Solved Older Dell with xp sp3, need good flashplayer

Discussion in 'Virus, Spyware and Malware Removal' started by chrystal_callahan, May 13, 2012.


Thread Status:
Not open for further replies.
  1. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,955
    Likes Received:
    775
    My System
    Loading...
    You can go into device manager and right click your graphics driver then select properties and select roll back driver.Here is a shot.

    rollback.JPG

    Also you may need to re-enable this entry via ccleaner.Prior to rebooting.
    O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\twatdog.exe

    Sorry about that sometimes these things happen but its nothing that cant be fixed.



    Edit: This has to do with graphics as well and also may need to be re-enabled.
    O4 - HKLM\..\Run: [RegServer] regserve.exe
  2. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    i did complete but half of what I did was finished in safe mode. Do I need to repeat steps in this mode? Adobe still crashing.
  3. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,955
    Likes Received:
    775
    My System
    Loading...
    No thats ok just please complete the prework and attach the logs here and I will move your thread since you say this computer is old there may be a chance that there is some malware on it.If you are still experiencing problems after you have been given the all clear by the security team then we will continue but I suspect that there may be malware on your machine.
    http://www.pchelpforum.com/xf/threads/prework-please-read-before-posting.131846/
  4. Google Advertisement

  5. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    I completed prework, was I supposed to post it here?

    Attached Files:

  6. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,955
    Likes Received:
    775
    My System
    Loading...
  7. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    here's other scan

    Attached Files:

  8. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,955
    Likes Received:
    775
    My System
    Loading...
  9. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    isn't that what I posted the first time? I renamed it prework, i will attach it again

    Attached Files:

  10. Malnutrition Moderator

    PCHF Staff
    Message Count:
    7,955
    Likes Received:
    775
    My System
    Loading...
    No that is the Extras file from otl you will need to Follow these instructions.

    Instructions Part 1 Diagnostic Scan With OTL:


    Please download OTL to your Desktop. (If you already have it downloaded, then just follow the instructions below).
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in
      Code:
      %systemroot%\Fonts\*.com
      %systemroot%\Fonts\*.dll
      %systemroot%\Fonts\*.ini
      %systemroot%\Fonts\*.ini2
      %systemroot%\Fonts\*.exe
      %systemroot%\system32\spool\prtprocs\w32x86\*.*
      %systemroot%\REPAIR\*.bak1
      %systemroot%\REPAIR\*.ini
      %systemroot%\system32\*.jpg
      %systemroot%\*.jpg
      %systemroot%\*.png
      %systemroot%\*.scr
      %systemroot%\*._sy
      %APPDATA%\Adobe\Update\*.*
      %ALLUSERSPROFILE%\Favorites\*.*
      %APPDATA%\Microsoft\*.*
      %PROGRAMFILES%\*.*
      %APPDATA%\Update\*.*
      %PROGRAMFILES%\bak. /s
      %systemroot%\system32\bak. /s
      %ALLUSERSPROFILE%\Start Menu\*.lnk /x
      %systemroot%\system32\config\systemprofile\*.dat /x
      %systemroot%\*.config
      %systemroot%\system32\*.db
      %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
      %USERPROFILE%\Desktop\*.exe
      %PROGRAMFILES%\Common Files\*.*
      %systemroot%\*.src
      %systemroot%\install\*.*
      %systemroot%\system32\DLL\*.*
      %systemroot%\system32\HelpFiles\*.*
      %systemroot%\system32\rundll\*.*
      %systemroot%\winn32\*.*
      %systemroot%\Java\*.*
      %systemroot%\system32\test\*.*
      %systemroot%\system32\Rundll32\*.*
      %systemroot%\AppPatch\Custom\*.*
      %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
      %PROGRAMFILES%\PC-Doctor\Downloads\*.*
      %PROGRAMFILES%\Internet Explorer\*.tmp
      %PROGRAMFILES%\Internet Explorer\*.dat
      %USERPROFILE%\My Documents\*.exe
      %USERPROFILE%\*.exe
      %systemroot%\ADDINS\*.*
      %systemroot%\assembly\*.bak2
      %systemroot%\Config\*.*
      %systemroot%\REPAIR\*.bak2
      %systemroot%\SECURITY\Database\*.sdb /x
      %systemroot%\SYSTEM\*.bak2
      %systemroot%\Web\*.bak2
      %systemroot%\Driver Cache\*.*
      %PROGRAMFILES%\Mozilla Firefox\*.exe
      %ProgramFiles%\Microsoft Common\*.*
      %ProgramFiles%\TinyProxy.
      %USERPROFILE%\Favorites\*.url /x
      %systemroot%\system32\*.bk
      %systemroot%\*.te
      %systemroot%\system32\system32\*.*
      %ALLUSERSPROFILE%\*.dat /x
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      %systemroot%\system32\*.sys
      %systemroot%\system32\drivers\*.dll
      %systemroot%\system32\drivers\*.ini
      %systemroot%\system32\drivers\*.exe
      %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
      %SYSTEMDRIVE%\*.*
      %PROGRAMFILES%\*.
      %appdata%\*.*
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      disk.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      usbstor.sys
      /md5stop
      CREATERESTOREPOINT
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs 
    • Make sure Use Safe List is selected under all categories
    • Make sure both Purity Check and LOP Check are selected
    • Make sure Scan All Users is selected
    • Make sure File Age is set to 30 days
    • Click the Run Scan button.
      When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
      Please Attach the contents of these logs for review by our Security Team
    The Security team needs the otl.txt file please you have posted the Extras.txt
  11. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    ok, sorry forgot to run custom scan, will send asap. thanks
  12. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    OK, here's the new scan.

    Attached Files:

    • OTL.Txt
      File size:
      199.2 KB
      Views:
      2
  13. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,864
    Likes Received:
    902
    My System
    Loading...
    Hi,


    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    Link 3

    When saving ComboFix rename it to Belahzur.exe to prevent it from being blocked by malware.


    Refer to this image:

    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click Belahzur.exe to run it.

      You will see the following image:
    [IMG]

    Click I Agree to start the program.

    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.
  14. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    here's combofix log.

    Attached Files:

    • log.txt
      File size:
      23.4 KB
      Views:
      2
  15. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,864
    Likes Received:
    902
    My System
    Loading...
    Looks okay.
    Can you try playing games using Google Chrome and see if that works? it could be a Firefox problem.
    www.google.com/chrome
  16. chrystal_callahan Silver Member

    Silver
    Message Count:
    128
    Likes Received:
    0
    My System
    Loading...
    google chrome won't work on this system cause it is too old, that is why we had to use firefox.

Older Dell with xp sp3, need good flashplayer

Thread Status:
Not open for further replies.