»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 12-12-2003, 05:59 AM   #1 (permalink)
Registered User
 
jch216's Avatar
 
Join Date: Dec 2002
Location: Atlanta Suburbs
Posts: 324
jch216 is on a distinguished road
Send a message via AIM to jch216 Send a message via Yahoo to jch216
Gaming Friend needs help... Hacked?

This is what he wrote to me:
Quote:
This is what I got when I tried to go to google...

"If you see this page your hosts file has been hacked. Please use the instruction below to clean your
machine.

You cannot reach the site you where trying to reach without following this procedure! - Please
follow the steps provided in this document and make sure to download all patches for your computer
from the Windows Update Site which can be found here:
http://windowsupdate.microsoft.com"

1. Start regedit,
find HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run ,
delete starting of svchost.exe file,
reboot your computer,
delete file svchost.exe in windows directory.

2. Reboot windows and start in
SAFE MODE (F8 key on keyboard before windows starting),
delete file winlogon.exe in directory: C:\Documents and Settings\All Users\Start Menu\Programs
Startup

3. Clear your 'hosts' file.
How to edit your hosts file: locate it first, either by browsing to the directory (as shown above)
or by hitting "Start - Search - select all files and folders - type in 'hosts' (without the
quotation marks) and hit search. When the file is found, click with your right mouse button on the
file and select 'Open With...' This will bring up a list of programs to edit the file with. Select
Notepad from that list and click OK. - Remove all lines from the file and type in: 127.0.0.1
localhost. Now close the file and save your changes.
For Windows 95/98/Millenium machines: Locate
the file hosts in your C:\Windows directory. Just delete it or edit it with a text editor like
notepad and make sure there is only one line there:
127.0.0.1 localhost
For Windows 2000 machines:
Locate the file hosts in your C:\Winnt\System32\Drivers\Etc directory. Just delete it or edit it
with a text editor like notepad and make sure there is only one line there:
127.0.0.1 localhost
For
Windows XP machines: Locate the file hosts in your C:\Windows\System32\Drivers\Etc directory. Just
delete it or edit it with a text editor like notepad and make sure there is only one line there:
127
0.0.1 localhost


Is this bogus or should he worry?

jch216 is offline   Reply With Quote
Old 12-12-2003, 06:03 AM   #2 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
The step 3 is only necessary step if your hosts file has been modified.

Don't do 1 and 2.
muno is offline   Reply With Quote
Old 12-12-2003, 06:26 AM   #3 (permalink)
Banned
 
Siliconjunkie's Avatar
 
Join Date: Feb 2003
Location: Houston, TX
Posts: 1,595
Siliconjunkie is on a distinguished road
Send a message via AIM to Siliconjunkie
Well, the going to Windowsupdate part at the top is a good idea too.
Siliconjunkie is offline   Reply With Quote
Old 12-14-2003, 12:11 AM   #4 (permalink)
Registered User
 
Join Date: Apr 2003
Location: Seattle
Posts: 732
consumertalks is on a distinguished road
This happned to me.. AdAware and SpyBot couldn't find the problem. I don't know how you can see the page if you can't see it (yeah, read that again ) but it's weird. I followed the directions and it fixed it.

Very weird. Anyone know how this actually happens?
consumertalks is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:57 AM.