RISOLTO pagine pubblicitarie

Pubblicità

rosy86

Nuovo Utente
Messaggi
49
Reazioni
0
Punteggio
26
tutto è cominciato quando ho cancellato, e non ho un back up, la cartella Chrome (e relative sottocartelle) in registro di sistema come da discussione cancellato cartella in registro di sistema. ora pur usando firefox ogni tanto, in particolare su sito tipo piratestreaming ma anche siti normali come you tube o anche questo sito, mi si apreono delle pagine pubblicitarie in IE. tecnico24 mi dice:
"Per le pagine pubblicitarie su IE segui queste istruzioni
pagine internet che si aprono da sole"
le ho seguite fino a reimpostare IE alle impostazioni iniziali a scaricare otl tecnico24 dice:
"In Avanzate , clicca sul tab Riemposta , per riportare IE alle condizioni iniziali.
Scarica OTL sul desktop:
http://oldtimer.geekstogo.com/OTL.exe
Avvia OTL.exe

Metti la spunta su SCAN ALL USERS.


Sotto output metti minimal output

Sotto File scans seleziona 60 Days

Spunta sia LOP Check che Purity Check.

premi su RUN SCAN

Al termine verrano rilasciati OTL.txt e Extras.txt e allegali sul forum."

allego ora i file OTL.txt e Extras.txt

Visualizza allegato Extras.TxtVisualizza allegato OTL.Txt


- - - Updated - - -

tutto è cominciato quando ho cancellato, e non ho un back up, la cartella Chrome (e relative sottocartelle) in registro di sistema come da discussione cancellato cartella in registro di sistema. ora pur usando firefox ogni tanto, in particolare su sito tipo piratestreaming ma anche siti normali come you tube o anche questo sito, mi si apreono delle pagine pubblicitarie in IE. tecnico24 mi dice:
"Per le pagine pubblicitarie su IE segui queste istruzioni
pagine internet che si aprono da sole"
le ho seguite fino a reimpostare IE alle impostazioni iniziali a scaricare otl tecnico24 dice:
"In Avanzate , clicca sul tab Riemposta , per riportare IE alle condizioni iniziali.
Scarica OTL sul desktop:
http://oldtimer.geekstogo.com/OTL.exe
Avvia OTL.exe

Metti la spunta su SCAN ALL USERS.


Sotto output metti minimal output

Sotto File scans seleziona 60 Days

Spunta sia LOP Check che Purity Check.

premi su RUN SCAN

Al termine verrano rilasciati OTL.txt e Extras.txt e allegali sul forum."

allego ora i file OTL.txt e Extras.txt

Visualizza allegato Extras.TxtVisualizza allegato OTL.Txt

ho reinserito in explorer la toolbar di norton, il pc lo usa tutta la famiglia e l'antivirus funziona meglio con la toolbar
comunque il problema persiste e non so cosa fare
 
Ultima modifica:
Apri OTL
nel box vuoto custom scans/fixes
copia ed incolla queste righe in grassetto (senza la parola codice)



Codice:
[FONT=arial][B]:Services
:Processes
KILLALLPROCESSES
:OTL
PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)
[/B][B]SRV - (SoftwareUpd) -- C:\Users\Rosy\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (PowerOffer Service) -- C:\Users\Rosy\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\Rosy\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
[/B][B]IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL]
[/B][B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{498424E0-5EA1-45D0-93D1-E25D054A0C01}: "URL" = http://www.google.it/search?hl=it&q={searchTerms}&meta=&rlz=1I7PBEA_it[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7PBEA_it&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=puCXG1_qDh1P6gM-Y8mSuxRX8eI?q={searchTerms}[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=15527&prt=360&chn=retail&geo=IT&ver=20&locale=it_IT&tpr=111
FF - prefs.js..browser.startup.homepage: " http://search.findeer.com"
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3a539854-6a70-11db-887c-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C04F858-257A-4E2E-8B99-6931777470DF}: NameServer = 176.31.229.24,176.31.229.25
[/B][B][2012/11/03 10.58.40 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\ServUpdater[/B]
[B][2012/11/03 10.58.40 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\PowerOffer
[/B][B][2012/11/03 10.58.39 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\PosService[/B]
[B][2012/11/03 10.34.39 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\SoftwareUpdater[/B]

[B]:Files
ipconfig /flushdns /c
C:\Users\Public\Documents\AppData\PoApp

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*" 

:commands
[/B][/FONT][B][purity]
[RESETHOSTS]
[Reboot][/B][FONT=arial][/FONT]


Clicca su RUN FIX
Attendi le operazioni
il pc si riavvierà , altrimenti fallo tu.
Naviga sul web e verifica.
 
Ultima modifica:
scusa ma esattamente cos'è che devo copiare non puoi evidenziarmelo ... sono una capra non so cosa significhi in grassetto e parola codice
 
Apri OTL
nel box vuoto custom scans/fixes
copia ed incolla queste righe in grassetto (senza la parola codice)



Codice:
[FONT=arial][B]:Services
:Processes
KILLALLPROCESSES
:OTL
PRC - C:\Users\Public\Documents\AppData\PoApp\PService.exe (PService)
[/B][B]SRV - (SoftwareUpd) -- C:\Users\Rosy\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe (SoftwareUpdService)[/B]
[B]SRV - (PowerOffer Service) -- C:\Users\Rosy\AppData\Local\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Users\Rosy\AppData\Local\ServUpdater\ServiceUpd.exe (ServiceUpd)
[/B][B]IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL][/B]
[B]IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [URL="http://search.findeer.com"]Search[/URL]
[/B][B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{498424E0-5EA1-45D0-93D1-E25D054A0C01}: "URL" = http://www.google.it/search?hl=it&q={searchTerms}&meta=&rlz=1I7PBEA_it[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7PBEA_it&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s=puCXG1_qDh1P6gM-Y8mSuxRX8eI?q={searchTerms}[/B]
[B]IE - HKU\S-1-5-21-4222817851-2843593734-1834144738-1002\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=15527&prt=360&chn=retail&geo=IT&ver=20&locale=it_IT&tpr=111
FF - prefs.js..browser.startup.homepage: " http://search.findeer.com"
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [PosService] C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe (PLauncher)[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3a539854-6a70-11db-887c-806e6f6e6963}: NameServer = 176.31.229.24,176.31.229.25[/B]
[B]O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5C04F858-257A-4E2E-8B99-6931777470DF}: NameServer = 176.31.229.24,176.31.229.25
[/B][B][2012/11/03 10.58.40 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\ServUpdater[/B]
[B][2012/11/03 10.58.40 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\PowerOffer
[/B][B][2012/11/03 10.58.39 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\PosService[/B]
[B][2012/11/03 10.34.39 | 000,000,000 | ---D | C] -- C:\Users\Rosy\AppData\Local\SoftwareUpdater[/B]

[B]:Files
ipconfig /flushdns /c
C:\Users\Public\Documents\AppData\PoApp

:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*" 

:commands
[purity]
[emptytemp]
[RESETHOSTS]
[Reboot]
[/B][/FONT]


Clicca su RUN FIX
Attendi le operazioni
il pc si riavvierà , altrimenti fallo tu.
Naviga sul web e verifica.

scusa ma esattamente cos'è che devo copiare non puoi evidenziarmelo ... sono una capra non so cosa significhi in grassetto e parola codice cioè tutta la roba scritta all'interno del box?

- - - Updated - - -

Da
:Services
fino a
[Reboot]

ok provo e ti faccio sapere

- - - Updated - - -

Da
:Services
fino a
[Reboot]

ok ho fatto michiedeva di cambiare l'impostazione predefinita di google come motore di ricerca predefinito ma gli ho detto di tenerlo come predefinito
mi è comparso questo:

All processes killed
========== SERVICES/DRIVERS ==========
========== PROCESSES ==========
========== OTL ==========
No active process named PService.exe was found!
Service SoftwareUpd stopped successfully!
Service SoftwareUpd deleted successfully!
C:\Users\Rosy\AppData\Local\SoftwareUpdater\SoftwareUpdService.exe moved successfully.
Service PowerOffer Service stopped successfully!
Service PowerOffer Service deleted successfully!
C:\Users\Rosy\AppData\Local\PosService\Pos.exe moved successfully.
Service ServUpdater stopped successfully!
Service ServUpdater deleted successfully!
C:\Users\Rosy\AppData\Local\ServUpdater\ServiceUpd.exe moved successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-4222817851-2843593734-1834144738-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-4222817851-2843593734-1834144738-1002\Software\Microsoft\Internet Explorer\SearchScopes\{498424E0-5EA1-45D0-93D1-E25D054A0C01}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{498424E0-5EA1-45D0-93D1-E25D054A0C01}\ not found.
Registry key HKEY_USERS\S-1-5-21-4222817851-2843593734-1834144738-1002\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-4222817851-2843593734-1834144738-1002\Software\Microsoft\Internet Explorer\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70D46D94-BF1E-45ED-B567-48701376298E}\ not found.
Registry key HKEY_USERS\S-1-5-21-4222817851-2843593734-1834144738-1002\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.
Prefs.js: " http://search.findeer.com" removed from browser.startup.homepage
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PosService deleted successfully.
C:\Users\Public\Documents\AppData\PoApp\PLauncher.exe moved successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3a539854-6a70-11db-887c-806e6f6e6963}\\NameServer| /E : value set successfully!
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5C04F858-257A-4E2E-8B99-6931777470DF}\\NameServer| /E : value set successfully!
C:\Users\Rosy\AppData\Local\ServUpdater\settings folder moved successfully.
C:\Users\Rosy\AppData\Local\ServUpdater folder moved successfully.
C:\Users\Rosy\AppData\Local\PowerOffer folder moved successfully.
C:\Users\Rosy\AppData\Local\PosService\settings folder moved successfully.
C:\Users\Rosy\AppData\Local\PosService folder moved successfully.
C:\Users\Rosy\AppData\Local\SoftwareUpdater\settings folder moved successfully.
C:\Users\Rosy\AppData\Local\SoftwareUpdater folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Configurazione IP di Windows
Cache del resolver DNS svuotata.
C:\Users\Rosy\Desktop\cmd.bat deleted successfully.
C:\Users\Rosy\Desktop\cmd.txt deleted successfully.
C:\Users\Public\Documents\AppData\PoApp\settings folder moved successfully.
C:\Users\Public\Documents\AppData\PoApp folder moved successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User

cosa significa? posso chiuderlo? devo salvarlo? devo fare altro con OTL?
 
Pubblicità
Pubblicità
Indietro
Top