Re: browser redirect prob



"BoyPete" <petcrow@xxxxxxxxxxx> wrote in message
news:3l6bs5F119pktU1@xxxxxxxxxxxxxxxxx
> Boo wrote:
>> In news:3l5v0lF10iv3oU1@xxxxxxxxxxxxxx,
>> BoyPete whispered softly in my ear...:
>>
>>> Sometimes........clicking on a link takes me to this blank page
>>> http://69.50.190.131/?to=dname&from=in
>>> Typing in the IP takes me here
>>> http://www.megatds.com/empty.html
>>> also blank. Removing stuff after the slash takes me here
>>> http://www.megatds.com/

Oh, oh!...
:-(

Bad news.
Sounds like your Browser/Operating System has been Hijacked!
:-(

>>> which is a traffic redirecting company. I've run all the usual
>>> virus/spyware stuff to no avail. I've searched my drives for files
>>> with megatds in.....nowt. This happens no matter which browser I
>>> use.
>>> Any ideas?? :)

Try doing do a Google Search for that IP Address (in Quotes, so as
to find Web Pages that include that IP Address - Pages with other people
who have the same (or similar) probs.

& do a HiJackThis Log & look at it to see what's been Hijacked.

Post it up & we can have a look through it & give some Hints, Tips
& suggestions on how to get it sorted.

>> Can you give us a for instance of the link you clicked? Maybe the
>> problem lies on that page/pages rather than on your pc. Did you
>> search
>> for files with that IP addy in?, maybe the name has not been resolved
>> in the problem file ( if there is one). Put that IP addy in your
>> hosts
>> file.

Sounds like his Hosts File has been Hijacked?
That IP Address may *already* be in his Hosts File, associated with
other Sites?

>> ooh , Boo had a few thoughts, and it aint even 10 o clock yet!
>
> The sixtysurfers site is one.
> http://www.sixtyplusurfers.co.uk/index.html
> Yikes! Just tried it again, and it took me to a porn site!
> I can't find a hosts folder.......Looked where I thought it should
> be.windows/system32/drivers/etc. Not there.
> Searched for the IP, no luck either. :(

Where (& what) did you "Search"?

You should have a Hosts *File* (not Folder in that "etc" Folder.
*Un*less, it's been Hijacked - something may have moved it.

WinXP uses a Registry Entry to find the Hosts File to use,

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters

The Value in that Key is called "DatabasePath"

Check to see that it's correct - it should say the Full Path to the
File, which by Default is:

%SystemRoot%\System32\drivers\etc

Another possibility is that the DNS Server (Name Servers) in your TCP/IP
Properties may have been changed, to point to the dodgy site (or one of
their Affiliates), so they can then serve up the IP Address of the Site
that they want you to visit.

You should check to see what Name Servers have been Assigned to the
Connection.

HTH

--
pmj


.



Relevant Pages

  • Re: IEHOST MESSAGE
    ... some sort of .dll error when I start up - but it still lets me startup ... I tried the hijack this instructions but I couldn't get to the spyware site. ... Look at the HijackThis at the ... > attributes and renames the HOSTS file incorrectly to hosts. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Hosts file/NAV cannot repair
    ... > attempted to edit the hosts file, ... and Windows XP would add a new hosts file. ... Before you remove malware, get LSPFix (or WinSockFix for XP which you ... scan with HijackThis. ...
    (microsoft.public.security)
  • Re: very slow WIN XP Pro and other issues
    ... >> Install, but do not run it yet, it will be needed later. ... Your hosts file is probably hijacked also. ... you'll get a Windows dialog box saying ... See below for HijackThis links. ...
    (microsoft.public.windowsxp.general)
  • Re: i suspect HijackThis virus in my pc-XIEPo$TER. What should i do??
    ... Let AD-Aware Scan your system for advertising Spyware ... If you use a HOSTS file, ... Scan and save the log file. ... then copy/paste your HijackThis .log file in your message. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Disappearing HOSTS file XP Pro SP2
    ... machines to access test servers that don't have 'public' DNS names ... and for virtual servers on the local loop so we don't have to ... whoa - ti was resolving to the public DNS entry. ... HOSTS file is one of those protected? ...
    (microsoft.public.windowsxp.network_web)