Ask Experts Questions for FREE Help !
Ask
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #1

    Mar 24, 2011, 05:45 AM
    C:\windows\system32\drivers\etc\hosts virus
    I went to a site and I think it was a java drive-by
    Now NOD32 is constantly giving a warning that there is a Qhost virus in the hosts file
    Only thing is, I don't know how to delete the virus

    I opened the hosts in notepad and found this:

    127.0.0.1 www.virustotal.com
    127.0.0.1 virustotal.com
    127.0.0.1 novirusthanks.org
    127.0.0.1 vscan.novirusthanks.org
    127.0.0.1 virusscan.jotti.org
    127.0.0.1 www.virusscan.jotti.org
    127.0.0.1 virscan.org
    127.0.0.1 www.virscan.org
    127.0.0.1 virus-trap.org
    127.0.0.1 www.virus-trap.org
    127.0.0.1 filterbit.com
    127.0.0.1 www.filterbit.com
    127.0.0.1 viruschief.com
    127.0.0.1 www.viruschief.com
    127.0.0.1 kaspersky.com
    127.0.0.1 www.kaspersky.com


    That's everything that's in hosts

    Someone knows the real hosts?

    Thanks
    NeedKarma's Avatar
    NeedKarma Posts: 10,635, Reputation: 1706
    Uber Member
     
    #2

    Mar 24, 2011, 06:01 AM
    Those entries are preventing any browser on that machine from accessing those sites. You can delete them all if you can. Try using the free version of this product to scan and disinfect your machine: Malwarebytes
    Try it in Safe Mode for best results.
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #3

    Mar 24, 2011, 07:10 AM

    You must spread some Reputation around before giving it to NeedKarma again.
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #4

    Mar 24, 2011, 08:02 AM

    What does your host file look like? Please include the whole text not just the blocked sites.

    The following is what mine looks like:
    # Copyright (c) 1993-1999 Microsoft Corp.
    #
    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
    #
    # This file contains the mappings of IP addresses to host names. Each
    # entry should be kept on an individual line. The IP address should
    # be placed in the first column followed by the corresponding host name.
    # The IP address and the host name should be separated by at least one
    # space.
    #
    # Additionally, comments (such as these) may be inserted on individual
    # lines or following the machine name denoted by a '#' symbol.
    #
    # For example:
    #
    # 102.54.94.97 rhino.acme.com # source server
    # 38.25.63.10 x.acme.com # x client host

    127.0.0.1 localhost
    127.0.0.1 www.facebook.com
    127.0.0.1 facebook.com
    127.0.0.1 login.facebook.com

    As you can see I am blocking Facebook. Before your PC accesses any DNS cache or DNS Server it inspects this file. Blocking what is listed.

    Can you delete all entries so the only thing listed is 127.0.0.1 localhost?
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #5

    Mar 24, 2011, 08:16 AM
    The list of blocked sites is all what´s in hosts
    Nothing else there
    NeedKarma's Avatar
    NeedKarma Posts: 10,635, Reputation: 1706
    Uber Member
     
    #6

    Mar 24, 2011, 08:17 AM
    Well to me it's a symptom of an infection. I would do a good deep scanning.
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #7

    Mar 24, 2011, 08:19 AM
    All right,I´m doing a deep scan on my PC now
    Also have changed the hosts file from the list of blocked sites to: 127.0.0.1 localhost

    So all that's in hosts now is 127.0.0.1 localhost
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #8

    Mar 24, 2011, 10:12 AM

    1. Are you scanning in safe-mode?
    2. Is your AV up-to-date?

    After deleting all but localhost, are you still receiving the message?
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #9

    Mar 24, 2011, 10:37 AM
    I have deleted all but localhost
    And haven't got the message yet
    I think it's gone now

    Thanks for the help guys!
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #10

    Mar 24, 2011, 01:15 PM

    What still concerns me is that you didn't put those entries in that host file, which means someone or something did. Am I correct?
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #11

    Mar 24, 2011, 01:17 PM
    Yes I think you're right and I think I also know how I got this virus in my PC
    I went to a site not going to tell the site here for safety of you
    Guess it was a java drive-by
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #12

    Mar 24, 2011, 07:02 PM

    Safety of me huh?

    Either way, did the scan in safe mode with the most up-to-date AV retrieve anything?
    jawbone's Avatar
    jawbone Posts: 7, Reputation: 1
    New Member
     
    #13

    Mar 25, 2011, 03:02 AM
    No I meant the safety of everyone here

    And yes I did a new virus scan, nothing found
    So I think the virus is gone now
    Got another problem now though
    When I start my PC it doesn't start explorer.exe
    After logging into my account all I see is a black screen
    But if I open explorer.exe in task manager it works
    ITstudent2006's Avatar
    ITstudent2006 Posts: 2,243, Reputation: 329
    Networking Expert
     
    #14

    Mar 25, 2011, 08:21 AM
    System Restore?
    Reinstall?
    premdas's Avatar
    premdas Posts: 1, Reputation: 1
    New Member
     
    #15

    Mar 6, 2012, 09:32 AM
    127.0.0.1 www.internetdownloadmanager.com

Not your question? Ask your question View similar questions

 

Question Tools Search this Question
Search this Question:

Advanced Search

Add your answer here.


Check out some similar questions!

I have a virus in C:\WINDOWS\System32\drivers\etc\hosts [ 3 Answers ]

I have a virus in C:\WINDOWS\System32\drivers\etc\hosts I have tried everything!! I have used Spybot, Maleware-bytes, Spyware Doctor, Ad-aware, and a couple others. All of them say that there is a virus, however only spybot said it couldn't be removed, access denied. I tried going into the host...

Virus in Hosts File inside Windows System32 folder [ 25 Answers ]

I have a virus in C:\\WINDOWS\system32\drivers\etc\hosts I'm using AVG free edition. I've put the file in the virus vault, it says it's possible to heal the file except that there isn't enough info to do so. Any ideas of what I should do?

C:\windows\system32\drivers\etc\hosts virus [ 4 Answers ]

Last night got a virus, I don't know how.. might have been in a torrent or something. But yeah my avg is going crazy the resident shield is popping up every few minutes C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS virus Although when I click heal or move to vault nothing happens Done a bit of...


View more questions Search