Browser Hijack/Redirects

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by RadAct, Dec 13, 2009.

  1. RadAct

    RadAct Private E-2

    I just finished repairing a customer's machine and thought that all was ok. Explorer opened up ok and displayed the ninemsn.com.au default webpage ok, but when I tried to access google.com or google.com.au I would get a timeout and the page would not display. Not even pinging the site from cmd prompt would work.

    Very odd.

    After re-running eset online scan, Malware bytes, etc and not finding any additional infections and stood there scratching my head when it dawned on me.. the hosts file!

    Opened CMD prompt, navigated to c:\windows\system32\drivers\etc but there was not 'hosts' file.

    DIR /AH revealed a hidden hosts file.

    EDIT HOSTS revealed a massively hijacked HOSTS file with redirects for google and many others. Aha!

    ATTRIB HOSTS revealed archived, read only, system, hidden attributes all on.

    ATTRIB -ARSH wouldn't work.

    Downloaded FILE ASSASSIN from Malwarebytes.org, even that wouldn't unlock the file. Even marking it for deletion on reboot.

    Took the drive out, piggy backed it on another system as a slave drive. Still couldn't delete the HOSTS file with DEL or FILE ASSASSIN. Very weird if you ask me.

    Time to get smart... Navigated back one level and renamed the ETC folder to ETCOLD, created a new folder called ETC. Copied all the other files from ETCOLD to the new ETC folder (all files except for HOSTS).

    Then copy/paste a clean HOSTS file (from the clean machine) to to the new ETC folder. ie. copy c:\windows\system32\drivers\etc\hosts f:\windows\system32\drivers\etc

    For some added protection, I then marked the HOSTS file as READ-ONLY, just to (maybe) protect future hijacks. (ATTRIB +R HOSTS)

    Put the drive back into the original computer and viola! Explorer opened up google first time!

    It's not the first time I've seen HOSTS file hijacks, but it's first time I couldn't delete the file or modify it.

    A simple solution if you're stuck with a stubborn hosts file.

    Good Luck!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Could have been due to a corrupted file system or it could be a file system permissions issue that tools like FileAssassin and others cannot work around.

    Note that setting the hosts file to read-only will not help since most of the current malware around already knows about that trick and they simply change the permissions again and then make their changes. This only worked for older malware that was not so smart.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds