Need Help Removing Offeroptimizer.com

But, when I click record, and play, It makes the same sound I heard when I start my computer. Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! I will take a look at it. 09-08-2004, 10:05 AM #9 beever Registered Member Join Date: Sep 2004 Posts: 7 OS: xp Thanks so much for the reply Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe O9 - Extra 'Tools' Check This Out

A pop up box will appear advising this process will permanently delete files from your system.6. Then please reboot once more and post a new log. __________________ Donations keep TSF moving forward. I'm not sure if ad-aware found the offeroptimizer...I'm still getting the pop-up of the xads. Once scan is done....keep it open... https://forums.techguy.org/threads/need-help-on-removing-xads-xlime-offeroptimizer.272407/

O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM\..\Run: [ccApp] Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box where it says Turn off System Restore.

  1. C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP199\A0819304.dll Infected!
  2. So here is the latest log, please let me know what I need to remove now that I have not already removed.
  3. Still not working...
  4. C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP199\A0819206.dll Infected!

Making registry repairs. Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{81DE1794-839C-4E7B-86A0-376B6C9732A2}" HKCR\Clsid\{81DE1794-839C-4E7B-86A0-376B6C9732A2} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D4DD0FC4-782A-4DF2-81EC-9321BC144C79}" HKCR\Clsid\{D4DD0FC4-782A-4DF2-81EC-9321BC144C79} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{96D9B38D-6C0C-4DFC-841F-E17B7A2A6E59}" HKCR\Clsid\{96D9B38D-6C0C-4DFC-841F-E17B7A2A6E59} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AAFCF8C7-A956-4AF4-AAE3-7612C61C0044}" HKCR\Clsid\{AAFCF8C7-A956-4AF4-AAE3-7612C61C0044} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{89701280-69D6-4508-BAF3-5DBAABE9E010}" HKCR\Clsid\{89701280-69D6-4508-BAF3-5DBAABE9E010} Restoring Windows certificates. and it's still in the tempfolder.So I strongly advise to unzip/extract hijackthis.zip.Read here how to unzip/extract properly:http://metallica.geekstogo.com/xpcompressedexplanation.htmlCreate a permanent folder and move hijackthis.exe into it.

Does the recycle bin work right?...when deleting files...they go to bin or just get deleted? Any way to make donations to this site, its a lifesaver and well worth anything if I can be rid of this horrific web pop up nonsense. Check and fix the following in HijackThis (make sure not to miss any): C:\WINDOWS\system32\uvyjpft.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - Default URLSearchHook is missing O2 - BHO: Band Class

Click "OK" and it will scan and clean your system.7.

First, you all are really helpful...been learning alot in this forum..so thanks. I have seen Twain before, but I thought it was for Photoshop, because when I run Photoshop, it says "Building twain menu items". HJT Log inside TY!!

Are you looking for the solution to your computer problem? Scan started at 5/14/2006 1:11:16 PM Infected! succeeded" afterwards.Then try the Online scan again. Installed HJT and posted the log.

Ask your husba ... well, delete any FOUND.*** folder present there - they all look similarDownload CCleaner1. Press "Continue" on the bottom right on your screen Next another pop-up will pop-up saying what type of update it is and what to do, press "Okay" and a download screen this contact form Attempting to delete: C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP202\A0819967.dll C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP202\A0819967.dll Deleted successfully!

Messenger (HKLM) O9 - Extra button: ICQ Pro (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O9 - Extra button: ComcastHSI (HKCU) O9 - Extra button: Help (HKCU) O9 - Extra Click here to join today! A confirmation dialog box will be shown before clearing the information.* Clean other Temporary files + Recycle bin Go to start > run and type: cleanmgr and click ok.

Attempting to delete: C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP202\A0820058.dll C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP202\A0820058.dll Deleted successfully! I did run Spybot, as well as Spyware Doctor and Spy Sweeper, before creating my original HJT log. Anyway thanks so much. navigate here I actually spent a day reviewing some of your other VX2/Win98 threads and was able to figure out what to do.

Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab O16 - DPF: Yahoo! Then select the items you wish to clean up. mobo, Sep 10, 2004 #2 leandrolics Thread Starter Joined: Sep 10, 2004 Messages: 2 Thanks mobo for your quick response....I followed your steps in updating and setting up of ad-aware se I've now re-run Spybot and run AdAware, and my new HJT log is below.

It opens a popup and INSTALLS Lycos side search, ISTbar, and PowerScan. Pls help. g. Brahms\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name)

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: FastDownloads - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Yosef\Application Data\FastDownloads[1].exe (file missing)O9 - Extra button: Messenger Press "Proceed" to save the settings Press "Next" on the bottom right hand corner. Attempting to delete: C:\WINDOWS\system32\hrrm0591e.dll C:\WINDOWS\system32\hrrm0591e.dll Deleted successfully! Look2Me-Destroyer will now shutdown your computer, click OK.Your computer will then shutdown.Turn your computer back on.If Look2Me-Destroyer does not reopen automatically, reboot and try again.If you receive a message from your

Logfile of HijackThis v1.98.2 Scan saved at 12:46:17 AM, on 9/11/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe Sign In Become an Icrontian Sign In · Register All Discussions Categories Categories All Discussions Activity Best Of...