Home > Need Help > Need Help With OfferOptimizer/zserv.dll Removal!

Need Help With OfferOptimizer/zserv.dll Removal!

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dllO2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} Reboot. C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP200\A0819702.dll Infected! Select the View Tab.

See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources Update your AntiVirus Software - It is imperitive that Attempting to delete: C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP199\A0819304.dll C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP199\A0819304.dll Deleted successfully! Started by sic, 12 Jan 2005 10 replies 1,988 views WinHelp2002 18 Feb 2005 help me please Started by kssone, 10 Jan 2005 8 replies 903 views WinHelp2002 18 C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP207\A0820220.dll Infected!

Back to top #4 Grinler Grinler Lawrence Abrams Admin 42,748 posts OFFLINE Gender:Male Location:USA Local time:05:17 AM Posted 17 January 2005 - 10:34 PM Log looks clean...great job!Now that you Click the System Restore tab. Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/22a3eb09455deb92c218/netzip/RdxIE601.cab

I did run Spybot, as well as Spyware Doctor and Spy Sweeper, before creating my original HJT log. Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXEO4 Is there anything else? well, delete any FOUND.*** folder present there - they all look similarDownload CCleaner1.

Select the View Tab. Typical Google could start sending up custom JavaScript from JavaScript repository. Please do this: Turn off System Restore. MS - MVP Consumer Security 2006 thru 2016 Back to top #5 cawthor cawthor New Member Members 8 posts Posted 21 January 2005 - 11:33 PM Here's the next one...thanks again

Download AboutBuster and unzip it to a folder on your the Desktop. It will ask you if you want a second scan, choose Yes. Receiving email attachments as... » Site Navigation » Forum> User CP> FAQ> Support.Me> Steam Error 118> 10.0.0.2> Trusteer Endpoint Protection All times are GMT -7. Readmore» Uninstall ZServ with FreeFixer I'm working on a general purpose tool for removing unwanted software.

Click Properties. This is really important!!After the several reboots, perform next..* Download AlcanShorty from here.Click the download button below and agree to download the fix.Download Alcanshorty to your desktop.DoubleClick alcanshorty_en.exe and click installThis Started by cawthor , Jan 21 2005 01:01 PM Please log in to reply 11 replies to this topic #1 cawthor cawthor New Member Members 8 posts Posted 21 January 2005 By continuing to browse our site you agree to our use of data and cookies.Tell me more | Cookie Preferences Partially Powered By Products Found At Lampwrights.com PC Advisor Phones

You should not have any open browsers when you are following the procedures below. Logfile of HijackThis v1.99.0 Scan saved at 10:27:46 AM, on … http://xadsjt-a.offeroptimizer.com 3 replies I keep on getting this pop up. Your ticket code is ***. Put your HijackThis.exe there, and double click to run it. (this is to save the backups in, that HJT makes) Download CWshredder (the 'stand alone').

Open My Computer. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Tech Reviews Tech News Tech How To Best Tech Reviews Tech Buying Advice Laptop Reviews PC Reviews Printer Reviews Smartphone Reviews Tablet Reviews Wearables Reviews Storage Reviews Antivirus Reviews Latest Deals Thanks!

Reboot back to normal mode and post a fresh log please. Uncheck: Hide file extensions for known file types Uncheck the Hide protected operating system files (recommended) option. AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help!

Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Log In

As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged When HJT fixes anything, it makes backups of the original files in the folder it is in. Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{81DE1794-839C-4E7B-86A0-376B6C9732A2}" HKCR\Clsid\{81DE1794-839C-4E7B-86A0-376B6C9732A2} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D4DD0FC4-782A-4DF2-81EC-9321BC144C79}" HKCR\Clsid\{D4DD0FC4-782A-4DF2-81EC-9321BC144C79} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{96D9B38D-6C0C-4DFC-841F-E17B7A2A6E59}" HKCR\Clsid\{96D9B38D-6C0C-4DFC-841F-E17B7A2A6E59} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AAFCF8C7-A956-4AF4-AAE3-7612C61C0044}" HKCR\Clsid\{AAFCF8C7-A956-4AF4-AAE3-7612C61C0044} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{89701280-69D6-4508-BAF3-5DBAABE9E010}" HKCR\Clsid\{89701280-69D6-4508-BAF3-5DBAABE9E010} Restoring Windows certificates. Delete all that it marks in red.

Manual removal Please follow the instructions below if you would like to remove ZServ manually. C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP202\A0820058.dll Infected! Back to top #10 skepticlial skepticlial Topic Starter Members 11 posts OFFLINE Local time:06:17 AM Posted 15 May 2006 - 09:20 PM Oh I'm Sorry Look2Me-Destroyer V1.0.12 Scanning for infected Attempting to delete: C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP207\A0820220.dll C:\System Volume Information\_restore{FF2640C6-614A-491E-B4A5-1A38710B609D}\RP207\A0820220.dll Deleted successfully!

Kephyr Labs - Find out what is going on at Kephyr. You can't tell me they just have well-doing spree and are sharing to help. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dllO2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} Look2Me-Destroyer will now shutdown your computer, click OK.Your computer will then shutdown.Turn your computer back on.If Look2Me-Destroyer does not reopen automatically, reboot and try again.If you receive a message from your

Read Discussion Reply to All Quick Links Ask a Question Start a Discussion Search Chat My Account My Account My Profile My Preferences My Ignored Users My Email Updates able2know Rules This will ensure your computer has always the latest security updates available installed on your computer. Logfile of HijackThis v1.99.0 Scan saved at 11:30:31 AM, on 1/20/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe Back to top #4 skepticlial skepticlial Topic Starter Members 11 posts OFFLINE Local time:06:17 AM Posted 14 May 2006 - 01:29 PM I can't download the AlcanShorty.

Reboot Then it’s time for Ad-AwareAd-Aware Install and update by using the globe icon. I have attempted to delte with Hijack … spybot german error message 8 replies when i start spybot i get a message that says this "Fehler bei EinfÜgen von Rich edit-Zeile" Both of the products we recommend here are proven to be excellent products and a worthy addition to the arsenal of software protecting your computer. Please notice that you must follow the instructions very carefully and delete everything that is mentioned.

If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell