What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Closed TopicStart new topic
> [Resolved] Uninstalling Tudou
Darkraver
post Jul 15 2009, 08:21 AM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 67
Joined: 4-October 04
Member No.: 15,931



I foolishly installed the Tudou helper on my computer, and now it is stuck there, and good. Can you please help?
I've just run ComboFix, and my log is below.

---------------------
ComboFix 09-07-14.08 - Amanda Bell 15/07/2009 10:08.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1014.374 [GMT -4:00]
Running from: c:\documents and settings\Amanda Bell\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\2e2a7.msi
c:\windows\system32\muzapp.exe
c:\windows\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.

2009-07-03 15:55 . 2009-07-03 15:55 -------- d-----w- c:\program files\Tudou
2009-07-02 17:33 . 2009-07-02 17:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-07-02 16:36 . 2009-07-02 16:36 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-07-02 16:33 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll
2009-07-02 16:33 . 2009-07-02 16:33 -------- d-----w- c:\program files\Nitro PDF
2009-07-02 16:24 . 2009-07-02 16:24 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-02 16:23 . 2009-07-02 16:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\program files\NOS
2009-06-27 04:28 . 2009-06-27 04:28 -------- d-----w- c:\program files\Convert VOB to AVI
2009-06-26 14:57 . 2009-06-26 14:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 13:48 . 2008-08-30 20:53 -------- d-----w- c:\program files\Symantec AntiVirus
2009-07-15 13:48 . 2008-05-11 12:52 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\uTorrent
2009-07-15 13:39 . 2007-10-20 13:26 -------- d-----w- c:\program files\ApexDC++
2009-07-02 16:28 . 2006-02-21 15:35 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-27 04:14 . 2008-10-06 21:35 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\dvdcss
2009-06-24 21:28 . 2009-02-12 00:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-24 21:28 . 2008-06-19 21:36 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-24 21:28 . 2007-02-15 11:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-20 02:17 . 2006-09-11 21:06 -------- d-----w- c:\program files\Google
2009-06-09 22:38 . 2007-02-26 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-08 18:48 . 2006-09-03 20:49 108824 ----a-w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-07 15:32 . 2006-02-21 08:37 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 17:22 . 2009-05-06 17:22 390664 ----a-w- c:\documents and settings\Amanda Bell\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-04-29 04:56 . 2006-02-21 08:37 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2006-02-21 08:37 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2006-02-21 08:37 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-02-19 19:52 . 2008-09-13 19:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2007-02-12 21:42 . 2007-01-13 05:15 88 --sh--r- c:\windows\system32\F88901A949.sys
2007-03-20 14:11 . 2006-09-11 11:37 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"CrawlerNotes"="c:\progra~1\crawler\notes\cnotes.exe" [2007-12-21 1010688]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 570664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-14 88203]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264]
"NDSTray.exe"="NDSTray.exe" [BU]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\
’“_śEUIA1.lnk - c:\program files\Tudou\śEUTudou\TudouVa.exe [2009-5-18 1234328]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-21 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-24 21:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Amanda Bell^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Amanda Bell\\Desktop\\DrJava.exe"=
"c:\\Program Files\\Java\\jre1.5.0_14\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\java.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Tudou\\·ÉĖŁTudou\\TudouVa.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17436:TCP"= 17436:TCP:BitComet 17436 TCP
"17436:UDP"= 17436:UDP:BitComet 17436 UDP

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2008 5:36 PM 327688]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/02/2009 8:06 PM 298776]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/02/2009 10:43 AM 101936]
S2 gupdate1c9e7e4c75e015a;Google Update Service (gupdate1c9e7e4c75e015a);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 10:56 PM 133104]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464]
.
Contents of the 'Scheduled Tasks' folder

2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56]

2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56]
.
- - - - ORPHANS REMOVED - - - -

BHO-{43BEAFD9-E005-483D-A367-146BA6C8A32E} - c:\program files\Tudou\·ÉĖŁTudou\tudouDetector.dll


.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
FF - ProfilePath - c:\documents and settings\Amanda Bell\Application Data\Mozilla\Firefox\Profiles\mono2lv9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?referrer=ign#max56
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 10:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-15 10:16
ComboFix-quarantined-files.txt 2009-07-15 14:16

Pre-Run: 22,767,648,768 bytes free
Post-Run: 22,740,340,736 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

187 --- E O F --- 2009-06-27 16:00
---------------------

Thank you!
Go to the top of the page
 
+Quote Post

Posts in this topic
- Darkraver   [Resolved] Uninstalling Tudou   Jul 15 2009, 08:21 AM
- - CatByte   QUOTE Why we don't ask you to run ComboFix fro...   Jul 19 2009, 07:40 AM
- - Darkraver   Thanks for your response. I've had no problem...   Jul 19 2009, 10:20 PM
- - CatByte   If you have script blocking it will likely be incl...   Jul 20 2009, 02:44 AM
- - Darkraver   Hi there, Please find DDS.txt and Attach.txt atta...   Jul 21 2009, 11:02 AM
- - CatByte   Hi, Please do the following: Very Important...   Jul 21 2009, 11:28 AM
- - Darkraver   Hey, Here is the log from the ComboFix scan. ---...   Jul 22 2009, 06:21 PM
- - CatByte   Hi, You appear to have two antivirus programs ins...   Jul 22 2009, 06:30 PM
- - Darkraver   Hi there! Below is the log from MBAM and the ...   Jul 23 2009, 09:28 PM
- - CatByte   Hi, One of the files found by malwarebytes was a ...   Jul 23 2009, 09:46 PM
- - Darkraver   Hi there, Thanks for your help! The only outs...   Jul 26 2009, 09:27 PM
- - CatByte   Hi, that message will probably disappear when we ...   Jul 26 2009, 09:49 PM
- - Darkraver   Thanks for all your help and recommendations. Eve...   Jul 27 2009, 10:57 AM
- - Darkraver   WAIT, DON'T SHUT IT DOWN YET! Everything ...   Jul 27 2009, 11:13 AM
- - CatByte   uninstall spyware guard do a system restore to y...   Jul 27 2009, 11:15 AM
- - Darkraver   I didn't do a system restore, but uninstalling...   Jul 27 2009, 01:16 PM
- - CatByte   Good, glad that's resolved it, sometimes the o...   Jul 27 2009, 01:30 PM
- - CatByte   Since this issue appears to be resolved ... this T...   Jul 27 2009, 08:55 PM


Closed TopicStart new topic

 


RSS Time is now: 19th March 2010 - 03:22 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy