Can't Edit Hosts File on Windows XP

I have a windows XP machine that has a host file that is set as a system file and is hidden.  When i go to c:\windows\system32\drivers\etc\hosts I see a ton of entries to all sorts of google and microsoft sites.  This explains why im getting so many redirects when going to google.  So i try and clear out all the entries and save it and it doesn't allow me to.

So i have tried many programs to remove the permissions but i have no luck.  Is there a way to remove the host file manually and re-create it?  
jmkotmanAsked:
Who is Participating?
 
houssam_balloutCommented:

Try to edit in safe mode

After that scan your virus with malware & combofix:

http://www.malwarebytes.org/

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 
CluskittCommented:
That happens because you've been infected with a rootkit. You need to clean your XP and then use a tool to delete the file. I've had this happen on my sister's pc recently. I ended up using Unlocker to do it. Though you can use a live CD as well.
0
 
jmkotmanAuthor Commented:
Ill give unlocker a try tonight and see.  I ran malwarebytes and hitman pro but they seem to thing everything is fine
0
Cloud Class® Course: Microsoft Exchange Server

The MCTS: Microsoft Exchange Server 2010 certification validates your skills in supporting the maintenance and administration of the Exchange servers in an enterprise environment. Learn everything you need to know with this course.

 
jmkotmanAuthor Commented:
I did try and edit in safe mode and still no love
0
 
houssam_balloutCommented:
Try combofix

Try this unlocker:

http://ccollomb.free.fr/unlocker/
0
 
JsblantonCommented:
This could also just be because you have run spybot search and destroy which locks down the hosts file. There is a whole process for recreating it, or unlocking it to edit that I can't remember right now. But, if you have run spybot in the past this is probably what it is, and why you aren't coming up with any infections. Cheers.
0
 
johnb6767Commented:
Right click it, and take ownership. Then click OK and go back into the Advanced Security Tab, and click the Top box, to inherit the permissions. Then Click OK again. Right Click the file, and deselect "Read Only"......

Now you should be able to save it.....

More than likely, all ACEs have been deleted to the file, and without them, Windows doesnt know who is allowed to access/edit the file....

0
 
johnb6767Commented:
Oh, and if this is NOT XP Pro, do this in Safe NMode, as you will not se the Security Tab in regular mode in XP Home....
0
 
johnb6767Commented:
Oh, and Right Click>Security>Advanced>Owner....As the first step. Re read ity and it was incomplete above.....
0
 
flubbsterCommented:
Download the following batch file to your desktop and run it. This will free up the hosts file and allow you to remove it completely.
http://download.bleepingcomputer.com/bats/hosts-perm.bat

Delete the C:\Windows\System32\Drivers\etc\HOSTS file. Once it is deleted, download the following HOSTS file by right-clicking the link and select "Save Target As"
and save it in the C:\Windows\System32\Drivers\etc folder

http://download.bleepingcomputer.com/misc/host-files/windows-xp/hosts

You should be all set.

0
 
GlobaLevelProgrammerCommented:
you can try HijackThis...its one of the best by Trend Micro...if this doesnt fix it..take it to your local Geek Squad...at best buy
http://free.antivirus.com/hijackthis/
0
 
jmkotmanAuthor Commented:
Is there a way to see the file though if its hidden.  Even if i say "view hidden files and folders" it doesn't appear.  But i know its there b/c i can navigate to it through run command
0
 
CluskittCommented:
You have to uncheck the option "Hide system files and folders", found in the same place where you find "View hidden files and folders", a bit further down.
0
 
flubbsterCommented:
Beware of a rogue (fake )hosts file also. I don't think you can do anything from a permissions standpoint to get access and delete the file. According to Malwarebytes, the best way is via the instructions I posted.

Up to you.....
0
 
CluskittCommented:
If you use unlocker, you can delete it. Unlocker will fail the delete and ask to delete it on next boot. Say yes and it will be done. You can then use one of Microsoft's FixIt to reset the hosts file.

Another easy way is to simply boot a live CD (like Ubuntu) and simply delete it from there.
0
 
jmkotmanAuthor Commented:
Combofix fixed the issue!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.