January 5th, 2005, 11:11 AM
|
#1 (permalink)
| | Junior Member
Join Date: Jan 2005
Posts: 4
|
Hello,
I am new to this and would like some help removing XLIME ads that keep poping up, I ran adaware, spybot, and Hijack this. Still no luck any tips.
Thanks, |
| |
January 5th, 2005, 11:25 AM
|
#2 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Philadelphia, PA
Posts: 1,542
|
__________________ "Mercy for the guilty is treason to the innocent" |
| |
January 5th, 2005, 11:28 AM
|
#3 (permalink)
| | Junior Member
Join Date: Jan 2005
Posts: 4
|
I ran HIjack this but the Xlime ads still appear. Any other suggestions? |
| |
January 5th, 2005, 11:30 AM
|
#4 (permalink)
| | Junior Member
Join Date: Jan 2005
Posts: 4
|
Actually the name of the pop up is xlime.adofferoptimizer.com I CAN't be the only one getting this thing. |
| |
January 5th, 2005, 12:02 PM
|
#5 (permalink)
| | Ultimate Member
Join Date: May 2002 Location: Stow, Ohio, Sol III
Posts: 1,190
|
Welcome to TechIMO.
First off this should be in the Security and Privacy forum. Not community. You can ask a Mod to move it for you.
Second, post your 'Hijackthis' log. Hijackthis will not remove anything by itself. The link that Undeadlord gave tells you how to remove it manually.
__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
|
| |
January 5th, 2005, 12:02 PM
|
#6 (permalink)
| | Pump you sucker! Pump!
Join Date: Oct 2001 Location: Sacto, Colliefornia
Posts: 7,340
|
Try doing a search for xlime on your computer. You may need to go to safe mode to delete it.
What browser are you running?
BTW: Welcome to Techimo! 
__________________
America has spoken; Now it is time for our enemies to speak.
|
| |
January 5th, 2005, 04:56 PM
|
#7 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Philadelphia, PA
Posts: 1,542
|
Sorry about that, maybe I should have been abit more clear. Hijackthis just gives you a quick overview of some settings and programs that are running. Its up to you to take that data and use it to remove the Xlime Ads.
The first link I gave should have had directions for doing that.
Undeadlord |
| |
January 6th, 2005, 09:06 AM
|
#8 (permalink)
| | Junior Member
Join Date: Jan 2005
Posts: 4
|
Thanks for the help guys, Here is the log I got from Hijack this but I don't see the Xlime in there anywhere.
Logfile of HijackThis v1.99.0
Scan saved at 8:04:46 AM, on 1/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\spoolsv.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Windows\system32\MsgSys.EXE
C:\Windows\Explorer.EXE
C:\Windows\system32\fzocqgq.exe
C:\Windows\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jeff Evans\Desktop\HijackThis.exe
O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\Windows\ZServ.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O4 - HKLM\..\Run: [baksakeogp] C:\Windows\system32\fzocqgq.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O23 - Service: Ati HotKey Poller - Unknown - C:\Windows\System32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe |
| |
January 6th, 2005, 09:16 AM
|
#9 (permalink)
| | Ultimate Member
Join Date: Aug 2003 Location: Gateshead U.K.
Posts: 8,838
|
under suspicion immediatetly are any references to fzocqgq.exe and wscntfy.exe. google them. the second may be legit, but check it anyway.
O2 - BHO: ZServObj Class - {00000000-C1EC-0345-6EC2-4D0300000000} - C:\Windows\ZServ.dll may warrant further investigation.
fzocqgq.exe is 99% certain malware. |
| |
January 6th, 2005, 09:22 AM
|
#10 (permalink)
| | Ultimate Member
Join Date: Aug 2003 Location: Gateshead U.K.
Posts: 8,838
|
wscntfy.exe is part of windows.
fzocqgq.exe won't google. it is now 99.98% certain to be malware. it is probably one of the random name changing type programs, so it runs with a different process name every time it starts. http://www.doxdesk.com/parasite/Transponder.html talks about ZServ.dll |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |