Help - Search - Members - Calendar
Full Version: Supertrick XG
B.I.S.S. Forums > Bluetack Software > HOSTS Section > Host Submissions
Pages: 1, 2
Moore
Hmm , Iceblue did you have anything to do with this biggrin.gif



http://www.lavahelp.com/articles/v6/04/05/2201.html

QUOTE
Attention Ad-Aware users
Ad-Aware has decided to include a new detection when scanning the HOSTS file. This now creates a "Bad hosts file entry" in the log file generated at the end of a scan. The best thing to do is to place a check in each entry, right-click and select: "Add selection to ignorelist". Otherwise if you let AWW "fix" these items it will trash the HOSTS file! Even if you have it "locked" by [example] SpywareBlaster or Winpatrol. It does not return the attributes and renames the HOSTS file incorrectly to hosts. [more info]

SYMPTOM
During an Ad-aware scan, several entries are listed in the scan results indicating that a "Possible Hostsfile Hijack" is taking place.  The entries listed may be created by a known source, such as a pre-assembled hosts file designed to help prevent items such as trackware from being successfully downloaded, or by a program designed to use the hosts file in its normal operation.

CAUSE
Some of the entries included in these pre-assembled hosts file lists and by some programs which use the hosts file are also used by items in Ad-aware's detection.  Since Ad-aware cannot determine the source of the entry in the hosts file, and that the entry could possibly be created by an item in Ad-aware's detection, the item in the hosts file is listed.

RESOLUTION
If the system is using a hosts file which has been pre-assembled, or is running a program which utilizes the hosts file, and the listing is related to these reasons, add the items listed by Ad-aware to the ignorelist to prevent their listings during future scans.
Xero Grid
That's the link people at the Lavasoft forum were pointing me to... and everyone else who said Ad-aware makes false/positives regarding certain HOSTS file entries. dry.gif

It would be pretty funny if iceblue had something to do with that. laugh.gif

-- Xero Grid --
Moore
So it's just the disclaimer then , i thought it might have ben new laugh.gif oh well , silly me tongue.gif . i might start sleeping a bit more.. hard to think clearly ... ohmy.gif
iceblue
QUOTE
It would be pretty funny if iceblue had something to do with that. 

biggrin.gif lol, no, that was before my time and was posted when I looked through that thread.
But I can tell you that a major review has been initiated for all the CWS domains and IPs,
and that's a good sign across the board, but will involve re-jigging block lists when it's done.

And there's plenty of stirrings happening in this area.
Mike Burgess is giving Lavasoft a decent serve here: cool.gif
http://www.lavasoftsupport.com/index.php?showtopic=28691

Me, I'm more interested in working out the problem. Ad-aware does not pick up those exact entries in my Hosts file. Why is this?
Still getting a handle on those flagged entries, and I think the bookmarked Spybot entry might hold a clue. Wondered if the properties of the file edit/- that contained those entries was being picked up by the scan - just thinking aloud here - just how those entries are referenced might be the key - is it part of the formatting?
Could a simple merging of a hosts file like hpgurus, using the updated enties to overwrite the old ones, and try it out hosted on another site, to see if Ad-aware still flags it. Quite simply, there has to be a way to include those entries and not have them flagged.
What are your thoughts? There's a need to run a few tests, IMO.

Ice
iceblue
and ya gotta love Merijn....he always fixes the problems overnight...

QUOTE
CWShredder 1.59.0000
* Added new variant CWS.Docobj (uses filename docobj.exe, hijacks to fast-search.us, also drops winstyle.css and winboot.hta).
* Added new variant CWS.Hputi (hijacks to solongas.com and hp.uti, uses filename sysstartup.exe).
* Added new variant CWS.Jsconsole (hijacks to myexexex.com, uses filename jsconsole.dll and c:\spad\start.html, creates fake 'Javascript Console' buttons in IE buttons bar).
* Fixed CWS.Msconfig bug where legitimate Msconfig autorun entry was deleted. This would've happened earlier had someone actually told me about it. tongue.gif
* Fixed a F/P: several entries from the Spybot S&D hosts file were deleted.


Ice
r00ted
this thread could be stickied to make the forum easier to navigate.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.