![]() |
|
#1
|
|||
|
|||
|
Yesterday AV (5.2.9.1) block some malware to change my hosts file, from C:\WINDOWS\system32\drivers\etc\, and add fosts file to quarantine.
End now, on every start up/reboot my host are missing, even if I move him again to ETC folder. Every single reboot his gone? Any suggestions pls? P.S. I delete everything from quarantine. |
|
#2
|
|||
|
|||
|
Are you seeing additional threat alerts saying the hosts file has been moved to the quarantine? What you are describing would most likely be the result of undetected malware running on your system which is attempting to modify the file with malicious redirects on a regular basis, which causes it to be removed. Contacting Eset support with a SysInspector log would be a good first course of action.
|
|
#3
|
|||
|
|||
|
I don't see any alert, and NOD quarantine is empty.
If I reboot in safe mode, host is here, not deleted. But if reboot normally, it's gone. I clear all temp, cache, etc... no suspicious .vbs scripts... |
|
#4
|
|||
|
|||
|
If you reboot normally and run the command 'attrib \Windows\System32\drivers\etc\hosts' from the command line, what output do you get? I'm thinking something may have just flagged the file with a hidden or system attribute.
|
|
#5
|
|||
|
|||
|
@SmackyTheFrog it's not hidden. All my hidden/protected system files, are unchecked. So I can see them all.
I think it's added some reg key for deleting hosts, but can't find him. Tnx anyway. |
|
#6
|
|||
|
|||
|
After uninstalling the NOD32 AV, problem gone. It was a NOD32 bug. He store somewhere previous action (quarantined hosts file), and on every reboot he delete him constantly
Now it's time to change AV ![]() |
|
#7
|
|||
|
|||
|
Hosts file is only removed if it contains redirects set by malware and is detected by ESET.
|
|
#8
|
||||
|
||||
|
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#9
|
|||
|
|||
|
You don't get it?
NOD32 AV delete hosts file on every startup. Every time win start, I add NEW fresh/clean hosts to etc folder, and on next win start his gone. After I uninstall NOD (5.2.9.1), this issue disappeared. |
|
#10
|
||||
|
||||
|
Submit and issue ticket to ESET.
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM |
|
#11
|
|||
|
|||
|
Quote:
I've tried that and it was only deleted if it contained malicious records. I assume some malware modifies it which triggers detection and the file is removed. I was unable to reproduce it with a clean hosts file. I'd suggest supplying the content of your ESET's quarantine as well as your Threat log to ESET for analysis. |
|
#12
|
|||
|
|||
|
Quote:
Tnx for the tips Marcos, but it's to late. I already uninstall NOD ![]() Btw, I try this infected soft through Sandboxie, and he try to replace hosts, when he deleted by NOD. This probably cause that bug, and he constantly delete hosts files during reboot.. |
|
#13
|
||||
|
||||
|
probably a malware program running that tried to mod hosts each boot up imo not from nod..
__________________
Meatwad you're up next, with your knock-knock. Meatwad make the money see. Meatwad get the honeys G. Drivin in my car, living like a star ice on my fingers and my toes, and im a taurus "Some days your the windshield. Some days your the bug" Eset ESS V6 / Webroot WSA / Avast! IS V8 |
|
#14
|
|||
|
|||
|
Deleting hosts file is not a bug as long as it contains malicious records.
|
|
#15
|
|||
|
|||
|
* it's NOD bug.
DONE here & with NOD! Arrivederci! Last edited by Cudni : May 27th, 2012 at 04:49 AM. Reason: * mod edit |
|
#16
|
||||
|
||||
|
Removing malware is what AV does and if it happens to be in hosts file then it has to go. Thanks all.
__________________
once we only had ideals, today they are the only things we are missing Microsoft MVP, 2006 - 2013/14 |
|
#17
|
|||
|
|||
|
Quote:
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|