header



Welcome to the Micro Center Tech Support Blog!
Find free technical support on a variety of products featured at Micro Center and plenty of how-tos on new technology. Start searching our Blog below or search our Tech Center archives »

Can't find what your looking for? Take advantage of our Tech Support services »

Join the MC Tech Support Community Forum: Get direct advice from the Knowledge Experts @ Micro Center.
Click here to access the Forum »

Search This Blog

Showing posts with label computer virus. Show all posts
Showing posts with label computer virus. Show all posts

Tuesday, June 11, 2013

Tech Tip: How to clean out the Windows Hosts file if malware has tampered with it

Viruses attack computers not just by posting pop-up ads for phony software. They also cripple the computer's basic functions so that the virus is difficult to get rid of. One of the chief objectives of viruses is to prevent internet browsers from going to web sites chosen by the user. There are several ways that viruses steer a browser away from its intended destination. Sometimes they install a Proxy Server into the web browser (See Part 3 in this series, "How to clear the Proxy Server setting"). At other times a virus will insert unwanted IP addresses into the network settings (See Part 4 in this series, "How to reset Static IP addresses to dynamic IP addresses"). A third way that viruses hijack internet connections is rarer, but it does happen. If previous attempts at solving the problem do not work, it is worth investigating a Windows feature called the Hosts file.

The WindowsHosts file serves to map user-friendly and familiar web site addresses (such as Google) to the actual IP addresses that are behind such names (such as 216.239.51.99). The Hosts file is sometimes used by network administrators for managing fixed networks. Unfortunately, it is also a target for viruses that want to hijack a computer's internet connectivity. Fortunately, however, if the Hosts file has been attacked and unwanted material written into it, the file can be manually cleaned.

The Hosts file is located deep in the Windows folder. It is not easy to find, but following these steps will help you locate it, inspect it and-if necessary-clean it up.

First, you need to open up the Windows text editor called Notepad. (For Windows Vista, 7 and 8, this needs to be launched with administrator privileges.) Depending on which version of Windows you have, this is done differently:

1) In Windows XP:

  • Click on the Start button
  • Click the Run button in the menu
  • Type notepad in the box, hit the Enter key

2) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

3) In Windows Vista:

  • Click on the Start button
  • Type notepad in the search box
  • Right-click the Notepad program in the list
  • Click Run as administrator in the drop-down menu
  • Click Yes to allow the program to make changes (if this option appears on the screen)

4) In Windows 8:

  • Open the Charms menu and click on the Search Charm
  • Type “notepad” in the Apps search window
  • Right-click the program Notepad that appears in the results in the upper left corner
  • In the taskbar that opens at the bottom of the screen, click Run as administrator
  • Click Yes to allow the program to make changes (if this option appears on the screen)

When notepad is opened up, you will see a new window for the Notepad text editor that looks like this:

notepad 

notepad

With the Notepad application open click on File in the menu bar, then click on Open in the drop-down menu (as indicated by the red arrow, above).

To locate the Hosts file, start with a double-click on the C drive in the left panel, then the Windows folder, the System32 folder, the drivers folder, and finally the etc folder. Once the etc folder is open, click on Text documents (*.txt) and drop down to the next option which is All files (*.*). If you are in the correct folder, you will see a list of 3 to 5 files in the window, as shown below. Now, double-click the Hosts file (circled) to open it up in the text editor.

All files

The example below is of an actual hijacked Hosts file. All the lines of text that are preceded by the # sign are legitimate (comments). All the others were inserted by a virus to steer users in various countries to the unintended IP address of 74.50.127.5 (the web site designed by the virus author) instead of Google.

hijacked host file

To remove the intruding instructions in the host file is simply a matter of deleting the lines that are not wanted. Using Notepad, move the cursor to the area (as highlighted, above) and delete those lines, leaving the original lines in the Hosts file.

A clean Hosts file will look something like this:
clean Hosts file

When finished editing, simply save the file, reboot the computer, and try to use your browser normally. Hopefully, the experience of being steered away from desired web sites will be gone, and you will be able to browse freely.

For more assistance contact Technical Support here.

Friday, August 3, 2012

Tech Tip of the Day: How to download and run Chameleon by Malwarebytes

** THIS POST HAS BEEN UPDATED **

Malwarebytes Chameleon is a tool that was developed in order to get Malwarebytes Anti-Malware running when blocked by an active infection on a user's system.

It accomplishes this in several ways, but in order to run, Chameleon itself must be able to run in spite of the infection as well.  That's where the filenames come in and is the reason you'll find files like 'svchost.exe', 'winlogon.exe' and 'iexplore.exe' among others within the Chameleon folder.  Those are actually just renamed copies of the main Chameleon executable, mbam-chameleon.exe.  The reason that we do this is because infections, particularly rogue/fake antivirus programs, will often block processes from launching simply based on their file or process names, or they will only allow certain 'whitelisted' processes to run.  These whitelisted processes are often a user's internet browser (hence the use of names like 'firefox.exe' and 'iexplore.exe') or critical system processes (hence 'svchost.exe', 'winlogon.exe' and 'rundll32.exe').

There are several methods for launching Chameleon itself, depending on the situation that the user is dealing with. 
Malwarebytes provides a help file called 'chameleon.chm' which is accessible via the START menu under All Programs\Malwarebytes' Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk'.  This is the best and simplest way to use Chameleon as all the user has to do is open the help file and follow the instructions.

Unfortunately, launching the help file is not always possible, so
Malwarebytes does provide other methods to get Chameleon running.
 
If Malwarebytes Anti-Malware is already installed but the Chameleon help file will not open, the user may attempt to launch the Chameleon executables manually by browsing to their Malwarebytes Anti-Malware program folder under 'Chameleon' and double-clicking on the executables located there one by one until they find one which is able to launch which will be indicated by a command prompt window providing instructions on what to do next to run Chameleon.

Once Chameleon is up and running, it will attempt to update Malwarebytes Anti--Malware's database, kill all malicious processes running in memory, and then initiate a scan with Malwarebytes Anti-Malware.  Upon completion of the scan, the user may remove the infections from their system, rebooting if required, and their system should be running normally again, free of infection.

If Windows Explorer is not running, the same method can be used to launch the help file or executables by using Windows Task Manager and simply browsing to the location of the files and trying to open them one by one that way.

Now, if Malwarebytes Anti-Malware is not already installed, Chameleon can get it installed for the user. 
Malwarebytes has provided Chameleon as a separate download available here on their website: http://www.malwarebytes.org/products/chameleon

All the user needs to do is download that file, extract it to a new folder in a convenient location such as their desktop, and then attempt to use the included help file (Chameleon.chm) to run Chameleon.  If the help file will not open, then the user should proceed with the same method applied above by double-clicking on each of the provided Chameleon executables one by one until they find one that opens.

Upon opening, the user should follow the onscreen instructions and Chameleon will proceed to download and install Malwarebytes Anti-Malware for the user and then will proceed to run through the same process as described above (updating the database, killing malicious processes and performing a scan).


*All information provided by Samuel E. Lindsey of Malwarebytes Corporation

Tuesday, April 10, 2012

Tech Tip of the Day: How to run Kaspersky TDSSKiller

Description: Run this tool if you get can infection on your PC.

The Kaspersky TDSSKiller is a good tool to run on an infected computer as it can find different forms of malware and adware that may be lurking in the background of a user's PC which a standard antivirus scan may miss. It is also a good tool when trying to find out if the PC possibly has a rootkit on it.

  1. First download the TDSSKiller from the manufacturer's website, currently:
    http://support.kaspersky.com/faq/?qid=208283363
  2. Once downloaded, run the executable file to start the application. Click on the Change Parameters option to add additional options to your scan.

    TDSSKiller

  3. Click the Start Scan option and allow the scan to completely go through the user's computer.

    Start scan

  4. Once finished the user should get a screen similar to the one above if no threats or infections are found. If infections were found, you would be given options on what to do with them such as ignore, quarantine, or kill/delete.
For more assistance contact Technical Support, click here.