problem with PB

· PS FAQ · Search Forum · Any ET related problems? Post them here
Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

problem with PB

Postby Buchcio » Thu Nov 06, 2008 17:42

Hi,
I have a problem with PB: disallowed program/driver [80251]
I tried reinstall ET, PB and uptade PB and nothing!!!!!!
I format my hard drive!! It was empty... I install ET and... one more time nothing!!!!
I'm using antivirus MKSvir_2k7, so I don't have any viruses :(
Can u help me :?: :?: :?: :?: :?:

Spam God
User avatar
Posts: 1457
Joined: Fri Feb 08, 2008 1:00

Postby flow » Thu Nov 06, 2008 19:17

i dont know does this work...
but some ppls have solved it this way...

pdate Drivers
Download the latest drivers for your video card. You can find your video card drivers at your manufacturer's website, such as Nvidia or ATI.

Also try downloading and reinstalling DirectX. Your current version may be corrupt.

Reinstall PunkBuster
Try fully Reinstalling PunkBuster.

Be sure that PnkBstrA.exe and PnkBstrB.exe have access to the internet and are not blocked by your anti-virus program and/or firewall.

Uninstall Anti-Virus
There have been reports that various anti-virus programs have been conflicting with PunkBuster, therefore causing this error. You may want to try uninstalling your anti-virus software to at least see if it's the cause of the problem.

Check for Corrupt Files
Rogue from TWL suggested checking for corrupted Windows files.
1. Go to Start > Run
2. Type SFC /purgecache
3. Go to Start > Run again
4. Type: SFC /scannow

Delete Oreans32.sys
PunkBuster has apparently been giving out instructions to delete a file called oreans32.sys from your system, located in C:\Windows\System32\Drivers. Supposedly deleting the file and then restarting your computer will allow you to play again. Mirfster from TWL has provided instructions on how to do this.

To Delete oreans32.sys

1. Go to Start > Run
2. Type cmd
3. Type Net Stop Oreans32
4. Type SC Delete Oreans32
5. Browse to C:\Windows\System32\Drivers and delete the Oreans32.sys file.
6. Restart your computer.


hope this help
[ǝʌɐS-ԀX] 2# uoɹpɐnbS ǝɯ!ɹԀ Ⅎo uǝℲ

Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Thu Nov 06, 2008 19:53

I do that instructions tomorrow. Today I must kearning :)
This error is only on PS#5 serwer. I played on PS#1 and i have good game :)

Spam God
User avatar
Posts: 1457
Joined: Fri Feb 08, 2008 1:00

Postby flow » Thu Nov 06, 2008 20:35

yea thats because 5 is pb server and 1 isnt... :)
hope you get your problem fixed :D

(and i hope that i get too :) )
[ǝʌɐS-ԀX] 2# uoɹpɐnbS ǝɯ!ɹԀ Ⅎo uǝℲ

Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Fri Nov 07, 2008 18:20

I uptade my video and audio drivers, reinstall and uptade PB, delete Oreans32 file, reinstall my antivirus :( I install new antivirus and nothing :evil: Now I am downloading DX. Maybe it help :D

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Fri Nov 07, 2008 18:31

It not help in my problem :(

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Fri Nov 07, 2008 19:14

Is it a pre-installed PC/laptop with standard software from the manufacturer? Does it run XP or Vista?

You should check your processes by bringing up your taskmanager (ctrl + alt + delete) and try to kill processes from any 3rd party software currently installed at your pc. Do this before you start the game and see if it helps.

Make sure you don't kill any Windows related processes such as; svchost.exe, Isass.exe, explorer.exe, rundll32.exe, alg.exe.

I would also open a support ticket at Evenbalance and explain them your problem;
http://www.evenbalance.com/troubleticke ... hp?game=et

They will probably ask you for a detailed overview of the processes running at your pc.
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Fri Nov 07, 2008 21:16

I was tried to kill all processes long time ago. I write the ticket and they give write me on e-mali, they can't understant what it is :( I do all what I can do!! Today i tried play on another serwer with pb and error was... :(

I am using Windows XP Home Edition... 3 months ago all was ok. I give my computer to repair and they talk about new BIOS software... Maybe it BIOS is wrong? But I can't do anything with my computer, it is new and i can't lose my safeguard :(

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Sun Nov 09, 2008 13:52

Buchcio wrote:I was tried to kill all processes long time ago. I write the ticket and they give write me on e-mali, they can't understant what it is :( I do all what I can do!! Today i tried play on another serwer with pb and error was... :(


You didn't mention that in your opening post ;)
But i suppose you gave them a list of your processes?

If Evenbalance can't figure out why their software is messing around with your pc im not sure if we'll be able to find a solution for your problem.

BIOS seems unlikely as it does nothing with files within your OS (as far as i know).

Could you post a list of your processes. You can use a freeware tool like Hijack This! for that.
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Sun Nov 09, 2008 17:31

This is my LOGFILE:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:28:38, on 2008-11-09
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PC Tools Internet Security\pctsTray.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\PC Tools Internet Security\pctsAuxs.exe
C:\Program Files\PC Tools Internet Security\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Tools Internet Security\TFEngine\TFService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL (file missing)
O1 - Hosts: 78.46.45.81 L2authd.lineage2.com
O1 - Hosts: 78.46.45.81 l2testauthd.lineage2.com
O1 - Hosts: 78.46.45.81 l2authd.lineage2.com
O1 - Hosts: 216.107.250.194 nProtect.lineage2.com
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S93.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Internet Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Internet Security\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\PC Tools Internet Security\TFEngine\TFService.exe

--
End of file - 6204 bytes

Official Member
User avatar
Posts: 2598
Joined: Wed Dec 26, 2007 1:00
Location: Estonia

Postby deep » Sun Nov 09, 2008 18:18

u need some cleanup imo, i clean my register with hijackthis once every week. i also use abexo free registry cleaner, this might help u out a bit also.

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Sun Nov 09, 2008 18:41

Diamond wrote:u need some cleanup imo, i clean my register with hijackthis once every week. i also use abexo free registry cleaner, this might help u out a bit also.


Hijack This! does nothing with your registry (perhaps you mean ccleaner?), not to mention that most 'registry cleaners' are pretty useless and in some cases do more harm than good.


@ Buchcio

Did you install Skype deliberately? If you're not using it try to uninstall it.

You can also safely remove the following line within hijack this (it will create a backup for you as well);
Code: Select all
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL (file missing)


Could you scan the following file;

Code: Select all
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe


at http://virusscan.jotti.org and post the result here.
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Mon Nov 10, 2008 15:14

This is info about this file
A-Squared
Found Virus.Worm.Win32.AutoRun.pgm!IK
AntiVir
Found TR/Crypt.XPACK.Gen
ArcaVir
Found Worm.Autorun.Pgm
Avast
Found Win32:Gamona
AVG Antivirus
Found PSW.OnlineGames.2.S
BitDefender
Found Worm.Generic.28716
ClamAV
Found Worm.Autorun-1742
CPsecure
Found nothing
Dr.Web
Found Trojan.Nsanti.Packed
F-Prot Antivirus
Found W32/Onlinegames.gen (probable variant)
F-Secure Anti-Virus
Found Worm.Win32.AutoRun.pgm
G DATA
Found Win32:Gamona
Ikarus
Found Virus.Worm.Win32.AutoRun.pgm
Kaspersky Anti-Virus
Found Worm.Win32.AutoRun.pgm
NOD32
Found a variant of Win32/Pacex.Gen
Norman Virus Control
Found nothing
Panda Antivirus
Found W32/Lineage.JVW
Sophos Antivirus
Found Troj/Agent-HTK
VirusBuster
Found nothing
VBA32
Found Worm.Win32.AutoRun.pgm

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Mon Nov 10, 2008 17:45

Well there's your problem, time for new anti-virus software ;)

Delete the file/virus (ckvo.exe) from your pc, reboot your pc and see if the file is gone.
You may want to download and run Malwarebytes for a final check.
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Mon Nov 10, 2008 19:51

Woo!!!!!!!!!!!
Warren, you're a GENIUS!!!!!!
Thanks you all for help!!!!
Yeah!!!!!!

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Mon Nov 10, 2008 20:13

Is the PB problem gone? Have you checked your pc with the program above? Did it find anything else?

But i think you seriously need to reconsider your anti-virus tool, and use a proper freeware scanner like; Avast or Avira AntiVir
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Tue Nov 11, 2008 14:54

Malwarebytes find 8 another viruses and delete it. ET & PB works :)
I want buy Kaspersky AV. Is it good?

Veteran
User avatar
Posts: 2241
Joined: Fri Jan 11, 2008 1:00

Postby Ajit » Tue Nov 11, 2008 15:14

Buchcio wrote:Malwarebytes find 8 another viruses and delete it. ET & PB works :)
I want buy Kaspersky AV. Is it good?


yes its good but dont buy it use crack :)

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Tue Nov 11, 2008 22:09

Buchcio wrote:Malwarebytes find 8 another viruses and delete it. ET & PB works :)


Okay, great to hear 8)

I want buy Kaspersky AV. Is it good?


Yep, one of the best, not as bloated and slow as Norton/McAfee and very accurate virus definitions.


Garfield wrote:yes its good but dont buy it use crack :)


Yes.. and what a good way to get those viruses on your system again.. :roll: "Don't do crack" ;)
"When the pin is pulled, Mr. Grenade is not our friend." Image

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Wed Nov 12, 2008 15:15

Thanks for all guyz :D :D :D :D :D :D :D :D

Veteran
User avatar
Posts: 2241
Joined: Fri Jan 11, 2008 1:00

Postby Ajit » Wed Nov 12, 2008 15:35

warren-the-ape wrote:
Garfield wrote:yes its good but dont buy it use crack :)


Yes.. and what a good way to get those viruses on your system again.. :roll: "Don't do crack" ;)



i use crack and i have no viruses 8O

Spam Kid
User avatar
Posts: 25
Joined: Mon Sep 29, 2008 0:00
Location: Gryfice/Kolobrzeg, Poland

Postby Buchcio » Wed Nov 12, 2008 17:31

Garfield, can u give me a link to this program and to crack?

Veteran
User avatar
Posts: 2241
Joined: Fri Jan 11, 2008 1:00

Postby Ajit » Thu Nov 13, 2008 8:27

Buchcio wrote:Garfield, can u give me a link to this program and to crack?


seems like i have to PM it for you coz someone has deleted my post 8O :evil:

Website Manager
User avatar
Posts: 6378
Joined: Tue May 09, 2006 0:00
Location: Netherlands

Postby warren-the-ape » Thu Nov 13, 2008 13:57

Let me point you at our Rulebook

No Illegal Content

Posting illegal content or linking to illegal content in the Prime Squadron Forums, such as; cheats, multihacks, cracked programs, serial keys etc. is forbidden in any way. Posts or topics containing that kind of content will be removed without notice.
"When the pin is pulled, Mr. Grenade is not our friend." Image

Veteran
User avatar
Posts: 2241
Joined: Fri Jan 11, 2008 1:00

Postby Ajit » Thu Nov 13, 2008 16:17

warren-the-ape wrote:Let me point you at our Rulebook

No Illegal Content

Posting illegal content or linking to illegal content in the Prime Squadron Forums, such as; cheats, multihacks, cracked programs, serial keys etc. is forbidden in any way. Posts or topics containing that kind of content will be removed without notice.


:oops: :oops: sry

Return to ET Help Desk

Who is online

Users browsing this forum: No registered users and 21 guests