Link to home
Start Free TrialLog in
Avatar of wicker-gk
wicker-gk

asked on

If you see this page your hosts file has been hacked? <- authentic?

Recently i attempted to open Google but recieved this instead:

If you see this page your hosts file has been hacked. Please use the instruction below to clean your machine.

You cannot reach the site you where trying to reach without following this procedure! - Please follow the steps provided in this document and make sure to download all patches for your computer from the Windows Update Site which can be found here:
http://windowsupdate.microsoft.com 

1. Start regedit,
find HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ,
delete starting of svchost.exe file,
reboot your computer,
delete file svchost.exe in windows directory.

2. Reboot windows and start in
SAFE MODE (F8 key on keyboard before windows starting),
delete file winlogon.exe in directory: C:\Documents and Settings\All Users\Start Menu\Programs\Startup

3. Clear your 'hosts' file.
How to edit your hosts file: locate it first, either by browsing to the directory (as shown above) or by hitting "Start - Search - select all files and folders - type in 'hosts' (without the quotation marks) and hit search. When the file is found, click with your right mouse button on the file and select 'Open With...' This will bring up a list of programs to edit the file with. Select Notepad from that list and click OK. - Remove all lines from the file and type in: 127.0.0.1 localhost. Now close the file and save your changes.
For Windows 95/98/Millenium machines: Locate the file hosts in your C:\Windows directory. Just delete it or edit it with a text editor like notepad and make sure there is only one line there:
127.0.0.1 localhost
For Windows 2000 machines: Locate the file hosts in your C:\Winnt\System32\Drivers\Etc directory. Just delete it or edit it with a text editor like notepad and make sure there is only one line there:
127.0.0.1 localhost
For Windows XP machines: Locate the file hosts in your C:\Windows\System32\Drivers\Etc directory. Just delete it or edit it with a text editor like notepad and make sure there is only one line there:
127.0.0.1 localhost

I have Nortons firewall/anti virus constantly up. No virus was found in a scan, and google wont open, basically is this real and i should do it, or is it an attempt to damage my system?
Avatar of war1
war1
Flag of United States of America image

Greetings, wicker-gk!
>> I have Nortons firewall/anti virus constantly up. No virus was found in a
>> scan, and google wont open, basically is this real and i should do it, or is
>> it an attempt to damage my system?

Yes, ignor the message. Don't do the registry edits. If you are concern about your HOSTS file, do a search for it (it is a hidden file) and open it up with a text editor.

Best wishes, war1
Avatar of wicker-gk
wicker-gk

ASKER

Great thanks, but what about Google? I cant use it? shall i just use other search engines?
ASKER CERTIFIED SOLUTION
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
If your win 9x or ME youll need to reboot :0)

PL
Google is the best search engine around.  So use it.
My point was i cant get to Google because of this warning

and so now i dont ignore it, i delete that one line?
Ne delete everything below that line, if theres nothing there, then your host file is fine, what OS are you using??

PL
Ne = No
>> My point was i cant get to Google because of this warning

If there is nothing in HOSTS file, then, yes, ignor the message. If the message is preventing from getting to Google, use another search engine.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
wicker-gk,
   We have not heard from you in awhile? Did any comment help you solve your problem? Do you have any more questions? If an Expert help you, please accept his/her answer with an excellent or good grade.

Thanks, war1
First of all I wouldn't think that site or page that loaded was real, I would load spybot search and destroy (FREE) or there are others too, and tell it to lock your hosts file.

I would also do a reboot to be safe, but NEVER NEVER do any reg editing from a webpages instructions. The only thing your hosts file would do if it dosn't work is not load certain pages or allow you to browse. MS would never give the average user an error that instructed them to edit the registry !!

I would also scan your machine for trojans
Hello, i also have this problem, and i delete addresses in hosts, but whenever i reboot my system, the hosts file is filled up again with sites and warez things.
jorjelu,
   You may want to ask what you want in a new question.
Ok, the idea is that i had my host file hacked too. I deleted everything under localhost. After i reboot i realize that the host file is filled up again. Does this have anything in common with some malicious registry? How can i protect my hosts file from being hacked? Thank yuo very much.
look for winlogon - i found a site (using google ;~}) that has all the text you mentioned - the root of the domain however had some small script files that ran together, and part of the script includes

C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\winlogon.exe

i'd look for that and lose it...
I cannot delete it...... :( Protected or in use. I cannot close the process even. What do i have to do with winlogon?
excellent - well - i mean - err.... that means tht we can delete it before the users log on....

open notepad

c:\windows\system32\attrib.exe -r -a -s -h c:\docume~1\alluse~1\startm~1\programs\startup\winlogon.exe >>c:\dellog.txt
del c:\docume~1\alluse~1\startm~1\programs\startup\winlogon.exe >>c:\dellog.txt

the line starting c:\...  ends with ....dellog.txt - it wraps in my window...
 if your windows dir is different, use that instead of windows!!


save that as c:\dellog.cmd  (save as, save as type : all files, encoding ANSI )

exit

download and install firedaemon
http://www.firedaemon.com/

then..
run it,
service,
new

program tab:
 short name           : killog
 display name         : killog
 working directory    :c:\
 executable             : c:\dellog.cmd

settings tab:
 upon program exit : shutdown firedaemon


click install
click OK
click cancel (you don't want to make a second)

reboot... how's that... check c:\ - open c:\dellog.txt and post it here... then uninstall firedaemon...
Hello this question has been open a while please take the time to come back and clean it up.

Closing Questions
https://www.experts-exchange.com/help.jsp#hs5


Best Wishes

Pete
www.petenetlive.com
In my opinion a split of points between experts should occur as a suitable response to the authors problem has been made.

Hypoviax