View Full Version : HOSTS gone...
XPSP3x32
May 24th, 2012, 11:44 AM
Yesterday AV (5.2.9.1) block some malware to change my hosts file, from C:\WINDOWS\system32\drivers\etc\, and add fosts file to quarantine.
End now, on every start up/reboot my host are missing, even if I move him again to ETC folder. Every single reboot his gone?
Any suggestions pls?
P.S. I delete everything from quarantine.
SmackyTheFrog
May 24th, 2012, 11:57 AM
Are you seeing additional threat alerts saying the hosts file has been moved to the quarantine? What you are describing would most likely be the result of undetected malware running on your system which is attempting to modify the file with malicious redirects on a regular basis, which causes it to be removed. Contacting Eset support with a SysInspector log would be a good first course of action.
XPSP3x32
May 24th, 2012, 12:41 PM
I don't see any alert, and NOD quarantine is empty.
If I reboot in safe mode, host is here, not deleted. But if reboot normally, it's gone.
I clear all temp, cache, etc... no suspicious .vbs scripts...
SmackyTheFrog
May 24th, 2012, 01:27 PM
If you reboot normally and run the command 'attrib \Windows\System32\drivers\etc\hosts' from the command line, what output do you get? I'm thinking something may have just flagged the file with a hidden or system attribute.
XPSP3x32
May 24th, 2012, 03:31 PM
@SmackyTheFrog it's not hidden. All my hidden/protected system files, are unchecked. So I can see them all.
I think it's added some reg key for deleting hosts, but can't find him.
Tnx anyway.
XPSP3x32
May 26th, 2012, 04:02 AM
After uninstalling the NOD32 AV, problem gone. It was a NOD32 bug. He store somewhere previous action (quarantined hosts file), and on every reboot he delete him constantly :thumbd:
Now it's time to change AV :)
Marcos
May 26th, 2012, 05:12 AM
Hosts file is only removed if it contains redirects set by malware and is detected by ESET.
siljaline
May 26th, 2012, 10:13 AM
ESET has a tool (http://kb.eset.com/esetkb/index?page=content&id=SOLN2933&ref=wsf) that helps reset the HOSTS file (http://en.wikipedia.org/wiki/Hosts_(file)) to default following a DNS poisoning (http://en.wikipedia.org/wiki/Dns_poisoning).
XPSP3x32
May 26th, 2012, 11:24 AM
You don't get it?
NOD32 AV delete hosts file on every startup.
Every time win start, I add NEW fresh/clean hosts to etc folder, and on next win start his gone. After I uninstall NOD (5.2.9.1), this issue disappeared.
siljaline
May 26th, 2012, 12:11 PM
Submit and issue ticket (http://go.eset.com/us/support/contact/s2/?seg=home#) to ESET.
Marcos
May 26th, 2012, 03:30 PM
-{ Quote: "You don't get it?
NOD32 AV delete hosts file on every startup.
Every time win start, I add NEW fresh/clean hosts to etc folder, and on next win start his gone. After I uninstall NOD (5.2.9.1), this issue disappeared." }-
I've tried that and it was only deleted if it contained malicious records. I assume some malware modifies it which triggers detection and the file is removed. I was unable to reproduce it with a clean hosts file. I'd suggest supplying the content of your ESET's quarantine as well as your Threat log to ESET for analysis.
XPSP3x32
May 26th, 2012, 05:06 PM
-{ Quote: "I've tried that and it was only deleted if it contained malicious records. I assume some malware modifies it which triggers detection and the file is removed. I was unable to reproduce it with a clean hosts file. I'd suggest supplying the content of your ESET's quarantine as well as your Threat log to ESET for analysis." }-
Tnx for the tips Marcos, but it's to late. I already uninstall NOD :)
Btw, I try this infected soft through Sandboxie, and he try to replace hosts, when he deleted by NOD. This probably cause that bug, and he constantly delete hosts files during reboot..
zfactor
May 26th, 2012, 10:58 PM
probably a malware program running that tried to mod hosts each boot up imo not from nod..
Marcos
May 27th, 2012, 02:33 AM
Deleting hosts file is not a bug as long as it contains malicious records.
XPSP3x32
May 27th, 2012, 04:41 AM
* it's NOD bug.
DONE here & with NOD!
Arrivederci!
Cudni
May 27th, 2012, 04:51 AM
Removing malware is what AV does and if it happens to be in hosts file then it has to go. Thanks all.
Marcos
May 27th, 2012, 05:48 AM
-{ Quote: "* it's NOD bug.
DONE here & with NOD!
" }-
Complaining that ESET has removed malware (not a clean file) from your computer cannot be considered a bug in any way, that's what security software is actually supposed to do.
vBulletin® Copyright ©2000-2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums