Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Dang...another computer! [RESOLVED]


  • This topic is locked This topic is locked

#16
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi em,

We'll try the easy way but i just know it won't work :tazz:

Please disable Microsoft Antispyware.

Reboot into Safe mode, rescan with HJT and check the following

O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O23 - Service: Remote Procedure Call (RPC) Helper ( 11F#`I) - Unknown owner - C:\WINNT\atlqy32.exe (file missing)


Ensure no windows open except HJT and click FIX CHECKED.

Now carry out the Delete an NT Service in HJT MISC tools

In the popup box paste the following

11F#`I

MAKE SURE THERE IS A SPACE IN FRONT OF THE FIRST NUMBER 1

Reboot normally, rescan with HJT and post the log back
  • 0

Advertisements


#17
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Hehehee......didn't work...

It let me fixed the check but not the delete NT services. But when I rebooted normally and ran the scan... it was back.... I guess this is gonna be a lil tricky?

I was able to type in the msconfig and the boxed popped up. Does that help? lol

Here's my log....Em

Logfile of HijackThis v1.99.1
Scan saved at 9:14:15 AM, on 6/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Hijack This\HijackThis.exe

O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1115056631785
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11F#`I) - Unknown owner - C:\WINNT\atlqy32.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
  • 0

#18
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
greetings, usetobe asked my to drop in and perhaps provide an assist


Is this Xp Pro or Home?

Do we have a new variant of a malware?
  • 0

#19
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Hi gerry

It's Pro

and as for the new variant? have no clue...this one is a doosey!

Thanks in advance...Em
  • 0

#20
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
want you to do the following

start > run
cmd
enter

in the black box, type

tasklist /svc > "%userprofile%"\desktop\services.txt

then

tasklist /m > "%userprofile%"\desktop\modules.txt

post or attach those two files (you will find them on your desktop) here
  • 0

#21
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Okay here we go....


Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 292 N/A
csrss.exe 340 N/A
winlogon.exe 364 N/A
services.exe 408 Eventlog, PlugPlay
lsass.exe 420 PolicyAgent, ProtectedStorage, SamSs
svchost.exe 588 RpcSs
svchost.exe 612 AudioSrv, Browser, CryptSvc, Dhcp, dmserver,
ERSvc, EventSystem, helpsvc, lanmanserver,
lanmanworkstation, Netman, Nla, NtmsSvc,
Schedule, seclogon, SENS, ShellHWDetection,
TermService, Themes, TrkWks, uploadmgr,
W32Time, winmgmt, wuauserv, WZCSVC
svchost.exe 684 Dnscache
svchost.exe 696 LmHosts, RemoteRegistry, SSDPSRV, WebClient
spoolsv.exe 816 Spooler
aswUpdSv.exe 956 aswUpdSv
svchost.exe 1216 stisvc
explorer.exe 1456 N/A
mm_tray.exe 1812 N/A
ctfmon.exe 1856 N/A
gcasDtServ.exe 1900 N/A
cmd.exe 1332 N/A
tasklist.exe 1796 N/A
wmiprvse.exe 456 N/A



Image Name PID Modules
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 292 ntdll.dll
csrss.exe 340 ntdll.dll, CSRSRV.dll, basesrv.dll,
winsrv.dll, USER32.dll, KERNEL32.dll,
GDI32.dll, ADVAPI32.dll, RPCRT4.dll, sxs.dll
winlogon.exe 364 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, GDI32.dll,
USER32.dll, USERENV.dll, NDdeApi.dll,
CRYPT32.dll, MSASN1.dll, Secur32.dll,
WINSTA.dll, PROFMAP.dll, NETAPI32.dll,
REGAPI.dll, WS2_32.dll, WS2HELP.dll,
AUTHZ.dll, PSAPI.DLL, VERSION.dll,
SETUPAPI.dll, MSGINA.dll, SHELL32.dll,
SHLWAPI.dll, COMCTL32.dll, ODBC32.dll,
comdlg32.dll, comctl32.dll, odbcint.dll,
SHSVCS.dll, sfc.dll, sfc_os.dll,
WINTRUST.dll, ole32.dll, IMAGEHLP.dll,
WINSCARD.DLL, WTSAPI32.dll, sxs.dll,
uxtheme.dll, WINMM.dll, cscdll.dll,
WlNotify.dll, WINSPOOL.DRV, MPR.dll,
rsaenh.dll, msv1_0.dll, wldap32.dll,
SAMLIB.dll, cscui.dll, NTMARTA.DLL,
COMRes.dll, OLEAUT32.dll, CLBCATQ.DLL,
wdmaud.drv, msacm32.drv, MSACM32.dll,
midimap.dll
services.exe 408 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, USER32.dll,
GDI32.dll, USERENV.dll, SCESRV.dll,
AUTHZ.dll, umpnpmgr.dll, WINSTA.dll,
NCObjAPI.DLL, secur32.dll, eventlog.dll,
WS2_32.dll, WS2HELP.dll, PSAPI.DLL,
wtsapi32.dll, netapi32.dll
lsass.exe 420 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, LSASRV.dll, msvcrt.dll,
Secur32.dll, USER32.dll, GDI32.dll,
SAMSRV.dll, cryptdll.dll, DNSAPI.dll,
WS2_32.dll, WS2HELP.dll, MSASN1.dll,
NETAPI32.dll, SAMLIB.dll, MPR.dll,
NTDSAPI.dll, WLDAP32.dll, msprivs.dll,
kerberos.dll, msv1_0.dll, netlogon.dll,
w32time.dll, MSVCP60.dll, iphlpapi.dll,
USERENV.dll, schannel.dll, CRYPT32.dll,
wdigest.dll, rsaenh.dll, scecli.dll,
SETUPAPI.dll, OLEAUT32.dll, OLE32.DLL,
shell32.dll, SHLWAPI.dll, comctl32.dll,
comctl32.dll, ipsecsvc.dll, oakley.DLL,
WINIPSEC.DLL, pstorsvc.dll, mswsock.dll,
wshtcpip.dll, dssenh.dll, psbase.dll
svchost.exe 588 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, rpcss.dll, msvcrt.dll,
WS2_32.dll, WS2HELP.dll, USER32.dll,
GDI32.dll, Secur32.dll, userenv.dll,
mswsock.dll, wshtcpip.dll, DNSAPI.dll,
iphlpapi.dll, winrnr.dll, WLDAP32.dll,
rasadhlp.dll, CLBCATQ.DLL, ole32.dll,
OLEAUT32.dll, COMRes.dll, VERSION.dll,
msv1_0.dll, netapi32.dll
svchost.exe 612 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, ole32.dll, GDI32.dll,
USER32.dll, shsvcs.dll, msvcrt.dll,
SHLWAPI.dll, shell32.dll, comctl32.dll,
comctl32.dll, WINSTA.dll, dhcpcsvc.dll,
DNSAPI.dll, WS2_32.dll, WS2HELP.dll,
iphlpapi.dll, Secur32.dll, mswsock.dll,
wshtcpip.dll, UxTheme.dll, rsaenh.dll,
wzcsvc.dll, rtutils.dll, WMI.dll,
OLEAUT32.dll, CRYPT32.dll, MSASN1.dll,
WTSAPI32.dll, ESENT.dll, WLDAP32.dll,
NETAPI32.dll, rastls.dll, ATL.DLL,
CRYPTUI.dll, WINTRUST.dll, IMAGEHLP.dll,
WININET.dll, MPRAPI.dll, ACTIVEDS.dll,
