Main Forum > General Computer Support
host file got hijacked ? (solved)
Gamezertruth:
I have a serious problem and I need help because of that something strange is change the host files on my system ! and i have already done a malware scanning with many Portable protection programs and Some of these programs have a feature to check and cleanup/restore the host file and i have also ran Tweaking.com - Windows Repair and unable to rest my host !
Rkill 2.7.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 05/10/2015 07:45:52 PM in x86 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Users\b\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe (PID: 2280) [UP-HEUR]
1 proccess terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
* HKLM\Software\Classes\exefile\shell\runas\command\\IsolatedCommand was changed. It was reset to "%1" %*!
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
20 out of 35 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 05/10/2015 07:47:40 PM
Execution time: 0 hours(s), 1 minute(s), and 47 seconds(s)
Samson:
Gamez, do you use/ have "Unchecky" installed? Those host file entries look like they are from Unchecky, blocking connections to those sites.
"The latest version of Unchecky adds entries to the Windows hosts file which block access to select servers used by installers to deliver third party offers. This is done automatically and without option to block this from happening. The entries are removed again when you uninstall the program."
Samson.
Gamezertruth:
aha I don’t know that and i don’t have Unchecky Installed on my pc/i don’t use Unchecky !
Samson:
If not Unchecky then some other security program? Those entries in the Hosts file are not malicious, they are entries that have been added by a security program to block advertising software.
Gamezertruth:
--- Quote from: Samson on May 10, 2015, 11:33:29 am ---If not Unchecky then some other security program? Those entries in the Hosts file are not malicious, they are entries that have been added by a security program to block advertising software.
--- End quote ---
I don’t think so , but If that is one of the security software does add host files (then, which security program is to do this?) And I honestly do not feel safe because of these entries :sarcastic:
Navigation
[0] Message Index
[#] Next page
Go to full version