Hi,

I have run HiJackThis and this is the log file: (please help me in further steps!!)

Logfile of HijackThis v1.99.1
Scan saved at 16:43:53, on 10.03.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\gearsec.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Spyware Doctor\swdoctor.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Programme\SpywareGuard\sgmain.exe
C:\Programme\SpywareGuard\sgbhp.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=Q304&bd=pavilion&pf=laptop
R3 - Default URLSearchHook is missing
O1 - Hosts: earthlink.net
O1 - Hosts: www.earthlink.net
O1 - Hosts: go.com
O1 - Hosts: www.go.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programme\SpywareGuard\dlprotect.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Programme\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cleaner] msn.exe
O4 - HKLM\..\RunServices: [Cleaner] msn.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Programme\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: SpywareGuard.lnk = C:\Programme\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B38CA65-2886-4FDE-8C6E-8EA885431ECF}: Domain =
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B38CA65-2886-4FDE-8C6E-8EA885431ECF}: NameServer = ,
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABABDA79-58D9-4996-A6D0-06B8C39B4B09}: Domain =
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABABDA79-58D9-4996-A6D0-06B8C39B4B09}: NameServer = ,
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Programme\iPod\bin\iPodService.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe

Dani AI

Generated

— short diagnosis and a focused cleanup checklist based on the symptoms shown in your HijackThis output. The log shows a homepage hijack to a known adware domain, hosts-file redirections of common sites to a numeric IP, and a suspicious autostart entry named like a “Cleaner” process. Those three things together are classic adware/host-file hijack behavior and must be addressed in this order: isolate, clean, verify, then harden.

Immediate steps (do these first)

  • Disconnect the PC from the network (unplug Ethernet / disable Wi‑Fi) to stop further redirections or downloads. Do not install Service Pack 2 or make major OS changes until the system is clean (as warned).
  • Boot to Safe Mode (F8) and disable System Restore for the infected drive (so the malware cannot hide in restore points).

Targeted cleanup (order matters)

  • Backup the hosts file (C:\Windows\system32\drivers\etc\hosts) and the registry export before editing. Replace the hosts file contents with a clean default, for example:
    # Default hosts file
    127.0.0.1 localhost

    Save as plain text; ensure Notepad shows "All files" when opening.

  • Use Autoruns (Sysinternals) or HijackThis to remove the suspicious Run/RunServices entry named “Cleaner” (and any autorun entries that are plain executables with no vendor). Be careful not to remove legitimate security/OS entries (Norton, msmsgs, etc.).
  • Run multiple updated scanners (on a clean machine if possible) — an on-demand anti‑malware (Malwarebytes or similar), a full AV scan, and an offline rescue scan if the infection persists. Use RKill/process explorer to stop persistent malicious processes before scanning.

Verification and follow‑up

  • Re-run HijackThis and confirm the homepage, URLSearchHook and hosts are restored. Clear browser cache and reset IE settings. Re-enable System Restore and create a fresh restore point.
  • If changes recur after these steps, a full OS reinstall is the safest resolution.

Note: ’s uninstall method can remove the visible app, but it often leaves registry/hosts changes behind — always verify the hosts file, autoruns, and scheduled tasks after using an uninstaller.

Recommended Answers

All 4 Replies

Try using SpyBot (Search in Google) and Upgrading Windows to WinXP Service Pack 2.

... and Upgrading Windows to WinXP Service Pack 2.

NOOOO!!!

It is absolutely not recommended that you upgrade to SP2 on a system which is currently infected with malware or is otherwise unstable! You stand a very good chance of magnifying your current problems if you do so.

NOOOO!!!

It is absolutely not recommended that you upgrade to SP2 on a system which is currently infected with malware or is otherwise unstable! You stand a very good chance of magnifying your current problems if you do so.

Yes. Sorry. I should have added that upgrading to SP2 should be done after removing the spyware... ejem... and that SP2 is an option but opens more vulnerabilities.... but whatever, we are talking about WinXP :D. I'll be careful in the future.

I just uninstalled hotoffers from my pc about 5 min ago.....

This may not be the method you choose....but it was posted from last year....

Removing Hotoffers via its own uninstall application

ReaperVelle

btw.... Some of the applications that I tried that failed to remove hotoffers:
Ad-aware (POS)
avast antivirus(did find and help though)
agv antivirus (kept seeing a trojan .dll, but it just kept coming back)
Microsoft Beta Antispyware (seems decent)
CWShredder (didnt see it at all v2.13)
Hijackthis (kept tabs on keys as applications removed them)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.