PC Review


Reply
Thread Tools Rate Thread

What does Defender action "Clean" mean?

 
 
Buck
Guest
Posts: n/a
 
      10th Mar 2009
Please help. Defender is telling us that our Hosts file is a possible Hijack
situation:

SettingsModifier:Win32/PossibleHostsFileHijack

Defender suggests the action "Clean". No idea what to do. Windows Help file
has no reference to an action named "Clean", there are no results when
searching for "clean" at the Defender forums at MS, and there is no mention
of an action named "Clean" anywhere in Defender documentation at MS. But
clicking on actions reveals only the following 4 choices: Clean, Ignore,
Remove, Quarantine

Resources File is listed as:
c:\windows\system32\drivers\etc\hosts

There is no other information listed on the Scan Results page.

What does "Clean" mean and is this a real threat?

 
Reply With Quote
 
 
 
 
RonKa
Guest
Posts: n/a
 
      10th Mar 2009
From info in the Announcements Section, this appears to be a False Positive.
I performed the CLEAN and now I am left with the choice to PERMIT or DENY the
ACTION. On the Review Changes to your computer settings line of WD it
states: "Permit changes only if you trust the program or the software
publisher. (And Importantly) Windows Defender can't undo changes you
permit."

Detected changes: Removed: 127.0.0.1 localhost

Therefore, I am not sure what to do first. Permit or Deny or update with
the WD fix (update) out today.

Question to those who understand the CLEAN function: Should I DENY the
change?

I just ran 'Norton IS' for 1h10 minutes and it did not find a problem.

Buck: I suggest that you hang tight and do not perform the CLEAN.


"Buck" wrote:

> Please help. Defender is telling us that our Hosts file is a possible Hijack
> situation:
>
> SettingsModifier:Win32/PossibleHostsFileHijack
>
> Defender suggests the action "Clean". No idea what to do. Windows Help file
> has no reference to an action named "Clean", there are no results when
> searching for "clean" at the Defender forums at MS, and there is no mention
> of an action named "Clean" anywhere in Defender documentation at MS. But
> clicking on actions reveals only the following 4 choices: Clean, Ignore,
> Remove, Quarantine
>
> Resources File is listed as:
> c:\windows\system32\drivers\etc\hosts
>
> There is no other information listed on the Scan Results page.
>
> What does "Clean" mean and is this a real threat?
>

 
Reply With Quote
 
RonKa
Guest
Posts: n/a
 
      10th Mar 2009
Okay. I selected DENY and then ran a WinDef Scan and got the False Positive
again (I am glad I did not select PERMIT!). Then I got the WinUpdate notice
that there were 5 updates ready. I selected 4 and left the WinDef 1.53.228.0
unchecked. After the 4 other updates were installed, configured, and after
the Restart, I installed the WinDef Update .228.0 with an automatic Restore
Point (so is would have a separate RS from the other 4 updates, in case there
were problems with WinDef update). After a Scan, the .228.0 update removed
the False Positive inherent within 1.53.256.0.

The irony is I was having trouble accessing the Internet with similar
results stated in the False Positive Host error. Coincidence!

In the future, instead of jumping to click on CLEAN, I am going to click on
IGNORE or simply close WinDef (as I most often do not use it except to keep
it updated since I use Norton IS), check here first to get info, and then go
from there.

Lesson Learned: False Positives Happen with MS Windows Defender.

Thanks go to Tim who posted on the Announcements section of this Newsgroup
for spotting the False Positive.


"RonKa" wrote:

> From info in the Announcements Section, this appears to be a False Positive.
> I performed the CLEAN and now I am left with the choice to PERMIT or DENY the
> ACTION. On the Review Changes to your computer settings line of WD it
> states: "Permit changes only if you trust the program or the software
> publisher. (And Importantly) Windows Defender can't undo changes you
> permit."
>
> Detected changes: Removed: 127.0.0.1 localhost
>
> Therefore, I am not sure what to do first. Permit or Deny or update with
> the WD fix (update) out today.
>
> Question to those who understand the CLEAN function: Should I DENY the
> change?
>
> I just ran 'Norton IS' for 1h10 minutes and it did not find a problem.
>
> Buck: I suggest that you hang tight and do not perform the CLEAN.
>
>
> "Buck" wrote:
>
> > Please help. Defender is telling us that our Hosts file is a possible Hijack
> > situation:
> >
> > SettingsModifier:Win32/PossibleHostsFileHijack
> >
> > Defender suggests the action "Clean". No idea what to do. Windows Help file
> > has no reference to an action named "Clean", there are no results when
> > searching for "clean" at the Defender forums at MS, and there is no mention
> > of an action named "Clean" anywhere in Defender documentation at MS. But
> > clicking on actions reveals only the following 4 choices: Clean, Ignore,
> > Remove, Quarantine
> >
> > Resources File is listed as:
> > c:\windows\system32\drivers\etc\hosts
> >
> > There is no other information listed on the Scan Results page.
> >
> > What does "Clean" mean and is this a real threat?
> >

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
"CELL("FILENAME") NOT UPDATE AFTER "SAVE AS" ACTION yossie6 Microsoft Excel Misc 1 16th Jun 2008 12:16 PM
Windows defender "action taken" markiemark Security and Anti-Spyware Community 0 26th Dec 2007 10:06 PM
Why does FP insert 'action="_derived/nortbots.htm" webbot-action=" =?Utf-8?B?aGF2YXN1?= Microsoft Frontpage 2 12th Mar 2007 02:50 AM
Set up "Clean" User or "Clean" boot for max memory for video editi =?Utf-8?B?bWltaQ==?= Windows XP Setup 1 13th Feb 2005 12:30 AM
<FORM METHOD="post" onSubmit="return fieldcheck()" name="orientation" action="http://ws-kitty.BU.edu/AT/survey/orientation/script/write.asp" language="JavaScript"> Joeyej Microsoft ASP .NET 0 4th Jun 2004 08:55 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:57 PM.