Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 32

Thread: Browse to save

  1. #11
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default

    and this is the rest: (the last reply was 203 Charakters too long...)

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2012.11.15 19:21:33 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Abelssoft
    [2012.11.24 10:41:18 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Amazon
    [2013.01.04 00:22:19 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Audacity
    [2012.09.16 17:14:26 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Buhl Data Service
    [2012.09.24 12:51:19 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Buhl Data Service GmbH
    [2012.09.16 17:25:54 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\DataDesign
    [2013.01.21 12:29:57 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Dropbox
    [2012.11.12 00:02:32 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\DVDVideoSoft
    [2012.12.16 16:11:13 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\fotobuch.de AG
    [2012.09.16 17:42:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\IrfanView
    [2012.10.09 08:49:41 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Juan M. Aguirregabiria
    [2012.09.16 16:39:53 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\LibreOffice
    [2013.01.10 13:54:59 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\MAGIX
    [2012.11.07 11:42:55 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Media Mushroom Limited
    [2012.12.09 16:28:17 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\MOBILedit
    [2013.01.04 02:44:16 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Mp3tag
    [2012.12.19 14:00:51 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\PDF Writer
    [2012.12.25 09:27:18 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\redsn0w
    [2012.11.15 18:59:49 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Samsung
    [2013.01.09 16:15:12 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\simplitec
    [2013.01.12 12:02:04 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Spotify
    [2013.01.12 17:05:11 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TeamViewer
    [2012.09.16 10:58:20 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Thunderbird
    [2013.01.11 10:15:27 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\TuneUp Software
    [2013.01.19 09:52:39 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Wacom
    [2013.01.19 09:52:44 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
    [2012.12.08 17:00:46 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\Wuala
    [2012.11.12 09:58:09 | 000,000,000 | ---D | M] -- C:\Users\Martin\AppData\Roaming\XMedia Recode

    ========== Purity Check ==========



    < End of report >


    (now I feel pretty naked )

  2. #12
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default

    as you can see it's still there.
    the uninstall tells me to uninstall the add-on. But there is no such add-on...

  3. #13
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi disneykiller,

    Next, double click on OTL.exe
    • Under the Custom Scans/Fixes box at the bottom, paste in the following
    • Do Not copy the word CODE
    • please note the fix starts with the :

    Code:
    :Services
    
    :OTL
    IE - HKU\S-1-5-21-4201702909-4008549763-78736917-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchab.com/?aff=7&uid=c61aca2d-4839-11e2-8e56-e8039ab06a14&q={searchTerms}
    FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
    FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
    FF - prefs.js..browser.search.order.1: "Privitize VPN"
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [createrestorepoint]
    Then click the Run Fix button at the top
    • Let the program run unhindered
    • Please save the resulting log to be posted in your next reply.
    Please post the OTL fix log.

    Reboot the computer. Any better?
    Member of UNITE and ASAP

  4. #14
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default

    That looks pretty good! No strange browse-to-save-hyperlinks where they used to appear (facebook, news-pages etc). Well, at least up to now.
    Anything else I have to do?


    All processes killed
    ========== SERVICES/DRIVERS ==========
    ========== OTL ==========
    Registry key HKEY_USERS\S-1-5-21-4201702909-4008549763-78736917-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
    Prefs.js: "Privitize VPN" removed from browser.search.defaultengine
    Prefs.js: "Privitize VPN" removed from browser.search.defaultenginename
    Prefs.js: "Privitize VPN" removed from browser.search.order.1
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Flash cache emptied: 56466 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Martin
    ->Temp folder emptied: 25243902 bytes
    ->Temporary Internet Files folder emptied: 123481808 bytes
    ->Java cache emptied: 175236 bytes
    ->FireFox cache emptied: 459750403 bytes
    ->Flash cache emptied: 57620 bytes

    User: Public

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 190389 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 84222 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes
    RecycleBin emptied: 155708725 bytes

    Total Files Cleaned = 729,00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 01222013_164308

    Files\Folders moved on Reboot...
    C:\Users\Martin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\windows\temp\JET6057.tmp moved successfully.
    C:\windows\temp\JETAD4E.tmp moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...

  5. #15
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default it's not gone

    :(

  6. #16
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi disneykiller,

    Stubborn little cuss isn't it?

    We may have to do this the hard way to find which extension is the problem.

    Open fireFox
    • click FireFox in the top left corner
    • in the menu highlite Help
    • click restart with add-on disabled
    FireFox will close and reopen. Do some usuall surfing and see if the add still appear.
    Member of UNITE and ASAP

  7. #17
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default

    Hmmm, couldn't do it your way. There's no FireFox in the top left corner and no option to start firefox without Add-ons (and it does not show me any installed add-ons - it says I have none). Anyway I managed to set up a second firefox-profile that starts without add-ons (WIN-k& r-key, firefox -p, new profile). In this simple firefox I didnt get any pop-ups til now. But if I have no add-ons on my default-firefox, they cant be the problem, right? Anyway I do have quite a few extensions, some plug-ins and a few scripts...

    Please excuse my weird writing, I'm german – and I'm tired

  8. #18
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi disneykiller,

    Try starting Firefox in Safe Mode by holding down the shift key while starting Firefox.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Right click SystemLook.exe and click "Run as Administrator" to run it.
    • Copy the content of the following codebox into the main textfield
    • Do not copy the word CODE , please note the script starts with the :
      Code:
      :regfind
      browse to save
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
    Member of UNITE and ASAP

  9. #19
    Junior Member
    Join Date
    Jan 2013
    Posts
    21

    Default

    SystemLook 30.07.11 by jpshortstuff
    Log created at 08:30 on 29/01/2013 by Martin
    Administrator - Elevation successful

    ========== regfind ==========

    Searching for "browse to save"
    No data found.

    -= EOF =-


    In the meantime I deinstalled firefox after making a mozbackup without extensions and then installed it again and restored it. It seemed to work but only for about a day, then these links appeared again.
    I consider changing my browser to chrome or opera or whatever. Do you think bts is only nagging or is it a threat? Should I just ignore it and use a different browser?
    Thank you for all the time you spend on my issue!!!

  10. #20
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi disneykiller,

    Sorry aboout the delay, been traveling.

    Even though you backed up FF without extensions there may be something in your profile that is causing the problem.

    Would you be willing to do a complete removal including your profile and preferences?
    Member of UNITE and ASAP

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •