google trouble

U

upset

when I try to go to google I get the following message:

WHAT DO I NEED TO DO TO FIX THIS!

If you see this page your hosts file has been hacked.
Please use the instruction below to clean your machine.

You cannot reach the site you where trying to reach
without following this procedure! - Please follow the
steps provided in this document and make sure to download
all patches for your computer from the Windows Update
Site which can be found here:
http://windowsupdate.microsoft.com

1. Start regedit,
find
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Run ,
delete starting of svchost.exe file,
reboot your computer,
delete file svchost.exe in windows directory.

2. Reboot windows and start in
SAFE MODE (F8 key on keyboard before windows starting),
delete file winlogon.exe in directory: C:\Documents and
Settings\All Users\Start Menu\Programs\Startup

3. Clear your 'hosts' file.
How to edit your hosts file: locate it first, either by
browsing to the directory (as shown above) or by
hitting "Start - Search - select all files and folders -
type in 'hosts' (without the quotation marks) and hit
search. When the file is found, click with your right
mouse button on the file and select 'Open With...' This
will bring up a list of programs to edit the file with.
Select Notepad from that list and click OK. - Remove all
lines from the file and type in: 127.0.0.1 localhost. Now
close the file and save your changes.
For Windows 95/98/Millenium machines: Locate the file
hosts in your C:\Windows directory. Just delete it or
edit it with a text editor like notepad and make sure
there is only one line there:
127.0.0.1 localhost
For Windows 2000 machines: Locate the file hosts in your
C:\Winnt\System32\Drivers\Etc directory. Just delete it
or edit it with a text editor like notepad and make sure
there is only one line there:
127.0.0.1 localhost
For Windows XP machines: Locate the file hosts in your
C:\Windows\System32\Drivers\Etc directory. Just delete it
or edit it with a text editor like notepad and make sure
there is only one line there:
127.0.0.1 localhost
 
P

PA Bear

Sounds like the recent Qhosts/Qhosts-1 exploit.

1. Update your virus definitions and then run a full system scan. From now
on, do both daily.

2. Check your system for "hijackware":

Dealing with Hijackware
http://mvps.org/winhelp2002/unwanted.htm
http://www.mvps.org/inetexplorer/Darnit.htm#tshoot
http://aumha.org/a/parasite.htm

You *must* seek updates for Ad-Aware, Spybot, etc., before each and every
use, even "right out of the box". But even then, they can't catch
everything. HijackThis (http://www.merijn.org/files/hijackthis.zip; [new
URL] ) is the preferred tool to use these days. It will help to both
identify and remove any hijackware/spyware. **Post your files to
http://forums.spywareinfo.com/ for expert analysis, not here.**
--
HTH...Please post back to this thread

~Robear Dyer (aka PA Bear)
MS MVP-Windows (IE/OE), AH-VSOP

Protect Your PC
http://www.microsoft.com/security/protect/default.asp

 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top