Technology Get the latest on technology, electronics and software…

IT: Windows 7 & Hosts File...WTF?!

Thread Tools
 
Old Jan 5, 2011 | 01:56 PM
  #1  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,106
Likes: 82
From: Northern VA
IT: Windows 7 & Hosts File...WTF?!

My dad recently got a virus. He managed to clean everything up himself except for the bad entries in the hosts file. Since he did the majority of the work himself, and he doesn't remember the name of the virus (or whatever it was) I don't have much to work with there.

According to MalwareBytes Anti-Malware and HijackThis, the funked up hosts file is the only problem left.

I want to replace his hosts file with the MVPS hosts file (http://www.mvps.org/winhelp2002/hosts.htm), but I'm having a heck of a time doing it. I know that, in Windows 7, this is one of those super ultra protected files. However, I'm experiencing something VERY weird.

In Explorer, with Show Hidden Files enabled, you cannot see the hosts file. It's like it doesn't exist.

Via an elevated Command Prompt, I can only see the hosts file with "dir /a". If it's truly hidden, this makes sense. However, the following does not.

I can open the file using Notepad if I do "notepad C:\Windows\System32\drivers\etc\hosts" via an elevated Command Prompt. I cannot overwrite the file. When I do a File > Save, it prompts me to save a text file. I change the file type to All Files and remove the extension. No dice, Notepad insists on a ".txt" extension.

If I try to delete the existing hosts file, I get the error message "Could Not Find C:\Windows\System32\drivers\etc\hosts"

If I try to change the file attributes, I get the error message "Not resetting hidden file - C:\Windows\System32\drivers\etc\hosts"

I went as far as enabling the system administrator account and, when using an elevated Command Prompt, doing a "runas /user:administrator notepad" and editing the file, and a "runas /user:administrator cmd" and issuing commands there.

My next thought is to reboot into Safemode with command prompt...but I don't have physical access to the laptop right now. All my work has been via TeamViewer.

How can I blow away the existing hosts file and replace it?

This: http://support.microsoft.com/kb/923947 or doing anything as an administrator doesn't seem to work.

I don't have a lot of Windows 7 experience, so maybe I'm missing something? I thought I was smarter than this! :angry:
Reply
Old Jan 5, 2011 | 02:50 PM
  #2  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
When you enabled show hidden files, did you check the "hide protected operating system files(recommended)" also?

To save a file without an extension, simple use quotes..ie..you would type "hosts" in the save box. Also, it does not matter what extension is picked in the drop down when you do this.

Edit: Also, you could manually change the file attrib for hidden like so.. "attrib -h c:\windows\system32\drivers\etc\hosts" at a command prompt (no quotes)

Last edited by rza49311; Jan 5, 2011 at 02:54 PM.
Reply
Old Jan 5, 2011 | 03:00 PM
  #3  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
Seems you might still have A rootkit running
Reply
Old Jan 5, 2011 | 03:03 PM
  #4  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
Originally Posted by #1 STUNNA
Seems you might still have A rootkit running
Wouldn't hurt to run Combofix and TDSSKiller on the machine.
Reply
Old Jan 5, 2011 | 03:11 PM
  #5  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,106
Likes: 82
From: Northern VA
I unchecked that, so now I can see it in Explorer. Forgot about that .

The file has been marked as "read only". I cannot remove this attribute!! I went as far as the following:

- Opened Command Prompt
- runas /user:administrator cmd

In Command Prompt ran by Administrator:

attrib -r c:\windows\system32\drivers\etc\hosts

And I get the error: Not resetting hidden file - C:\Windows\System32\drivers\etc\hosts

The same goes for if I try to remove the hidden attribute.

When trying to remove the read only attribute via Explorer, it goes through the prompts to grant my action administrative privileges, then comes back with an error about needing to give it administrative privileges!

I may need to see his laptop in person. :sigh:
Reply
Old Jan 5, 2011 | 03:13 PM
  #6  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,106
Likes: 82
From: Northern VA
Originally Posted by #1 STUNNA
Seems you might still have A rootkit running

Aha! That might be it. I completely forgot to run a rookit removal tool. Double . Any recommendations on which removal tool to use?
Reply
Old Jan 5, 2011 | 03:13 PM
  #7  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,106
Likes: 82
From: Northern VA
Originally Posted by rza49311
Wouldn't hurt to run Combofix and TDSSKiller on the machine.

That's it. I'm definitely doing that.
Reply
Old Jan 5, 2011 | 03:15 PM
  #8  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
If Combofix and TDSSKiller come up clean, the file might just be corrupted. I would get a copy of Hiren's BootCD and boot to MiniXP then you can probably replace the file.
Reply
Old Jan 5, 2011 | 03:22 PM
  #9  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
Originally Posted by rza49311
If Combofix and TDSSKiller come up clean, the file might just be corrupted. I would get a copy of Hiren's BootCD and boot to MiniXP then you can probably replace the file.
but that will require physical access
Reply
Old Jan 5, 2011 | 03:32 PM
  #10  
rza49311's Avatar
Drifting
iTrader: (1)
 
Joined: Feb 2006
Posts: 3,072
Likes: 8
From: Southern VA
Originally Posted by #1 STUNNA
but that will require physical access
Oops, forgot about that.
Reply
Old Jan 5, 2011 | 04:08 PM
  #11  
Ken1997TL's Avatar
Senior Moderator
20 Year Member
Liked
Loved
Community Favorite
 
Joined: May 2003
Posts: 45,641
Likes: 2,335
From: Better Neighborhood, Arizona
What does Microsoft Security Essentials have to say about it?
Reply
Old Jan 5, 2011 | 06:13 PM
  #12  
Vector02's Avatar
Drifting
 
Joined: Apr 2001
Posts: 3,023
Likes: 2
From: Kyle, TX
Originally Posted by rza49311
Wouldn't hurt to run Combofix and TDSSKiller on the machine.
Combofix doesn't run on 7 does it?
Reply
Old Jan 5, 2011 | 06:40 PM
  #13  
Whiskers's Avatar
Go Giants
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Aug 2004
Posts: 70,003
Likes: 1,260
From: PA
oh noes
Reply
Old Jan 5, 2011 | 07:32 PM
  #14  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
It doesn't run on 64bit
Reply
Old Jan 7, 2011 | 01:41 PM
  #15  
thunder04's Avatar
Thread Starter
Sweet!
iTrader: (1)
 
Joined: Jul 2007
Posts: 4,106
Likes: 82
From: Northern VA
I haven't had a chance to look at it much since when I originally started this thread.

He ran another AV scan this morning and "Troj/FakeAV-BCF" came up. I'm not sure if it's related to the funky locked-down hosts file, but it's at least a start.

I'll post as the saga evolves...
Reply
Old Jan 7, 2011 | 01:56 PM
  #16  
#1 STUNNA's Avatar
Sanest Florida Man
Photogenic
Photoriffic
Shutterbug
Community Influencer
 
Joined: Aug 2007
Posts: 45,965
Likes: 11,758
From: Florida
turn off system restore since it might be restoring it self from that.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
le^2
5G TLX (2015-2020)
32
Mar 17, 2026 05:06 AM
iRaw
ILX Photograph Gallery
30
Aug 5, 2016 04:41 PM
xsilverhawkx
2G TL Problems & Fixes
4
Oct 5, 2015 11:00 AM
xsilverhawkx
2G TL Problems & Fixes
5
Sep 28, 2015 06:51 PM




All times are GMT -5. The time now is 12:41 AM.