adsldpc.dll, SAMLIB.dll, SETUPAPI.dll,
RASAPI32.dll, rasman.dll, TAPI32.dll,
WINMM.dll, SCHANNEL.dll, USERENV.dll,
WinSCard.dll, raschap.dll, msv1_0.dll,
CLBCATQ.DLL, COMRes.dll, VERSION.dll,
schedsvc.dll, NTDSAPI.dll, MSIDLE.DLL,
NTMARTA.DLL, audiosrv.dll, wkssvc.dll,
cryptsvc.dll, certcli.dll, dmserver.dll,
ersvc.dll, es.dll, pchsvc.dll, srvsvc.dll,
ntmssvc.dll, NTMSDBA.dll, seclogon.dll,
sens.dll, winspool.drv, srsvc.dll,
POWRPROF.dll, tapisrv.dll, PSAPI.DLL,
trkwks.dll, w32time.dll, MSVCP60.dll,
wmisvc.dll, wbemcomn.dll, VSSAPI.DLL,
wuauserv.dll, wuaueng.dll, ADVPACK.dll,
SHFOLDER.dll, WINHTTP.dll, Cabinet.dll,
mspatcha.dll, sfc.dll, sfc_os.dll,
browser.dll, SXS.DLL, comsvcs.dll,
MTXCLU.DLL, WSOCK32.dll, colbact.DLL,
CLUSAPI.DLL, RESUTILS.DLL, mtxoci.dll,
termsrv.dll, ICAAPI.dll, AUTHZ.dll,
mstlsapi.dll, REGAPI.dll, netman.dll,
wups.dll, NETSHELL.dll, credui.dll,
hnetcfg.dll, upnp.dll, SSDPAPI.dll,
wbemcore.dll, esscli.dll, FastProx.dll,
msi.dll, wmiutils.dll, repdrvfs.dll,
wmiprvsd.dll, NCObjAPI.DLL, wbemess.dll,
rasadhlp.dll, RASDLG.dll, ncprov.dll,
wbemsvc.dll
svchost.exe 684 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, dnsrslvr.dll, msvcrt.dll,
USER32.dll, GDI32.dll, DNSAPI.dll,
WS2_32.dll, WS2HELP.dll, iphlpapi.dll,
mswsock.dll, wshtcpip.dll
svchost.exe 696 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, ole32.dll, GDI32.dll,
USER32.dll, lmhsvc.dll, msvcrt.dll,
iphlpapi.dll, WS2_32.dll, WS2HELP.dll,
webclnt.dll, WININET.dll, SHLWAPI.dll,
CRYPT32.dll, MSASN1.dll, OLEAUT32.dll,
comctl32.dll, shell32.dll, comctl32.dll,
Secur32.dll, wsock32.dll, regsvc.dll,
ssdpsrv.dll, mswsock.dll, wshtcpip.dll,
uxtheme.dll, DNSAPI.dll, rasadhlp.dll
spoolsv.exe 816 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, GDI32.dll,
USER32.dll, SPOOLSS.DLL, WS2_32.dll,
WS2HELP.dll, DNSAPI.dll, rasadhlp.dll,
localspl.dll, ole32.dll, OLEAUT32.dll,
VERSION.dll, Secur32.dll, sfc_os.dll,
WINTRUST.dll, CRYPT32.dll, MSASN1.dll,
IMAGEHLP.dll, USERENV.dll, winspool.drv,
netapi32.dll, cnbjmon.dll, LXASLMPM.DLL,
SHELL32.dll, SHLWAPI.dll, COMCTL32.dll,
comctl32.dll, uxtheme.dll, lxasbce.dll,
FXSMON.DLL, FXSEVENT.dll, pjlmon.dll,
tcpmon.dll, tcpmib.dll, WSOCK32.dll,
mgmtapi.dll, snmpapi.dll, wsnmp32.dll,
iphlpapi.dll, usbmon.dll, lxas2kpm.dll,
lxaspp.dll, mswsock.dll, winrnr.dll,
WLDAP32.dll, win32spl.dll, NETRAP.dll,
CLBCATQ.DLL, COMRes.dll, inetpp.dll,
icmp.dll, Lxasmdm.dll
aswUpdSv.exe 956 ntdll.dll, kernel32.dll, aswCmnS.dll,
aswCmnOS.dll, USER32.dll, GDI32.dll,
ADVAPI32.dll, RPCRT4.dll, MSVCP70.dll,
MSVCR70.dll, WSOCK32.dll, WS2_32.dll,
msvcrt.dll, WS2HELP.dll, aswCmnB.dll
svchost.exe 1216 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, wiaservc.dll, msvcrt.dll,
USER32.dll, GDI32.dll, OLEAUT32.dll,
OLE32.DLL, SHLWAPI.dll, CFGMGR32.dll,
