Home > General > Xlime.offeroptimizer.com

Xlime.offeroptimizer.com

Here's my Hijack log. Everytime i open IE i get popups from xlime.offeroptimizer.com. Go into HijackThis->Config->Misc. I ran the (housecall) scan with no virus' detected. 7) I did not do the last couple of steps with pandesoftware.com or the Find It file because it was getting late. this contact form

Dexter... 0 OptionsEdit Rjkorah Sep 2004 edited Sep 2004 Dexter, I fixed the problems and quarantined the files you told me to. Ignore that and let it continue to run until it finishes. Yes, my password is: Forgot your password? Thread Status: Not open for further replies.

Location: : S-1-5-21-351766111-2414425263-1466433608-1007\software\microsoft\office\11.0\word\recent templates Description : list of recent templates used by microsoft word MRU List Object Recognized! Location: : software\musicmatch\musicmatch jukebox\4.0\mmradio Description : information on the last station listened to using musicmatch radio MRU List Object Recognized! Cookiegal, Mar 7, 2005 #4 Lip314 Thread Starter Joined: Mar 6, 2005 Messages: 7 Hey Cookiegal, I followed your instructions last night, but I my system could not find some of

No, create an account now. Register now! It will open an Output.txt file when it completes. Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe O9 - Extra button: (no name)

Save Log. Location: : S-1-5-21-351766111-2414425263-1466433608-1007\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Lip314 Lip314, Mar 8, 2005 #5 Cookiegal Administrator Malware Specialist Coordinator Joined: Aug 27, 2003 Messages: 105,756 Look again in the Control Panel and if you have these listed there, If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell

so if it isn't i'm sorry. If you use a or b, let the disk cleanup manager scan your system for files to remove. Reboot into Safe Mode (hit F8 key until menu shows up). Type : IECache Entry Data : bryan [emailprotected][2].txt Category : Data Miner Comment : Value : C:\Documents and Settings\LocalService\Cookies\bryan [emailprotected][2].txt Tracking Cookie Object Recognized!

For the past few days I've been getting huge numbers of instances of IE running xlime.offeroptimizer.com/creat/cy/xxx... Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} A Short-Media community © 2003–2017. WHICH CAN BE EXTREMELY DANGEROUS TO ANYONE WHO DOES NOT KNOW WHAT THEY ARE WORKING WITH!!!) ...

Type : IECache Entry Data : bryan [emailprotected][2].txt Category : Data Miner Comment : Value : C:\Documents and Settings\LocalService\Cookies\bryan [emailprotected][2].txt Tracking Cookie Object Recognized! weblink It will tell you the steps to go through before posting a HJT log. whats our next move. Type : IECache Entry Data : bryan [emailprotected][1].txt Category : Data Miner Comment : Value : C:\Documents and Settings\LocalService\Cookies\bryan [emailprotected][1].txt Tracking Cookie Object Recognized!

I would like to see one more Hijack This log please to be sure all is OK and then if it's clean we will have you create a new system restore Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general Description : windows media sdk MRU List Object Recognized! On the General tab under "Temporary Internet Files" Click "Delete Files". navigate here Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [ccApp]

Icrontic › All Discussions › Spyware & Virus Removal Talk to Us Twitter @icrontic Facebook Page Helium Wars Steam Group The 5¢ Tour About Us Our Epic History Team Fortress 2 Sign In Become an Icrontian Sign In · Register All Discussions Categories Categories All Discussions Activity Best Of... Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 -

Post a fresh HJT log for review.

We would love to have you on our Team. Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} Save the log file and run HijackThis Analyzer in the same folder to get the result.txt log. Location: : S-1-5-21-351766111-2414425263-1466433608-1007\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru Description : list of recent documents opened by microsoft word MRU List Object Recognized!

When HJT fixes anything, it makes backups in the folder it's in. I bought some software by xoftspy for 40.00 and that haven't helped me at all. Otherwise, you will have to click on the Clean button to remove the VX2 infection. http://comvurgent.com/general/xads-offeroptimizer.html Location: : S-1-5-21-351766111-2414425263-1466433608-1007\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized!

I really appreciate any help or advise you can give me. xlime.offeroptimizer.com someone help me here! Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders" Next click on My Computer. Go into HijackThis->Config->Misc.

Cookiegal, Mar 6, 2005 #2 Lip314 Thread Starter Joined: Mar 6, 2005 Messages: 7 Logfile of HijackThis v1.99.1 Scan saved at 9:44:43 PM, on 3/6/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) When the scan is finished, the scan button will change to “Save Log”. Staff Online Now etaf Moderator TerryNet Moderator Advertisement Tech Support Guy Home Forums > Security & Malware Removal > Virus & Other Malware Removal > Home Forums Forums Quick Links Search Windows XP's search feature is a little different.

Get rid of the following items: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM AOL Spyware, Ad-Aware 6.0, and Norton Antivirus all pick it up, but only Ad-Aware can remove it, but it is back when I restart my comp ... See above link.

Thanks for all the help! Location: : S-1-5-21-351766111-2414425263-1466433608-1007\software\microsoft\windows\currentversion\explorer\runmru Description : mru list for items opened in start | run MRU List Object Recognized! thanks. I'm in the process of getting a refund and if I do and you can help me, I would be more than happy to give a donation to your website.

Apparently alot of people have been having this problem, but I'm not sure if I'm in the same exact situation. You are the best. Are you looking for the solution to your computer problem? Thanks!

I'm just getting so frustrated with this popup, I could just choke the people who gave me this thing. Now click "Apply to all folders" Click "Apply" then "OK" In safe mode navigate to the C:\Windows\Temp folder. Please help! It is not Windows Update - tricky isn't it.