A very strange thing is happening on my Windows 11 installation on every reboot:
A loopback rule that points www.virtustotal.com to 127.0.0.1 (localhost) add itself on every reboot, I'm suspecting some malicious malware tool... My Windows Defender is not reporting anything.
Anyone else have this issue? I can remove the rule manually but I like a permanent solution and of course finding the perpetrator. This is the rule automatically adding itself to my Win11 hosts file:
127.0.0.1 www.virustotal.com
What can I do to further investigate this strange issue?
Edit: I found the perpetrator using free "Kaspersky Virus Removal Tool", which did a great job indicating the path of the malware file. The malware was also running in my System Memory which caused the adding of the "127.0.0.1 www.virustotal.com" line in my hosts file.
After deleting the malware disguised as "msedge.exe" and rebooting the pc, the trojan horse was out of my pc case and the hosts file found back its peace.