Browser Hijacking
Viruses got you down? Spyware making your system sluggish? Post here for support on all your security needs.

Moderators: Forum Experts, Management

Browser Hijacking

Postby augie on Thu Sep 25, 2003 7:53 pm

If you are having trouble accessing search engines like google, yahoo or altavista, you may have been hijacked. This particular and latest one uses the hosts file to redirect all traffic from these major search engines to the following IP: 64.191.95.139

Do a search for 'hosts' no extension and open it in Notepad (If you use a hosts file and want to remove the offending entries manually). Remove all the lines that contain this IP address (see example below)

64.191.95.139 www.google.com


QUOTE
Where is the hosts file located ?

Windows 95/98/Me c:\windows\hosts

Windows NT/2000/XP Pro c:\winnt\system32\drivers\etc\hosts

Windows XP Home c:\windows\system32\drivers\etc\hosts

(you may need administrator access for Windows NT/2000/XP)

NOTE: Hosts is the name of the hosts file and not another directory name. It does not have an extension (extensions are the .exe, .txt, .doc, etc. endings to filenames) and so appears to be another directory in the example above.



If you do not use a hosts file, you can just delete the whole file using explorer as you would delete any other file.

Or you can get Hijack This and remove all of the lines that contain, again, this same IP as in this example:

O1 - Hosts: 64.191.95.139 www.google.com



More from Spyware info
User avatar
augie
Community Director
 
Posts: 13631
Joined: Sun Aug 25, 2002 8:55 pm
Location: Laurentians, Quebec

Postby kanaloa on Thu Sep 25, 2003 8:19 pm

Does AdWare not get rid of these?

I've had this happen and usually it was a spybot that Adware could remove.
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 25292
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby augie on Thu Sep 25, 2003 8:24 pm

This was just discovered by the Spybot people as we speak Well some 8 hrs. ago. Galadriel's post.
User avatar
augie
Community Director
 
Posts: 13631
Joined: Sun Aug 25, 2002 8:55 pm
Location: Laurentians, Quebec

Postby augie on Thu Sep 25, 2003 8:33 pm

User avatar
augie
Community Director
 
Posts: 13631
Joined: Sun Aug 25, 2002 8:55 pm
Location: Laurentians, Quebec

Postby Xstream on Thu Sep 25, 2003 9:13 pm

I use winpatrol http://www.winpatrol.com

"Detect, Disable Un-Wanted Programs, Cookies & Tasks.
Safely monitors changes to your system without
slowing down other applications and more!"

and its free!
User avatar
Xstream
PROfessional Member
 
Posts: 7573
Joined: Thu Mar 14, 2002 9:30 pm
Location: USA

Postby augie on Thu Sep 25, 2003 9:23 pm

Thanks Don, will try it out. It's all the unwashed that bother me.
User avatar
augie
Community Director
 
Posts: 13631
Joined: Sun Aug 25, 2002 8:55 pm
Location: Laurentians, Quebec

Postby kanaloa on Thu Sep 25, 2003 9:48 pm

Don?
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 25292
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Postby SCgone on Thu Sep 25, 2003 10:15 pm

Don?
SCgone
PRO ELITE
PRO ELITE
 
Posts: 12847
Joined: Thu Mar 14, 2002 6:59 pm
Location: South Carolina, USA

Postby augie on Thu Sep 25, 2003 10:46 pm

Corlione no? Didja watch the movie? :whistle
User avatar
augie
Community Director
 
Posts: 13631
Joined: Sun Aug 25, 2002 8:55 pm
Location: Laurentians, Quebec

Postby kanaloa on Thu Sep 25, 2003 10:52 pm

Guueeesss not, lol.
Image

Follow me on Twitter: http://twitter.com/JCDerrick
User avatar
kanaloa
President
 
Posts: 25292
Joined: Sat Mar 09, 2002 8:18 pm
Location: Columbia, SC
Real Name: John Derrick

Next

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 1 guest