Go to Advice start page

Check Your Hosts File VERY Carefully

The bad guys have been using entries in YOUR Hosts file, to block you from accessing the websites that can protect YOU, for quite a while now. So instructing you to examine your Hosts file, for entries like:

	127.0.0.1 www.symantec.com
is nothing new. This entry, if present in your Hosts file, will block you from getting access to the Symantec servers, including online help, and LiveUpdate. It's one of the earliest hijacks used by the bad guys.

Anyway, I just copied the above example line from this example Hijacked Hosts file. Go there, and see if you can find the example.

"No", you mighht answer. "The only non-comment line is:
	127.0.0.1 localhost".
But, you would be wrong. Look again, but look more carefully.

Now aware of this devious, and o so simple, mechanism that the bad guys can use, check YOUR Hosts file. To clean your Hosts file, if anything of interest is found, and assuming NO valid entries other than "127.0.0.1 localhost", simply:
  1. Place the cursor at the end of the "127.0.0.1 localhost" line.
  2. Hold down "Ctrl" and "Shift", and hit "End".
  3. With everything after "127.0.0.1 localhost" highlighted, hit "Delete".
  4. Save Hosts, as name "Hosts." (note the "."!), as type "All Files".
If you find that you have valid entries other than "127.0.0.1 localhost", which you need to retain, be aware of this hijack, and edit the file very carefully.