HKEY_CLASSES_ROOT\clsid\{52fe5233-367c-4efb-bdd7-0be4d212c107}

I have to remember to go back and reset them.I would also be suspicious of those settings after downloads from MS, especially if it has anything to do with part of However, some of the settings will need to be changed before your first scan.Close ALL windows except Ad-Aware SE.Click on the‘world’ icon at the top right of the Ad-Aware SE window I ran Spybot and Malewarebytes yesterday and fixed those errors. Open notepad and copy/paste the text in the quotebox below into it:QuoteFile::c:\program files\SysInternals.exeFolder::c:\program files\Sysinternals AntivirusRegistry::[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SysInternals AV"=-Save this as CFScript.txt, in the same location as ComboFix.exe Refering to the picture above, drag https://forums.techguy.org/threads/hijack-this-log-optimizer-ads.358761/

Lo by AussiePete / September 10, 2004 8:46 PM PDT In reply to: Destroying Spyware, IE toolbars, etc... (HijackThis! Even for an advanced computer user. Good LuckNewt Flag Permalink This was helpful (0) Back to Computer Help forum 7 total posts Popular Forums icon Computer Help 51,912 discussions icon Computer Newbies 10,498 discussions icon Laptops 20,411 Tried Spybot, Adaware , and others.

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exeO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 -

scanning hidden files ... http://www.wilderssecurity.com/threads/help-getting-rid-of-xlime-offer-optimizer-hijackthis-log-included.33580/ Thanks. Oooops! I am having to use IE because Firefox will no longer open.

Anything from the keyboard to the fw to the av has hooks at the kernel layer. have a peek at these guys THEY CAN BE BAD OR GOOD.YOU HAVE TO VERIFY THEM MANUALLY. hannah123: Logfile of HijackThis v1.99.1Scan saved at 22:08:43, on 16/02/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\wrauclt.exeC:\WINDOWS\System32\sistray.EXEC:\Program Files\Ahead\InCD\InCD.exeC:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\Java\jre1.5.0_01\bin\jusched.exeC:\Program Files\blueyonder Log) The posting of advertisements, profanity, or personal attacks is prohibited.

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... mail scanner - unknown owner - c:\program files\alwil software\avast4\ashmaisv.exe" /service (file missing)--------------------------------------------------------------------------------HARMFULL ITEMS IN THE DOCUMENTS AND SETTINGS FOLDER(S) :--------------------------------------------------------------------------------Nothing found.--------------------------------------------------------------------------------THE FOLLOWING ITEMS ARE NOT NEEDED TO LOADAT BOOTIME FOR THE

That is part of the process for using these specialized types of scanners. All is in order. krishan oldsodMay 16th, 2007, 05:49 AMI suppose the Vista Service Pack One will solve some of the known Vista issues. If this is an issue or makes it difficult for you -- please let me know. 4.

method of installing the spyware this time around. Lo by samnewton / September 12, 2004 6:01 AM PDT In reply to: Destroying Spyware, IE toolbars, etc... (HijackThis! Anyway, the (partial) fix was (note: I had to scroll way down in HKEY_CLASSES_ROOT to find the folder CLSID):Remove the following two entries in the registry using Regedit (go to Start/run/regedit)1. this content When I type a search in the bar, it redirects me to advertisement sites or a list of unrelated sites.

Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder. Although, when i tried to restart in a safe boot option, nothing happened, except normal rebooting. krishan faxMay 14th, 2007, 11:17 PMNope, looks clean... ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.3.

Thank you for helping us maintain CNET's great community. They are very informative and helpful for deciphering the HJT logs. Just paste your complete logfile into the textbox at the bottom of this page. and if it was a rootkit you would not be able to see it with HijackThis Log :8}Do you known this CLOAKER.EXE..