Most sites been hijacked (HOSTS file???)

G

Guest

I have IE6 and XP.SP2 installed but most of the websites (domains) I try and
access seem to be blocked and redirecting to a search page. I have ran
AdAware, MS Spyware, Norton Internet Security, SpyBot S+D but nothing seems
to be wrong (other than that I can't see my webpages)
 
J

Jan Il

Hi DATAjammer :)

You have a hijacker or other malware those programs can't detect it.
Download and install the programs below and run them to clean your machine.
Some malware can replicate itself repeatedly if not removed properly.

WARNING>>>> Backup all documents and files before removing any spyware!!

Dealing with Unwanted Spyware and Parasites:
http://mvps.org/winhelp2002/unwanted.htm
What You Should Know About Spyware
http://www.microsoft.com/athome/security/spyware/devioussoftware.mspx
What you can do about spyware and other unwanted software
http://www.microsoft.com/athome/security/spyware/spywarewhat.mspx
Most importantly, be sure to run CWShredder here
http://www.majorgeeks.com/download3019.html
Also this program searches for hidden .dlls that recreate the malware.
About Buster:
http://www.majorgeeks.com/download4289.html
Then visit these two sites to test for parasites and help basic cleaning:
On-Line Check
http://aumha.org/a/noads.htm
and
Quick-Fix Protocol.
http://aumha.org/a/quickfix.php
Basically, throw everything here at your "infection".

Also download and install HiJackThis -

How to download and install HiJackThis:
http://www.bleepingcomputer.com/forums/topict309.html
Please DO NOT post your log to this newsgroup, but to the HiJackThis Support
Forums below:
Aumha HiJackThis Forum
http://forum.aumha.org/viewforum.php?f=30
or Bleeping Computer Forum
http://www.bleepingcomputer.com/forums/forum22.html
to allow the experts there to evaluate your log and advise you of any
necessary steps to clean your system.
(Note: You will have to Register before posting on these Forums. Please
follow all posting instructions carefully to avoid having your log deleted
or ignored.

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

You should also get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also... From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)
or Winsock Fix Utility
http://www.dfwonline.net/files/WinsockFix.zip

NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again in Safe Mode to be
sure there are no lingering items on the system.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
G

Guest

Jan, thanks for the prompt reply.
Unfortunately this seems to have not had any effect :-( I couldn't access
most of the links and had to use the CD option. Even after I installed
everything and did all the scans (I think I am now doing more scans than the
CIA ;-) ) it didn't work.

I am considering just downgrading back to an older OS that is going to be
more secure for me (mother anyway)
 
J

Jan Il

Hi DATAjammer :)
Jan, thanks for the prompt reply.
Unfortunately this seems to have not had any effect :-( I couldn't access
most of the links and had to use the CD option. Even after I installed
everything and did all the scans (I think I am now doing more scans than
the
CIA ;-) ) it didn't work.

I am considering just downgrading back to an older OS that is going to be
more secure for me (mother anyway)

If you have Yahoo Companion, uninstall it, if you have any 3rd party
sofeware, such as toolbars or ad ad or popup blockers, disable them,
including the one in XP and IE, to see if that helps.

Then....

How to enable 3rd Party Extensions

Go to Tools>Internet Options>Advanced tab
Uncheck the option for "Enable third-party browser extensions"
Click Apply
Click OK
Close the browser, reopen and see if that helps.

If it does, then you do still have some kind of malware on your system, and
reverting to the older program will not remove it.

also...

There are a lot of security changes with Xp Sp2, and it may be that one of
these is preventing you from accessing these sites. You might try the
information here and see if it helps before reverting to the older program.

Make sure your Hosts file (c:\Windows\System32\Drivers\etc) does not
redirect those sites. (Open Hosts with Notepad to check.) If so, delete
that line.

Try adding one or two of the problem sites to your Host file and see if that
helps.
How to Edit HOST File:
http://www.lithiumdata.com/QandA/hosts.htm

Internet Explorer Cannot Connect to Secure Web Sites
http://www.helpwithwindows.com/WindowsXP/troub-10.html

Cannot Connect to Secure Sites
http://www.duxcw.com/faq/win/xp/secure.htm

or....

Why can't I browse certain websites
http://www.dslreports.com/faq/10082

How to troubleshoot problems accessing secure Web pages with IE6 SP2
http://support.microsoft.com/?kbid=870700

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Replies are posted only to the newsgroup for the benefit or other readers.
How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm

..
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top