Re: "Security site" address in my Hosts file

From: George (George_at_GreatWhiteNorth.ca)
Date: 11/02/04


Date: Tue, 2 Nov 2004 12:00:07 -0500


> Presumably you meant the fields within the extra or questionable entry
> were the other way around (where the IP address is listed first and then
> followed by the IP name).

Yes, you are right.

> "nslookup www.dcsresearch.com" returns:
> Name: www.dcsresearch.com
> Address: 12.170.116.68
>
> "nslookup 64.91.255.87" returns:
> Name: diamondcs.com.au
> Address: 64.91.255.87
>
> So someone or something added an entry to your hosts file to redirect
> you from www.dcsresearch.com to diamondcs.com.au. You enter
> http://www.dcsresearch.com but end up at 64.91.255.87 (instead of
> 12.170.116.68). ARIN's WhoIs (http://ws.arin.net/cgi-bin/whois.pl)
> lists 12.170.116.68 as allocated to AT&T Worldnet, so
> www.dcsresearch.com is a customer of AT&T. ARIN's WhoIs lists
> 64.91.255.87 as allocated to LiquidWeb in Michigan, USA and yet the TLD
> (top-level domain) for the domain was ".au" which is Australia. If you
> run "tracert 64.91.255.87", you'll see it hit LiquidWeb.com and then
> diamondcs.com.au. Could be LiquidWeb is a webhost provider.
> http://whois.aunic.net/ lists the registrant for diamondcs.com.au
> Diamond Computer Systems Pty. Ltd. in Melbourne (AU). A domain lookup
> on dcsresearch.com says it is owned by Tri-State Computer Centre Ltd in
> Pennsylvania, USA (which was also found at
>
http://tri-state-computer-centre-limited.9900118303001.worldpages-ads.com/).
> So this hosts file entry would redirect you from Tri-State's
> www.dcsresearch.com domain by IP name to Diamond's web site by IP
> address that is webhosted by LiquidWeb.
>
> When did you last run a full scan using a recently updated virus
> program? Have you scanned for malware by using Ad-Aware and Spybot?

I found the Hosts entry while cleaning out my computer using Spybot. I use
Norton AV regularly and have it running in the background all the time, but
recently I was seeing a lot of popups and a run of Spybot found several
spyware programs.

>
> Isn't Diamond Computer Systems the makers of TDS-3, an anti-trojan
> program? I did a Google on TDS-3 and it brought back
> tds.diamondcs.com.au. I've seen lots of folks praise this anti-trojan
> hunter program. While malware might add an entry to a hosts file to
> keep you from getting to anti-virus/trojan/malware web sites, this entry
> directs you to such a site.

Strange. Someone's obviously gone to a lot of trouble to do this.
Thanks for your input.
George

>
> --
> _________________________________________________________________
> ******** Post replies to newsgroup - Share with others ********
> Email: lh_811newsATyahooDOTcom and append "=NEWS=" to Subject.
> _________________________________________________________________
>



Relevant Pages

  • Re: "Security site" address in my Hosts file
    ... > I've just noticed an extra address in my Hosts file. ... Presumably you meant the fields within the extra or questionable entry ... Could be LiquidWeb is a webhost provider. ... Diamond Computer Systems Pty. ...
    (alt.computer.security)
  • Re: Adsense
    ... I'm not afraid to let you publicly humiliate yourself ... Locking the HOSTS file is a good start. ... You create an entry ... porn is the money maker. ...
    (alt.marketing.online.ebay)
  • Re: error 5006 - Microsoft Project Server was unable to log you on at this time...
    ... entry to your hosts file. ... > Thanks for your input - I checked my Hosts file again - you refer to ... > this might be a solution in my case with Project Server 2003? ... >> Gary Chefetz ...
    (microsoft.public.project.pro_and_server)
  • Re: MX failure - going to A record
    ... That sounds ominous - if an entry for mindspring.com in your hosts file ... FallbackMXhost or FallbackSmartHost or somesuch? ... I have a broadband connection, and use it to connect to a second ISP ...
    (comp.mail.sendmail)
  • Re: Hosts file
    ... I was just using SimpleText to edit the Hosts file, ... from the "System Folder" directory instead of "System", ... Anyhow, I cannot get the entry in NetInfo to function, and the only ... > Netinfo utility found in the Utilities folder to verify your entries are ...
    (microsoft.public.mac.explorer)

Quantcast