Hello everybody,
I am working on a computer that has this hotoffers bug wich keeps placing porn links on the desktop. I cant get on the internet with the infected computer, it only tries to go to their website and zonealarm block them out. Im using my jump drive to xfer files onto the infected computer. I also would need a link to what ever programs I would need to post the info you guys would need.

Dani AI

Generated

Notes for : treat the machine as quarantined — leave it offline (unplug network and disable wireless) so the adware cannot phone home. Use a clean PC to fetch removal tools and rescue ISOs, and copy them to your jump drive with autorun disabled before touching the infected box. That avoids further spread and gives you a trusted toolkit to work from.

Safe, practical next steps that complement what and have suggested: boot the machine from a rescue CD/USB (an offline AV rescue environment) and run a full scan to remove files and rootkits that block normal Internet access. If you can run programs from the hard drive, use Sysinternals Autoruns and Process Explorer to find the persistent startup entries, scheduled tasks and running process that are trying to contact hotoffers.info. Do not blindly delete unknown items — record names and locations first, and back up the registry before making changes.

Gathering useful artifacts for helpers: copy the firewall logs, the hosts file, a list of running processes and the Autoruns output to your clean PC for analysis. That information will show which executable is making outbound requests and where it is persistent. If you must move user files, copy only personal documents and media; avoid executables and scan the backup on a clean machine before restoring.

A final note: manual file deletion can work for some adware, but persistent infections or rootkits often survive. If scans and removal tools do not fully clean the system, plan for a reinstall. After cleanup, update Windows and AV, reset browsers, and change any passwords that were used on the infected machine.

Recommended Answers

All 3 Replies

Hotoffers infections have been a pretty popular topic here in the last few months. Please review the suggestions given in our recent hotoffers-related threads and see if one of those solutions works for you:

http://www.daniweb.com/techtalkforums/search.php?searchid=373139

If you cannot find a fix that works, or if you have any questions about the procedures described in those threads, please repost here. When you do, it would be a good idea to give us a HijackThis log as well:


Download HijackThis onto your jump drive:

You should be able to run HJT right from the jump drive, but if not, create a folder on the hard drive for HJT and move it there. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.

Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...". Save the log in the folder you created for HiajckThis, open the log in Windows Notepad, and cut-n-paste the entire contents of the log here. The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.

DMR, your DaniWeb link doesn't work :(

Chilkat, try this to get rid of HotOffers:

Boot into Safe Mode and do a search for these files:

param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe

Delete them, and then reboot normally

Delete all the HotOffer icons from your desktop.

Empty your Recycle Bin.

Get HijackThis as DMR suggested, and post the log as there will probably be some more cleanup to do.

DMR, your DaniWeb link doesn't work :(

Again??!!
I even made sure to test the link after I posted, because this has happened to me a few times before. I'll have to ask Dani if she can find out what makes search-result links "go stale"....

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.