<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Martin Falatic's Techno Blog &#187; Defender</title>
	<atom:link href="http://www.falatic.com/index.php/tag/defender/feed" rel="self" type="application/rss+xml" />
	<link>http://www.falatic.com</link>
	<description>Technobabble</description>
	<lastBuildDate>Tue, 18 May 2010 08:50:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Windows Defender apparent false alarm (Win32/PossibleHostsFileHijack)</title>
		<link>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack</link>
		<comments>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack#comments</comments>
		<pubDate>Tue, 10 Mar 2009 07:47:13 +0000</pubDate>
		<dc:creator>Marty</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[false positive]]></category>
		<category><![CDATA[Win32/PossibleHostsFileHijack]]></category>

		<guid isPermaLink="false">http://www.falatic.com/?p=5</guid>
		<description><![CDATA[I got an alarming popup from Windows Defender tonight: it had detected Win32/PossibleHostsFileHijack in the C:\Windows\System32\drivers\etc\hosts file.  That&#8217;s pretty worrisome and unexpected!  I looked at the file but it seemed uninteresting.  The only non-comment entries were:
127.0.0.1       localhost
::1             localhost
I made a backup of the file, then I let Defender &#8220;clean&#8221; it.  OK&#8230; it only removed the [...]]]></description>
			<content:encoded><![CDATA[<p>I got an alarming popup from Windows Defender tonight: it had detected <strong>Win32/PossibleHostsFileHijack</strong> in the <em>C:\Windows\System32\drivers\etc\hosts</em> file.  That&#8217;s pretty worrisome and unexpected!  I looked at the file but it seemed uninteresting.  The only non-comment entries were:</p>
<pre><span style="color: #ff0000;">127.0.0.1       localhost</span>
::1             localhost</pre>
<p>I made a backup of the file, then I let Defender &#8220;clean&#8221; it.  OK&#8230; it only removed the 127.0.0.1 line (in red above).  Weird: that&#8217;s a pretty standard setting and it doesn&#8217;t seem like it should be going anywhere.</p>
<p>I searched around for this and found <a title="Thread on the Norton forums" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;message.id=37891" target="_blank">this thread on the matter</a>.  I then used Windows update to get the latest version of the Defender database (it was last checked about 18 hours ago) and reverted the &#8220;fix&#8221; Defender had made (in Vista you must edit the <em>hosts </em>file with an editor running in Admin mode&#8230; as always <em>be careful</em>!)  Sure enough, it found and installed a newer version and a re-scan of the <em>hosts </em>file showed&#8230; no problems whatsoever.  Apparently one of Monday&#8217;s Defender definition updates might have had a bug in it.</p>
<p><em>Note: This is NOT to imply this is always a false alarm!  But if the only line that was removed is the standard localhost address as above, update Defender and re-scan.  This &#8220;problem&#8221; may not be a problem after all.</em></p>
<p>Now, I wonder how many people screwed up their <em>hosts</em> file today by letting this rather ubiquitous setting get removed?  I can imagine there are some apps that&#8217;ll be unhappy not to find a localhost route.  If this post helped you avoid some fun config headaches later please drop a quick comment.</p>
<p><strong>Update: <a title="More info" href="http://www.h-online.com/security/Windows-Defender-False-alarm-triggered-by-hosts-file--/news/112814" target="_blank">more info at this site </a>about this issue.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
