1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved My laptop sound not working

Discussion in 'Malware and Virus Removal Archive' started by udaykiran, 2013/08/31.

  1. 2013/09/02
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    OTL Extras logfile created on: 9/3/2013 9:57:10 AM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Administrator.ADMINISTRATOR\Desktop\Sound Issue
    Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 80.34% Memory free
    4.84 Gb Paging File | 4.26 Gb Available in Paging File | 88.03% Paging File free
    Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 48.83 Gb Total Space | 6.26 Gb Free Space | 12.81% Space Free | Partition Type: NTFS
    Drive D: | 48.83 Gb Total Space | 14.62 Gb Free Space | 29.94% Space Free | Partition Type: NTFS
    Drive E: | 36.34 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
    Drive F: | 51.39 Gb Total Space | 3.58 Gb Free Space | 6.97% Space Free | Partition Type: NTFS

    Computer Name: UDAY | User Name: Administrator | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1 ",%*
    exefile [open] -- "%1" %*
    InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0
    "ANTIVIRUSDISABLENOTIFY" = 0
    "FIREWALLDISABLENOTIFY" = 0
    "UPDATESDISABLENOTIFY" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:mad:xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 0
    "DisableNotifications" = 0
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "139:TCP" = 139:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Disabled:mad:xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
    "C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\SmartVoip.com\SmartVoip\SmartVoip.exe" = C:\Program Files\SmartVoip.com\SmartVoip\SmartVoip.exe:*:Enabled:SmartVoip -- (SmartVoip)
    "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
    "C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
    "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
    "C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
    "C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent -- (BitTorrent Inc.)
    "C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
    "C:\WINDOWS\system32\muzapp.exe" = C:\WINDOWS\system32\muzapp.exe:*:Enabled:MUZ AOD APP player -- (Musiccity Co.Ltd.)
    "C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 -- (Microsoft Corporation)
    "C:\Program Files\TeamViewer\Version7\TeamViewer.exe" = C:\Program Files\TeamViewer\Version7\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH)
    "C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service -- (TeamViewer GmbH)
    "C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)
    "C:\Program Files\GoforFiles\goforfilesdl.exe" = C:\Program Files\GoforFiles\goforfilesdl.exe:*:Enabled:GoforFiles
    "C:\Program Files\GoforFiles\GoforFiles.exe" = C:\Program Files\GoforFiles\GoforFiles.exe:*:Enabled:GoforFiles
    "C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{01C5A10F-AD9B-405B-853A-6659841A1242}" = Microsoft SQL Server 2008 Policies
    "{06A7EA72-0F00-4D53-A81C-A5D925711141}" = Microsoft SQL Server 2008 Full text search
    "{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
    "{0C485220-4029-48E7-9F27-965DA4A78D5E}" = Samsung Networking Wizard
    "{13AEC96A-884D-4413-A7B3-4409085465CE}" = TIBCO Rendezvous GAC Assembly Registration
    "{15CC861C-C69E-3758-8961-CE304C2595B6}" = Google Talk Plugin
    "{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{2020045B-8DCF-4449-8D5C-EB5BA37440F1}" = Microsoft SQL Server 2008 Management Studio
    "{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
    "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
    "{232DB76D-4751-41A9-9EC2-CDC0DAC1FAB6}" = WD SmartWare
    "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 24
    "{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Intel(R) PROSet/Wireless WiFi Software
    "{40F34A1C-65A2-4163-98CE-A0D0646CABEF}" = Microsoft SQL Server 2008 Integration Services
    "{4216D328-0FE8-48B8-85B8-BD300E6F080F}" = Nokia Connectivity Cable Driver
    "{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
    "{4D28EFCF-5999-44D2-8D4E-AC643E76C33F}" = Microsoft SQL Server 2008 Client Tools
    "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
    "{4F524A2D-5637-006A-76A7-A758B70C0300}" = Ask Toolbar
    "{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1" = Data Lifeguard Diagnostic for Windows 1.24
    "{5624C000-B109-11D4-9DB4-00E0290FCAC5}" = VPN Client
    "{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
    "{60D46DEE-5221-47AA-B978-BA25C5D9F560}" = Microsoft SQL Server 2008 Client Tools
    "{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}" = Microsoft SQL Server Compact 3.5 SP1 Query Tools English
    "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
