This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

undetected viruses/malware?

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My CPU never stops giving off that "plane takeoff" sound (sometimes louder sometimes softer)…and at the same time I have all the symptoms of undetected malware, in spite of constant "clean-slate" reports from AVG and Spybot S&D (which never run at the same time) In addition I can SEE all kinds of "ad-click" type malware being downloaded automatically…as indicated on the bottom left corner…. this happens all the time while the "plane-takeoff" sound is the loudest. Symptoms:…internet pages quit while working on them….links rendered inoperable…songs quitting on the player after playing a minute or two, etc….and popups in my face while working on things. And slow working speed. So what can I do now if I am no techie and don't know how to "hand-play" the spy-removal procedures? And IS there a connection between the noise and the faulty operation, how could it have happened and what is the remedy other than taking it somewhere or ditching it?
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!




Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt.





Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
thank you…I will try all that. Watch for my results kind friend. PS: I also run a free registry fixer all day long….useless thing, as useless as the two spyware busters ;=(
. DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 12:34:30 on 2011-08-07 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.990.446 [GMT -5:00] . AV: AVG Anti-Virus 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: *Disabled* . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxddserv.exe C:\WINDOWS\system32\lxddcoms.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\System32\snmp.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe C:\Program Files\AVG\AVG10\avgam.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\program files\real\realplayer\update\realsched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uSearch Bar = hxxp://www.google.com/ie uSearch Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uDefault_Search_URL = hxxp://www.google.com/ie uStart Page = hxxp://ib.startnow.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z057&partner_id=333&product_id=706&affiliate_id=&channel=DPGL18&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110722&user_guid=9BB0100287AC4B339B3CCB1813DF1DB1&machine_id=47c7234cf2ecd6deaa7c1a20a33ec424&browser=IE&os=win&os_version=5.1-x86-SP3 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.inbox.com/search/ie.aspx?tb_id=70001 mCustomizeSearch = hxxp://dnl.inbox.com/support/sa_customize.aspx?TbId=70001 mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: GoodSearch Toolbar: {4e7bd74f-2b8d-469e-95ba-ed6db186be32} - c:\progra~1\goodse~1\GOODSE~1.DLL BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll BHO: Window Shopper: {74f475fa-6c75-43bd-aab9-ecda6184f600} - c:\program files\superfish\window shopper\SuperfishIEAddon.dll BHO: (Gaming)2: {971f630e-ad68-4d6e-b0c3-1c627aac80f1} - (Gaming)2 BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll BHO: Updater For Simppull Toolbar: {c4b8bab4-1667-11df-a242-ba9455d89593} - Updater For Simppull Toolbar BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No File BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: GoodSearch Toolbar: {4e7bd74f-2b8d-469e-95ba-ed6db186be32} - c:\progra~1\goodse~1\GOODSE~1.DLL TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRunOnce: [RunNarrator] Narrator.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\audibl~1.lnk - c:\program files\audible\bin\AudibleDownloadHelper.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\superfish\window shopper\SuperfishIEAddon.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = [removed] [removed] [removed] TCP: Interfaces\{EE92B5AD-36D6-42AA-B1A9-29384E1DE0E1} : DhcpNameServer = [removed] [removed] [removed] Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll LSA: Notification Packages = :\windows\system3 Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\s88rag3e.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3036959&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://ib.startnow.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z057&partner_id=333&product_id=706&affiliate_id=&channel=DPGL18&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110722&user_guid=9BB0100287AC4B339B3CCB1813DF1DB1&machine_id=47c7234cf2ecd6deaa7c1a20a33ec424&browser=FF&os=win&os_version=5.1-x86-SP3 FF - prefs.js: keyword.URL - hxxp://ib.startnow.com/s/?src=addrbar&provider=bing&provider_name=bing&provider_code=Z057&partner_id=333&product_id=706&affiliate_id=&channel=DPGL18&toolbar_id=200&toolbar_version=2.1.0&install_country=US&install_date=20110722&user_guid=9BB0100287AC4B339B3CCB1813DF1DB1&machine_id=47c7234cf2ecd6deaa7c1a20a33ec424&browser=FF&os=win&os_version=5.1-x86-SP3&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\desktop\reader\browser\nppdf32.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\documents and settings\owner\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_ClickPotatoLiteSA.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll FF - plugin: c:\program files\mozilla firefox\plugins\npracplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\npstrlnk.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992] R0 AvgRkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 248656] R1 AvgMfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896] R1 AvgTdiX;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 297168] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service –> c:\windows\system32\lxddcoms.exe -service [?] R2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2008-2-24 99248] R2 SSFMONM;Spy Sweeper File System Filter Driver;c:\windows\system32\drivers\ssfmonm.sys [2010-1-6 39928] R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-5-20 210144] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-26 135664] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 947528] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-26 135664] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2008-7-15 32840] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2011-07-21 20:08:51 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys 2010-01-08 13:50:49 5135224 —-a-w- c:\program files\common files\wruninstall.exe 2010-01-07 00:17:45 712072 -c–a-w- c:\program files\common files\GenericSB.dll 2006-11-30 13:04:04 774144 -c–a-w- c:\program files\RngInterstitial.dll . ============= FINISH: 12:36:52.62 ===============
well I think I already screwed up…I only got what looked like ONE report, unless the second was included in the whole document. I mean…was it this for instance (last part of the other one…): ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 22992] R0 AvgRkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 248656] R1 AvgMfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34896] R1 AvgTdiX;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 297168] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service –> c:\windows\system32\lxddcoms.exe -service [?] R2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2008-2-24 99248] R2 SSFMONM;Spy Sweeper File System Filter Driver;c:\windows\system32\drivers\ssfmonm.sys [2010-1-6 39928] R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-5-20 210144] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-26 135664] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 947528] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-26 135664] S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?] S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2008-7-15 32840] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2011-07-21 20:08:51 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys 2010-01-08 13:50:49 5135224 —-a-w- c:\program files\common files\wruninstall.exe 2010-01-07 00:17:45 712072 -c–a-w- c:\program files\common files\GenericSB.dll 2006-11-30 13:04:04 774144 -c–a-w- c:\program files\RngInterstitial.dll . ============= FINISH: 12:36:52.62 ===============
The attach.txt file should have saved on your desktop, if it did not, it's ok. Just go ahead and run GMER and post the results for me please. I'll start looking at the DDS, but I will need to see the GMER before I can give you any instructions.
Ok more trouble following this…. I ran the GMER rootkit scanner and (1) after some falsestarts, got a huge list that is now gone…I couldn't save it, and didn't erase it, but it's gone. (2) then I discovered I had a list that looks something like this: GMER 1/.0.15.15641 Process Parameters PID Memory Thr Handler User Time Kernal Time System —– 0 28 1 0 0.000 38240.487 Idle System C:\PROGA 1\AVG ******************************************************************************** *********************** Ok I just copied the above to give an idea of what I had…it was a much shorter list and the "process…parameters…PID….etc were the headings and after the items entitled…."System Idle"……"System"….etc…..there were many more…..filled a page. Again, as I said I couldn't copy this or the really long one before…so I couldn't have sent them to you. Don't know what happens now.
It won't copy…..the long one wouldn't copy and the short one wouldn't copy…also the long one is gone and the short one is here but won't copy…..in my above post I described what "it" was and told you the headings etc….. I just can't copy the whole thing, and don't know what else to do. Please advise.
When you run GMER again, please be sure you have your AVG anti-virus disabled during the scan. Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here


Ideally, we'd like to run GMER in normal mode, but if it still won't run in normal mode please do the following:

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account

Then try running GMER with just "sections" and the "c:\" drive checked, leave everything else blank. After running it, reboot into normal mode.

If you still can't get it to run, please let me know.
umm….ran the scanner again and got the long list again and was wondering again how I would get it to you and then the whole system mysteriously crashed and rebooted itself and I can get that list back but have no idea how to get it to you… All I have on my desktop was that thing I already sent you. But until I hear from you I will just keep trying.
As I said in my last post it sounds like your AVG is interfering with GMER running properly. That is why I provided the additional instructions for you to try disabling it. If you are unable to copy what GMER produces then we will need to try a different rootkit detection tool. It is important that I know what kind of malware we are dealing with to properly remove it.


Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.

    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:/ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
ok I am running the thing again and maybe I can try to photograph it and scan you the results….will I need an email address to do that? it's not on safe mode…but the two spyware busters are off. There was just no way to SAVE any of that and there still won't be. At least from what I could see. I could also hand-copy you out the first two lines or so, but how that will help I don't know.
ok another thing..this is the 3rd time I was able to gt a scan report and each time I hit "save" and saved it to the desktop…and all three times NOTHING SHOWED ON DESKTOP. So now what?
Ok here it is:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-07 16:09:03
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3100011A rev.3.02
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\fgwdyaow.sys


—- System - GMER 1.0.15 —-

SSDT 868B4758 ZwAllocateVirtualMemory
SSDT 868B8B28 ZwCreateKey
SSDT 86878118 ZwCreateProcess
SSDT 868E9918 ZwCreateProcessEx
SSDT 86878CC8 ZwCreateThread
SSDT 868B8AB0 ZwDeleteKey
SSDT 8689C238 ZwDeleteValueKey
SSDT 86878190 ZwOpenKey
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF6A33738]
SSDT 868B4A18 ZwQueueApcThread
SSDT 868FCC28 ZwReadVirtualMemory
SSDT 868EA190 ZwRenameKey
SSDT 86823EF0 ZwSetContextThread
SSDT 8689D1D0 ZwSetInformationKey
SSDT 868FE578 ZwSetInformationProcess
SSDT 86823F68 ZwSetInformationThread
SSDT 868B5548 ZwSetValueKey
SSDT 868FE500 ZwSuspendProcess
SSDT 868B4A90 ZwSuspendThread
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xF6A337DC]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF6A33878]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF6A33914]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF51FA360, 0x3CDCE5, 0xE8000020]
init C:\WINDOWS\System32\Drivers\sunkfilt.sys entry point in "init" section [0xF1CC3300]
? C:\DOCUME~1\Owner\LOCALS~1\Temp\fgwdyaow.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] kernel32.dll!FindResourceW 7C80BC6E 5 Bytes JMP 00429D40 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] kernel32.dll!FindResourceA 7C80BF29 5 Bytes JMP 00429D00 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!LoadStringW 7E419E36 5 Bytes JMP 00429F20 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!CreateDialogParamW 7E41EA3B 5 Bytes JMP 00429DF0 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!LoadStringA 7E42C908 5 Bytes JMP 00429FD0 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!LoadMenuW 7E42EB48 5 Bytes JMP 00429EC0 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!CreateDialogParamA 7E43C7DB 5 Bytes JMP 00429D80 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[2372] USER32.dll!LoadMenuA 7E44FA83 5 Bytes JMP 00429E60 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 1068EDA6 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 1068ED38 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 104A5451 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 104A5A99 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\program files\real\realplayer\update\realsched.exe[3576] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Mozilla Firefox\firefox.exe[3840] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00401410 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

Device \Driver\Tcpip \Device\Ip 85D96D18

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Tcp 85D96D18

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Udp 85D96D18

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\RawIp 85D96D18

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\IPMULTICAST 85D96D18

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\AAFFile@PreferExecuteOnMismatch 1
Reg HKLM\SOFTWARE\Classes\AAFFile@ Audible Audio
Reg HKLM\SOFTWARE\Classes\AAFFile@FriendlyTypeName @C:\WINDOWS\inf\unregmp2.exe,-9998
Reg HKLM\SOFTWARE\Classes\AAFFile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\AAFFile\DefaultIcon@ wmplayer.exe,-120
Reg HKLM\SOFTWARE\Classes\AAFFile\shell
Reg HKLM\SOFTWARE\Classes\AAFFile\shell@ play
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open@LegacyDisable
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open\command
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open\command@ "C:\Program Files\Windows Media Player\wmplayer.exe" /Open "%L"
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open\DropTarget
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\open\DropTarget@CLSID {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play@MUIVerb @C:\WINDOWS\inf\unregmp2.exe,-9991
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play@LegacyDisable
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play\command
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play\command@ "C:\Program Files\Windows Media Player\wmplayer.exe" /Play "%L"
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play\DropTarget
Reg HKLM\SOFTWARE\Classes\AAFFile\shell\play\DropTarget@CLSID {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPAddToPlaylist
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPAddToPlaylist@ {F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPBurnAudioCD
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPBurnAudioCD@ {8DD448E6-C188-4aed-AF92-44956194EB1F}
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPPlayAsPlaylist
Reg HKLM\SOFTWARE\Classes\AAFFile\shellex\ContextMenuHandlers\WMPPlayAsPlaylist@ {CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro@ AvgBro Object
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid
Reg HKLM\SOFTWARE\Classes\aAvgAPI.AvgBro\Clsid@ {18B30EBF-6B58-425E-AC54-831C05D91B5A}
Reg HKLM\SOFTWARE\Classes\AVG.Office@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer
Reg HKLM\SOFTWARE\Classes\AVG.Office\CurVer@ AVG.Office.8
Reg HKLM\SOFTWARE\Classes\AVG.Office.8@ AVG plugin for the Microsoft Office
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID
Reg HKLM\SOFTWARE\Classes\AVG.Office.8\CLSID@ {04373D9C-5ED8-44f2-BA00-7895D6A5A2DA}
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBAR@ AVGTOOLBAR
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBAR\Clsid
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBAR\Clsid@ {A057A204-BACC-4D26-9990-79A187E2698E}
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button@ AVGTOOLBARMenu Button
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button\Clsid
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARMenu Button\Clsid@ {A057A204-BACC-4D26-9990-79A187E26990}
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button@ AVGTOOLBARToggle Button
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button\Clsid
Reg HKLM\SOFTWARE\Classes\avgtoolbar.AVGTOOLBARToggle Button\Clsid@ {A057A204-BACC-4D26-9990-79A187E2698F}
Reg HKLM\SOFTWARE\Classes\CLSID\{A211FD50-104A-552A-E783321B77B5C9DA}\{4E700FFC-D5B6-D24A-08D9C51A05E3FA14}\{72F82311-8741-4D82-9043D22F7FAD5282}
Reg HKLM\SOFTWARE\Classes\CLSID\{A211FD50-104A-552A-E783321B77B5C9DA}\{4E700FFC-D5B6-D24A-08D9C51A05E3FA14}\{72F82311-8741-4D82-9043D22F7FAD5282}@CTXOAUOBU3EISUCMRDYZEULOPG1 0x01 0x00 0x01 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{BF1EE1FE-1932-A99C-B95E9DB4FC5D390D}\{14AB012F-1755-CBB6-E6EC0E63008B2B35}\{6CBF63F5-AF79-823D-FB168B9FCC8939EB}
Reg HKLM\SOFTWARE\Classes\CLSID\{BF1EE1FE-1932-A99C-B95E9DB4FC5D390D}\{14AB012F-1755-CBB6-E6EC0E63008B2B35}\{6CBF63F5-AF79-823D-FB168B9FCC8939EB}@CTXOAUOBU3EISUCMRDYZEULOPG1 0x01 0x00 0x01 0x00 …
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler@ Google Updater Scheduler class
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CLSID
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CLSID@ {B53B7061-6584-46AA-A033-D610EB10BD9B}
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CurVer
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CurVer@ GUSchedulerCtl.UpdaterScheduler.1
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1@ Google Updater Scheduler class
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1\CLSID
Reg HKLM\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1\CLSID@ {B53B7061-6584-46AA-A033-D610EB10BD9B}
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater@ Google Silent Updater class
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CLSID
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CLSID@ {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CurVer
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CurVer@ GUServiceCtl.SilentUpdater.1
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1@ Google Silent Updater class
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1\CLSID
Reg HKLM\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1\CLSID@ {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter@ AVG Safe Search
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CLSID
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CLSID@ {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CurVer
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter\CurVer@ LinkScannerIE.NavFilter.1
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1@ AVG Safe Search
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1\CLSID
Reg HKLM\SOFTWARE\Classes\LinkScannerIE.NavFilter.1\CLSID@ {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B97117-49FF-7156-32BF-F235B5939E7A}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B97117-49FF-7156-32BF-F235B5939E7A}@eakhpicbpj 0x66 0x61 0x69 0x68 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B97117-49FF-7156-32BF-F235B5939E7A}@dahmeagi 0x64 0x62 0x61 0x6F …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B97117-49FF-7156-32BF-F235B5939E7A}@iackaopccejgngcdpi 0x6A 0x61 0x66 0x6C …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21B97117-49FF-7156-32BF-F235B5939E7A}@haaoobhighhmdneg 0x69 0x61 0x6F 0x6C …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{630BB371-9612-5497-E4CF-3CE259B7B0D4}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{630BB371-9612-5497-E4CF-3CE259B7B0D4}@gaaipeacledcko 0x61 0x63 0x6A 0x62 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{630BB371-9612-5497-E4CF-3CE259B7B0D4}@halhmcgpagcnefkd 0x6E 0x61 0x64 0x66 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{630BB371-9612-5497-E4CF-3CE259B7B0D4}@halhmcgphnfikmdb 0x6E 0x62 0x64 0x69 …

—- EOF - GMER 1.0.15 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI