MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.

Closed Thread
Thread Tools Display Modes
Old 12-13-09, 23:20
RadAct RadAct is offline
Private E-2
Join Date: Dec 2009
Posts: 1
Thanks: 0
Thanked 1 Time in 1 Post
Default Browser Hijack/Redirects

I just finished repairing a customer's machine and thought that all was ok. Explorer opened up ok and displayed the default webpage ok, but when I tried to access or I would get a timeout and the page would not display. Not even pinging the site from cmd prompt would work.

Very odd.

After re-running eset online scan, Malware bytes, etc and not finding any additional infections and stood there scratching my head when it dawned on me.. the hosts file!

Opened CMD prompt, navigated to c:\windows\system32\drivers\etc but there was not 'hosts' file.

DIR /AH revealed a hidden hosts file.

EDIT HOSTS revealed a massively hijacked HOSTS file with redirects for google and many others. Aha!

ATTRIB HOSTS revealed archived, read only, system, hidden attributes all on.

ATTRIB -ARSH wouldn't work.

Downloaded FILE ASSASSIN from, even that wouldn't unlock the file. Even marking it for deletion on reboot.

Took the drive out, piggy backed it on another system as a slave drive. Still couldn't delete the HOSTS file with DEL or FILE ASSASSIN. Very weird if you ask me.

Time to get smart... Navigated back one level and renamed the ETC folder to ETCOLD, created a new folder called ETC. Copied all the other files from ETCOLD to the new ETC folder (all files except for HOSTS).

Then copy/paste a clean HOSTS file (from the clean machine) to to the new ETC folder. ie. copy c:\windows\system32\drivers\etc\hosts f:\windows\system32\drivers\etc

For some added protection, I then marked the HOSTS file as READ-ONLY, just to (maybe) protect future hijacks. (ATTRIB +R HOSTS)

Put the drive back into the original computer and viola! Explorer opened up google first time!

It's not the first time I've seen HOSTS file hijacks, but it's first time I couldn't delete the file or modify it.

A simple solution if you're stuck with a stubborn hosts file.

Good Luck!
The Following User Says Thank You to RadAct For This Useful Post:
melm (12-16-09)
Sponsored links
Old 12-16-09, 17:34
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 81,674
Thanks: 66
Thanked 8,190 Times in 4,526 Posts
Default Re: Browser Hijack/Redirects

Welcome to Major Geeks!
Originally Posted by RadAct View Post
It's not the first time I've seen HOSTS file hijacks, but it's first time I couldn't delete the file or modify it.
Could have been due to a corrupted file system or it could be a file system permissions issue that tools like FileAssassin and others cannot work around.

Note that setting the hosts file to read-only will not help since most of the current malware around already knows about that trick and they simply change the permissions again and then make their changes. This only worked for older malware that was not so smart.
"There are 10 types of people in this world. Those who understand binary and those who don't."

Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
browser redirects hardcor Malware Removal 1 11-28-09 23:51
Browser Redirects kwaka Malware Removal 3 04-27-09 15:58
Browser Redirects cahandy Malware Removal 9 03-06-09 00:54
Browser Search Redirects hdebo Malware Removal 8 07-04-08 12:16
Browser always redirects to QSRCH.COM via DNS wormsign Malware Removal 1 06-16-05 09:26

All times are GMT -5. The time now is 22:12.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds

All content Copyright source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger