header



Welcome to the Micro Center Tech Support Blog!
Find free technical support on a variety of products featured at Micro Center and plenty of how-tos on new technology. Start searching our Blog below or search our Tech Center archives »

Can't find what your looking for? Take advantage of our Tech Support services »

Join the MC Tech Support Community Forum: Get direct advice from the Knowledge Experts @ Micro Center.
Click here to access the Forum »

Search This Blog

Showing posts with label HOSTS File. Show all posts
Showing posts with label HOSTS File. Show all posts

Tuesday, June 11, 2013

Tech Tip: How to clean out the Windows Hosts file if malware has tampered with it

Viruses attack computers not just by posting pop-up ads for phony software. They also cripple the computer's basic functions so that the virus is difficult to get rid of. One of the chief objectives of viruses is to prevent internet browsers from going to web sites chosen by the user. There are several ways that viruses steer a browser away from its intended destination. Sometimes they install a Proxy Server into the web browser (See Part 3 in this series, "How to clear the Proxy Server setting"). At other times a virus will insert unwanted IP addresses into the network settings (See Part 4 in this series, "How to reset Static IP addresses to dynamic IP addresses"). A third way that viruses hijack internet connections is rarer, but it does happen. If previous attempts at solving the problem do not work, it is worth investigating a Windows feature called the Hosts file.

The WindowsHosts file serves to map user-friendly and familiar web site addresses (such as Google) to the actual IP addresses that are behind such names (such as 216.239.51.99). The Hosts file is sometimes used by network administrators for managing fixed networks. Unfortunately, it is also a target for viruses that want to hijack a computer's internet connectivity. Fortunately, however, if the Hosts file has been attacked and unwanted material written into it, the file can be manually cleaned.

The Hosts file is located deep in the Windows folder. It is not easy to find, but following these steps will help you locate it, inspect it and-if necessary-clean it up.

First, you need to open up the Windows text editor called Notepad. (For Windows Vista, 7 and 8, this needs to be launched with administrator privileges.) Depending on which version of Windows you have, this is done differently:

1) In Windows XP:

  • Click on the Start button
  • Click the Run button in the menu
  • Type notepad in the box, hit the Enter key

2) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

3) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

4) In Windows 8:

  • Open the Charms menu and click on the Search Charm
  • Type “notepad” in the Apps search window
  • Right-click the program Notepad that appears in the results in the upper left corner
  • In the taskbar that opens at the bottom of the screen, click Run as administrator
  • Click Yes to allow the program to make changes (if this option appears on the screen)

When notepad is opened up, you will see a new window for the Notepad text editor that looks like this:

notepad 

notepad

With the Notepad application open click on File in the menu bar, then click on Open in the drop-down menu (as indicated by the red arrow, above).

To locate the Hosts file, start with a double-click on the C drive in the left panel, then the Windows folder, the System32 folder, the drivers folder, and finally the etc folder. Once the etc folder is open, click on Text documents (*.txt) and drop down to the next option which is All files (*.*). If you are in the correct folder, you will see a list of 3 to 5 files in the window, as shown below. Now, double-click the Hosts file (circled) to open it up in the text editor.

All files

The example below is of an actual hijacked Hosts file. All the lines of text that are preceded by the # sign are legitimate (comments). All the others were inserted by a virus to steer users in various countries to the unintended IP address of 74.50.127.5 (the web site designed by the virus author) instead of Google.

hijacked host file

To remove the intruding instructions in the host file is simply a matter of deleting the lines that are not wanted. Using Notepad, move the cursor to the area (as highlighted, above) and delete those lines, leaving the original lines in the Hosts file.

A clean Hosts file will look something like this:
clean Hosts file

When finished editing, simply save the file, reboot the computer, and try to use your browser normally. Hopefully, the experience of being steered away from desired web sites will be gone, and you will be able to browse freely.

For more assistance contact Technical Support here.

Tuesday, April 24, 2012

Tech Tip of the Day: How to use a HOSTS File to proactively defend your Windows computer against most known Malware programs

Description: This article describes the processes of installing and updating a 3rd party HOSTS file to provide a strong layer of defense against most known forms of malware, immunizing your system from many malicious programs before they become a threat.

Background: The HOSTS file is a File used by the Windows operating system to map the location of computers or web addresses on its network. It is similar in function to the Domain Name System (DNS) which maps server Internet Protocol (IP) addresses to domain names, such as ‘google.com’ (Google’s Top-Level Domain [TLD]), which directs internet traffic to the IP address of one of Google’s servers, such as ‘72.14.204.105’. As such, it is important to be very careful when making any changes to this system. Fortunately, there are several reputable groups which actively maintain and test custom HOSTS file configurations which are freely available on the internet today.

This guide will cover the installation process for two popular HOSTS files which are regularly tested and are considered safe to use. It is important to choose only one guide to follow, as attempting to install multiple HOSTS files can lead to conflicts.

Note: If you are attempting to follow this guide on a computer connected to a home or work network, please contact your Network Administrator before continuing, as making changes to the HOSTS file may affect network connectivity in certain situations.

  1. MVPS HOSTS
    • Download ‘hosts.zip’ from the following web page:
      http://winhelp2002.mvps.org/hosts.htm

      hosts.zip
    • Extract the contents of the ‘hosts.zip’ file by Right Clicking on the file from within Windows Explorer and selecting the ‘Extract All’ option from the menu.

      extract all
    • Right click on ‘mvps.bat’ and select the ‘Run as Administrator’ option from the menu.
      • Click ‘Continue’ in the User Account Control (UAC) prompt, if one appears.
      • In Windows XP, or if the ‘Run as Administrator’ option is not available, you may simply Double-Click on ‘mvps.bat’ or Right Click on the file and select ‘Open’ from the menu.

        Run as admin
    • Press Any Key when prompted.
      • The window background should turn Blue and display a message stating
        "THE MVPS HOSTS FILE IS NOW UPDATED", signifying that the process has completed successfully.

        completed
    • Restart Your Computer to complete the installation.

  2. Spybot - Search & Destroy
    • Download Spybot-S&D from one of the Mirror Sites listed at this link:
      http://www.safer-networking.org/en/mirrors/index.html

      Download Spybot
    • Double-Click on the .exe file you just downloaded (the file should be named ‘spybotsd162.exe’ or something similar) and follow the Installation Wizard to install the program.

      Installation Wizard
    • Start Spybot-S&D by Double-Clicking on the Icon on your desktop or from the Start Menu by clicking on the Start Button in the lower left corner of your screen and going to ‘All Programs’ » ‘Spybot - Search & Destroy’ and Clicking on the ‘Spybot - Search & Destroy’ Link from the list.

      Search and Destroy

      • The First time you run the program, you may be presented with an Initial Setup Wizard window. Click ‘Next’ on this window and follow the steps to complete the initial setup and updating of the program.

        Next
    • On the Main ‘Spybot - Search & Destroy’ window, click the ‘Immunize’ option from the Menu Bar on the Left.

      Spybot

      • The program will run a quick scan to check the current protection status of your computer.
    • Click the ‘Immunize’ button to begin the immunization process.
      • This may take some time depending on the specifications of your computer.

        Immunize
    • Restart your computer to complete the installation.
For more assistance contact Technical Support here.

Tuesday, November 15, 2011

How to Reset the HOSTS File on Your Windows Computer Automatically Using ‘Microsoft Fix it’

Description: This article describes the processes of restoring your Windows HOSTS file using the ‘Microsoft Fix it tool’.
  1. Go to the Microsoft Support Knowledge Base (KB) article entitled "How can I reset the Hosts file back to the default?" by clicking the following link in Internet Explorer: http://support.microsoft.com/kb/972034
  2. Scroll to the ‘Fix it for me’ section, and click on the ‘Microsoft Fix it’ logo.

    Microsoft Fix it

  3. Click "Run" when asked to run or save ‘MicrosoftFixit50267.msi’

    Run

  4. Click the Checkbox next to ‘I Agree’ in the Installation Wizard that appears to accept the Microsoft Software Licensing Agreement and click ‘Next’ to begin the installation of the ‘Microsoft Fix it’ solution.
    • Click ‘Continue’ on the User Account Control (UAC) dialog window if one appears.

    I Agree

  5. Restart Your Computer to complete the process.
For more assistance contact Technical Support here.

Friday, November 11, 2011

How to Use a HOSTS File to Proactively Defend Your Windows Computer against Most Known Malware Programs

Description: This article describes the processes of installing and updating a 3rd party HOSTS file to provide a strong layer of defense against most known forms of malware, immunizing your system from many malicious programs before they become a threat.

Background: The HOSTS file is a File used by the Windows operating system to map the location of computers or web addresses on its network. It is similar in function to the Domain Name System (DNS) which maps server Internet Protocol (IP) addresses to domain names, such as ‘google.com’ (Google’s Top-Level Domain [TLD]), which directs internet traffic to the IP address of one of Google’s servers, such as ‘72.14.204.105’. As such, it is important to be very careful when making any changes to this system. Fortunately, there are several reputable groups which actively maintain and test custom HOSTS file configurations which are freely available on the internet today.

This guide will cover the installation process for two popular HOSTS files which are regularly tested and are considered safe to use. It is important to choose only one guide to follow, as attempting to install multiple HOSTS files can lead to conflicts.

Note: If you are attempting to follow this guide on a computer connected to a home or work network, please contact your Network Administrator before continuing, as making changes to the HOSTS file may affect network connectivity in certain situations.
  1. MVPS HOSTS
    • Download ‘hosts.zip’ from the following web page: http://winhelp2002.mvps.org/hosts.htm

      hosts.zip

    • Extract the contents of the ‘hosts.zip’ file by Right Clicking on the file from within Windows Explorer and selecting the ‘Extract All’ option from the menu.

      extract all

    • Right click on ‘mvps.bat’ and select the ‘Run as Administrator’ option from the menu.
      • Click ‘Continue’ in the User Account Control (UAC) prompt, if one appears.
      • In Windows XP, or if the ‘Run as Administrator’ option is not available, you may simply Double-Click on ‘mvps.bat’ or Right Click on the file and select ‘Open’ from the menu.

        Run as admin

    • Press Any Key when prompted.
      • The window background should turn Blue and display a message stating "THE MVPS HOSTS FILE IS NOW UPDATED", signifying that the process has completed successfully.

        completed

    • Restart Your Computer to complete the installation.

  2. Spybot - Search & Destroy
    • Download Spybot-S&D from one of the Mirror Sites listed at this link: http://www.safer-networking.org/en/mirrors/index.html

      Download Spybot

    • Double-Click on the .exe file you just downloaded (the file should be named ‘spybotsd162.exe’ or something similar) and follow the Installation Wizard to install the program.

      Installation Wizard

    • Start Spybot-S&D by Double-Clicking on the Icon on your Desktop or from the Start Menu by Clicking on the Start Button in the Lower Left corner of your screen and going to ‘All Programs’ » ‘Spybot - Search & Destroy’ and Clicking on the ‘Spybot - Search & Destroy’ Link from the list.

      Search and Destroy

      • The First time you run the program, you may be presented with an Initial Setup Wizard window. Click ‘Next’ on this window and follow the steps to complete the initial setup and updating of the program.

        Next

    • On the Main ‘Spybot - Search & Destroy’ window, Click the ‘Immunize’ option from the Menu Bar on the Left.

      Spybot

      • The program will run a quick scan to check the current protection status of your computer.
    • Click the ‘Immunize’ button to begin the immunization process.
      • This may take some time depending on the specifications of your computer.

        Immunize

    • Restart Your Computer to complete the installation.
For more assistance contact Technical Support here.