Re: "we have been hacked"

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 12/15/03


Date: Mon, 15 Dec 2003 16:29:34 -0500


"Jeff Cochran" <jcochran.nospam@naplesgov.com> wrote in message
news:3feafae8.446018090@msnews.microsoft.com...
> On Fri, 12 Dec 2003 20:01:22 -0500, "Karl Levinson [x y] mvp"
> <levinson_k@despammed.com> wrote:

> >Also, I'm not familiar with this trojan / virus that both uses a file
named
> >SVCHOST.EXE and also modifies the hosts file. Which one is it? Or have
> >they possibly confused the welchia and qhosts removal instructions?
>
> It appears a combination of Welchia/Qhosts and possibly others. I
> wouldn't think SVCHost would normally be an issue to pull out of
> Startup, and it's a common method of loading several
> viruses/trojans/malware/etc.

FYI, I searched www.sarc.com to try to find a virus that used svchost.exe
and modified the hosts file, couldn't find any. I have to wonder if the
instructions on the website are misguided, or maybe they know something we
don't.



Relevant Pages

  • Virus/Trojan/Ad/Spy/Malware that modifies hosts file when any program is run?
    ... that modifies the ... We're using zonelab pro with the "OS firewall" enabled but every time ... the hosts file remains the same (with just the single ...
    (alt.comp.anti-virus)
  • Re: c:winntsystem32driversetchosts
    ... Trojan.Ecure.C is a Trojan horse that modifies the Hosts file and the Internet ... "George Hester" wrote in message ...
    (microsoft.public.win2000.general)
  • Re: deny-access browser?
    ... mail.yahoo.com in your local hosts file. ... talking about the .hosts file for the login account, ... to be modified read upon login, or does it work as soon as one modifies ...
    (comp.sys.mac.system)