setupapi.dll, USERENV.dll, mscms.dll,
WINSPOOL.DRV, WINSTA.dll, VERSION.dll,
CLBCATQ.DLL, COMRes.dll, hpojwia.dll,
actxprxy.dll, sti.dll
explorer.exe 1456 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, GDI32.dll,
USER32.dll, SHLWAPI.dll, SHELL32.dll,
ole32.dll, OLEAUT32.dll, BROWSEUI.dll,
SHDOCVW.dll, UxTheme.dll, comctl32.dll,
comctl32.dll, appHelp.dll, CLBCATQ.DLL,
COMRes.dll, VERSION.dll, cscui.dll,
CSCDLL.dll, Secur32.dll, USERENV.dll,
actxprxy.dll, LINKINFO.dll, ntshrui.dll,
ATL.DLL, NETAPI32.dll, SAMLIB.dll, msi.dll,
SETUPAPI.dll, shellextension.dll,
NETSHELL.dll, credui.dll, WS2_32.dll,
WS2HELP.dll, iphlpapi.dll, urlmon.dll,
MSCTF.dll, mslbui.dll, WINSTA.dll,
webcheck.dll, stobject.dll, BatMeter.dll,
POWRPROF.dll, WTSAPI32.dll, WINMM.dll,
wdmaud.drv, msacm32.drv, MSACM32.dll,
midimap.dll, printui.dll, WINSPOOL.DRV,
ACTIVEDS.dll, adsldpc.dll, WLDAP32.dll,
CFGMGR32.dll, MPR.dll, fxsst.dll,
FXSAPI.dll, NTMARTA.DLL, WINTRUST.dll,
CRYPT32.dll, MSASN1.dll, IMAGEHLP.dll,
rsaenh.dll, SXS.DLL, drprov.dll,
ntlanman.dll, NETUI0.dll, NETUI1.dll,
NETRAP.dll, davclnt.dll, WININET.dll
mm_tray.exe 1812 ntdll.dll, kernel32.dll, COMCTL32.dll,
GDI32.dll, USER32.dll, ADVAPI32.dll,
RPCRT4.dll, CoreDll.dll, ole32.dll,
OLEAUT32.dll, MSVCRT.DLL, MMVCP70.dll,
MMVCR70.dll, SHELL32.dll, SHLWAPI.dll,
Enforce.dll, MMC70U.DLL, TrackUtils.dll,
comctl32.dll, uxtheme.dll, MSCTF.dll,
FileAssoc.dll
ctfmon.exe 1856 ntdll.dll, kernel32.dll, ADVAPI32.dll,
RPCRT4.dll, USER32.dll, GDI32.dll,
MSCTF.dll, msvcrt.dll, MSUTB.dll,
uxtheme.dll, ole32.dll, OLEAUT32.DLL
gcasDtServ.exe 1900 ntdll.dll, kernel32.dll, MSVBVM60.DLL,
USER32.dll, GDI32.dll, ADVAPI32.dll,
RPCRT4.dll, ole32.dll, OLEAUT32.dll,
MSVCRT.DLL, uxtheme.dll, MSCTF.dll,
CLBCATQ.DLL, COMRes.dll, VERSION.dll,
gcAntiSpywareLibrary.dll, GCCollection.dll,
SHLWAPI.dll, SXS.DLL, msi.dll, shell32.dll,
comctl32.dll, comctl32.dll, hashlib.dll,
CRYPT32.dll, MSASN1.dll
cmd.exe 1332 ntdll.dll, kernel32.dll, msvcrt.dll,
USER32.dll, GDI32.dll, ADVAPI32.dll,
RPCRT4.dll, Apphelp.dll
wmiprvse.exe 456 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, USER32.dll,
GDI32.dll, FastProx.dll, wbemcomn.dll,
OLEAUT32.dll, OLE32.DLL, NCObjAPI.DLL,
uxtheme.dll, CLBCATQ.DLL, COMRes.dll,
VERSION.dll, wbemprox.dll, wbemsvc.dll,
wmiutils.dll, cimwin32.dll, framedyn.dll,
Secur32.dll, SETUPAPI.dll, WTSAPI32.dll,
WINSTA.dll, CFGMGR32.DLL, WMI.DLL,
NETAPI32.DLL
tasklist.exe 1532 ntdll.dll, kernel32.dll, msvcrt.dll,
ADVAPI32.dll, RPCRT4.dll, USER32.dll,
GDI32.dll, MPR.dll, ole32.dll, OLEAUT32.dll,
Secur32.dll, WS2_32.dll, WS2HELP.dll,
framedyn.dll, NETAPI32.dll, DBGHELP.dll,
VERSION.dll, uxtheme.dll, MSCTF.dll,
CLBCATQ.DLL, COMRes.dll, wbemprox.dll,
wbemcomn.dll, Winsta.dll, wbemsvc.dll,
fastprox.dll


