Windows Defender apparent false alarm (Win32/PossibleHostsFileHijack)
Posted in General on Mar 10th, 2009
I got an alarming popup from Windows Defender tonight: it had detected Win32/PossibleHostsFileHijack in the C:\Windows\System32\drivers\etc\hosts file. That’s pretty worrisome and unexpected! I looked at the file but it seemed uninteresting. The only non-comment entries were:
127.0.0.1 localhost
::1 localhost
I made a backup of the file, then I let Defender “clean” it. OK… it only removed the [...]