hi,im new here.and my computer is beeing taken over by this hotoffers stuff.i only have spybot:S&D and dont know what to do next.i am a total idiot because dont have a clue how to remove this stuff.so, please help me before i become more crazy.PLEASE
greycat 0 Newbie Poster
Dani AI
Generated
HotOffers is a classic browser‑hijacker/adware variant that changes Internet Explorer start/search pages and spawns popups. It often installs several components so it survives simple scans and reboots; cleaning it usually means removing both registry startup hooks and the files those hooks point to. (juniper.net)
Good baseline: work offline, back up personal files to removable media (scan those backups from a different, clean machine), and use up‑to‑date removal tools you download from a clean PC. Modern adware removers such as Malwarebytes AdwCleaner are designed for exactly this class of problem and are a good next step after an offline quarantine. If a helper asked you for a diagnostic log, capture one — focus on homepage/search redirections, URLSearchHooks/BHOs, unknown auto‑start entries and services. (malwarebytes.com)
Check and restore the Windows HOSTS file if browsing still redirects; Microsoft documents the exact default HOSTS contents and how to replace a modified file safely. Also note that System Restore can contain archived copies of malware; remove or reset restore points while cleaning and then create a fresh restore point once the machine is clean. Follow the documented Microsoft steps for both tasks rather than deleting files by guesswork. (support.microsoft.com)
A few practical cautions: don’t run uninstallers or executables from suspicious pages you were redirected to, and avoid deleting random system files without confirmation (that’s why diagnostic logs are useful). If the infection resists removal, the safest long‑term fix is to copy essential data (after scanning it on a clean machine) and do a clean OS reinstall. If posting logs here, include the diagnostic scan output and a short list of running services so responders can point to specific entries to remove. (sm-u.com)
crunchie 990 Most Valuable Poster Team Colleague Featured Poster
greycat. Hi and welcome to Daniweb :).
We ask that members not tag onto the end of other members threads, especially here in the hijackthis forum. It becomes too difficult to diagnose more than 1 problem in the same thread.
==============
Download the Pocket KillBox
Unzip the file to your desktop.
Go offline until you have completed all the below.
Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. Click on the button with the red circle and an X in the middle after you enter each file (see the files below).
C:\WINDOWS\System32\param32.dll
C:\WINDOWS\System32\guninst.exe
C:\WINDOWS\System32\popup_bl.dll
C:\WINDOWS\System32\svrhost.exe
C:\WINDOWS\System32\systr.dll
Reboot afterwards if the files are successfully deleted.
If all files are not deleted, do not reboot yet. Run Pocket Killbox again and paste the full file path in the box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File will be deleted on next reboot, Process and Reboot now?" Click "Yes" to reboot only after the last file you enter.
=================
Download HijackThis selfextracting zip version from here. Once downloaded, double click on the file & it will install into it's own, permanent folder.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
Be a part of the DaniWeb community
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.