Hijacked hosts file.

Discussion in 'Malware Help (A Specialist Will Reply)' started by 54|2k, Aug 7, 2010.

  1. 54|2k

    54|2k Private E-2

    Sigh, I'm growing so tired of this. Every time I surf the internet, it stalls a webpage an redirects me to result5.google.com with "webpage not available" error, most of the time the explanation is "DNS not resolved".

    It first started when I reformatted and as vulnerable as it is with no AV, I accidentally got infected by those fake AV's. I managed to delete every tiny byte of the malware except for the hijacked HOSTS file, I resorted to the reformat option.

    Things I tried before reformatting:
    • Resettings HOSTS file.
    • Running MBAM.
    Unfortunately, I wasn't so smart and didn't think of visiting this website of which I have known for quite some time.

    Errors I've gotten when attempting the above:
    I couldn't reset the HOSTS file as it's if the directory doesn't exist, I countered it by creating a new HOSTS file, since it was hiding itself from "../drivers/etc", but the problem occurred every few websites. I managed to read some entries of the hijacked HOSTS file before I attempted to counter it by creating a new one by entering "...drivers/etc/HOSTS" in the address bar. Most of them were simply redirecting google to ad filled websites. I have no clue how it redirects other websites not listed in the HOSTS file tough.

    ANYWAYS, now that I reformatted, I was so relieved! *Types google.ca* , "Webpage not available" OH DEAR GOD! I have no clue if it's even possible, I clearly reformated using the "full reformat" when reformatting using the windows xp disc. Oh well, you MajorGeek's specialists are the only ones who are capable of helping me.

    Just so you know, my hosts file is clean, no different entries and I can't access the hijacked one by entering ".../drivers/etc/HOSTS" in the address bar. I have also tried everything I found in the search results concerning this problem. As it might seem it isn't the HOSTS file that's infected, my computer is behaving the SAME way as it was when it had the hijacked hosts file.
     

    Attached Files:

  2. 54|2k

    54|2k Private E-2

    TDSSkiller log and RRlog, maximum of 4 file to upload :/
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs.

    Now:
    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    Now attach your hosts file so I can see it.
     
  4. 54|2k

    54|2k Private E-2

    As I said, I tried all the solution mentioned in the search results concerning this problem and that solution is one of many that didn't work.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are fixing the wrong things. The problem is not with your hosts file which you just attached and is a normal default host file. The problem is likely that your router hardware has become infected due to DNS poisoning.

    If you have a router hooked up then you need to follow the instructions for your hardware and reset it to factory default settings. Normally there is a recessed push button type switch that needs to be held down for some number of seconds to do this. After resetting to factory defaults on your router, you will need to reconfigure the router for your network if you have made any changes to the default network setup.
     
  6. 54|2k

    54|2k Private E-2

    That would be possible except that my dad's computer is hooked to the same router as mine is and he doesn't have this problem. I'll still try that, just need to find my router's manual online... Somewhere...
    Is it possible resetting it, but not "physically", something in it's settings ("192.168.0.1")?

    Edit
    How lucky! There was a button exactly for that purpose, now that I reseted to factory settings, I'll see if the problem still occurs and and report back if not, I'll go for the "final steps" of which you people repeat so many times!

    Edit

    Zzz, nope.. The problem doesn't leave.
    Just made a quick google search for "malwa", I clicked for one of the results and it redirected me here:
    http://results5.google.ca/click.php...group.com/&ref=http://www.google.ca/search?hl
    I also forgot to mention that sometimes it changes a random page to all blank and I have to refresh several times for the content to appear.
     
    Last edited: Aug 8, 2010
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's collect some additional info since it only happens on your PC.
    • What browser are you using when it happens? Is it Chrome. Try 2 other browsers like both IE and FireFox to see if it is browser related!!!!
    • Check to see if it also happens when you boot in safe mode. (Again with more than one browser and make sure you always test IE)
    • In msg # 4 you attached a hosts file. Is that exactly what you see in your hosts file? If so, then it is not your problem as that is the default.
     
    Last edited: Aug 8, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds