<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Just Too Little Time &#187; Computer</title>
	<atom:link href="http://alittleboysblog.com/category/computer/feed/" rel="self" type="application/rss+xml" />
	<link>http://alittleboysblog.com</link>
	<description>Too much to do too little time</description>
	<lastBuildDate>Sat, 12 Mar 2011 01:06:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>My New Toy</title>
		<link>http://alittleboysblog.com/2010/01/my-new-toy/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=my-new-toy</link>
		<comments>http://alittleboysblog.com/2010/01/my-new-toy/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 04:27:19 +0000</pubDate>
		<dc:creator>elna</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Office Work]]></category>
		<category><![CDATA[HP Pavilion dm3-1028TX]]></category>
		<category><![CDATA[HP Pavilion dm3t series]]></category>
		<category><![CDATA[HP Pavilion dv4-1532TX Moonlight White]]></category>
		<category><![CDATA[HP Pavilion dv4t entertainment series]]></category>
		<category><![CDATA[Win7 Home Premium]]></category>

		<guid isPermaLink="false">http://alittleboysblog.com/?p=652</guid>
		<description><![CDATA[I finally got my new laptop this week . Well, it&#8217;s not really mine, it&#8217;s my office&#8217;s. Last month when I was still on leave my boss told me to search for a new laptop since my old HP is already out of date. Later I told her that my choice was either HP Pavilion [...]]]></description>
			<content:encoded><![CDATA[<div style="text-align:center;width:100%;margin:10px 0px 10px 0px;"><div style="margin:auto;"><script type="text/javascript"><!--
google_ad_client = "pub-6725783630795478";
/* Under Post  Title 468x15 */
google_ad_slot = "4914008089";
google_ad_width = 468;
google_ad_height = 15;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div></div><div style="width:100%;min-width:100%;"><p style="text-align: justify;">I finally got my <a href="http://alittleboysblog.com/2009/12/i-found-the-laptop-i-want/">new laptop</a> this week <img src='http://alittleboysblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . Well, it&#8217;s not really mine, it&#8217;s my office&#8217;s. Last month <em>when I was still on leave</em> my boss told me to search for a new laptop since my old HP is already out of date. Later I told her that my choice was either HP Pavilion dv4-1532TX Moonlight White or HP Pavilion dm3-1028TX.</p>
<p style="text-align: justify;">It should have been ready on the first day I came back to work two weeks ago if our new IT guy just approved one of my choices. Instead he told our GA department to hold and waited until I came because he wanted to talk to me first.</p>
<p style="text-align: justify;">Later he told me the specs of those two laptops were too high for legal department. But I said those laptops were within $1,100 budget. He said he had a list of cheaper laptop with the same or lesser specs. WTF! I told him if that was the case, then my boss shouldn&#8217;t bother to call me during my leave on the first place. Just bought any laptop they wanted and surprised me later!</p>
<div id="attachment_658" class="wp-caption alignleft" style="width: 260px"><a href="http://alittleboysblog.com/wp-content/uploads/2010/01/22012010047.jpg"><img class="size-full wp-image-658" title="My HP Pavilion dv4-1532TX Moonlight White" src="http://alittleboysblog.com/wp-content/uploads/2010/01/22012010047.jpg" alt="HP Pavilion dv4-1532TX Moonlight White" width="250" height="153" /></a><p class="wp-caption-text">My new HP Pavilion dv4-1532TX Moonlight White</p></div>
<p style="text-align: justify;">Anyway, I insisted. There was a reason why I was called to search for my own laptop which was because my boss trusted my choice. Finally, it was settled. Earlier this week my new toy arrived. It&#8217;s an HP Pavilion dv4-1532TX Moonlight White bundled with Windows 7 Home Premium. The HP symbol on the cover will glow when turned on. Beautiful isn&#8217;t it? I should be very careful with it though, as it&#8217;s in all white <em>including the keyboard</em> so it&#8217;s easy to get dirty.</p>
<p>So it&#8217;s time to say good bye to my old lappy. It&#8217;s not easy though, since I&#8217;ve been using that laptop for over five years, so it&#8217;s almost like a soul mate to me. She witnessed my up and down mood at work, sometimes I slapped her when I was upset (oops). I&#8217;m gonna miss you lappy <img src='http://alittleboysblog.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<div id="attachment_661" class="wp-caption aligncenter" style="width: 210px"><a href="http://alittleboysblog.com/wp-content/uploads/2010/01/100_1340.jpg"><img class="size-full wp-image-661" title="My Old P-4 HP Laptop" src="http://alittleboysblog.com/wp-content/uploads/2010/01/100_1340.jpg" alt="My Old P-4 HP Laptop" width="200" height="200" /></a><p class="wp-caption-text">My Old Lappy</p></div>
