In order to view some of the files and folders mentioned here,
be sure your system is set to show hidden files and folders. Open
Windows Explorer, go to
Tools, and in
Folder Options, select
Show hidden files and folders, and uncheck
Hide protected operating system files.
If you don't already have it, get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip
Unzip the file to your desktop.
Go offline until this is completed (you may wish to print these instructions).
Reboot into Safe Mode.
Do a search for these files and delete any instances found:
param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe
If any could not be deleted, run
Pocket Killbox and paste the full file path of file in the box and click on
Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying
File will be deleted on next reboot, Process and Reboot now?, Click
Yes to reboot. (Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll)
Scan with hijackthis, and have it fix:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotoffers.info/ad0278/
Be sure to close any open windows, other then HijackThis, and hit the
Fix checked button.
Empty your Recycle Bin and reboot normally.
Delete any unwanted icons from your desktop and empty your Recycle Bin.
HotOffers should now be gone. If it still remains, please follow these instructions:
Go to
Start,
Run, type
regedit in the box, and hit
Enter.
At the top of the Registry Editor window, click on
File, and then
Export. In the
Export range panel (at the bottom), click
All, give the file a name, and then
Save your registry as a backup to a location where you will be able to locate it easily, if necessary.
Navigate to, and delete, the following subkeys:
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{145E6FB1-1256-44ED-A336-8BBA43373BE6}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{1D27320E-2DA2-41E2-A103-B5FD9D6A798B}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{B599C57E-113A-4488-A5E9-BC552C4F1152}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{D56A1203-1452-EBA1-7294-EE3377770000}
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Interface
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Typelib
\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}
HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL
HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database
\Distribution Units\{11120607-1001-1111-1000-110199901123}
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version
\Uninstall\Internet Connection Update and HomeP KB234087
HKEY_USERS\Software\Microsoft\Internet Explorer\Extensions
\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Ext
\Stats\{081669BA-EFC4-48C2-A8F4-874052D02553}
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion
\Policies\System
Navigate to the subkey HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, and in the right pane, delete the value: "WindowsFY" = "C:\wp.exe"
Navigate to the subkey HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version
\Explorer\SharedTaskScheduler, and in the right pane, delete the value: "{D56A1203-1452-EBA1-7294-EE3377770000}" = "Interlinking Memory Support"
Navigate to the subkey HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks, and in the right pane, delete the value: "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}" = ""
Exit the Registry Editor.
Now, close any open browser windows, scan with HijackThis, and post a new log please