Steve: That last part you have to type as you see it.
Click start, click on Run..., and type CMD, and hit enter.
When the Command Prompt window appears, you type each line and hit enter:
CD %systemroot%\drivers\etc
ATTRIB -R -H -S -A HOSTS
DEL HOSTS
----
The name servers (202.188.0.133 | 202.188.1.5) are OK. They resolve addresses to IPs and vice versa. You can use the command NSLOOKUP in Windows XP to access the nameserver. Each time you connect to, say, 'www.google.com', your nameserver looks it up -- here's what my output looks like from CMD:
At any rate, yeah, you wouldn't technically be able to access the internet, except by IP address, so don't remove the nameserver entries (when I give Windows custom nameservers, hijackthis says they're removable as well -- it's normal). Tarun must have been sleepy, because you shouldn't remove that
Tarun - I also doubled up on the 'safe to remove' text in your program, sorry, haha (I'm sure you can fix it now). (Domain hijack, safe to remove. Safe to remove:) Change the wording to 'Custom nameserver, not recommended to remove' or something.
Steve: That last part you have to type as you see it.
Click start, click on Run..., and type CMD, and hit enter.
When the Command Prompt window appears, you type each line and hit enter:
CD %systemroot%\drivers\etc
ATTRIB -R -H -S -A HOSTS
DEL HOSTS
----
The name servers (202.188.0.133 | 202.188.1.5) are OK. They resolve addresses to IPs and vice versa. You can use the command NSLOOKUP in Windows XP to access the nameserver. Each time you connect to, say, 'www.google.com', your nameserver looks it up -- here's what my output looks like from CMD:
At any rate, yeah, you wouldn't technically be able to access the internet, except by IP address, so don't remove the nameserver entries (when I give Windows custom nameservers, hijackthis says they're removable as well -- it's normal). Tarun must have been sleepy, because you shouldn't remove that
Tarun - I also doubled up on the 'safe to remove' text in your program, sorry, haha (I'm sure you can fix it now). (Domain hijack, safe to remove. Safe to remove:) Change the wording to 'Custom nameserver, not recommended to remove' or something.
That might be why you can't open any website thereafter.
He already posted his hijackthis log remember, no domain hijacks were there, i wouldn't of suggested it otherwise , anyway, he already PM'ed me with his results from LSPfix.
Merijn it's also O17 - Lop.com domain hijacks
Not always to do with Lop.com malware, can be, but also some ISP's and computer manufacturers use it for reseting web settings to thier defaults rather then IE's.
^^ This one usually comes back, unless you do what Tarun said, which is "using the GUI", which actually means to use the appropriate interface for disabling MSNM startup, which is:
With MSNM running, go to Tools, Options, Preferences (or in MSN 7, "General"), and uncheck "Automatically run messenger when I log on to Windows"
Done as told.
You should simply delete your hosts file and start it over.
1) Start, Run... CMD
2) CD %systemroot%\drivers\etc
2) ATTRIB -R -H -S -A HOSTS
3) DEL HOSTS
Then run spybot s&d, go to advanced mode, then Tools, then checkmark Hosts file, then click the button to "add spybot s&d's hosts file"
Click on the button richt (above) Make Host writeble
Click after that on the button Restore Original Host
Your problem is over now.
=====
If you have WinPatrol, that programm wil see the changing. Klik Yes en you can read an example of wath Microfoft has done. That message is not importent. Close it and run Spybot for dure again. I can tell you, that yout problem is over.
What I can with my age of 64 years, you can also. I left the High school for a long ago, so time I had sure make mistakes with my English, but I'm sure you understand my message.
You only really want to disable it if you have no programs that are dependant on it. Some may "report" to be, but don't really need it. You can do so under the Administrative Tools in Control Panel.
Your problem is easy. I had this problem too. Do the folowing things. I've my knowledge from reading forum sites.
Click on the button richt (above) Make Host writeble
Click after that on the button Restore Original Host
Your problem is over now.
=====
If you have WinPatrol, that programm wil see the changing. Klik Yes en you can read an example of wath Microfoft has done. That message is not importent. Close it and run Spybot for dure again. I can tell you, that yout problem is over.
What I can with my age of 64 years, you can also. I left the High school for a long ago, so time I had sure make mistakes with my English, but I'm sure you understand my message.