<p style="text-align: justify;">And welcome new lappy! Hopefully we&#8217;re gonna have fun working together for (at least) the next five years <img src='http://alittleboysblog.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div id="attachment_662" class="wp-caption aligncenter" style="width: 260px"><a href="http://alittleboysblog.com/wp-content/uploads/2010/01/22012010050.jpg"><img class="size-full wp-image-662" title="My New Laptop" src="http://alittleboysblog.com/wp-content/uploads/2010/01/22012010050.jpg" alt="My New HP Pavilion dv4-1532TX Moonlight White" width="250" height="250" /></a><p class="wp-caption-text">My New Lappy</p></div>
</div>]]></content:encoded>
			<wfw:commentRss>http://alittleboysblog.com/2010/01/my-new-toy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Got Trojan Agent On My Computer</title>
		<link>http://alittleboysblog.com/2009/11/got-trojan-agent-on-my-computer/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=got-trojan-agent-on-my-computer</link>
		<comments>http://alittleboysblog.com/2009/11/got-trojan-agent-on-my-computer/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 20:39:59 +0000</pubDate>
		<dc:creator>elna</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[anti malware]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[avira]]></category>
		<category><![CDATA[clam antivirus]]></category>
		<category><![CDATA[computer repairman]]></category>
		<category><![CDATA[csrss.exe]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[kaspersky online scanner]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[malwarebytes anti-malware]]></category>
		<category><![CDATA[spyware terminator]]></category>
		<category><![CDATA[trojan agent]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://alittleboysblog.com/?p=339</guid>
		<description><![CDATA[I was using my computer the other day when suddenly a message appeared on my screen saying microsoft visual c++ runtime library buffer overrun detected C:\Documents and Settings\All Users\Application Data/csrss.exe A buffer overrun has been detected which has corrupted the program&#8217;s internal state. The program cannot safely continue execution and must now be terminted. I [...]]]></description>
			<content:encoded><![CDATA[<p>I was using my computer the other day when suddenly a message appeared on my screen saying</p>
<blockquote><p>microsoft visual c++ runtime library buffer overrun detected</p>
<p>C:\Documents and Settings\All Users\Application Data/csrss.exe</p>
<p>A buffer overrun has been detected which has corrupted the program&#8217;s internal state. The program cannot safely continue execution and must now be terminted.</p></blockquote>
<p>I could see there was something not right in that message. File csrss.exe was a legitimate Windows core system file but it supposed to be located in Windows\System32 not in Documents and Settings\All Users\Application Data. So I immediately suspected my computer was infected by virus or spyware or malware or whatever it was called (I still don&#8217;t understand the difference between them).</p>
<p>I knew there was an easy, fast, reliable and (the most important was) <strong>FREE</strong> way to handle computer problems in my house. <em>Easy</em> because all I have to do is call the computer repairman, <em>fast</em> because he usually knows what to do, <em>reliable</em> because he&#8217;s done it so many times and <em>FREE</em> because he is my brother (or his friends), lol. But no, this time I chose the hardest way. I tried to solve them by myself, so I started to do some search (a lot of search to be exact) on Google instead.</p>
<p>After two days (yes that long) of trying several free anti-virus, anti spyware and anti-malware downloaded from the net, finally, I could solve the problem. Apparently my computer was infected with Trojan Agent and thankfully <a href="http://malwarebytes.gt500.org/mbam-setup.exe">Malwarebytes&#8217; Anti-Malware</a> could detect and kill it for free, here&#8217;s the log file.</p>
<blockquote><div style="overflow:auto;width:400px;height:200px;padding:10px;border:1px solid #eee">Malwarebytes&#8217; Anti-Malware 1.41<br />
Database version: 2775<br />
Windows 5.1.2600 Service Pack 2</p>
<p>10/31/2009 11:04:29 PM<br />
mbam-log-2009-10-31 (23-04-29).txt</p>
<p>Scan type: Full Scan (D:\|)<br />
Objects scanned: 132807<br />
Time elapsed: 28 minute(s), 28 second(s)</p>
<p>Memory Processes Infected: 1<br />
Memory Modules Infected: 0<br />
Registry Keys Infected: 1<br />
Registry Values Infected: 0<br />
Registry Data Items Infected: 0<br />
Folders Infected: 0<br />
Files Infected: 3</p>
<p>Memory Processes Infected:<br />
D:\Documents and Settings\All Users\Application Data\csrss.exe (Trojan.Agent) -> Unloaded process successfully.</p>
<p>Memory Modules Infected:<br />
(No malicious items detected)</p>
<p>Registry Keys Infected:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Csrss (Trojan.Agent) -> Quarantined and deleted successfully.</p>
<p>Registry Values Infected:<br />
(No malicious items detected)</p>
<p>Registry Data Items Infected:<br />
(No malicious items detected)</p>
<p>Folders Infected:<br />
(No malicious items detected)</p>
<p>Files Infected:<br />
D:\Documents and Settings\All Users\Application Data\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.<br />
D:\Documents and Settings\Elle\Local Settings\Temp\csrss2.dll (Trojan.Agent) -> Quarantined and deleted successfully.<br />
D:\WINDOWS\system32\csrss2.dll (Trojan.Agent) -> Delete on reboot.</p></div>
</blockquote>
<p>There were other programs that could detect the Trojan but they asked me to register (read: pay) before I could use to remove it, so I skipped them. Other programs failed to detect it but found other types of infections instead, most were found in my browser&#8217;s cookies.</p>
<p>Satisfied with my accomplishment, I called my brother to brag about it.<br />
<span id="more-339"></span><br />
<blockquote>&#8220;Hei, I got virus on my computer!&#8221;<br />
&#8220;Oh! You want me to check?&#8221;<br />
&#8220;Nah, fixed it already with malwarebytes&#8221;<br />
&#8220;No wonder you sound happy. Where did you get the program?&#8221;<br />
&#8220;Google&#8221; <em>(sparing the details about how long it took me to find it)</em><br />
&#8220;Try to rescan with Kaspersky&#8221;<br />
&#8220;Why? Is it better?&#8221;<br />
&#8220;Just to make sure there&#8217;s nothing left. Sometimes different program can find what others can&#8217;t&#8221;<br />
&#8220;I don&#8217;t like installing another anti-virus, already got too many of them&#8221;<br />
&#8220;Use the online scan, you don&#8217;t have to install it&#8221;<br />
&#8220;Oh ok, I&#8217;ll try&#8221;<br />
&#8220;How many anti-virus you installed by the way?&#8221;<br />
&#8220;Some. Bye!&#8221;</p></blockquote>
<p>So I tried to online antivirus scan with <a href="http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html">Kaspersky</a>. Of course another threats found, here&#8217;s the log file.</p>
<blockquote><div style="overflow:auto;width:400px;height:200px;padding:10px;border:1px solid #eee">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
KASPERSKY ONLINE SCANNER 7.0: scan report<br />
 Monday, November 2, 2009<br />
 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)<br />
 Kaspersky Online Scanner version: 7.0.26.13<br />
 Last database update: Monday, November 02, 2009 16:08:40<br />
 Records in database: 3114865<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Scan settings:<br />
	scan using the following database: extended<br />
	Scan archives: yes<br />
	Scan e-mail databases: yes</p>
<p>Scan area &#8211; Folder:<br />
	D:\Documents and Settings</p>
<p>Scan statistics:<br />
	Objects scanned: 12867<br />
	Threats found: 1<br />
	Infected objects found: 4<br />
	Suspicious objects found: 0<br />
	Scan duration: 00:10:06</p>
<p>File name / Threat / Threats count<br />
D:\Documents and Settings\Elle\Local Settings\Temp\plugtmp-90\plugin-board_review_view.php	Infected: Exploit.Win32.Pidief.crv	1<br />
D:\Documents and Settings\Elle\Local Settings\Temp\plugtmp-97\plugin-IMG_1084.php	Infected: Exploit.Win32.Pidief.crv	1<br />
D:\Documents and Settings\Elle\Local Settings\Temp\plugtmp-99\plugin-IMG_1084-1.php	Infected: Exploit.Win32.Pidief.crv	1<br />
D:\Documents and Settings\Elle\Local Settings\Temp\plugtmp-99\plugin-IMG_1084.php	Infected: Exploit.Win32.Pidief.crv	1</p>
<p>Selected area has been scanned.</p></div>
</blockquote>
<p>Those files seemed harmless (I guess) as they were located in temp folder. I deleted them anyway. </p>
<p>I found Malwarebytes was quite good in handling malware, the only downfall was the free version didn&#8217;t support real-time protection. So to give a real-time protection to my computer I installed Spyware Terminator (free version). It was integrated with Clam AntiVirus so could perform as anti-virus as well. Before, I used the free version of Avira (which was good) as my anti-virus but it couldn&#8217;t protect me from spyware or malware, so I temporarily disabled it and would see if Spyware Terminator could do better. </p>
<p>Now is my computer safe? Hopefully.</p>
]]></content:encoded>
			<wfw:commentRss>http://alittleboysblog.com/2009/11/got-trojan-agent-on-my-computer/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

