heklind
(Jasiee123)
18 Kwiecień 2013 17:58
#1
Witam,
Taki komunikat otrzymuję zawsze, gdy próbuje uruchomic instalację jakiejś gry… Dodam, że dopiero dzisiaj zauważyłem ten problem, wczesniej musiałem sie uporać z jakimś toolbarem, który mi sie zainstalował na komputerze z jakims programem. Udało mi sie usunąć tego toolbara ale pewnie jakieś pozostałości zostały, komputer przeskanowałem AVG, oraz Malwarebytes Anti-Malware.
Logi OTL:
http://wklej.to/JDbxY
http://wklej.to/bY6M7
Czekam na odp. z niecierpliwością i pozdrawiam.
Atis
(Atis)
18 Kwiecień 2013 18:16
#2
Odinstaluj BrowseToSave.
Do okna Własne opcje skanowania / skrypt wklej:
:OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.helpmefindyour.info/?p … g=EN&cc=PL IE - HKLM…\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: “URL” = http://websearch.helpmefindyour.info/?l=1&q={searchTerms}&pid=658&r=2013/04/18&hid=1819071508&lg=EN&cc=PL IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.b1.org/?bsrc=4hixr&chid=c167991 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.helpmefindyour.info/?p … g=EN&cc=PL IE - HKCU…\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: “URL” = http://websearch.helpmefindyour.info/?l=1&q={searchTerms}&pid=658&r=2013/04/18&hid=1819071508&lg=EN&cc=PL FF - prefs.js…keyword.URL: “http://websearch.helpmefindyour.info/?pid=658&r=2013/04/18&hid=1819071508&lg=EN&cc=PL&l=1&q= ” FF - prefs.js…network.proxy.autoconfig_url: “https://secure.premiumize.me/c0ac820d7d5f48e5c6b19bd8962df695/proxy.pac ” [2013-04-18 11:58:33 | 000,000,633 | ---- | M] () – C:\Users\Jasie\AppData\Roaming\mozilla\firefox\profiles\6ub0671f.default\searchplugins\WebSearch.xml [2012-11-13 10:15:07 | 000,006,520 | ---- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml O4 - HKCU…\Run: [iDMan] C:\Users\Jasie\AppData\Local\Temp\IDMan.exe /onboot File not found O8:64bit: - Extra context menu item: Ściągnij przez IDM - C:\Users\Jasie\AppData\Local\Temp\IEExt.htm File not found O8:64bit: - Extra context menu item: Ściągnij wszystkie linki przez IDM - C:\Users\Jasie\AppData\Local\Temp\IEGetAll.htm File not found O20 - AppInit_DLLs: (c:\program files (x86)\browse~1\sprote~1.dll) - c:\Program Files (x86)\BrowseToSave\sprotector.dll () O27:64bit: - HKLM IFEO\kiesagent.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27:64bit: - HKLM IFEO\play online.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27:64bit: - HKLM IFEO\setup.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27:64bit: - HKLM IFEO\uninst.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27 - HKLM IFEO\kiesagent.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27 - HKLM IFEO\play online.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27 - HKLM IFEO\setup.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found O27 - HKLM IFEO\uninst.exe: Debugger - “C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe” File not found [2013-04-18 11:58:33 | 000,020,488 | ---- | C] (Systweak Inc., (http://www.systweak.com )) – C:\Windows\SysNative\roboot64.exe [2013-04-18 11:58:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrrowSe2sayvvea [2013-04-18 11:58:22 | 000,000,000 | —D | C] – C:\ProgramData\BrrowSe2sayvvea [2013-03-27 02:31:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\BrowseToSave [2013-03-27 02:31:07 | 000,000,000 | —D | C] – C:\ProgramData\BirowwsyE2savee [2013-03-27 02:25:01 | 000,000,000 | —D | C] – C:\Users\Jasie\AppData\Local\B1E [2013-03-27 02:24:56 | 000,000,000 | —D | C] – C:\Users\Jasie\AppData\Roaming\B1Toolbar [2013-03-26 10:49:02 | 000,000,000 | —D | C] – C:\ProgramData\SoftSafe [2013-03-26 10:48:51 | 000,000,000 | —D | C] – C:\ProgramData\InstallMate :Commands [emptytemp]
Kliknij Wykonaj skrypt i zatwierdź restart.
Pokaż raport z usuwania i nowy log Skanuj.
heklind
(Jasiee123)
18 Kwiecień 2013 18:26
#3
Wykonałem skrypt, wszsytko juz gra, wielkie dzieki
All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}\ not found. Prefs.js: “http://websearch.helpmefindyour.info/?pid=658r=2013/04/18hid=1819071508lg=ENcc=PLl=1q= ” removed from keyword.URL Prefs.js: “https://secure.premiumize.me/c0ac820d7d5f48e5c6b19bd8962df695/proxy.pac ” removed from network.proxy.autoconfig_url C:\Users\Jasie\AppData\Roaming\mozilla\firefox\profiles\6ub0671f.default\searchplugins\WebSearch.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\IDMan deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ściągnij przez IDM\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ściągnij wszystkie linki przez IDM\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_Dlls:c:\program files (x86 deleted successfully. c:\Program Files (x86)\BrowseToSave\sprotector.dll moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kiesagent.exe\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\play online.exe\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninst.exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kiesagent.exe\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\play online.exe\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uninst.exe\ not found. C:\Windows\SysNative\roboot64.exe moved successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BrrowSe2sayvvea folder moved successfully. C:\ProgramData\BrrowSe2sayvvea folder moved successfully. C:\Program Files (x86)\BrowseToSave folder moved successfully. C:\ProgramData\BirowwsyE2savee\data folder moved successfully. C:\ProgramData\BirowwsyE2savee folder moved successfully. C:\Users\Jasie\AppData\Local\B1E folder moved successfully. C:\Users\Jasie\AppData\Roaming\B1Toolbar folder moved successfully. C:\ProgramData\SoftSafe\Setup folder moved successfully. C:\ProgramData\SoftSafe folder moved successfully. C:\ProgramData\InstallMate{E58E1B35-9EA3-4C92-AE79-D6813E6D39C3} folder moved successfully. C:\ProgramData\InstallMate{8AF9592E-397F-445F-A6B4-715D511A7BD8} folder moved successfully. C:\ProgramData\InstallMate{5BE9280C-BB31-4A09-A8E2-F313800A0AFA} folder moved successfully. C:\ProgramData\InstallMate{3050AE00-71EC-4C0B-AEE0-39CEEBB38CF6} folder moved successfully. C:\ProgramData\InstallMate folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default -Temp folder emptied: 0 bytes -Temporary Internet Files folder emptied: 0 bytes User: Default User -Temp folder emptied: 0 bytes -Temporary Internet Files folder emptied: 0 bytes User: Jasie -Temp folder emptied: 459116536 bytes -Temporary Internet Files folder emptied: 28379289 bytes -FireFox cache emptied: 209577941 bytes -Google Chrome cache emptied: 239463115 bytes -Flash cache emptied: 26708 bytes User: Packard Bell User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 69380 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 85396 bytes RecycleBin emptied: 696317416 bytes Total Files Cleaned = 1 557,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 04182013_202204 Files\Folders moved on Reboot… C:\Users\Jasie\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Atis
(Atis)
18 Kwiecień 2013 18:34
#4
Uruchom OTL i kliknij Sprzątanie.
Usuń stare punkty przywracania:
Aby usunąć wszystkie punkty przywracania
Uruchom SecurityCheck i aktualizuj programy oznaczone jako Out of date