This is driving me crazy and im soo tired of

Logfile of HijackThis v1.99.1
Scan saved at 12:59:20 PM, on 3/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Faxon\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Dani AI

Generated

This looks like a straightforward browser‑hijack/adware case (the "hotoffers" redirect). , it’s annoying but usually removable without reinstalling Windows. ’s tip about running HijackThis cleanly is a good start; combine that with a targeted cleanup workflow below to remove persistence, check for host/proxy tampering, and verify no hidden autoruns are left behind.

  1. Back up important files and create a System Restore point.
  2. Reboot to Safe Mode with Networking and update on‑demand scanners, then run them (start with Malwarebytes and follow with AdwCleaner if available).
  3. Use Sysinternals tools to find persistence: run Autoruns to inspect auto‑start entries and Process Explorer to examine any suspicious running process (check image path and digital signature before removal).
  4. Inspect the hosts file (C:\Windows\System32\drivers\etc\hosts) and the browser proxy settings; reset Internet Explorer settings if needed. Clear temp/IE cache and reboot to normal mode.
  5. Run full AV scans, recheck Autoruns for leftovers, then create a new restore point when clean.

Cautions: export the registry or create a restore point before deleting entries and avoid running aggressive removal tools (like ComboFix) without experienced guidance. When ready to post an updated HijackThis log, follow ’s approach (run HJT from its own folder with browsers closed) and include the scan time, current Windows/service pack level, and any changes you observe after the scans.

Hi Comp Ilit., welcome to DaniWeb :)

I understand your frustration with malware, but please don't take it out on us, we're here to try and help (your title sounds rather demanding, which may put some people off, preventing you from getting the help you seek).

Before anything else, try the steps in this thread; it's had quite a bit of success:
http://www.daniweb.com/techtalkforums/thread19959-hotoffers.html

You also need to put hijackthis into it's own folder; to do this, right-click on your desktop, select New, Folder. Give the new folder a name of your choosing (something like HJT or HijackThis would be good), and then drag the hijackthis.exe icon that is on your desktop into that new folder.

Whenever you scan with hijackthis, make sure all browser windows are closed.

After following the steps in the above link, close all browser windows, scan with HJT, and post a new log please.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.