    "{70DBC1DF-0103-41A1-8B0A-D39401F10C28}" = Ace2Three
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
    "{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
    "{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
    "{A2289997-10A3-48F2-AA03-99180D761661}" = Fingerprint Reader Suite 5.6
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A351224F-533A-4EED-89F4-0BF3417FD31D}" = WD Backup
    "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
    "{A6F5703D-A4B1-4857-9EDD-DC0ABBBB0D96}" = TuneUp Utilities Language Pack (en-US)
    "{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
    "{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
    "{AEB03FAF-90EB-4B4F-BA32-9C4DDE2C9804}" = Microsoft SQL Server 2008 Integration Services
    "{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
    "{B91D1C13-62F4-484A-8C6E-D56227364A81}" = TIBCO EMS GAC Assembly Registration
    "{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
    "{BE6F412F-C276-4FD8-B3E1-F996CC172776}" = WD Spindown or Stop Utility for External Drive, v1.00
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
    "{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
    "{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
    "{D4AEC53C-1720-41D9-B6D7-6A60DE62D444}" = PC Connectivity Solution
    "{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
    "{DB09C3D8-5ED0-42A3-8EC8-3B9F665971EF}" = WD FAT32 Formatter
    "{E03CD71A-F595-49DF-9ADC-0CFC93B1B211}" = PlayMemories Home
    "{E30E7561-A466-4393-B8BF-FD93E733EF3C}" = Microsoft Office Live Meeting 2007
    "{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
    "{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
    "{FA9C3624-C693-4423-8A8B-2BC2B9F607AB}" = Microsoft SQL Server 2008 Management Studio
    "{FD6C6B7F-5696-48C5-A601-2EE9E50C3D46}" = WD Firewire HID Driver
    "4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
    "504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus
    "AVG SafeGuard toolbar" = AVG SafeGuard toolbar
    "BitMeter" = BitMeter
    "BitTorrent" = BitTorrent
    "Bullzip PDF Printer_is1" = Bullzip PDF Printer 8.4.0.1425
    "CPUID CPU-Z_is1" = CPUID CPU-Z 1.64.0
    "Creative OEM002" = Laptop Integrated Webcam Driver (1.02.01.0612)
    "DMX5_is1" = DriverMax 7
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "Expense Minder" = Expense Minder
    "Free Easy Burner_is1" = Free Easy Burner V 4.1
    "Freemake Video Downloader_is1" = Freemake Video Downloader
    "Google Updater" = Google Updater
    "ie8" = Windows Internet Explorer 8
    "Internet Usage Monitor Lite Edition" = Internet Usage Monitor Lite Edition
    "KLiteCodecPack_is1" = K-Lite Codec Pack 5.7.0 (Full)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft SQL Server 10" = Microsoft SQL Server 2008
    "Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
    "Mozilla Firefox 23.0.1 (x86 en-US)" = Mozilla Firefox 23.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "Nero8Lite_is1" = Nero 8 Micro 8.3.2.1
    "ProInst" = Intel PROSet Wireless
    "Reliance Netconnect - Broadband+" = Reliance Netconnect - Broadband+
    "SynTPDeinstKey" = Dell Touchpad
    "Tata Photon+" = Tata Photon+
    "TeamViewer 7" = TeamViewer 7
    "Total Video Converter 3.71_is1" = Total Video Converter 3.71 100812
    "TuneUp Utilities 2013" = TuneUp Utilities 2013
    "Veetle TV" = Veetle TV 0.9.17
    "VLC media player" = VLC media player 1.1.2
    "Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "WinRAR archiver" = WinRAR archiver
    "WMFDist11" = Windows Media Format 11 runtime
    "WordWeb" = WordWeb
    "Yahoo! Messenger" = Yahoo! Messenger

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "3031938863.portal.qtrax.com" = Qtrax Player
    "8e3135b376bd523e" = Dell System Detect Bootstrapper
    "GoforFiles" = GoforFiles
    "Qtrax" = Qtrax

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 8/27/2013 5:37:40 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 17806
    Description = SSPI handshake failed with error code 0x8009030c while establishing
    a connection with integrated security; the connection has been closed. [CLIENT:
    223.30.35.109]

    Error - 8/27/2013 6:55:44 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 17806
    Description = SSPI handshake failed with error code 0x8009030c while establishing
    a connection with integrated security; the connection has been closed. [CLIENT:
    14.99.111.222]

    Error - 8/28/2013 12:17:25 PM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 30064
    Description = SQL Server failed to set security information on the full-text FilterData
    directory in the FTData folder. Full-text indexing of some types of documents may
    fail until this issue is resolved. You will need to repair the SQL Server installation.

    Error - 8/28/2013 12:17:25 PM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 9954
    Description = SQL Server failed to communicate with filter daemon launch service
    (Windows error: The service cannot be started, either because it is disabled or
    because it has no enabled devices associated with it. ). Full-Text filter daemon
    process failed to start. Full-text search functionality will not be available.

    Error - 8/29/2013 5:04:55 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 30064
    Description = SQL Server failed to set security information on the full-text FilterData
    directory in the FTData folder. Full-text indexing of some types of documents may
    fail until this issue is resolved. You will need to repair the SQL Server installation.

    Error - 8/29/2013 5:04:55 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 9954
    Description = SQL Server failed to communicate with filter daemon launch service
    (Windows error: The service cannot be started, either because it is disabled or
    because it has no enabled devices associated with it. ). Full-Text filter daemon
    process failed to start. Full-text search functionality will not be available.

    Error - 8/29/2013 8:22:21 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 30064
    Description = SQL Server failed to set security information on the full-text FilterData
    directory in the FTData folder. Full-text indexing of some types of documents may
    fail until this issue is resolved. You will need to repair the SQL Server installation.

    Error - 8/29/2013 8:22:21 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 9954
    Description = SQL Server failed to communicate with filter daemon launch service
    (Windows error: The service cannot be started, either because it is disabled or
    because it has no enabled devices associated with it. ). Full-Text filter daemon
    process failed to start. Full-text search functionality will not be available.

    Error - 8/30/2013 3:23:06 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 30064
    Description = SQL Server failed to set security information on the full-text FilterData
    directory in the FTData folder. Full-text indexing of some types of documents may
    fail until this issue is resolved. You will need to repair the SQL Server installation.

    Error - 8/30/2013 3:23:06 AM | Computer Name = UDAY | Source = MSSQLSERVER | ID = 9954
    Description = SQL Server failed to communicate with filter daemon launch service
    (Windows error: The service cannot be started, either because it is disabled or
    because it has no enabled devices associated with it. ). Full-Text filter daemon
    process failed to start. Full-text search functionality will not be available.

    [ OSession Events ]
    Error - 7/13/2010 4:47:04 AM | Computer Name = ADMINISTRATOR | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6214.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 18942
    seconds with 3300 seconds of active time. This session ended with a crash.

    Error - 11/19/2010 9:09:57 AM | Computer Name = ADMINISTRATOR | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6214.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 13008
    seconds with 5940 seconds of active time. This session ended with a crash.

    Error - 11/24/2010 3:53:03 AM | Computer Name = ADMINISTRATOR | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
    12.0.6214.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 3217
    seconds with 3180 seconds of active time. This session ended with a crash.

    [ System Events ]
    Error - 9/1/2013 11:34:32 PM | Computer Name = UDAY | Source = SRService | ID = 104
    Description = The System Restore initialization process failed.

    Error - 9/1/2013 11:34:32 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7023
    Description = The System Restore Service service terminated with the following error:
    %%2

    Error - 9/2/2013 3:06:32 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7034
    Description = The DCService.exe service terminated unexpectedly. It has done this
    1 time(s).

    Error - 9/2/2013 3:33:17 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7009
    Description = Timeout (30000 milliseconds) waiting for the Computer Backup (MyPC
    Backup) service to connect.

    Error - 9/2/2013 3:33:17 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7000
    Description = The Computer Backup (MyPC Backup) service failed to start due to the
    following error: %%1053

    Error - 9/2/2013 3:33:20 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SYMTDI

    Error - 9/2/2013 9:29:39 PM | Computer Name = UDAY | Source = DCOM | ID = 10005
    Description = DCOM got error "%1058" attempting to start the service gusvc with
    arguments " " in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

    Error - 9/2/2013 11:16:19 PM | Computer Name = UDAY | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SYMTDI

    Error - 9/3/2013 12:07:14 AM | Computer Name = UDAY | Source = Service Control Manager | ID = 7000
    Description = The vToolbarUpdater15.5.0 service failed to start due to the following
    error: %%2

    Error - 9/3/2013 12:07:15 AM | Computer Name = UDAY | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SYMTDI


    < End of report >
     
  2. 2013/09/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following
    Code:
    :OTL
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe -- (vToolbarUpdater15.5.0)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmnetadapter.sys -- (VMnetAdapter)
    DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\taphss.sys -- (taphss)
    DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\Drivers\SYMEVENT.SYS -- (SymEvent)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
    DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
    DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
    DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
    DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\HssDrv.sys -- (HssDrv)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ADMINI~1.ADM\LOCALS~1\Temp\cpuz136\cpuz136_x32.sys -- (cpuz136)
    DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
    DRV - [2005/01/26 06:22:20 | 000,280,344 | ---- | M] (Zone Labs LLC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
    FF - user.js - File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    O2 - BHO: (SBCONVERT Class) - {A1056498-D09A-41E4-864B-505EDD640D9E} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll File not found
    O15 - HKCU\..Trusted Domains: essar.com ([myequations] https in Trusted sites)
    O15 - HKCU\..Trusted Domains: google.co.in ([www] http in Trusted sites)
    O15 - HKCU\..Trusted Domains: google.com ([www] https in Trusted sites)
    O18 - Protocol\Handler\linkscanner - No CLSID value found
    
    
    :Services
    
    :Reg
    
    :Files
    C:\FRST
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
    
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    Last scans....

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     

  3. to hide this advert.

  4. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    OTL:
    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    Service vToolbarUpdater15.5.0 stopped successfully!
    Service vToolbarUpdater15.5.0 deleted successfully!
    File C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe not found.
    Service WDICA stopped successfully!
    Service WDICA deleted successfully!
    Service VMnetAdapter stopped successfully!
    Service VMnetAdapter deleted successfully!
    File system32\DRIVERS\vmnetadapter.sys not found.
    Service USBAAPL stopped successfully!
    Service USBAAPL deleted successfully!
    File System32\Drivers\usbaapl.sys not found.
    Service taphss stopped successfully!
    Service taphss deleted successfully!
    File system32\DRIVERS\taphss.sys not found.
    Service SYMTDI stopped successfully!
    Service SYMTDI deleted successfully!
    File C:\WINDOWS\System32\Drivers\SYMTDI.SYS not found.
    Service SymEvent stopped successfully!
    Service SymEvent deleted successfully!
    File C:\WINDOWS\system32\Drivers\SYMEVENT.SYS not found.
    Service PDRFRAME stopped successfully!
    Service PDRFRAME deleted successfully!
    Service PDRELI stopped successfully!
    Service PDRELI deleted successfully!
    Service PDFRAME stopped successfully!
    Service PDFRAME deleted successfully!
    Service PDCOMP stopped successfully!
    Service PDCOMP deleted successfully!
    Service PCIDump stopped successfully!
    Service PCIDump deleted successfully!
    Service lbrtfdc stopped successfully!
    Service lbrtfdc deleted successfully!
    Service i2omgmt stopped successfully!
    Service i2omgmt deleted successfully!
    Service HssDrv stopped successfully!
    Service HssDrv deleted successfully!
    File system32\DRIVERS\HssDrv.sys not found.
    Service cpuz136 stopped successfully!
    Service cpuz136 deleted successfully!
    File C:\DOCUME~1\ADMINI~1.ADM\LOCALS~1\Temp\cpuz136\cpuz136_x32.sys not found.
    Service Changer stopped successfully!
    Service Changer deleted successfully!
    Error: No service named catchme was found to stop!
    Service\Driver key catchme not found.
    File C:\ComboFix\catchme.sys not found.
    Service vsdatant stopped successfully!
    Service vsdatant deleted successfully!
    C:\WINDOWS\system32\vsdatant.sys moved successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1056498-D09A-41E4-864B-505EDD640D9E}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A1056498-D09A-41E4-864B-505EDD640D9E}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\essar.com\myequations\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google.co.in\www\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google.com\www\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\linkscanner\ deleted successfully.
    File Protocol\Handler\linkscanner - No CLSID value found not found.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\FRST not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 134 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 56620 bytes

    User: Administrator.ADMINISTRATOR
    ->Temp folder emptied: 2324639 bytes
    ->Temporary Internet Files folder emptied: 54882499 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 19895377 bytes
    ->Google Chrome cache emptied: 241093310 bytes
    ->Flash cache emptied: 5950 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 402 bytes
    ->Flash cache emptied: 41044 bytes

