i dun have the permit to upload the extension. lol
HP Pavillion DV6-6XXX series Owners Lounge V6, >9000 owners. Like a boss.
HP Pavillion DV6-6XXX series Owners Lounge V6, >9000 owners. Like a boss.
|
|
Dec 25 2012, 10:32 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
i dun have the permit to upload the extension. lol
|
|
|
|
|
|
Dec 25 2012, 10:33 PM
|
|
Elite
14,813 posts Joined: Nov 2006 |
mediafire also fine.
|
|
|
Dec 25 2012, 10:35 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
http://www.4shared.com/file/nEXfeNub/hijackthis.html?
this is the trojan This post has been edited by chahupping: Dec 25 2012, 10:44 PM Attached thumbnail(s) |
|
|
Dec 25 2012, 10:43 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
^ your HOSTS file have been tampered?
QUOTE O1 - Hosts: 199.193.118.246 www.google-analytics.com. O1 - Hosts: 199.193.118.246 ad-emea.doubleclick.net. O1 - Hosts: 199.193.118.246 www.statcounter.com. O1 - Hosts: 199.193.118.246 connect.facebook.net. O1 - Hosts: 93.115.241.27 www.google-analytics.com. O1 - Hosts: 93.115.241.27 ad-emea.doubleclick.net. O1 - Hosts: 93.115.241.27 www.statcounter.com. O1 - Hosts: 93.115.241.27 connect.facebook.net. Fix all these entries from HJT or edit your HOSTS file. |
|
|
Dec 25 2012, 10:44 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
|
|
|
Dec 25 2012, 10:49 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
rescan with HJT to check if the entries really gone and then open command prompt with admin powah and run ipconfig /flushdns
|
|
|
|
|
|
Dec 25 2012, 10:53 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
|
|
|
Dec 25 2012, 10:56 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
can you edit the HOSTS file yourself?
|
|
|
Dec 25 2012, 10:59 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
hows?
|
|
|
Dec 25 2012, 11:01 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
if ur UAC is disabled, paste this in run command
CODE notepad c:\windows\system32\drivers\etc\hosts else, go to c:\windows\system32\drivers\etc\ and open file name HOSTS with word editor like notepad. |
|
|
Dec 25 2012, 11:03 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
|
|
|
Dec 25 2012, 11:06 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
uh.. attach the file here.
|
|
|
Dec 25 2012, 11:08 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
# Copyright © 1993-2006 Microsoft
Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost ::1 localhost 199.193.118.246 www.google- analytics.com. 199.193.118.246 ad-emea.doubleclick.net. 199.193.118.246 www.statcounter.com. 199.193.118.246 connect.facebook.net. 93.115.241.27 www.google-analytics.com. 93.115.241.27 ad-emea.doubleclick.net. 93.115.241.27 www.statcounter.com. 93.115.241.27 connect.facebook.net. |
|
|
|
|
|
Dec 25 2012, 11:09 PM
|
|
Elite
14,813 posts Joined: Nov 2006 |
delete
199.193.118.246 www.google- analytics.com. 199.193.118.246 ad-emea.doubleclick.net. 199.193.118.246 www.statcounter.com. 199.193.118.246 connect.facebook.net. 93.115.241.27 www.google-analytics.com. 93.115.241.27 ad-emea.doubleclick.net. 93.115.241.27 www.statcounter.com. 93.115.241.27 connect.facebook.net. and save |
|
|
Dec 25 2012, 11:13 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
QUOTE(lee_what2004 @ Dec 26 2012, 12:09 AM) delete saved but the thing wont removed.199.193.118.246 www.google- analytics.com. 199.193.118.246 ad-emea.doubleclick.net. 199.193.118.246 www.statcounter.com. 199.193.118.246 connect.facebook.net. 93.115.241.27 www.google-analytics.com. 93.115.241.27 ad-emea.doubleclick.net. 93.115.241.27 www.statcounter.com. 93.115.241.27 connect.facebook.net. and save |
|
|
Dec 25 2012, 11:16 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
ur UAC is disabled right?
|
|
|
Dec 25 2012, 11:18 PM
|
|
Elite
14,813 posts Joined: Nov 2006 |
and check the hosts file is read-only or not.
|
|
|
Dec 25 2012, 11:24 PM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
6,612 posts Joined: Jan 2003 From: Tomorrow |
oh wait.. did you save it as HOSTS or HOSTS.txt? If the latter, remove the txt extension.
|
|
|
Dec 25 2012, 11:39 PM
|
![]() ![]()
Junior Member
137 posts Joined: May 2009 |
|
|
|
Dec 25 2012, 11:43 PM
|
|
Elite
14,813 posts Joined: Nov 2006 |
don't save as hosts.txt,
save it as hosts. Choose the type as All Files (*.*) |
| Change to: | 0.0339sec
0.96
6 queries
GZIP Disabled
Time is now: 20th December 2025 - 02:25 PM |