I’ve written before about using the hosts file to block domains that are hosting malware. The idea is pretty simple. There’s a known list of domains that are either hosting or controlling malware, so by blocking your computer from accessing those domains, you make it much harder to get infected in the first place, and in the event that you do get infected, at least you block access to the command and control servers.
The problem is that Windows doesn’t make this easy. Well, I found an easy way: Hostsman. You can have it up and running in minutes.
Update: Don’t mess around with hosts files. It’s more efficient and more effective to change DNS servers instead.
Here’s what you do. Download Hostsman from the link above. Extract it. Run it. Click Run as administrator if needed. Click Select sources. Tick the box labeled Malware Domains. Click Close. Click Check For Updates. Let it download and merge the hosts file. After it finishes, click Dismiss. Click Configure Updater and tick the box for the second option, Automatically check and download new hosts file updates. I also uncheck the option to ask for confirmation. Click OK.
That’s it. I got it done in five minutes, even with writing this up and getting interrupted every 30 seconds.
This isn’t a substitute for antivirus software by any stretch, but it augments antivirus. Here’s the theory behind it.
The most feared malware going around right now is a program called Cryptolocker. If you get infected, it encrypts all your Office documents with military-grade encryption (AES 256), then demands payment in bitcoins within 72 or 100 hours. If you don’t pay up, it destroys the key, making decryption impossible. Well, for 15-20 years at least, which is when most experts believe brute-forcing AES will become somewhat practical.
But if you block the servers Cryptolocker uses for command and control, you can be infected but never show the signs of infection. That gives your antivirus software time to find and remove the infection before it encrypts all of your documents.
It’s free and it’s simple, so I recommend it.