"Hosts" file locked

Discussion in 'Software' started by dlb, Oct 25, 2010.

  1. dlb

    dlb MajorGeek

    I've de-virused a PC -it's totally clean- but the attributes on the HOSTS file have been set by the malware so that I can't rename/change/delete it. I've tried from an elevated command prompt, I've tried from a PECD. I need to get rid of it or change it because it's re-routing all attempts to get to google to some rogue page, and we can't have that. I've even tried using the attrib command to change the attributes, and I'm denied each time.
     
  2. motc7

    motc7 Vice Admiral (Starfleet)

    You cannot delete it with any type of program?
     
  3. motc7

    motc7 Vice Admiral (Starfleet)

    Just doing some searches on this, they are recommending Combofix...do it! :major
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download HostsXpert and unzip it to your desktop, Do not run it yet.

    Next.

    Download OTM by Old Timer and save it to your Desktop.

    Right-click OTM.exe And select " Run as administrator " to run it.





    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Next.


    • Double click on HostsXpert.exe to launch the programme.
    • When prompted with:
      HOSTS file does not exist, press OK to create HOSTS file, Cancel to quit.
    • Select OK.
    • Check to see if top button on left hand side says Make Writable?
      • If it does. click on it then proceed to next instruction.
      • If not, just proceed to next instruction
    • Click on Restore MS Hosts File to restore your Hosts file to its default condition
    • When prompted to confirm, click OK.
    • Click on the Download button (lower left hand side)
      • Click on MVPs Hosts... button.
      • Click on Replace button.
      • Press OK in the box that pops up. (HostsXpert will now download and update your Hosts file)
    • When finished.
      • Click on File Handling button.
      • Click on Make Read Only? to secure it against infection.
    • Exit the programme.
     
  5. motc7

    motc7 Vice Admiral (Starfleet)

    Just out of curiosity, why go through all of this if Combofix would fix the problem and likely get rid of any leftover malware crap?
     
    Last edited by a moderator: Oct 25, 2010
  6. dlb

    dlb MajorGeek

    If it matters, the OS is X64 Windows7.....

    That's a good question! ;)

    Thanks Tim! I'll give that a go here in a few minutes and let you know what happens.....
    :-D
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    He is free to try doing it with Combo. Have at it. ;)

    EDIT: Combo won't run on your system.
     
  8. motc7

    motc7 Vice Admiral (Starfleet)

    Why not?
     
  9. dlb

    dlb MajorGeek

    :celebrate Problem solved! I tried one last thing: I booted to safe mode, right-clicked, chose "Properties" and selected the "Security" tab and messed around with the settings there, and was finally able to delete it, then I created a new "HOSTS" file.... but I've already saved a link to this thread for future use. ;)

    I think ComboFix is for X86 (32bit) Windows only.... right? :confused
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right, it will not work on 64 bit systems.
     
  11. motc7

    motc7 Vice Admiral (Starfleet)

    yeah, that will do! Good to hear you solved it in Safe Mode. Honestly wouldn't have thought that would have given you some leverage but whatever works!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds