Home > Help With > Help With Hijack Please. I Need To Remove Xlime Offeroptimizer

Help With Hijack Please. I Need To Remove Xlime Offeroptimizer

If you do opt for AVG be sure and uninstall Norton as running both can create a conflict. Various Irritating Things OfferOptimizer...Urrgh Adware Hijack This Log Ad-Aware SE won't delete Prosearching HELP! I kept telling her not to thank me, that it was Joe London....but she wasn't having it. So, after telling it to remove all that you suggested, I just clicked "exit" and reboot manually. (minor thing I assume...just making sure) Thanks!Warning!

Keith Back to top blenderSite AdminJoined: 19 Jan 2004Last Visit: 09 Apr 2014Posts: 10886Location: Ontario Posted: Thu Mar 24, 2005 10:54 am Post subject: Hi sounds like you likely got it....there The homepage is not resetting, but getting popups to seemingly random sites, no porn oddly enough. Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... I am rid of all popups.

Hijack entry "O4 - Startup: huptgk.exe" was not there....perhaps removed by something done in a previous step. Joe. Total of file sizes: 13,012 bytes 12.71 K ------------ Strings.exe Qoologic Results ------------C:\WINDOWS\LPT$VPN.343: TROJ_QOOLOGIC.CC:\WINDOWS\LPT$VPN.343: TROJ_QOOLOGIC.BC:\WINDOWS\LPT$VPN.343: TROJ_QOOLOGIC.AC:\WINDOWS\VPTNFILE.343: TROJ_QOOLOGIC.CC:\WINDOWS\VPTNFILE.343: TROJ_QOOLOGIC.BC:\WINDOWS\VPTNFILE.343: TROJ_QOOLOGIC.AC:\WINDOWS\eoubpi.dll: updates.qoologic.comC:\WINDOWS\coolapi32.dll: adsrv.qoologic.comC:\WINDOWS\hzmwul.exe: updates.qoologic.comC:\WINDOWS\cyzoul.dll: updates.qoologic.comC:\WINDOWS\hntecn.dll: excl_urls=adsv2.delfinproject.com,popup.msn.com,i.emarketresearchgroup.com,u.clkoptimizer.com,ezula.com,ads2.revenue.net,banners.pennyweb.com,counters.honesty.com,ads.bidclix.com,oz.valueclick.com,radio.launch.yahoo.com,zone.msn.com,sr.adwave.com,xlime.offeroptimizer.com,clickit.go2net.com,us.update.companion.yahoo.com,kill-pop-ups.com,qksrv.net,clickspring.net,cdn-aimtoday.aol.com,search200.com,servedby.adscpm.com,xanga.com,count.exitexchange.com,jnictech.cjt1.net,xadsq.offeroptimizer.com,paypopup.com,popuptraffic.com,cdn-cf.aol.com,allaboutsearching.com,hotmail.msn.com,adfarm.mediaplex.com,by.optimost.com,amch.questionmarket.com,akapp.whenu.com,newupdates.lzio.com,cfg.mywebsearch.com,searcheffect.com,ads.delfinproject.com,master.mx-targeting.com,hotmail.com,ctl.twain-tech.com,mail.yahoo.com,m2.doubleclick.net,insider.msg.yahoo.com,focusin.ads.targetnet.com,e.rn11.com,jmnad1.com,topicks.com,ad.doubleclick.net,m3.doubleclick.net,as.casalemedia.com,pgq.yahoo.com,webpdp.gator.com,stopzilla.com,ayb.lop.com,xadso.offeroptimizer.com,download.smileycentral.com,mm.delfinproject.com,view.atdmt.com,delfinproject.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,as.adwave.com,popuppers.com,look2me.com,wisapidata.weatherbug.com,ads.addynamix.com,ar.atwola.com,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,weatherbug.com,jicmedia.cjt1.net,games.yahoo.com,adsrv.qoologic.com,servedby.advertising.com,ww2.weatherbug.com,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,mmm.media-motor.net,hop.clickbank.net,media76.fastclick.net,websearch.com,isapi60.weatherbug.com,web.tickle.com,messenger.zango.com,wwp.icq.com,smileycentral.com,adserv1.gruvmedia.com,cdn.icq.com,s.clkoptimizer.com,tv.180solutions.com,pops.browseraid.com,download.abetterinternet.com,adserv.internetfuel.com,messenger.msn.com,sr.websearch.com,top-banners.com,advert.runescape.com,join1.winhundred.com,odysseusmarketing.com,v4.windowsupdate.microsoft.com,adverts.lzio.com,windowsupdate.microsoft.com,filter.belkin.com,comcast.net,sc.musicmatch.com,license.hotbar.com,trk.pcsecurityshield.com,web.icq.com,whenusearch.com,jbigpops.cjt1.net,isg05.casalemedia.com,yahoo.com,aol.com,anrdoezrs.net,microsoft.com,target.com,aim-charts.pf.aol.com,download.websearch.com,actualdeals.com,images.trafficmp.com,mydailyhoroscope.net,couponage.com,c5.zedo.com,ekmas.com,ads.mydailyhoroscope.net,creativeby.viewpoint.com,affiliates.4lowrates.com,hits.clickandtrack.net,jcontent.bns1.net,clickserve.cc-dt.com,popups.ad-logics.com,adlog2.lzio.com,host239.ipowerweb.com,bv.channel.aol.com,img2.mailpostdirect.com,dw.dailywinner.net,toprebates.com,trk.bestmagsdirect.com,ads.clickagents.com,a.websponsors.com,sandboxer.com,media.fastclick.net,click2.containsitall.com,ads234.com,http300.edge.ru4.com,adlog.com.com,rs.websearch.com,ads.com.com,server.iad.liveperson.net, -------------- Strings.exe Aspack Results -------------C:\WINDOWS\vsapi32.dll: ASPack 1.08.04C:\WINDOWS\vsapi32.dll:

Thread Status: Not open for further replies. Register now! Help with Virus Java/ByteVerify Any help is appreciated (XLime) need help to remove .dll Can't remove search extender/shopping wizard! Join our site today to ask your question.

Total of file sizes: 1,362,624 bytes 1.30 M ------------ Strings.exe Qoologic Results ------------ C:\WINDOWS\hggtgn.dll: excl_urls=photobucket.com,c1.zedo.com,media.deskwizz.com,stats.eblocs.com,passportimages.com,banners.searchingbooth.com,ads234.com,click2.containsitall.com,media.fastclick.net,sandboxer.com,a.websponsors.com,ads.clickagents.com,trk.bestmagsdirect.com,toprebates.com,ad.doubleclick.net,as.casalemedia.com,m3.doubleclick.net,dw.dailywinner.net,img2.mailpostdirect.com,bv.channel.aol.com,adlog2.lzio.com,host239.ipowerweb.com,popups.ad-logics.com,clickserve.cc-dt.com,hits.clickandtrack.net,ads.mydailyhoroscope.net,c5.zedo.com,affiliates.4lowrates.com,couponage.com,ekmas.com,creativeby.viewpoint.com,mydailyhoroscope.net,images.trafficmp.com,actualdeals.com,download.websearch.com,aim-charts.pf.aol.com,aol.com,target.com,yahoo.com,microsoft.com,anrdoezrs.net,isg05.casalemedia.com,jbigpops.cjt1.net,whenusearch.com,trk.pcsecurityshield.com,license.hotbar.com,web.icq.com,sc.musicmatch.com,comcast.net,filter.belkin.com,clickit.go2net.com,adverts.lzio.com,windowsupdate.microsoft.com,v4.windowsupdate.microsoft.com,odysseusmarketing.com,join1.winhundred.com,advert.runescape.com,top-banners.com,sr.websearch.com,messenger.msn.com,download.abetterinternet.com,adserv.internetfuel.com,pops.browseraid.com,banners.pennyweb.com,tv.180solutions.com,s.clkoptimizer.com,adserv1.gruvmedia.com,cdn.icq.com,messenger.zango.com,smileycentral.com,wwp.icq.com,web.tickle.com,isapi60.weatherbug.com,websearch.com,hop.clickbank.net,media76.fastclick.net,mmm.media-motor.net,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,ww2.weatherbug.com,servedby.advertising.com,adsrv.qoologic.com,games.yahoo.com,weatherbug.com,jicmedia.cjt1.net,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,ar.atwola.com,ads.addynamix.com,wisapidata.weatherbug.com,popuppers.com,as.adwave.com,look2me.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,delfinproject.com,view.atdmt.com,mm.delfinproject.com,download.smileycentral.com,xadso.offeroptimizer.com,webpdp.gator.com,ayb.lop.com,stopzilla.com,pgq.yahoo.com,jmnad1.com,topicks.com,e.rn11.com,focusin.ads.targetnet.com,insider.msg.yahoo.com,m2.doubleclick.net,mail.yahoo.com,jcontent.bns1.net,ctl.twain-tech.com,master.mx-targeting.com,hotmail.com,searcheffect.com,ads.delfinproject.com,cfg.mywebsearch.com,akapp.whenu.com,newupdates.lzio.com,allaboutsearching.com,amch.questionmarket.com,adfarm.mediaplex.com,hotmail.msn.com,by.optimost.com,cdn-cf.aol.com,paypopup.com,popuptraffic.com,xadsq.offeroptimizer.com,jnictech.cjt1.net,xanga.com,count.exitexchange.com,servedby.adscpm.com,search200.com,cdn-aimtoday.aol.com,kill-pop-ups.com,us.update.companion.yahoo.com,qksrv.net,clickspring.net,xlime.offeroptimizer.com,sr.adwave.com,zone.msn.com,radio.launch.yahoo.com,ads.bidclix.com,counters.honesty.com,oz.valueclick.com,i.emarketresearchgroup.com,ads2.revenue.net,popup.msn.com,adsv2.delfinproject.com,u.clkoptimizer.com,ezula.com,server.iad.liveperson.net,loadingwebsite.com,pan-advert.com,t.trafficmp.com,clicktrk.com,aaabesthomepage.com,ads.exitexchange.com,us.a1.yimg.com,trafficmp.com,yimg.com,a.as-us.falkag.net,a1.yimg.com,z1.adserver.com,falkag.net,as-us.falkag.net,loginnet.passport.com,ads.inet1.com,pagead2.googlesyndication.com,login.passport.net,v8.alwaysupdatednews.com,adv.eblocs.com,alwaysupdatednews.com,fxfeeds.mozilla.org,cdn.aim.com,ar.atwola.com,c4.maxserving.com,maxserving.com,mediaplex.com,altfarm.mediaplex.com,topmoxie.com,global.msads.net,msads.net,banner.goldenpalace.com,goldenpalace.com,us.i1.yimg.com,cdn.comcast.net,us.yimg.com,us.js1.yimg.com,js1.yimg.com,switch.atdmt.com,atdmt.com,update32.searchmiracle.com,onemoresearch.net, -------------- Strings.exe Aspack Results ------------- ----------------- HKLM Run Key ------------------ -------------- Strings.exe Umonitor Results ------------- REGEDIT4 Flrman1, Mar 2, 2005 #2 This thread has been Locked and is not open to further replies. Grisoft AVG Download Site.http://www.grisoft.com/us/us_index.phpI saw that line in Hijack, but that listing in add/remove, the folder it references, and wo.exe are not on this computer. Don't attach the log, open it in Notepad, then select all (CTRL-A) copy it to clipboard (CTRL-C) and paste it into a reply here.

As this is an older machine please pay attention to the system requirements. If I click Yes I want to continue running scripts, all aspects of Norton say "refreshing". Yes, my password is: Forgot your password? Advertisements do not imply our endorsement of that product or service.

Now you have C:\HJT\ folder. Please Help! Copy and paste the contents of the HijackThis log into your post. Wait for help.

It won't let me update or run a scan. Someone pls help me READ THIS! Only one issue remains. Hawk :beer: Vista will never be gone as long as Windows 7 is here!

Back to top #11 Jaybird934 Jaybird934 Topic Starter Members 110 posts OFFLINE Local time:04:20 PM Posted 16 January 2005 - 04:19 PM I don't have the "C:\PROGRAM Files\Web Offer" folder No justice in this world. If I have helped you in any way, please consider a donation: Member of UNITE and ASAP. Help! :( Pop up ads- ugh!!!

If you're not already familiar with forums, watch our Welcome Guide to get started. My yahoo account problem. If you keep your computer updated with the latest security software updates and practice safe Internet browsing, you're already doing a lot to help keep the hijackers away.Don’t know if your

Hijacked Security against KeyLoggers about blank Trojan horse found in windows '98SE c:programs/winad client - can not heal or vault HijackThis Log - 9/13/04 - OfferOptimizer Problem.

Post log HERE: http://pcpitstop.ibf...php?act=SF&f=25 Good luck. Logfile of HijackThis v1.99.0Scan saved at 8:29:57 PM, on 01/12/2005Platform: Windows 98 Gold (Win9x 4.10.1998)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\WIORUV.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\GWHOTKEY.EXEC:\LAUNCHBOARD\LNCHBRD.EXEC:\WINDOWS\SYSTEM\STIMON.EXEC:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXEC:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXEC:\WINDOWS\SYSTEM\SECURE.EXEC:\WINDOWS\STARTER.EXEC:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXEC:\WINDOWS\SYSTEM\RNAAPP.EXEC:\WINDOWS\SYSTEM\TAPISRV.EXEC:\WINDOWS\DESKTOP\HIJACK\HIJACKTHIS.EXEC:\WINDOWS\NOTEPAD.EXEC:\WINDOWS\SYSTEM\PSTORES.EXER0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Several functions may not work. HiJack Log follows: Thanks, Keith Logfile of HijackThis v1.99.1 Scan saved at 3:30:02 PM, on 03/22/2005 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL

oh no, not another hijackthis log. I would like to try online scanner to show em all to me. HiJack This Log Attached Help! When opening Norton, I get a script error that says "Permission denied".

If I have helped you in any way, please consider a donation: Member of UNITE and ASAP. Not everyone gets that gift but is common. Log Included 2 problems - Wupdate and system restore not working Can someone help me get rid of this trojan plz Can't find ne fault, can you? Joe.