Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

I'm back with a new log, can you guys help me find the virus?


  • Please log in to reply

#1
shadowcyke

shadowcyke

    New Member

  • Member
  • Pip
  • 3 posts
ComboFix 09-05-29.01 - Sean 06/14/2009 23:21.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.754 [GMT -5:00]
Running from: c:\documents and settings\Sean\Desktop\ComboFix.exe
AV: PC Tools AntiVirus 6.0.0.19 *On-access scanning enabled* (Updated) {832E7172-E406-4bb2-8B19-6D29F2C93A98}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Autorun.inf
c:\documents and settings\Sean\Start Menu\Programs\freshplay
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\program files\RelevantKnowledge
c:\program files\RelevantKnowledge\rloci.bin
c:\program files\RelevantKnowledge\rlph.dll
c:\program files\RelevantKnowledge\rlservice.exe
c:\program files\RelevantKnowledge\rlxf.dll
c:\program files\Zumie
c:\program files\Zumie\home.js
c:\program files\Zumie\readme.html
c:\program files\Zumie\uninstall.exe
c:\program files\Zumie\zopt.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\gaopdxdqjkwpuy.sys
c:\windows\system32\drivers\gaopdxpupkvrir.sys
c:\windows\system32\drivers\gaopdxrsilashf.sys
c:\windows\system32\drivers\gaopdxwidoetym.sys
c:\windows\system32\drivers\gaopdxxumoqvss.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxqjpwqoeh.dll

.
((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.

2009-06-14 05:22 . 2009-05-06 16:06 4784464 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{B661D4BA-F106-4A39-A177-DB5EA2915AC4}\mpengine.dll
2009-06-02 05:38 . 2009-05-06 16:06 4784464 ----a-w c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2009-06-02 05:35 . 2009-06-02 05:35 -------- d-----w c:\program files\Windows Defender
2009-05-31 07:37 . 2009-06-14 08:30 -------- d-----w c:\documents and settings\Sean\Application Data\ErrorKiller
2009-05-31 07:37 . 2009-06-14 08:30 -------- d-----w c:\program files\ErrorKiller
2009-05-31 06:52 . 2009-05-31 06:52 -------- d-----w c:\documents and settings\Sean\Application Data\PC Tools
2009-05-31 06:50 . 2009-03-06 21:45 130424 ----a-w c:\windows\system32\drivers\PCTCore.sys
2009-05-31 06:50 . 2008-12-18 17:16 73840 ----a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-05-31 06:49 . 2009-05-31 06:49 -------- d-----w c:\program files\Common Files\PC Tools
2009-05-31 06:49 . 2009-02-10 15:13 21904 ----a-w c:\windows\system32\drivers\AVRec.sys
2009-05-31 06:49 . 2009-02-10 15:13 28560 ----a-w c:\windows\system32\drivers\AVHook.sys
2009-05-31 06:49 . 2009-02-10 15:13 21904 ----a-w c:\windows\system32\drivers\AVFilter.sys
2009-05-31 06:49 . 2009-06-15 04:20 -------- d-----w c:\program files\PC Tools AntiVirus
2009-05-31 06:49 . 2009-05-31 06:52 -------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-05-27 03:54 . 2009-05-27 03:54 2709 ----a-w c:\windows\system32\arytog.dat
2009-05-25 05:56 . 2009-05-25 05:56 -------- d-----w c:\program files\nLite
2009-05-25 05:28 . 2009-05-25 05:28 -------- d--h--w c:\windows\system32\GroupPolicy
2009-05-17 05:58 . 2009-05-17 05:58 -------- d-----w C:\VundoFix Backups

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 04:20 . 2009-03-07 05:54 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-06-14 08:06 . 2008-07-02 01:03 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-14 05:14 . 2008-07-01 23:29 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-31 07:20 . 2008-07-20 00:05 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-30 05:17 . 2008-07-01 23:56 11242 ----a-w c:\windows\system32\nvModes.dat
2009-05-29 03:22 . 2008-07-17 11:40 -------- d-----w c:\program files\quarantine
2009-05-25 05:40 . 2009-05-31 05:55 170936 ----a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-05-24 05:25 . 2008-08-04 00:58 -------- d-----w c:\documents and settings\Sean\Application Data\Azureus
2009-05-14 20:58 . 2009-05-14 04:29 2709 ----a-w c:\windows\system32\gcracob.dat
2009-05-07 15:44 . 2006-02-28 12:00 344064 ----a-w c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2006-02-28 12:00 659456 ----a-w c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2006-02-28 12:00 81920 ----a-w c:\windows\system32\ieencode.dll
2009-04-23 04:30 . 2009-04-23 04:28 -------- d-----w c:\program files\BitLord
2009-04-23 04:14 . 2009-04-23 04:14 -------- d-----w c:\program files\Ares
2009-04-18 05:26 . 2008-08-15 03:33 -------- d-----w c:\documents and settings\Sean\Application Data\LimeWire
2009-04-17 09:58 . 2006-02-28 12:00 1846656 ----a-w c:\windows\system32\win32k.sys
2009-04-17 03:48 . 2009-04-17 03:48 49403 ----a-w c:\windows\system32\rn.tmp
2009-04-15 15:11 . 2006-02-28 12:00 584192 ----a-w c:\windows\system32\rpcrt4.dll
2008-12-19 08:05 . 2008-07-19 21:51 67688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 08:05 . 2008-07-19 21:51 54368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 08:05 . 2008-07-19 21:51 34944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 08:05 . 2008-07-19 21:51 46712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 08:05 . 2008-07-19 21:51 172136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-25 17:40 . 2008-09-25 17:40 6144 --sha-w c:\windows\system32\higawaka.dll
2008-12-21 21:27 . 2008-12-21 21:27 522 --sh--w c:\windows\system32\nezusena.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-06-19 50528]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-01 68856]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
"ErrorKiller"="c:\program files\ErrorKiller\ErrorKiller.exe" [2009-05-18 3297280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"GC75-Manager-Class"="c:\program files\Dell TrueMobile 5100\GPRSMgr.exe" [2004-03-27 721017]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
"PCTAVApp"="c:\program files\PC Tools AntiVirus\PCTAV.exe" [2009-02-19 1374096]
"MRT"="c:\windows\system32\MRT.exe" [2009-06-01 23635392]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-BA7E-000000000003}\_SC_Acrobat.exe [2008-7-2 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\WINDOWS\\system32\\WLTRYSVC.EXE"=
"c:\\Program Files\\Adobe\\Acrobat 8.0\\Acrobat\\acrotray.exe"=
"c:\\Program Files\\Apoint\\ApntEx.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7Debug\\mdm.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/31/2009 1:50 AM 130424]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [7/17/2008 6:34 AM 58464]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [10/23/2003 4:04 PM 76160]
S3 PCX500;Cisco Wireless LAN Adapters Driver;c:\windows\system32\drivers\pcx500.sys [10/5/2008 12:43 AM 169984]
.
Contents of the 'Scheduled Tasks' folder

2008-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]

2009-06-14 c:\windows\Tasks\ErrorKiller Scheduled Scan.job
- c:\program files\ErrorKiller\ErrorKiller.exe [2009-05-18 11:58]

2009-06-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-01 05:35]

2009-06-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Sean\Application Data\Mozilla\Firefox\Profiles\j8fxiu3q.default\
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\qfaservices.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-14 23:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-436374069-764733703-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7E502217-A2EA-C2C5-E935-4CB4A2FA29DB}*]
"hacpdpaenjolnkoh"=hex:69,61,68,6e,6b,68,67,63,6e,63,68,6f,6c,69,68,6c,63,6c,
00,00
"iaadjnngchjjolcomb"=hex:6a,61,6a,6e,65,67,66,65,68,64,68,6c,6a,62,6b,70,65,68,
63,64,00,00
"hampbkcllamhgmam"=hex:61,61,00,7e
"hampbkclkahjdiih"=hex:61,61,00,7e
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(824)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll

- - - - - - - > 'lsass.exe'(880)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll

- - - - - - - > 'explorer.exe'(756)
c:\program files\Common Files\Nero\Lib\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\browselc.dll
c:\program files\Microsoft Office\Office10\msohev.dll

- - - - - - - > 'csrss.exe'(772)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
.
Completion time: 2009-06-15 23:24
ComboFix-quarantined-files.txt 2009-06-15 04:24

Pre-Run: 6,607,228,928 bytes free
Post-Run: 6,715,617,280 bytes free

220 --- E O F --- 2009-06-14 08:07
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,147 posts
  • MVP
You really ought to consider getting rid of your P2P programs. Area, Vuze, Azureus, Limewire, BitLord, utorrent, and friends are all very dangerous to use since you never know where a file has been or what has been done to it.

I went back and looked at your first log and you had a DNS hijacker so let's do this first:
1. Click "Start," click "Control Panel," click "Network and Internet Connections," and then click "Network Connections."
2. Right-click the network connection that you want to configure (the one you use to connect to the Internet), and then click Properties.
3. On the General tab (for a local area connection), or the Networking tab (for all other connections), click "Internet Protocol (TCP/IP)", and then click "Properties."

4. Click "Use the following DNS server addresses," and then type 199.166.28.10 in the Preferred DNS server and 4.2.2.1 in the Alternate DNS server boxes.

5. Click "OK"

Verify that the changes worked:

Click "Start," Click "Run," type: cmd , OK to bring up a black command window. Type with an Enter after each line

ipconfig /release
ipconfig /renew
ipconfig /flushdns
ipconfig /all

(There will be an entry for DNS Server. Verify that it has the 199.168.28.10 and 4.2.2.1 addresses.)

Combofix killed off a nasty rootkit but there are still a few bad guys visible.

Copy the text between the lines of stars by highlighting and Ctrl + c.

******************************************

Killall:


File::
c:\windows\system32\higawaka.dll
c:\windows\system32\nezusena.exe
c:\windows\system32\rn.tmp
c:\windows\system32\gcracob.dat
c:\windows\system32\arytog.dat


RegNull::
[HKEY_USERS\S-1-5-21-436374069-764733703-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7E502217-A2EA-C2C5-E935-4CB4A2FA29DB}*]


RegLock::
[HKEY_USERS\S-1-5-21-436374069-764733703-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7E502217-A2EA-C2C5-E935-4CB4A2FA29DB}]

Registry::
[-HKEY_USERS\S-1-5-21-436374069-764733703-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7E502217-A2EA-C2C5-E935-4CB4A2FA29DB}*]


******************************************
The last three entries with [ ] should each be one line tho it looks like the forum has wrapped them.

Now open notepad (Start, Run, notepad, OK) and Ctrl + V to paste the text into Notepad. Make sure you got it all then File, SAVE AS, (to your Desktop), CFScript , OK. Close notepad. You should see a file CFScript.txt on your desktop.

Drag it over to Combofix and let it start as before.

Post the new log.

Run:

Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.

Finally do a free a free Kaspersky online scan as a final check to see if we missed anything. http://www.kaspersky.com/virusscanner
It takes a while (hours) and you have to turn off your antivirus while you are running it but it is pretty thorough. It doesn't fix anything so if it finds something (that is not in Qoobox, or your antivirus's subfolders) you should save the log and post it in a reply.
If windows blocks the active x then try putting Kaspersky in your trusted sites: In IE, Tool, Internet Options, Security, Trusted Sites, Sites. Then uncheck the HTTPS box and put in *.kaspersky.com then ADD. OK.



Ron
  • 0

#3
shadowcyke

shadowcyke

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Thanks Ron. I can't run any programs except firefox, unless I'm in safe mode. But I can't get online in safe mode. I'll print off your post and follow the instructions.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP