Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Hosts file is detected as malware in Windows Defender


View products that this article applies to.

Symptoms

Consider the following scenario: 
  • You install Windows 8.
  • You change the Hosts file by specifying custom IP-address-to-host-name mappings to prevent users from browsing to some websites.
  • You run a scan in Microsoft Windows Defender.
In this scenario, the Hosts file is detected as a SettingsModifier:Win32/PossibleHostsFileHijack malware threat by Windows Defender.

↑ Back to the top


Cause

This issue occurs because Windows Defender may determine incorrectly that the Hosts file was changed by malware, such as adware or spyware. Typically, malware programs change the Hosts file to redirect users to malicious websites. Therefore, Windows Defender may detect the Hosts file as a security threat.

↑ Back to the top


Resolution

To resolve this issue, exclude the Hosts file from scanning in Windows Defender. To do this, follow these steps:
  1. Open Windows Defender.
  2. On the Settings tab, click Excluded files and locations.
  3. Under File locations, click Browse.
  4. Locate and then click the Hosts file.

    Note By default, the Hosts file is located in the %systemroot%\system32\drivers\etc folder.
  5. Click Add, and then click Save changes.

  6. Exit Windows Defender.

↑ Back to the top


References

For more information about the SettingsModifier:Win32/PossibleHostsFileHijack malware threat, go to the following Microsoft Malware Protection Center encyclopedia entry:

SettingsModifier:Win32/PossibleHostsFileHijack

For information about how to reset the Hosts file to the default settings, click the following article number to go to the article in the Microsoft Knowledge Base:
972034 How can I reset the Hosts file back to the default?

↑ Back to the top


Keywords: kbsurveynew, kbentirenet, kbprb, kbtshoot, kb

↑ Back to the top

Article Info
Article ID : 2764944
Revision : 1
Created on : 1/7/2017
Published on : 10/5/2012
Exists online : False
Views : 173