Just yesterday, my IE explorer had been hijacked by the HotofferS!!!! I have downloaded the hijackthis program.... and fixed all the situations.... but after fixing, i ran scanning for many times, the problems still remained the same. Ang very irritating, almost every minute, it will come out the IE program and the webpage appeared..... shit!!!!! How can I fix this problem??? Now, i post my log file here:

Logfile of HijackThis v1.99.1
Scan saved at 6:38:00 PM, on 3/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Microsoft AntiSpyware\gcasDtServ.exe
C:\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\DC++\DCPlusPlus.exe
C:\Documents and Settings\Chin Ling\Local Settings\Temp\Temporary Directory 13 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

Dani AI

Generated

The symptoms described (IE repeatedly opening ads and the homepage being forced) are classic adware/hijack behavior. Stop browsing with the infected machine if possible and follow a careful cleanup workflow: run tools from the hard drive (not from inside a zip/temp folder), work in Safe Mode when removing persistent components, and always make backups before changing the registry.

  • Boot into Safe Mode (or Safe Mode with Networking if you need updates).
  • As suggested, run HijackThis from a real folder on the hard drive and use its Config → Backups to restore any entries you removed accidentally. Do not remove unknown items blindly.
  • Run up-to-date scanners (your AV plus an on-demand anti-spyware scanner) in Safe Mode to remove files and registry entries left by the adware. Repeat scans after a reboot.
  • Inspect startup points with Autoruns (Sysinternals) or msconfig and check HKCU\Software\Microsoft\Windows\CurrentVersion\Run, HKLM\Software\Microsoft\Windows\CurrentVersion\Run, the Startup folder, and Scheduled Tasks for suspicious entries. Disable first, then remove files after verification.
  • Check browser helper objects and toolbars (use Autoruns to list BHOs) and remove anything unknown. Also examine the hosts file at C:\Windows\system32\drivers\etc\hosts for redirected entries.
  • Clear temporary files and Internet cache before rescanning. If the Winsock stack is affected, consider a winsock reset tool or a supported OS command (export/backup settings first).
  • If removal fails, use System Restore to a point before the infection or, as a last resort, back up data and perform a clean reinstall.

If unsure about any HijackThis entries, post a fresh log after you run HijackThis from a proper folder (do not paste system files). Note any changes you already made and whether you were able to restore HijackThis backups.

first thing, you are running hijackthis from within the zip program pelase unzip it to your hard drive ,in a foler name it C:\hjk,.also what did you fix with hijackthis , hijack is a tool that is use to show people who know how to decipher the log ,and instruct you on what is safe to remove ,it looks like you have removed quite a bit .!
if hijack saved backups of what you removed you should open hijack,go to config/backups and check off all and restore ,then unzip it to harddrive as suggested and rescan and post a new log .

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.