Home > General > Xlime.offeroptimizer

Xlime.offeroptimizer

For Windows XP or ME, Disable System Restore. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. Be wary of strong drink. C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow this contact form

Say hello! Tools->Open process manager. O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} Is this only happening on certain websites or on any site? 0 OptionsEdit vannesskid Mar 2005 edited Mar 2005 helping my mother with this stupid pop up i have used you

but now i have this message when i start up saying : "C:\Program Files\Wild Tangent\Apps\CDA\cdaEngine0400.dll The specific module cannot be found" i don't know if that's important or not. Please re-enable javascript to access full functionality. Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab O16 - DPF: Yahoo!

Make sure to keep them updated, and scan at least once a week. 0 OptionsEdit vannesskid Jan 2005 edited Jan 2005 ya u can make it resolved looks to be great If things looks clean, re-enable your system restore and set a new restore point. There are still some O9 - Extra button: (no name) entries. A very sincere thank you … Howdy, Stranger!

Blackjack - http://download.game...nts/y/jt0_x.cabO16 - DPF: Yahoo! Spyblast is on the list of rogue programs and should be removed. - http://www.spywarewa...nti-spyware.htmI don't think that SpywareBlaster has a paid version...You need to look over all the items in Step Blackjack - http://download.game...nts/y/jt0_x.cabO16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object)

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXEO4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Also the latest version of Spybot is 1.3.Run HijackThis and place a check next to the following items to be fixed:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Jump to Restart your computer, Next Check your Anti Virus for updates, Next Reboot to safe mode ( by tapping the F8 key on start up) Run a full system scan with your

The start-up list is only useful in very limited circumstances. XP's search feature is a little different. Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0522.dllO9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dllO9 - Extra button: Messenger - FIX errors are rare, but you WOULD NOT want to be the one it happened to. ----------------------------------------------------------------------------- Download Hijack This from HERE: http://radiosplace.com/ PLEASE DO NOT ATTEMPT TO FIX ANYTHING YOURSELF

Thanks for all the help! weblink Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXEO4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Here’s the latest log.I have removed the tools and extra buttons for “Party-Poker” I never use the buttons in the browser anyway but I do love to play Texas Hold’em.

Make sure to close any open browsers. I am using Spyblaster , I thought that was supposed to help but maybe I set it up wrong or need to buy the full version? Xlime.offeroptimizer.com Started by ovaller , Sep 01 2004 04:12 PM This topic is locked 9 replies to this topic #1 ovaller ovaller Member Members 13 posts Posted 01 September 2004 - navigate here Open the Log in Notepad.

Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab O16 - DPF: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: (no name) Logfile of HijackThis v1.98.2 Scan saved at 7:14:53 AM, on 10/8/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Post whatever questions you may have in the forum and we will take a look at it when we get to it.

Spybott cleared out some other things (Internet Optimizer, Clear search, DyFuCa, what ever that is) and I have SpywareBlaster installed.http://housecall.tre.../start_corp.asp found and deleted Troj IMISERV.C located in …HJT\backups and Troj. I am running XP with SP2. I will take a look at it. 10-08-2004, 12:35 PM #9 ssubayar Registered Member Join Date: Oct 2004 Posts: 5 OS: XP Everything seems to be working great, Do you mean SpywareBlaster?

I ran Norton’s and fixed some “Trojan" problems.Date: 11/15/2004, Time: 11:39:56, The fileC:\winnt\system32\cdsm32.dllis infected with the Trojan.StartPage virus.Unable to repair this file.Date: 11/15/2004, Time: 11:39:56, The fileC:\winnt\system32\cdsm32.dllwas infected with the Trojan.StartPage I will take a look at it. 10-08-2004, 11:19 AM #5 ssubayar Registered Member Join Date: Oct 2004 Posts: 5 OS: XP Ok, I've ran the process like Any problems now? __________________ Please do NOT PM me. http://comvurgent.com/general/xads-offeroptimizer.html If you have waited for more than 3 days, you may then and ONLY then PM me for assistance.

I think I will also reevaluate the internet security settings on my daughters profile and invest in a firewall. Make sure you click the "Fix" button Next Download Ad-Aware SE Use the: "Check for Updates Now" option and download the latest reference files Use the Start button, and on the here is all my stuff Logfile of HijackThis v1.99.0 Scan saved at 11:34:17 PM, on 1/7/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dllO4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run:

Ad-aware found more stuff in safe mode ( Coolweb search and a bunch of files “VX2… something). Back to top #9 bluemam bluemam Member Full Member 24 posts Posted 19 November 2004 - 06:37 PM Well I’m back to many things to list so little time. You can download Spyware Shooter (link in my signature) to prevent you from getting spyware. Logfile of HijackThis v1.98.2 Scan saved at 11:21:13 AM, on 10/8/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe

Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab O16 - DPF: Yahoo! Sign In Become an Icrontian Sign In · Register All Discussions Categories Categories All Discussions Activity Best Of... Thanks for the help.Logfile of HijackThis v1.98.0Scan saved at 5:40:49 PM, on 11/15/2004Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\System32\CTsvcCDA.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINNT\System32\nvsvc32.exeC:\WINNT\System32\svchost.exeC:\WINNT\system32\devldr32.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\SK9910DM.EXEC:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\NORTON~1\navapw32.exeC:\Program Files\Microsoft Several functions may not work.

Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) Thanks again. Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Intel\ASF Agent\ASFAgent.exe C:\WINDOWS\System32\cisvc.exe C:\PROGRA~1\Navnt\defwatch.exe C:\Program Files\Dell\OpenManage\Client\Iap.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\PROGRA~1\Navnt\rtvscan.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\system32\HPPROPTY.EXE C:\Program Files\Navnt\vptray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe Go into HijackThis->Config->Misc.

I am only estimating something like 35000 points a day at Full Pow… Sonorous Shredmaster, [email protected] Fanatic Virginia 8 Mar Massalinie's march to 100 MILLION! @Massalinie has broken the doors down Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy HOME FORUMS You should not have any open browsers when you are following the procedures below. I could only find "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hypllp.exe" in safe mode.

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dllO3 - Toolbar: Norton AntiVirus Backgammon - http://download.games.yahoo.com/games/clients/y/at1_x.cab O16 - DPF: Yahoo!