I've (well, not me, but merijin)..discovered one major SERIOUS flaw in using the HOSTS file in windows to block popups/adware, as referenced in the doxdesk links
It involves an activex control that's been d/l and runs on the local pc as it's own web-server..
Read this article
this is a clip ot text taken from that article
-------------------------snip---------------------------
More current variants also install a small web server, contained in a file named svchost32.exe. It adds several google addresses (google.de, google.ch, google.ca, etc) search.yahoo.com, and search.msn.com to the HOSTS file, telling windows that the IP addresses for those sites is 127.0.0.1, and that's where it's webserver is listening.
---------------------------------------------------------
Just wanted to update everyone, if they were unaware....
TT4U
Notification:
These are just "my" thoughts....and should be carefully measured against other opinions. Backup All Important Data/Docs..All involved shall be spared the grief.
Thanks for the update, tho his instructions on using the host file must be somewhere else on the site, as they were not included in those articles. Following those instructions, running CWshredder, and rechecking Hijack This should cleanup the trojan. I don't believe it would be nessecary to even open the hosts file.
You're correct....I don't even run a HOSTS file.
I had read the doxdesk thing and decided to try it (I don't have a popup issue, but i thought i'd give it a go, as one particular site achieves a bothersome pop-under on me.......and i thought maybe the pages elsewhere would load faster, as described in how it would work.)
I'm a minimalist as far as software running on the box.
I have all my cache cleaned after each session.
Anyway, as far as disabling activex and java and overall
security settings, it's a decent place to direct people.
TT4U
Notification:
These are just "my" thoughts....and should be carefully measured against other opinions. Backup All Important Data/Docs..All involved shall be spared the grief.
Carr,
I would like to post my log from hijack this and have someone check it out. I was being hijacked by a site called best web search. I have made the log and saved it, how do I post it for you to see. I'm new at this site.
Here is my log, I figured you just paste it.
Logfile of HijackThis v1.97.7
Scan saved at 11:39:45 AM, on 2/4/2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
O4 - HKLM\..\Run: [stcloader] C:\WINNT\System32\stcloader.exe
O4 - HKLM\..\Run: [Winhost] C:\WINNT\winh.exe (this one is a virus malware known as LOLAWEB_A, see here:
Carr,
Thanks, and sorry about the 95/98 thread. This was my first post to teck tips. I am running the scan and it has found so far a Trojan.startpage virus that it is saying non-cleanable. I am hoping the scan program will tell me what to do about it.
Thanks again for your help!
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.