Version: 2008
  • On BNET: Online porn struggles for profits
Advanced Search
advertisement
advertisement

Forum display:

Spyware, viruses, & security : Windows Defender: False alarm triggered by hosts file

by Marianna Schmudlach Moderator - 3/10/09 8:30 AM
Post 1 of 1

Windows Defender: False alarm triggered by hosts file

by Marianna Schmudlach Moderator - 3/10/09 8:30 AM

10 March 2009

Since Monday evening, Microsoft's Windows Defender spyware detection software has mistakenly raised the Win32/PossibleHostsFileHijack alarm on some clean PCs. According to Microsoft, the error is caused by a flawed signature deployed via automatic update on Monday. Another signature update has now been issued to solve the problem.

In our German partners' editorial offices, the erroneous behaviour has so far only affected a few Windows Vista systems. The exact conditions that trigger the false alarm are still unclear. According to Microsoft, the problem is caused by the hosts file. Windows uses this file for the static name resolution between computer names and IP addresses and many malware samples target it for manipulating network traffic.

Users are advised to ignore the warning and update the signature database of Windows Defender via the Windows Update feature. Those who have put the alleged intruder into quarantine, or even deleted it, should use the Notepad text editor to at least create a minimal hosts file consisting of the following two lines:

127.0.0.1 localhost
::1 localhost

http://www.h-online.com/security/Windows-Defender-False-alarm-triggered-by-hosts-file--/news/112814

Forum legend:
Locked Locked thread
Moderator Moderator
CNET staff CNET staff
Samsung staff Samsung staff
Norton Authorized Support team Norton Authorized Support team
AVG staff AVG staff
Windows Outreach team Windows Outreach team
Dell staff Dell staff
Intel staff Intel staff
Powered by Jive Software