Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 24th, 2012, 11:44 AM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default HOSTS gone...

Yesterday AV (5.2.9.1) block some malware to change my hosts file, from C:\WINDOWS\system32\drivers\etc\, and add fosts file to quarantine.

End now, on every start up/reboot my host are missing, even if I move him again to ETC folder. Every single reboot his gone?

Any suggestions pls?

P.S. I delete everything from quarantine.
  #2  
Old May 24th, 2012, 11:57 AM
SmackyTheFrog SmackyTheFrog is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Lansing, Michigan
Posts: 767
Default Re: HOSTS gone...

Are you seeing additional threat alerts saying the hosts file has been moved to the quarantine? What you are describing would most likely be the result of undetected malware running on your system which is attempting to modify the file with malicious redirects on a regular basis, which causes it to be removed. Contacting Eset support with a SysInspector log would be a good first course of action.
  #3  
Old May 24th, 2012, 12:41 PM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default Re: HOSTS gone...

I don't see any alert, and NOD quarantine is empty.
If I reboot in safe mode, host is here, not deleted. But if reboot normally, it's gone.
I clear all temp, cache, etc... no suspicious .vbs scripts...
  #4  
Old May 24th, 2012, 01:27 PM
SmackyTheFrog SmackyTheFrog is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Lansing, Michigan
Posts: 767
Default Re: HOSTS gone...

If you reboot normally and run the command 'attrib \Windows\System32\drivers\etc\hosts' from the command line, what output do you get? I'm thinking something may have just flagged the file with a hidden or system attribute.
  #5  
Old May 24th, 2012, 03:31 PM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default Re: HOSTS gone...

@SmackyTheFrog it's not hidden. All my hidden/protected system files, are unchecked. So I can see them all.
I think it's added some reg key for deleting hosts, but can't find him.

Tnx anyway.
  #6  
Old May 26th, 2012, 04:02 AM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Lightbulb Re: HOSTS gone...

After uninstalling the NOD32 AV, problem gone. It was a NOD32 bug. He store somewhere previous action (quarantined hosts file), and on every reboot he delete him constantly

Now it's time to change AV
  #7  
Old May 26th, 2012, 05:12 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: HOSTS gone...

Hosts file is only removed if it contains redirects set by malware and is detected by ESET.
  #8  
Old May 26th, 2012, 10:13 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,139
Post Re: HOSTS gone...

ESET has a tool that helps reset the HOSTS file to default following a DNS poisoning.
  #9  
Old May 26th, 2012, 11:24 AM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default Re: HOSTS gone...

You don't get it?

NOD32 AV delete hosts file on every startup.
Every time win start, I add NEW fresh/clean hosts to etc folder, and on next win start his gone. After I uninstall NOD (5.2.9.1), this issue disappeared.
  #10  
Old May 26th, 2012, 12:11 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,139
Post Re: HOSTS gone...

Submit and issue ticket to ESET.
  #11  
Old May 26th, 2012, 03:30 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: HOSTS gone...

Quote:
Originally Posted by XPSP3x32
You don't get it?

NOD32 AV delete hosts file on every startup.
Every time win start, I add NEW fresh/clean hosts to etc folder, and on next win start his gone. After I uninstall NOD (5.2.9.1), this issue disappeared.

I've tried that and it was only deleted if it contained malicious records. I assume some malware modifies it which triggers detection and the file is removed. I was unable to reproduce it with a clean hosts file. I'd suggest supplying the content of your ESET's quarantine as well as your Threat log to ESET for analysis.
  #12  
Old May 26th, 2012, 05:06 PM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default Re: HOSTS gone...

Quote:
Originally Posted by Marcos
I've tried that and it was only deleted if it contained malicious records. I assume some malware modifies it which triggers detection and the file is removed. I was unable to reproduce it with a clean hosts file. I'd suggest supplying the content of your ESET's quarantine as well as your Threat log to ESET for analysis.

Tnx for the tips Marcos, but it's to late. I already uninstall NOD
Btw, I try this infected soft through Sandboxie, and he try to replace hosts, when he deleted by NOD. This probably cause that bug, and he constantly delete hosts files during reboot..
  #13  
Old May 26th, 2012, 10:58 PM
zfactor's Avatar
zfactor zfactor is offline
Massive Poster
 
Join Date: Mar 2005
Location: on my zx10-r
Posts: 4,274
Default Re: HOSTS gone...

probably a malware program running that tried to mod hosts each boot up imo not from nod..
__________________
Meatwad you're up next, with your knock-knock.
Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus

"Some days your the windshield. Some days your the bug"
Eset ESS V6 / Webroot WSA / Avast! IS V8
  #14  
Old May 27th, 2012, 02:33 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: HOSTS gone...

Deleting hosts file is not a bug as long as it contains malicious records.
  #15  
Old May 27th, 2012, 04:41 AM
XPSP3x32 XPSP3x32 is offline
Infrequent Poster
 
Join Date: Jun 2011
Posts: 12
Default Re: HOSTS gone...

* it's NOD bug.

DONE here & with NOD!

Arrivederci!

Last edited by Cudni : May 27th, 2012 at 04:49 AM. Reason: * mod edit
  #16  
Old May 27th, 2012, 04:51 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: HOSTS gone...

Removing malware is what AV does and if it happens to be in hosts file then it has to go. Thanks all.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #17  
Old May 27th, 2012, 05:48 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: HOSTS gone...

Quote:
Originally Posted by XPSP3x32
* it's NOD bug.
DONE here & with NOD!
Complaining that ESET has removed malware (not a clean file) from your computer cannot be considered a bug in any way, that's what security software is actually supposed to do.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:30 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums