Less Than Ideal, It's True

Something Strange

When I started using my computer today to check the news, it brought up Look2Me-Destroyer without action on my part and when I opened the task manager it was displayed as a system task. Is that usual??
 
Another Thing

I closed the S&D Resident window about "Rces" and then it threw up another 1. Category: "System Startup user entry". Change: "Value deleted". Entry: "Cxvwhnv". Old data: "C:\DOCUME`1\Aaron\APPLIC`1\PPATCH`1\RNDLL`1.EXE". Again, my choices R obscured by "Remember this decision?" What's supposed to happen?? I find the black and white lists for Resident to B very confusing!
 
Another Thing

I closed the S&D Resident window about "Rces" and then it threw up another 1. Category: "System Startup user entry". Change: "Value deleted". Entry: "Cxvwhnv". Old data: "C:\DOCUME`1\Aaron\APPLIC`1\PPATCH`1\RNDLL`1.EXE". Again, my choices R obscured by "Remember this decision?" What's supposed to happen?? I find the black and white lists for Resident to B very confusing!
 
Ok

It automatically denied the other Resident deal. I reset TeaTimer. Here R the goods:


Logfile of HijackThis v1.99.1
Scan saved at 4:21:07 PM, on 6/23/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [Rces] "C:\PROGRA~1\RACLE~1\dllhost.exe" -vt mt
O4 - HKCU\..\Run: [Cxvwhnv] C:\DOCUME~1\Aaron\APPLIC~1\PPATCH~1\RNDLL~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} -
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{844448B7-0F10-403D-840D-455BE67224E9}: NameServer = 64.105.172.26,64.105.163.106
O20 - Winlogon Notify: Run - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
 
OK do this in the order written

Turn Off Tea timer

Start Hijackthis and place a check next to these items If there.
O4 - HKCU\..\Run: [Cxvwhnv] C:\DOCUME~1\Aaron\APPLIC~1\PPATCH~1\RNDLL~1.EXE
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} -
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -
O20 - Winlogon Notify: Run - C:\WINDOWS\
====================================
Hit fix checked and close Hijackthis.

Run resetteatimer.bat then turn Tea timer back on.
In the furture do not tick the box remember this desision
There are several fix's mentioned in this thread for tea timers gui problem
http://forums.spybot.info/showthread.php?t=122
 
Point of Note

I followed your instructions. When I ran ResetTeaTimer.bat it threw up a DOS window and then quickly closed it. It looked like there were about five lines of text saying that it couldn't find various files but it went by 2 quickly to B sure. I clicked the .bat many more times in order to get a better look at that text but it's a little 2 quick for me. I'm going to reboot and run another HJT log for the next post.
 
This Is It

Logfile of HijackThis v1.99.1
Scan saved at 5:04:47 PM, on 6/23/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [Rces] "C:\PROGRA~1\RACLE~1\dllhost.exe" -vt mt
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{844448B7-0F10-403D-840D-455BE67224E9}: NameServer = 64.105.172.26,64.105.163.106
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
 
Anything Else??

The diagnostic tool had a lot of mumbo-jumbo for me. It also tried to change my registry (which I denied) before bringing up the diagnostic window. "Blocked VLK" showed up in red on the first line and there were many other letters and numbers under a handful of tabs which I could relate to U if U'd like.
 
Hey!

I've been doing the things that U ask me to! My last post was to report what happened. What am I supposed to do??
 
Look

I ran the diagnostic tool. I explored both of your links and nothing that Liu said seemed applicable to me. As I said before, the first line of MGADiag.exe ("Genuine Validation Status") reads "Blocked VLK" in red text. Further down, "Download Center code" says "Expired Code." WGA Version = Registered, 1.5.530.0. Signature Type = Microsoft.

I'm happy to relate to U any other relevant information found by running MGADiag.exe but U have to B specific. U may have picked up from my speech patterns, grammar, and spelling that I have some degree of intelligence. I'm not that savvy when it comes to computers. It's important that U R specific in your instructions to me; that way, there is less time wasted in this back-and-forth banter.

We learn through repetition. Specificity is key.
 
LTIIT said:
I'm not that savvy when it comes to computers.

I suggest you take that computer to a repair shop and then get Windows updated and patched.

Good luck. :)
 
Hey, U Guys

Thanks a lot for helping clean my computer. The pop-ups have stopped and it's only every few days that 1 of my progs finds a new bit of ware to obliterate. I learned quite a lot about viruses and proper security and most of it is thanks to your direction both in this thread and others. Here's my personal log:

:confused: :mad: :confused: :( :confused: :sick: :blush: ;) :bigthumb: :)

Have a good 1.
 
Im Glad we could help
Since the problems are solved Im going to close the topic now, this keeps others with similar problems from posting there logs/question here, they should start a new topic.
 
Back
Top