    User: Default User.WINDOWS
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: fbwuser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: KIRAN

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 402 bytes

    User: LocalService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 7238 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 134 bytes

    User: NetworkService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 49941 bytes
    ->Google Chrome cache emptied: 25579722 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 2577 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 1882100 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33321 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 330.00 mb


    [EMPTYJAVA]

    User: Administrator
    ->Java cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Java cache emptied: 0 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User

    User: Default User.WINDOWS

    User: fbwuser

    User: KIRAN

    User: LocalService

    User: LocalService.NT AUTHORITY

    User: NetworkService

    User: NetworkService.NT AUTHORITY

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Flash cache emptied: 0 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Default User.WINDOWS

    User: fbwuser

    User: KIRAN

    User: LocalService

    User: LocalService.NT AUTHORITY
    ->Flash cache emptied: 0 bytes

    User: NetworkService

    User: NetworkService.NT AUTHORITY

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 09042013_160513

    Files\Folders moved on Reboot...
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temp\JavaDeployReg.log moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\S8XINWK2\mgadget[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\S8XINWK2\recentposts[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\S8XINWK2\xd_arbiter[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Q3BVS7MZ\fastbutton[2].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Q3BVS7MZ\frame[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Q3BVS7MZ\like[5].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CSKIFRKM\106092-active-my-laptop-sound-not-working-2[1].html moved successfully.
    File\Folder C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CSKIFRKM\bind[2].htm not found!
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CSKIFRKM\mail[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CSKIFRKM\proxy[1].html moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CSKIFRKM\xd_arbiter[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CGVJ2OVC\canvas[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CGVJ2OVC\d=1[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CGVJ2OVC\mail[2].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\CGVJ2OVC\postmessageRelay[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  5. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    SECURITY CHECK:

    Results of screen317's Security Check version 0.99.73
    Windows XP Service Pack 3 x86
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Disabled!
    Avira AntiVir PersonalEdition
    McAfee Anti-Virus and Anti-Spyware
    Antivirus out of date!
    `````````Anti-malware/Other Utilities Check:`````````
    SUPERAntiSpyware
    Malwarebytes Anti-Malware version 1.75.0.1300
    TuneUp Utilities 2013
    TuneUp Utilities Language Pack (en-US)
    TuneUp Utilities 2013
    Java(TM) 6 Update 24
    Java 7 Update 25
    Adobe Flash Player 11.8.800.94
    Adobe Reader XI
    Mozilla Firefox (23.0.1)
    Google Chrome 28.0.1500.95
    ````````Process Check: objlist.exe by Laurent````````
    Malwarebytes Anti-Malware mbamservice.exe
    Malwarebytes Anti-Malware mbamgui.exe
    Avira Antivir avgnt.exe
    Avira Antivir avguard.exe
    Malwarebytes' Anti-Malware mbamscheduler.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C:: 8%
    ````````````````````End of Log``````````````````````
     
  6. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    FSS:

    Farbar Service Scanner Version: 28-08-2013
    Ran by Administrator (administrator) on 04-09-2013 at 16:19:38
    Running from "C:\Documents and Settings\Administrator.ADMINISTRATOR\Desktop\Sound Issue "
    Microsoft Windows XP Professional Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    WAN connected
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall "=DWORD:0


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Security Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    File Check:
    ========
    C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
    C:\WINDOWS\system32\netman.dll => MD5 is legit
    C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\WINDOWS\system32\srsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
    C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
    C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
    C:\WINDOWS\system32\qmgr.dll => MD5 is legit
    C:\WINDOWS\system32\es.dll => MD5 is legit
    C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit

    Extra List:
    =======
    DNE(14) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
    0x0F0000000500000001000000020000000300000004000000080000000C0000000F0000000D0000000600000007000000090000000A0000000E00000010000000
    IpSec Tag value is correct.

    **** End of log ****
     
  7. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    TFC: I've copied and saved the data into txt file for ur info


    Getting user folders.

    Stopping running processes.

    Emptying Temp folders.


    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Temp folder emptied: 131349 bytes
    ->Temporary Internet Files folder emptied: 25849845 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 20750528 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 602 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User.WINDOWS
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: fbwuser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: KIRAN

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Google Chrome cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 387 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes

    Emptying RecycleBin. Do not interrupt.

