Red X's

How about browser hijacker ? :wink: I’ve seen that before… that’s why I wanted him to post contains of that hosts file… to see what’s inside…

S.Z.C.
I did a search for Hosts and came up with about 7 hits.

But how do I paste into the forum?

When I highlighted the hits, only the names showed, not where the hits were located on the C drive. I did go ahead and perfomed the copy command. I came to this site and tried to paste it in a post reply, but paste would not stand out in bold when I right-clicked.

I am a knowledgeable user of the computer, but this one little action has me completely stumped. :-\

You need the one called hosts (no extension) and it is likely in \windows\system32\drivers\etc\

That’s the one I deleted.

Guess we are now both on the same page as far as this problem is concerned.

Thank you very much for your help+

  1. From So. Calif.

Ye3ah Gert2. Eddy told you exactly where that fiel is located if you use Windows XP. If you use any previous version it should be in Windows / System directory.

Find that file, and OPEN it in some text editor (NOTEPAD for example) . Then, when you see contents of that file, just mark everything (CTRL+A) and copy everything into clipboard (by pressing CTRL+C).

After that, make a new reply in this thread and paste everything (CTRL+V)

Let us know if you have problems…

Cheers !

Well mark (copy/paste) everything there that doesn’t start with REM since those lines are just remarks and have nothing to do with the system and will not change any behaviour :wink:

And what about my question? (Who changed it in the first place) Someone or something has changed it, since it is not just changing by itself.

S.Z.C. How did you get the search window into your post?

Eddy, I don’t have a clue. I do have on my desktop this file:

copyright (c) 1993-1999 microsoft corp.

this is a sample hosts file used by microsoft tcp/ip for windows.

this file contains the mappings of ip addresses to host names. each

entry should be kept on an individual line. the ip address should

be placed in the first column followed by the corresponding host name.

the ip address and the host name should be separated by at least one

space.

additionally, comments (such as these) may be inserted on individual

lines or following the machine name denoted by a ā€˜#’ symbol.

for example:

102.54.94.97 rhino.acme.com # source server

38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
127.0.0.1 www.doubleclick.net
127.0.0.1 ad.preferances.com
127.0.0.1 ad.doubleclick.com
127.0.0.1 ads.web.aol.com
127.0.0.1 ad.doubleclick.net
127.0.0.1 ad.preferences.com
127.0.0.1 ad.washingtonpost.com
127.0.0.1 adpick.switchboard.com
127.0.0.1 ads.doubleclick.com
127.0.0.1 ads.infospace.com
127.0.0.1 ads.msn.com
127.0.0.1 ads.swit

and the list goes on and on for several pages. Where I got this, I don’t know.

I cannot copy/paste from Search!

What do you mean by SEARCH WINDOW ? I just posted screenshot of the search window results, when it found what I asked for.

Also I see you have doubleclick.net inside your hosts file. Nast adware I would say…

Read about it here (Just read few first top lines and everything will be much clearer to you):

http://sam.zoy.org/writings/internet/doubleclick.html

Among the other things, it says this:

Advertising networks like doubleclick.net are evil. They are spammers, they track private information, and they are a spectacular waste of bandwidth

Cheers !

EDIT: My advice, erase everything inside hosts file except first line where it says 127.0.0.1 localhost

The search window to me is:

Start - Search

I know where I got the hosts now. I downloaded Avast and the program wanted to change my IP address. I did it initially. When I started having some problems with my email, I deleted it and went back to my Spam Blocker and 86It.

Listen and slow down a little bit, Gert2… no need to hurry…

Of course avast! tried to change something in order to be able to check your incomming and outgoing e-mails… otherwise there is no point in having antivirus e-mail protection… right ?

Second thing… HOSTS file is nothing bad. You should have hosts file in above mentioned directory, but all those nasty things inside your hosts file, shouldn’t be there… when I say nasty things, I mean on these you mentioned before:

127.0.0.1 www.doubleclick.net
127.0.0.1 ad.preferances.com
127.0.0.1 ad.doubleclick.com
127.0.0.1 ads.web.aol.com
127.0.0.1 ad.doubleclick.net
127.0.0.1 ad.preferences.com
127.0.0.1 ad.washingtonpost.com
127.0.0.1 adpick.switchboard.com
127.0.0.1 ads.doubleclick.com
127.0.0.1 ads.infospace.com
127.0.0.1 ads.msn.com
127.0.0.1 ads.swit

As I said before, you should have 127.0.0.1 localhost only inside your HOSTS file.

You shouldn’t erase hosts file, just those keys mentioned above…

And btw, I know what you meant by SEARCH window, but I still don’t understand what you meant by this:

S.Z.C. How did you get the search window into your post?

Where do you see SEARCH window inside my post ? All I can see is just screenshot of that window I took to show you what hosts file you need to find… No one told you to erase that file, just to open it in some text editor and post back what’s inside. It looks I was right… inside your hosts file, there is a lot of nasty things that shouldn’t be there…

It needs one good general spyware and adware cleaning… use Ad-Aware latest version with latest updates, and SPYBOT - Search & Destroy… also update definitions…

Sasha’
The very end of the host file with all of those nasties ends this way:
# End of entries inserted by Spybot - Search & Destroy
They are also in my host file and are placed there to block all those nasty places.
They will also be there for any one else using Spybot S&D
Hope that clears up the mystery.;D

Well, I’m using Spybot search and destroy and I don’t have them inside. Most likely 'cause I didn’t want to start that tea timer or whatever it is… I’ve noticed it made so many problems to my customers’es browsing experience…

There is really no need for that thing to keep it installed… there are much better antispyware solutions out there.

EDIT: Sorry, it’s not Tea Timer, it’s SDHelper… sorry again…

I use Spybot S&D on a regular basis. Ran it yesterday. Nothing came up. I also have Adaware from Lavasoft and Spyblaster. All run yesterday.