pavilion dv4-1532TX Moonlight White

Anyway, I insisted. There was a reason why I was called to search for my own laptop which was because my boss trusted my choice. Finally, it was settled. Earlier this week my new toy arrived. It’s an HP Pavilion dv4-1532TX Moonlight White bundled with Windows 7 Home Premium. The HP symbol on the cover will glow when turned on. Beautiful isn’t it? I should be very careful with it though, as it’s in all white including the keyboard so it’s easy to get dirty.

So it’s time to say good bye to my old lappy. It’s not easy though, since I’ve been using that laptop for over five years, so it’s almost like a soul mate to me. She witnessed my up and down mood at work, sometimes I slapped her when I was upset (oops). I’m gonna miss you lappy :(

My Old P-4 HP Laptop

My Old Lappy

And welcome new lappy! Hopefully we’re gonna have fun working together for (at least) the next five years :)

My New HP Pavilion dv4-1532TX Moonlight White

My New Lappy

Got Trojan Agent On My Computer

I was using my computer the other day when suddenly a message appeared on my screen saying

microsoft visual c++ runtime library buffer overrun detected

C:\Documents and Settings\All Users\Application Data/csrss.exe

A buffer overrun has been detected which has corrupted the program’s internal state. The program cannot safely continue execution and must now be terminted.

I could see there was something not right in that message. File csrss.exe was a legitimate Windows core system file but it supposed to be located in Windows\System32 not in Documents and Settings\All Users\Application Data. So I immediately suspected my computer was infected by virus or spyware or malware or whatever it was called (I still don’t understand the difference between them).

I knew there was an easy, fast, reliable and (the most important was) FREE way to handle computer problems in my house. Easy because all I have to do is call the computer repairman, fast because he usually knows what to do, reliable because he’s done it so many times and FREE because he is my brother (or his friends), lol. But no, this time I chose the hardest way. I tried to solve them by myself, so I started to do some search (a lot of search to be exact) on Google instead.

After two days (yes that long) of trying several free anti-virus, anti spyware and anti-malware downloaded from the net, finally, I could solve the problem. Apparently my computer was infected with Trojan Agent and thankfully Malwarebytes’ Anti-Malware could detect and kill it for free, here’s the log file.

Malwarebytes’ Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 2

10/31/2009 11:04:29 PM
mbam-log-2009-10-31 (23-04-29).txt

Scan type: Full Scan (D:\|)
Objects scanned: 132807
Time elapsed: 28 minute(s), 28 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
D:\Documents and Settings\All Users\Application Data\csrss.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Csrss (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Documents and Settings\All Users\Application Data\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Elle\Local Settings\Temp\csrss2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\csrss2.dll (Trojan.Agent) -> Delete on reboot.

There were other programs that could detect the Trojan but they asked me to register (read: pay) before I could use to remove it, so I skipped them. Other programs failed to detect it but found other types of infections instead, most were found in my browser’s cookies.

Satisfied with my accomplishment, I called my brother to brag about it.
Read more