Announcement

Collapse
No announcement yet.

delete hosts file

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • delete hosts file

    helo everyone.

    I encounter this problem for the first time.
    On a fully updated winxppro after fully updated ad aware 6 pro & spybot 1.3 scans, whenever I go to the web the home page is being hijacked to : res://xobxu.dll/index.htm/#37049
    Also my hosts file is being deleting.
    the processes that are responsible for this is changing its names after every time im killing them.
    ad aware recognize it as coolwebsearch entries.
    Any suggestions before format and new clean install ?
    crocus

  • #2
    run adware again

    of change the homepage first to something else... and rerun ad-aware
    Marcel
    Technical Consultant
    Netherlands
    http://www.phetios.com
    http://blog.nessus.nl

    MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
    "No matter how secure, there is always the human factor."

    "Enjoy life today, tomorrow may never come."
    "If you're going through hell, keep going. ~Winston Churchill"

    Comment


    • #3
      If AdAware / Spybot can't resolve this, use google search for cwshredder and "hijack this" run those.
      Andrew

      ** Remember to give credit where credit is due and leave reputation points sigpic where appropriate **

      Comment


      • #4
        nothing, nothing help. it keeps coming back and hijacked.
        seems that the only way through is a new clean install
        crocus

        Comment


        • #5
          how to solve

          Since last time that finished in clean new install I encounter this problem
          On more and more computers. To solve this hijacking problem im doing the following:
          1 - spybot 1.3
          2 - adaware 6 pro
          3 - hijack this 1.98
          4 - AboutBuster 1.25
          kill all suspected running processes and write down their names.
          Uncheck them on startup (msconfig)
          Boot to safe mode.
          Going through 1-4 in safe mode
          5 - run hoster 1.4
          6 - antivirus full scan.
          7 - delete all suspected processes entries from system32 folder.
          Boot to normal mode
          Done!
          Next time do not surf to sex web sites
          crocus

          Comment

          Working...
          X