<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Martin Falatic’s Techno Blog &#187; Win32/PossibleHostsFileHijack</title>
	<atom:link href="http://www.falatic.com/index.php/tag/win32possiblehostsfilehijack/feed" rel="self" type="application/rss+xml" />
	<link>http://www.falatic.com</link>
	<description>Technobabble...</description>
	<lastBuildDate>Thu, 20 Oct 2011 05:26:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows Defender apparent false alarm (Win32/PossibleHostsFileHijack)</title>
		<link>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack</link>
		<comments>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack#comments</comments>
		<pubDate>Tue, 10 Mar 2009 07:47:13 +0000</pubDate>
		<dc:creator>Martin Falatic</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Defender]]></category>
		<category><![CDATA[false positive]]></category>
		<category><![CDATA[Win32/PossibleHostsFileHijack]]></category>

		<guid isPermaLink="false">http://www.falatic.com/?p=5</guid>
		<description><![CDATA[I got an alarming popup from Windows Defender tonight: it had detected Win32/PossibleHostsFileHijack in the C:\Windows\System32\drivers\etc\hosts file.  That&#8217;s pretty worrisome and unexpected!  I looked at the file but it seemed uninteresting.  The only non-comment entries were: 127.0.0.1       localhost ::1             localhost &#8230; <a class="more-link" href="http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I got an alarming popup from Windows Defender tonight: it had detected <strong>Win32/PossibleHostsFileHijack</strong> in the <em>C:\Windows\System32\drivers\etc\hosts</em> file.  That&#8217;s pretty worrisome and unexpected!  I looked at the file but it seemed uninteresting.  The only non-comment entries were:</p>
<pre><span style="color: #ff0000;">127.0.0.1       localhost</span>
::1             localhost</pre>
<p><span id="more-5"></span></p>
<p>I made a backup of the file, then I let Defender &#8220;clean&#8221; it.  OK&#8230; it only removed the 127.0.0.1 line (in red above).  Weird: that&#8217;s a pretty standard setting and it doesn&#8217;t seem like it should be going anywhere.</p>
<p>I searched around for this and found <a title="Thread on the Norton forums" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;message.id=37891" target="_blank">this thread on the matter</a>.  I then used Windows update to get the latest version of the Defender database (it was last checked about 18 hours ago) and reverted the &#8220;fix&#8221; Defender had made (in Vista you must edit the <em>hosts </em>file with an editor running in Admin mode&#8230; as always <em>be careful</em>!)  Sure enough, it found and installed a newer version and a re-scan of the <em>hosts </em>file showed&#8230; no problems whatsoever.  Apparently one of Monday&#8217;s Defender definition updates might have had a bug in it.</p>
<p><em>Note: This is NOT to imply this is always a false alarm!  But if the only line that was removed is the standard localhost address as above, update Defender and re-scan.  This &#8220;problem&#8221; may not be a problem after all.</em></p>
<p>Now, I wonder how many people screwed up their <em>hosts</em> file today by letting this rather ubiquitous setting get removed?  I can imagine there are some apps that&#8217;ll be unhappy not to find a localhost route.  If this post helped you avoid some fun config headaches later please drop a quick comment.</p>
<p><strong>Update: <a title="More info" href="http://www.h-online.com/security/Windows-Defender-False-alarm-triggered-by-hosts-file--/news/112814" target="_blank">more info at this site </a>about this issue.</strong></p>
<p><a class="a2a_button_reddit" href="http://www.addtoany.com/add_to/reddit?linkurl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;linkname=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" title="Reddit" rel="nofollow" target="_blank"><img src="http://www.falatic.com/wp-content/plugins/add-to-any/icons/reddit.png" width="16" height="16" alt="Reddit"/></a><a class="a2a_button_linkedin" href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;linkname=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://www.falatic.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a><a class="a2a_button_tumblr" href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;linkname=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" title="Tumblr" rel="nofollow" target="_blank"><img src="http://www.falatic.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a><a class="a2a_button_slashdot" href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;linkname=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" title="Slashdot" rel="nofollow" target="_blank"><img src="http://www.falatic.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a><!--[if IE]><iframe frameborder="0" allowTransparency="true" class="addtoany_special_service google_plusone" src="https://plusone.google.com/u/0/_/%2B1/fastbutton?url=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;size=medium&amp;count=true" scrolling="no" style="border:none;overflow:hidden;width:90px;height:20px"></iframe><![endif]--><!--[if !IE]><!--><iframe class="addtoany_special_service google_plusone" src="https://plusone.google.com/u/0/_/%2B1/fastbutton?url=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;size=medium&amp;count=true" scrolling="no" style="border:none;overflow:hidden;width:90px;height:20px"></iframe><!--<![endif]--><!--[if IE]><iframe frameborder="0" allowTransparency="true" class="addtoany_special_service facebook_like" src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;layout=button_count&amp;show_faces=false&amp;width=75&amp;action=like&amp;colorscheme=light&amp;height=20&amp;ref=addtoany" scrolling="no" style="border:none;overflow:hidden;width:90px;height:21px"></iframe><![endif]--><!--[if !IE]><!--><iframe class="addtoany_special_service facebook_like" src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;layout=button_count&amp;show_faces=false&amp;width=75&amp;action=like&amp;colorscheme=light&amp;height=20&amp;ref=addtoany" scrolling="no" style="border:none;overflow:hidden;width:90px;height:21px"></iframe><!--<![endif]--><!--[if IE]><iframe frameborder="0" allowTransparency="true" class="addtoany_special_service twitter_tweet" src="http://platform.twitter.com/widgets/tweet_button.html?url=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;counturl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;count=horizontal&amp;text=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" scrolling="no" style="border:none;overflow:hidden;width:130px;height:20px"></iframe><![endif]--><!--[if !IE]><!--><iframe class="addtoany_special_service twitter_tweet" src="http://platform.twitter.com/widgets/tweet_button.html?url=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;counturl=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;count=horizontal&amp;text=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" scrolling="no" style="border:none;overflow:hidden;width:130px;height:20px"></iframe><!--<![endif]--><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.falatic.com%2Findex.php%2F5%2Fwindows-defender-apparent-false-alarm-win32possiblehostsfilehijack&amp;title=Windows%20Defender%20apparent%20false%20alarm%20%28Win32%2FPossibleHostsFileHijack%29" id="wpa2a_2"><img src="http://www.falatic.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.falatic.com/index.php/5/windows-defender-apparent-false-alarm-win32possiblehostsfilehijack/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

