Can you delete / modify the hosts file in safe mode?
Main Topics
Browse All TopicsI have been cleaning a computer of rogue antivirus programs. Specifically "security solutions antivirus" and "windows security suite". The PC is running XP home edition sp3.
I have used malwarebytes, spybot s&d and panda global 2010, everything appears clean now apart from security centre still says there are 2 antivirus programs installed (not so!) and the hosts file is hijacked and not accessible.
The hosts file is not showing in the etc folder (even though folders are set to show hidden). however, I can navigate directly to the hosts file using explorer but find on opening it that it has been hijacked and all default text is gone and it contains only some redirects to rogue antivirus sites.
I cannot amend the hosts file in the usual way using notepad, even though i have unchecked it from being read only.
I have tried replacing the hosts file using hostsxpert and the program cannot make the changes either.
If I boot using ultimate boot cd for windows I can see the hosts file but still cannot make any changes, despite removing the read-only attribute.
Any advice on what to try next, much appreciated!
Lin
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Worth a try - but no guarantees.
If no joy with that, there is always SuperAntiSpyware or Combofix:
http://www.supera
http:
In safe cmd prompt i am told the hosts file is not there. When l list the DIR of the etc folder it does not list the hosts file!
I know it is there - I've seen it and opened it and viewed its contents.
In safe mode itself, i can navigate (by typing the full address: c:\windows\system32\driver
When I open the hosts file I cannot same any changes.
I will try running combo fix and take a look at a prevx scan too.
It will not allow me to rename the file or change it in anyway at the moment.
I am running combo fix which brought to my attention that an antivirus: "windows system suite" (a relative of the malware i've been chasing) is running. There are no processes which I can see which are obviously "windows system suite".
I've attached the log for combofix. It hasn't fixed the hosts file, but it has removed a lot of chaff from the etc directory by the looks of it.
The hosts file is still inaccessible.
Thanks, jhyiesla,
That has solved the initial problem as I do now have a brand new working host file in the new etc folder.
and it may well be that i can use "unlocker" now to delete the troublesome host file in the old renamed directory. I'll try that.
However, I am still stuck with the remnants of this malware which caused this problem in the first place - windows security centre still says "windows system suite" is running as an antivirus on this pc.
Since jhyiesla did help solve the main hosts file question I will award him the points for this and open a new question about the rogue antivirus showing in security centre.
Business Accounts
Answer for Membership
by: jhyieslaPosted on 2009-09-21 at 05:11:10ID: 25382051
Have you tried booting into safe Mode and using the command prompt access to attempt to delete the hosts file? You might also try scanning through the registry looking for any key has to do with the hosts file to see if one looks suspicious.
I might also recommend that you download the Prevx scanner (www.prevx.com) The scanner is free to download. Run it in full scan mode. It should give you a second opinion on what's still affecting your computer. The free version won't remove anything, but may point out something that other programs are missing.
If the PC was too infected, even if it "appears" that you have it completely cleaned at some point, it may be worth taking the time to wipe and reload... that way you are sure that it's clean... but I don't think you're to that point yet.