Welcome! Register for a free account (or login) > How does it work?
|
|


Jul 15 2009, 08:21 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
I foolishly installed the Tudou helper on my computer, and now it is stuck there, and good. Can you please help?
I've just run ComboFix, and my log is below. --------------------- ComboFix 09-07-14.08 - Amanda Bell 15/07/2009 10:08.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1014.374 [GMT -4:00] Running from: c:\documents and settings\Amanda Bell\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\2e2a7.msi c:\windows\system32\muzapp.exe c:\windows\system32\pac.txt . ((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 ))))))))))))))))))))))))))))))) . 2009-07-03 15:55 . 2009-07-03 15:55 -------- d-----w- c:\program files\Tudou 2009-07-02 17:33 . 2009-07-02 17:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2009-07-02 16:36 . 2009-07-02 16:36 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-07-02 16:33 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll 2009-07-02 16:33 . 2009-07-02 16:33 -------- d-----w- c:\program files\Nitro PDF 2009-07-02 16:24 . 2009-07-02 16:24 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-07-02 16:23 . 2009-07-02 16:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\program files\NOS 2009-06-27 04:28 . 2009-06-27 04:28 -------- d-----w- c:\program files\Convert VOB to AVI 2009-06-26 14:57 . 2009-06-26 14:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-15 13:48 . 2008-08-30 20:53 -------- d-----w- c:\program files\Symantec AntiVirus 2009-07-15 13:48 . 2008-05-11 12:52 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\uTorrent 2009-07-15 13:39 . 2007-10-20 13:26 -------- d-----w- c:\program files\ApexDC++ 2009-07-02 16:28 . 2006-02-21 15:35 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-27 04:14 . 2008-10-06 21:35 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\dvdcss 2009-06-24 21:28 . 2009-02-12 00:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-06-24 21:28 . 2008-06-19 21:36 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 21:28 . 2007-02-15 11:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-06-20 02:17 . 2006-09-11 21:06 -------- d-----w- c:\program files\Google 2009-06-09 22:38 . 2007-02-26 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-08 18:48 . 2006-09-03 20:49 108824 ----a-w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-07 15:32 . 2006-02-21 08:37 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-06 17:22 . 2009-05-06 17:22 390664 ----a-w- c:\documents and settings\Amanda Bell\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-04-29 04:56 . 2006-02-21 08:37 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2006-02-21 08:37 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2006-02-21 08:37 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-02-19 19:52 . 2008-09-13 19:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2007-02-12 21:42 . 2007-01-13 05:15 88 --sh--r- c:\windows\system32\F88901A949.sys 2007-03-20 14:11 . 2006-09-11 11:37 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536] "CrawlerNotes"="c:\progra~1\crawler\notes\cnotes.exe" [2007-12-21 1010688] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 570664] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-14 88203] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264] "NDSTray.exe"="NDSTray.exe" [BU] "TFncKy"="TFncKy.exe" [BU] "TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\ _śEUIA1.lnk - c:\program files\Tudou\śEUTudou\TudouVa.exe [2009-5-18 1234328] c:\documents and settings\All Users\Start Menu\Programs\Startup\ RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-21 155648] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-06-24 21:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk] backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Amanda Bell^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Documents and Settings\\Amanda Bell\\Desktop\\DrJava.exe"= "c:\\Program Files\\Java\\jre1.5.0_14\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\java.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Tudou\\·ÉĖŁTudou\\TudouVa.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "17436:TCP"= 17436:TCP:BitComet 17436 TCP "17436:UDP"= 17436:UDP:BitComet 17436 UDP R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2008 5:36 PM 327688] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/02/2009 8:06 PM 298776] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/02/2009 10:43 AM 101936] S2 gupdate1c9e7e4c75e015a;Google Update Service (gupdate1c9e7e4c75e015a);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 10:56 PM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464] . Contents of the 'Scheduled Tasks' folder 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] . - - - - ORPHANS REMOVED - - - - BHO-{43BEAFD9-E005-483D-A367-146BA6C8A32E} - c:\program files\Tudou\·ÉĖŁTudou\tudouDetector.dll . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta FF - ProfilePath - c:\documents and settings\Amanda Bell\Application Data\Mozilla\Firefox\Profiles\mono2lv9.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?referrer=ign#max56 FF - prefs.js: network.proxy.type - 2 FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-15 10:13 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-15 10:16 ComboFix-quarantined-files.txt 2009-07-15 14:16 Pre-Run: 22,767,648,768 bytes free Post-Run: 22,740,340,736 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 187 --- E O F --- 2009-06-27 16:00 --------------------- Thank you! |
|
|
|
Darkraver [Resolved] Uninstalling Tudou Jul 15 2009, 08:21 AM
CatByte QUOTE Why we don't ask you to run ComboFix fro... Jul 19 2009, 07:40 AM
Darkraver Thanks for your response.
I've had no problem... Jul 19 2009, 10:20 PM
CatByte If you have script blocking it will likely be incl... Jul 20 2009, 02:44 AM
Darkraver Hi there,
Please find DDS.txt and Attach.txt atta... Jul 21 2009, 11:02 AM
CatByte Hi,
Please do the following:
Very Important... Jul 21 2009, 11:28 AM
Darkraver Hey,
Here is the log from the ComboFix scan.
---... Jul 22 2009, 06:21 PM
CatByte Hi,
You appear to have two antivirus programs ins... Jul 22 2009, 06:30 PM
Darkraver Hi there!
Below is the log from MBAM and the ... Jul 23 2009, 09:28 PM
CatByte Hi,
One of the files found by malwarebytes was a ... Jul 23 2009, 09:46 PM
Darkraver Hi there,
Thanks for your help! The only outs... Jul 26 2009, 09:27 PM
CatByte Hi,
that message will probably disappear when we ... Jul 26 2009, 09:49 PM
Darkraver Thanks for all your help and recommendations.
Eve... Jul 27 2009, 10:57 AM
Darkraver WAIT, DON'T SHUT IT DOWN YET!
Everything ... Jul 27 2009, 11:13 AM
CatByte uninstall spyware guard
do a system restore to y... Jul 27 2009, 11:15 AM
Darkraver I didn't do a system restore, but uninstalling... Jul 27 2009, 01:16 PM
CatByte Good, glad that's resolved it, sometimes the o... Jul 27 2009, 01:30 PM
CatByte Since this issue appears to be resolved ... this T... Jul 27 2009, 08:55 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | ajones | 107 | Today, 02:10 AM Last post by: oldman960 |
|||
![]() |
11 | pacificjade | 128 | Yesterday, 05:00 PM Last post by: LDTate |
|||
![]() |
7 | 3streamMusic | 166 | Yesterday, 02:39 PM Last post by: LDTate |
|||
![]() |
14 | ShawBuck | 169 | Yesterday, 10:50 AM Last post by: CatByte |
|||
|
Time is now: 19th March 2010 - 03:22 PM |