PDA

View Full Version : Redirect Virus



swamp
11-05-2009, 09:27 PM
When attempting to access most web address I am redirected to another random site. I have run Spyware Doctor and it does not seem to help. Any assistance would be appreciated.

haapy
11-05-2009, 09:51 PM
Check your Hosts file. It probably has been hacked.

The only entry should be:

127.0.0.1 localhost

Edit the file with Wordpad or Notepad.

tigertheboo
11-06-2009, 02:27 AM
As usual I follow up on Haapy often out of curiousity

In vista there is a second entry that is normal for hosts something like ::1 in the second line. I have little idea what it means, just checked with my university's IT pros who answered me using language that I didn't follow but assuring me it was fine in Vista.

haapy
11-06-2009, 02:31 AM
Good call tiger.

Probably true for Windows 7 as well.

I have Vista on my test PC, but use it very little.

I may die using XP!

Thanks for the update.

:D

swamp
11-06-2009, 03:06 PM
Thanks for the help.
I found a "hosts" file in c:\windows\system32\drivers\etc that only contained the line 127.0.0.1 localhost
Is this the correct hosts file? By the way, my OS is Windows XP pro. Thanks

haapy
11-06-2009, 03:53 PM
Yes, that is the correct entry.

For the next step, I suggest that you run a HiJackThis scan and post the results here.

swamp
11-06-2009, 08:27 PM
HiJackthis will not work the Trend Micro FAQ had the following which seems to be what is happening. I renamed it to no avail.

Why does HijackThis immediately close when I try to run the utility?
Some variants of malware have been known to force HijackThis to exit as soon as you open the program. If this is happening on your PC you should try renaming HijackThis. For example change HijackThis.exe to Hijack.exe this should allow you to run HijackThis once again.

haapy
11-06-2009, 08:34 PM
Can you try HiJackThis in Safe mode?


Other than that, I am out of ideas.

AChen
11-08-2009, 10:45 PM
Could you try running the Malware Dectective tool (from SD) in safemode?
Also, do you know whether you are infected by a rogue-antispyware? Did this infection install any new icons on your desktop etc...