Welcome! Register for a free account (or login) > How does it work?
|
|


Jul 15 2009, 08:21 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
I foolishly installed the Tudou helper on my computer, and now it is stuck there, and good. Can you please help?
I've just run ComboFix, and my log is below. --------------------- ComboFix 09-07-14.08 - Amanda Bell 15/07/2009 10:08.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1014.374 [GMT -4:00] Running from: c:\documents and settings\Amanda Bell\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\2e2a7.msi c:\windows\system32\muzapp.exe c:\windows\system32\pac.txt . ((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 ))))))))))))))))))))))))))))))) . 2009-07-03 15:55 . 2009-07-03 15:55 -------- d-----w- c:\program files\Tudou 2009-07-02 17:33 . 2009-07-02 17:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2009-07-02 16:36 . 2009-07-02 16:36 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-07-02 16:33 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll 2009-07-02 16:33 . 2009-07-02 16:33 -------- d-----w- c:\program files\Nitro PDF 2009-07-02 16:24 . 2009-07-02 16:24 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-07-02 16:23 . 2009-07-02 16:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\program files\NOS 2009-06-27 04:28 . 2009-06-27 04:28 -------- d-----w- c:\program files\Convert VOB to AVI 2009-06-26 14:57 . 2009-06-26 14:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-15 13:48 . 2008-08-30 20:53 -------- d-----w- c:\program files\Symantec AntiVirus 2009-07-15 13:48 . 2008-05-11 12:52 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\uTorrent 2009-07-15 13:39 . 2007-10-20 13:26 -------- d-----w- c:\program files\ApexDC++ 2009-07-02 16:28 . 2006-02-21 15:35 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-27 04:14 . 2008-10-06 21:35 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\dvdcss 2009-06-24 21:28 . 2009-02-12 00:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-06-24 21:28 . 2008-06-19 21:36 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 21:28 . 2007-02-15 11:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-06-20 02:17 . 2006-09-11 21:06 -------- d-----w- c:\program files\Google 2009-06-09 22:38 . 2007-02-26 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-08 18:48 . 2006-09-03 20:49 108824 ----a-w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-07 15:32 . 2006-02-21 08:37 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-06 17:22 . 2009-05-06 17:22 390664 ----a-w- c:\documents and settings\Amanda Bell\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-04-29 04:56 . 2006-02-21 08:37 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2006-02-21 08:37 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2006-02-21 08:37 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-02-19 19:52 . 2008-09-13 19:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2007-02-12 21:42 . 2007-01-13 05:15 88 --sh--r- c:\windows\system32\F88901A949.sys 2007-03-20 14:11 . 2006-09-11 11:37 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536] "CrawlerNotes"="c:\progra~1\crawler\notes\cnotes.exe" [2007-12-21 1010688] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 570664] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-14 88203] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264] "NDSTray.exe"="NDSTray.exe" [BU] "TFncKy"="TFncKy.exe" [BU] "TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\ _śEUIA1.lnk - c:\program files\Tudou\śEUTudou\TudouVa.exe [2009-5-18 1234328] c:\documents and settings\All Users\Start Menu\Programs\Startup\ RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-21 155648] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-06-24 21:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk] backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Amanda Bell^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Documents and Settings\\Amanda Bell\\Desktop\\DrJava.exe"= "c:\\Program Files\\Java\\jre1.5.0_14\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\java.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Tudou\\·ÉĖŁTudou\\TudouVa.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "17436:TCP"= 17436:TCP:BitComet 17436 TCP "17436:UDP"= 17436:UDP:BitComet 17436 UDP R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2008 5:36 PM 327688] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/02/2009 8:06 PM 298776] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/02/2009 10:43 AM 101936] S2 gupdate1c9e7e4c75e015a;Google Update Service (gupdate1c9e7e4c75e015a);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 10:56 PM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464] . Contents of the 'Scheduled Tasks' folder 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] . - - - - ORPHANS REMOVED - - - - BHO-{43BEAFD9-E005-483D-A367-146BA6C8A32E} - c:\program files\Tudou\·ÉĖŁTudou\tudouDetector.dll . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta FF - ProfilePath - c:\documents and settings\Amanda Bell\Application Data\Mozilla\Firefox\Profiles\mono2lv9.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?referrer=ign#max56 FF - prefs.js: network.proxy.type - 2 FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-15 10:13 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-15 10:16 ComboFix-quarantined-files.txt 2009-07-15 14:16 Pre-Run: 22,767,648,768 bytes free Post-Run: 22,740,340,736 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 187 --- E O F --- 2009-06-27 16:00 --------------------- Thank you! |
|
|
|
![]() |
Jul 27 2009, 08:55 PM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
Darkraver [Resolved] Uninstalling Tudou Jul 15 2009, 08:21 AM
CatByte QUOTE Why we don't ask you to run ComboFix fro... Jul 19 2009, 07:40 AM
Darkraver Thanks for your response.
I've had no problem... Jul 19 2009, 10:20 PM
CatByte If you have script blocking it will likely be incl... Jul 20 2009, 02:44 AM
Darkraver Hi there,
Please find DDS.txt and Attach.txt atta... Jul 21 2009, 11:02 AM
CatByte Hi,
Please do the following:
Very Important... Jul 21 2009, 11:28 AM
Darkraver Hey,
Here is the log from the ComboFix scan.
---... Jul 22 2009, 06:21 PM
CatByte Hi,
You appear to have two antivirus programs ins... Jul 22 2009, 06:30 PM
Darkraver Hi there!
Below is the log from MBAM and the ... Jul 23 2009, 09:28 PM
CatByte Hi,
One of the files found by malwarebytes was a ... Jul 23 2009, 09:46 PM
Darkraver Hi there,
Thanks for your help! The only outs... Jul 26 2009, 09:27 PM
CatByte Hi,
that message will probably disappear when we ... Jul 26 2009, 09:49 PM
Darkraver Thanks for all your help and recommendations.
Eve... Jul 27 2009, 10:57 AM
Darkraver WAIT, DON'T SHUT IT DOWN YET!
Everything ... Jul 27 2009, 11:13 AM
CatByte uninstall spyware guard
do a system restore to y... Jul 27 2009, 11:15 AM
Darkraver I didn't do a system restore, but uninstalling... Jul 27 2009, 01:16 PM
CatByte Good, glad that's resolved it, sometimes the o... Jul 27 2009, 01:30 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
6 | ROOFIE(MTL) | 89 | A minute ago Last post by: CatByte |
|||
![]() |
15 | Amebeo | 231 | 5 minutes ago Last post by: CatByte |
|||
![]() |
12 | ChadA | 203 | 7 minutes ago Last post by: CatByte |
|||
![]() |
21 | billed | 330 | 28 minutes ago Last post by: schrauber |
|||
|
Time is now: 20th March 2010 - 06:43 AM |