Strange looking Host found?

dwdraw2

New member
Local time
12:29 AM
Messages
31
I ran a small check with the "MiniToolBox," and this is what I found in the Hosts content:

54.204.28.26 imfpmncmbojnbdhnogcegojocabhpbnh. What is this, is it Ad-ware? I would appreciate it if someone could let me know. I can find it and delete it if necessary, I have no problem with that. But It just seems that it doesn't belong? I ran: Hitman Pro, Malwarebytes Pro, and Avast, but they never caught it.



MiniToolBox by Farbar Version: 18-12-2013
Ran by Dan (administrator) on 26-01-2014 at 23:34:06
Running from "C:\Users\Dan\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= Hosts content: =================================

54.204.28.26 imfpmncmbojnbdhnogcegojocabhpbnh
127.0.0.1 localhost


Thanks for your time.

dwdraw2 :confused:
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
It seems like Adware to me. You can use SuperAntiSpyware to remove it.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Bulid/Self made
OS
Windows 11 x64
CPU
i5 2500K @ 3.3 GHz
Motherboard
ASUS P8 Z77 V pro
Memory
16 GB DDR 3 @ 1600Mhz
Graphics Card(s)
MSI 1050TI 4GB OC version
Sound Card
On Board (Realtek HD audio)
Monitor(s) Displays
Samsung 22" LCD
Screen Resolution
1920*1080
Hard Drives
Seagate 1 TB, WD 1TB, Seagate 2 TB ( I use a lot of space)
PSU
coolermaster 750 W
Case
Coolermaster HAF912
Cooling
Coolermaster hyper 212 EVO
Keyboard
Samsung
Mouse
Dell Wireless
Internet Speed
Wireless 50 Mbps
Antivirus
AVG 2016 Internet Security
Browser
Google Chrome
The easiest solution might be to simply reset the hosts file and flush the DNS cache.

Run this .bat file as administrator to do that - it will automatically reboot your computer when its completed.

View attachment flush.bat
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
The IP address resolves to:
Code:
ec2-54-204-28-26.compute-1.amazonaws.com
The letters...
imfpmncmbojnbdhnogcegojocabhpbnh
...look very much like a Chrome extension ID.

I've never seen a Chrome extension ID in the HOSTS file.

Google returns a few hits on those letters...
...but you should be careful if you research this.
Dr.Web Anti-virus - How To Remove Virus (Adware.Downware.2032) - [DRWEBHK.COM]

Look in Programs and Features for StartSavin or Start Savin

Remove any Chrome extensions with the same name and/or any extension that you don't want. But they might come right back. If you do have an extension written by the grey hats at 215apps, you might be in for a long thread like this one http://www.sevenforums.com/system-security/316404-instant-savings-app.html
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Thanks everybody for your suggestions. I will embark on them to see what works or, what happens? I appreciate your help.

Thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Were you using any Amazon Web / Cloud services?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home built (GeneO industries)/Model 4
OS
Windows 10 Pro. EFI boot partition, full EFI boot
CPU
i7 4770k 4.4GHz (44-44-43-43 turbo) @ 1.248V
Motherboard
ASUS Maximus VI Hero
Memory
16GB (8GBx2) @2200 MHz G.skill Sniper 10-11-10-30-1, 1.6V
Graphics Card(s)
MSI GTX 970 Gaming 4G
Sound Card
Onboard SupremeFX Audio
Monitor(s) Displays
NEC Spectraview 2490WUXi-SV
Screen Resolution
1920 x 1200
Hard Drives
Samsung 850 Pro 256GB (OS), Samsung 2x 128GB 840 Pro SSD in RAID0, 3x WD Blue 6Gb/s 1TB RAID0, WD 2TB Black external USB 3.0, 2TB WD20EARS Green external USB 3.0, 2x 500GB Seagate and 1 750 GB external USB, 1x 350GB external USB3
PSU
Seasonic X-850 (2012 KM3 model)
Case
Fractal Design Define R4
Cooling
NH-D14, NF-F12, NF-A15; NF-P14, NF-P12,NF-A14, S12A PWM
Keyboard
Cooler Master Storm Quickfire Rapid - Brown
Mouse
Logitech G602
Internet Speed
126.4 Mb/s down, 24.3 Mb/s up
Other Info
USB 3.0 x8 , SATA III x8, eSATA, USB 2.0 x6. Samsung DVD R/W drive.

WEI: CPU 7.8, Memory 7.9, Graphics 7.9, Disk 7.9
Thanks for the reply.

I don't actively use any web/cloud services, other than Hitman Pro, which uploads to the cloud to check on a potential virus. Sometimes I watch a movie from Netflix, but there, I get hit with "PUP's from time to time. I have no problem getting them out. The other day, I just removed a virus called "pcreg." That's been on my computer for a few months. I thought that was a legit function. It wouldn't let me open it, so I just let it be until I decided to check it out on the web the other day. Turned out to be a virus. I used SuperSpyHunter to browse to it then pried it out, I then took SuperSpyHunter off because it is a memory hog. I used the trial version.

Lately, I have reading that the Host files can be updated? I have been looking around to figure out how to do that. I haven't got a solid grip on that yet. So, I haven't done anything with the files. From what I understand thus far, the files may or may not be needed, depending on the programs one has in their computer. The files can be used to re-direct ad's, from what I read. So, they can be used in your favor. But, a hacker can use them against you too.

Some of these sites say it's easy to work with Host files. For me, easy is when you understand it-I don't yet. So I haven't made a move on them. So, for now, I just stare (glare) at them from time to time.

If you can find out, if I need only one file, the 127.0.0.1 Localhost, for my computer to keep running the associated programs, then I can delete the other host (54.204.28.26 imfpmncmbojnbdhnogcegojocabhpbnh). I would appreciate your help here.

Thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
The HOSTS file that comes with Windows 7 is shown in the code box below.

Every line that starts with a # character is a remark line (comment line).

As you can see, all lines are comments. You do not need a HOSTS file at all.

The zipped (compressed) file attached to this post contains all of the (unmodified) files that are normally found in this folder: C:\Windows\System32\drivers\etc

Code:
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
#      102.54.94.97     rhino.acme.com          # source server
#       38.25.63.10     x.acme.com              # x client host

# localhost name resolution is handled within DNS itself.
#    127.0.0.1       localhost
#    ::1             localhost
 

Attachments

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Thanks for the reply.

I will check this out. I will either delete both or just the one.

I appreciate your help.

Thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
The HOSTS file (and the other files in the folder) are protected. You can copy the HOSTS file to the desktop, change it and then copy it back. Or, just copy the one that I attached.

Do you have the Chrome browser installed?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Make sure proxy settings are disabled ....


Disable the proxy settings in Internet Explorer:
1) Under “Tools” in the browser tool bar select “Internet Options”.
2) In the “Internet Options” window that pops up, click the “Connections” tab at the top.
3) Click “LAN Settings” near the bottom of the “Connections” section.
4) If the “Proxy server” checkbox is marked with a check, click it to deselect/uncheck it.
5) Click “Ok” to close the “Local Area Network (LAN) Settings” window.
6) Click “Ok” to close the “Internet Options” window.
Reboot
Make sure "Proxy server" is still disabled under your LAN Settings.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
No, I do not have the Chrome browser installed. I did have it on but several days ago I uninstalled it. I was having some problems with it. I installed Firefox in it's place.

Here's what I did so far: I found the folder by your posting (thanks.) I went to the folder, opened the window, erased (deleted) the file closed just the window, and reopened it, only to find that it came back?

So, which files do I copy from your post to copy into the Host file?

Thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Thanks Jacee for the reply.

I'll make a copy of the instruction and follow them to the "T."

Thanks again

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Jacee, do I go back and reset the Proxy after changing the Host?

thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Thanks USERNAMEISSUES for the downloads. I have them downloaded in explorer.

I'll check back later to see if there is more instructions.

Thanks again.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Just make sure proxy settings are disabled! ... it doesn't really matter what order.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Thanks Jacee and Usernameissues.

You both have been a lot of help. Jacee, the Proxy unchecked. I pasted the text provided by Usernameissues. and below is a copy of a system check by "rkill":


Rkill 2.6.4 by Lawrence Abrams (Grinler)
Bleeping Computer - Technical Support and Computer Help
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
RKill - What it does and What it Doesn't - A brief introduction to the program - Anti-Virus and Anti-Malware Software

Program started at: 01/28/2014 06:09:41 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Firewall Disabled

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 01/28/2014 06:09:52 PM
Execution time: 0 hours(s), 0 minute(s), and 11 seconds(s)


The text provided by Usernameissues cleared the rogue host. Awesome!

Thanks again for your help.

Thanks for your time.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
No, I do not have the Chrome browser installed. I did have it on but several days ago I uninstalled it. I was having some problems with it. I installed Firefox in it's place.

Here's what I did so far: I found the folder by your posting (thanks.) I went to the folder, opened the window, erased (deleted) the file closed just the window, and reopened it, only to find that it came back?

So, which files do I copy from your post to copy into the Host file?

Thanks for your time.

dwdraw2
This might not be a problem - but it is not the norm for a stock install of W7. It might be AVAST that is putting the file back or it might be something bad putting it back (or changing it). Jacee will walk you thru checking for bad things.



You might not need this info now, but you can copy/paste any or all of the standard (unmodified) files from that zip into that folder. In the detail view, they should look close to this:

hosts.PNG
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
You could just Remark the suspicious entry (see post #8) and then see if it reappears when you:

  • Reboot
  • Try to browse the Internet
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
n/a
OS
W7 Ultimate SP1, LM19.2 MATE, W10 Home 1703, W10 Pro 1703 VM, #All 64 bit
CPU
AMD Phenom II x6 1100T, 3.3 GHz
Motherboard
ASUS M4A88T-M/USB3 (AM3)
Memory
12GB DDR3 1333 G-Skill (4GB x 2), G-Skill (2GB x 2)
Graphics Card(s)
NVIDIA GeForce GTX 660
Sound Card
Realtek?
Monitor(s) Displays
Samsung S23B350
Screen Resolution
1920x1080
Hard Drives
WD Green 2TB (SATA), WD Green 3TB (SATA), WD Blue 4TB (SATA), WD Blue 6TB (SATA)
PSU
Cooler Master
Case
Antec GX300 Tower
Cooling
3x Antec TRICOOL 120mm Fans
Mouse
Wired Optical
Internet Speed
DSL
Antivirus
Avast
Browser
Pale Moon (64 bit)
Other Info
2018-12-27 Upgraded HDDs
2015-12-10 Upgraded case, graphics card, storage
2015-08-15 Upgraded motherboard & RAM
2015-07-15 Upgraded LM17.1 to LM17.2
Thanks for the reply Usernameissue.

It took a few tries, but it finally took the pasted files. I have checked it and your files have not changed. It worked. The Rkill list above shows the host with "no issues found." I'm thinking that Chrome might have put that strange host there when I installed it-if not maybe someone else did? But anyway, it's finally gone thanks to the files you sent to me.

I saved those files in case that I might need them later-never know.

Thanks for your time-I appreciate it.

dwdraw2
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Home, 64 bit
CPU
i7 quad core, 64 Bit
Memory
6 GB
Antivirus
Avast
Browser
IE
Back
Top