Try this to get rid of HotOffers:

Get the Pocket Killbox from here:
http://bleepingcomputer.com/files/spyware/KillBox.zip

Unzip the file to your desktop.

Go offline until this is completed (you may wish to print these instructions).

Boot into Safe Mode and do a search for these files and delete any instances found:

param32.dll
guninst.exe
popup_bl.dll
systr.dll
svrhost.exe

If any could not be deleted, (most likely param32.dll), run Pocket Killbox and paste the full file path of file in the box and click on Delete on Reboot. Click on the button with the red circle and an X in the middle; you will get a message saying File will be deleted on next reboot, Process and Reboot now?, Click Yes to reboot. (Note: the 'file path' will be something like C:\WINDOWS\System32\param32.dll)

scan with hijackthis, and have it fix:

R0 (or R1) - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

Reboot normally and delete any unwanted icons from your desktop.

Empty your Recycle Bin.

Ok..I did all this...why am I still having problems...IT JUST WON"T LEAVE ME ALONE!!! :mad: :cry:

Dani AI

Generated

Persistent adware like HotOffers often uses several persistence mechanisms at once (startup entries, browser helpers, background services, scheduled tasks and even System Restore points). Because one deleted file or homepage change can be reinstalled by another component, a staged, multi-tool approach works best. has already tried initial removals and is asking for the HijackThis log; add the diagnostics below before or while you post that log.

Run an up-to-date on-demand scanner first (it removes many active components). Malwarebytes is a good first pass: Malwarebytes. For a different signature set and an offline option consider the Microsoft Safety Scanner: Microsoft Safety Scanner. Use Sysinternals tools to inspect persistence manually: Autoruns shows everything that runs at startup, and Process Explorer helps identify which process loaded a suspicious DLL or is spawning popups.

Practical cautions: back up important files first. Do not delete unknown system files or registry keys blindly. System Restore can reintroduce malware — after cleaning, delete old restore points and then re-enable restore. Check browser add-ons/toolbars, proxy settings and the Hosts file for redirects. Avoid running multiple real-time AV products at once.

If the problem persists, post the full HijackThis scan as requested and include an Autoruns export (File -> Save), Windows version, browser and a short list of recently installed programs. Redact personal data (passwords, account tokens) before posting. If the PC runs an unsupported OS or the infection resists all reasonable removal attempts, consider using a trusted rescue disk or a clean OS reinstall after backing up data.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.