Jump to content

Malwarebytes

host file hi-jack


9 replies to this topic

#1
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
i have the hostsman host file wich has mvp/hp hosts/ hp hosts partial/ hp ad and tacking and peter lowes hosts as well as spyblasters hosts and search and destroys hosts.

on a scan with search and destoy (spybot) i am getiing 9 entries flagged as being Microsoft.Windows.RedirectedHosts.
is this a incomplabilty issue with spybot or are theses really hi-jacked?

i dont want to post the entries in case someone whos not knollageble in antimalware decides to look at the sites as the sites might be classed as rouge witch i think they are and this is just spybot playing up and not a hi jack.


one off them really bugs me becuase it relates to the author off hi jack this in its name.
i know the author might have changed sites.

Merijn.nu being the real site.

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Can you post the entries in question?
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
hi mystery.

Microsoft.Windows.RedirectedHosts
www.experts-exchange.com=127.0.0.1
experts-exchange.com=127.0.0.1
merijn.org=127.0.0.1
www.merijn.org=127.0.0.1
ask.com=127.0.0.1
www.ask.com=127.0.0.
www.google.co.kr=127.0.0.1
www.google.com.tr=127.0.0.1
google.co.kr=127.0.0.1


i think there rouge sites imo,and i can set spybot to ignore this.however i am obviously not 100% as to why their being flagged thou. or i wouldnt ask.

#4
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
These are F/P's and should've been removed when Hostsman sync'd with hpHosts;

www.google.co.kr=127.0.0.1
www.google.com.tr=127.0.0.1
google.co.kr=127.0.0.1

The rest aren't F/P's ;)
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
there not f/ps and should be removed? go ahead and let spybot remove them?
and what do i do about the f/ps?

#6
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
You can let it remove the Google ones, but not the rest.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
oh stuipd me,i understand what your saying now.
sorry mate its been a crazy day and some.

thanks for your time.

#8
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
No problem :)

Btw, I'm hoping to have a new hpHosts release out next week (would've been this week, but getting dragged out for my birthday tomorrow so don't have time), so HostsMan would've removed the google ones for you anyway ;)
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
now i understood it more and relised it wasnt a threast i didnt remove it as yet,so i guess i will wait till next week anyway.

in advance as i wont be online t/m or till next week.

#10
mbyuser

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 234 posts
i cant get that jpg. to work.

oh well it was a happy birthday gretting.

happy birthday ;)





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us