    RecycleBin emptied: 0 bytes
    Process complete!

    Total Files Cleaned = 45.00 mb
     
  8. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    ESET:

    C:\Documents and Settings\Administrator.ADMINISTRATOR\Desktop\Old Firefox Data\8nkz9gap.default\extensions\8pp8gcdj@iueeu.com\content\bg.js Win32/Adware.MultiPlug.H application
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Desktop\Old Firefox Data\8nkz9gap.default\extensions\ai_t@el-tgz.net\content\bg.js Win32/Adware.MultiPlug.H application
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Desktop\Old Firefox Data\8nkz9gap.default\extensions\xzaoqcuqfm@yiuazyl-.org\content\bg.js Win32/Adware.MultiPlug.H application
     
  9. 2013/09/04
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    My sys is performing better than earlier :) i.e., boot up time has reduced but my sound is not yet working....:(
     
  10. 2013/09/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Now when your computer is clean you may want to repost your sound issue in Windows forum.

    Here....

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    8. Run Temporary File Cleaner (TFC) weekly.

    9. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    10. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    11. (Windows XP only) Run defrag at your convenience.

    12. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    13. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

    14. Please, let me know, how your computer is doing.
     
  11. 2013/09/06
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    Done OTL

    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Temp folder emptied: 148216 bytes
    ->Temporary Internet Files folder emptied: 11519247 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 187580086 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 602 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User.WINDOWS
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: fbwuser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: KIRAN

    User: LocalService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: LocalService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Flash cache emptied: 0 bytes

    User: NetworkService
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: NetworkService.NT AUTHORITY
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes
    ->Google Chrome cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\dllcache .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 258 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 190.00 mb


    [EMPTYFLASH]

    User: Administrator
    ->Flash cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Flash cache emptied: 0 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Default User.WINDOWS

    User: fbwuser

    User: KIRAN

    User: LocalService

    User: LocalService.NT AUTHORITY
    ->Flash cache emptied: 0 bytes

    User: NetworkService

    User: NetworkService.NT AUTHORITY

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: Administrator
    ->Java cache emptied: 0 bytes

    User: Administrator.ADMINISTRATOR
    ->Java cache emptied: 0 bytes

    User: ADMINI~1~ADM

    User: All Users

    User: All Users.WINDOWS

    User: BABBY

    User: Default User

    User: Default User.WINDOWS

    User: fbwuser

    User: KIRAN

    User: LocalService

    User: LocalService.NT AUTHORITY

    User: NetworkService

    User: NetworkService.NT AUTHORITY

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 09062013_004847

    Files\Folders moved on Reboot...
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temp\JavaDeployReg.log moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\50_22_210_181[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\5174[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\ddc[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\ff2[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\p-01-0VIaSjnOLg[1].gif moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\p-01-0VIaSjnOLg[2].gif moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\postmessageRelay[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\visitormatch[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\Y8XQMPFR\xd_arbiter[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\V4HUHUKZ\106092-active-my-laptop-sound-not-working-2[1].html moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\V4HUHUKZ\CheckConnection[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\V4HUHUKZ\context_sync[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\V4HUHUKZ\fastbutton[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\V4HUHUKZ\frame[2].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\ads[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\ads[2].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\pixel[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\ServiceLogin[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\si[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\GZHKLODS\tatadocomo_yahoo_com[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\984742556[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\activity[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\adTag[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\adTag[2].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\adTag[3].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\cse[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\ff2[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\like[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\si[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\Content.IE5\8JV3ABBC\xd_arbiter[1].htm moved successfully.
    C:\Documents and Settings\Administrator.ADMINISTRATOR\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  12. 2013/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Way to go!! [​IMG]
    Good luck and stay safe :)
     
  13. 2013/09/06
    udaykiran

    udaykiran Inactive Thread Starter

    Joined:
    2013/08/04
    Messages:
    31
    Likes Received:
    0
    Thnx Broni.....for your guidance & suggestions........my sys speed has really increased....bootup time got reduced by nearly 70%....feeling rly gud....thnQ once again boss...

    pls let me know whr i've to post my query regarding sound of my laptop.....pls help me in resolving dat issue tooo..:)
     
  14. 2013/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Create new topic in Windows forum.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.