Hope this helps ya...Em
  • 0

#22
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
OK, I see nothing that is keeping this running...

what exactly is in the DR. TEMP folder?
  • 0

#23
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
Also, go to
http://www.dougknox..../file_assoc.htm

download and run the RESTORE MSC FILE ASSOCIATION FILE,

then, I want you to right click MY COMPUTER< choose PROPERTIES, choose ADVANCED, then click ENVIRONMENT VARIABLES.

Then, select PATH in hte SYSTEM VARIABLES box, and EDIT, then select everything in the VARIABLE VALUE, hit CTRL-C, then

in your next reply hit CTRL-V (paste), into this box.

Then cancel the VARIABLE VALUE box so you do not accidently overwrite.
  • 0

#24
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
I am at home now. I had to shut down the computer because its a computer at the office....I will follow your instructions when i get back on Monday. In the Dr. Temp folder it is something called.... bho (something) I can't remeber the whole thing but underneath it says BetterInternet.com. I hope this makes sense.

Thanks again..Em
  • 0

#25
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
whoa--work computer? Now things are becoming a little clear
This computer is part of a domain? You have system policies preventing you from accessing some vital parts. Do you have a tech support person? Who set up your group policy?
  • 0

Advertisements


#26
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Things becoming clearer now
  • 0

#27
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Good Morning.....Yes this is part of work domain. The computer tech part is kinda wierd..lol. I am the tech. I was promoted to tech when the position became open. I am hired to train the staff how to use the programs that are on thier computers, generate reports, maintain the web site...etc. When the staff started complaining of pop ups, homepages being changed, and all that, I knew our agency was infected. So I started checking all the computers in the office and sure enough more than half of the computers were infected, some very bad. I have cleaned up all of them except for the 2 that I just couldn't fix. That was the one usetobe helped me w/(well the 1st one) and now this one. When I started, I picked up what the tech should have been taking care of. I do have all rights to the system but still in training. Thats whats going on...

Em
  • 0

#28
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts

Also, go to
http://www.dougknox..../file_assoc.htm

download and run the RESTORE MSC FILE ASSOCIATION FILE,

then, I want you to right click MY COMPUTER< choose PROPERTIES, choose ADVANCED, then click ENVIRONMENT VARIABLES.

Then, select PATH in hte SYSTEM VARIABLES box, and EDIT, then select everything in the VARIABLE VALUE, hit CTRL-C, then

in your next reply hit CTRL-V (paste), into this box.

Then cancel the VARIABLE VALUE box so you do not accidently overwrite.

View Post



did you do the above?

meanwhile download and install the following

http://www.sysintern...ssExplorer.html

start her up and do a screen capture so we can see the processes it identifies.
  • 0

#29
gerryf

gerryf

    Retired Staff

  • Retired Staff
  • 11,365 posts
finally, what happens if you double click services.msc, which you will find in the c:\winnt\system32 directory?
  • 0

#30
EmilyPam

EmilyPam

    Member

  • Topic Starter
  • Member
  • PipPip
  • 75 posts
Sorry been busy ..... :tazz:

%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM

There's the 1st thing you ask for..working on the rest

Thanks...Em
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP