Norton modify hosts file and says it’s malware

I replicated the problem on a second PC to show the error process.

Here is my hosts file before I restarted my PC and ran a full scan

After I restarted it Norton (I assume) added these entries at the end of the file

I ran a full scan and Norton detected malware in the hosts file

After you quarantine this file your hosts file is basically deleted

What’s going on?

One thing to note you cannot get rid of the stuff norton added at the bottom even if you restore the file. I believe they added that code maybe 2 days ago. Even if you make a new hosts file using microsofts instructions. Something has gone horribly wrong here.

1 Like

@Mykola Norton is aware of and monitoring this thread and one other with the same issue. I too am having this issue as well. Its 100% Norton generated and should NOT be happening. Overwriting the Windows hosts files in a serious no no.

SA

If this is the case will norton repair the hosts file with the windows instructions onces its fixed. Cant really edit it back in when norton marks it as malware when i do

I just encountered this issue as well a few moments ago as I was prompted to do a scan as today is the typical day (patch Tuesday) for updates to be made available from various companies. If there are others getting those scan prompts there could be a lot of attention on this bug today/tomorrow.

I just find it hilarious that norton is updating the hosts file, which it really shouldn’t be doing, and then flagging the new entries as malware. :laughing:

Quarantining the file could blow away someones carefully crafted host file if they need specific entries in the host file for their network to function correctly. Not good!

1 Like

I deleted the hosts file that norton generated (that only has the norton add ons) after quarantining the original and restored the quarantined file (that does have the microsoft text and the norton add ons). Is this safe until they get to the bottom of this. I really don’t know. I’ve had issues with norton before and this does seem like a genuine false positive due to Norton tomfoolery. .but, damn, what’s going on?

Is the norton add ones part of its webshield that they just didn’t do properly?

We won’t know what and why this is happening until Norton has had a review of it. They ARE actively investigating. This is definitely Norton writing into the hosts file, if I remove those entries it writes a brand new host file. Please note that the standard Microsoft text is missing after deleting the current host file, rebooting and allowing Windows to recreate the file. Not good. I might add that, I HAVE NOT ran Smart Scan or any other Norton scan prior to nor since this discovery. Norton is NOT marking my host file as malware.

SA

I just unquarantined the original hosts file that had both the standard microsoft text and norton add-ons. I’m gonna leave it be now since this is norton and not anything else. Is that okay?

Yes!! Allow Norton to tell us what is going on to be safe. This is the format from Norton for a standard host file:

Copyright (c) 1993-2006 Microsoft Corp.

  #	
  # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
  #
  # This file contains the mappings of IP addresses to host names. Each
  # entry should be kept on an individual line. The IP address should
  # be placed in the first column followed by the corresponding host name.
  # The IP address and the host name should be separated by at least one
  # space.
  #
  # Additionally, comments (such as these) may be inserted on individual
  # lines or following the machine name denoted by a '#' symbol.
  #
  # For example:
  #
  #    102.54.94.97  rhino.acme.com   # source server
  #    38.25.63.10   x.acme.com       # x client host
    # 127.0.0.1 localhost
    # ::1 localhost

SA

1 Like

Okay.

On two of my three computers, I kept the norton targeted hosts file in quarantine. Earlier this morning, I restored the targeted host file back into the etc file under system32/drivers. I left the house for a bit but when I came home, I scanned my computer with full scan and came back with no warnings, even though it was the quarantined file. So I went to my second computer and restored the quarantined host file and scanned it and it too came back with a clean full system scan.

I do not know if this is a fluke or something they fixed on their end but that’s the long and short of it.

The quarantined files that are restored include both the microsoft text and what norton added. Computer is also about to update so I’ll see what happens.

Okay so I want to clear a few things up. I believe this is a massive Norton security flaw.

We can all restore the hosts file using the Microsoft support page.

Great? No. As soon as you restart your computer Norton edits the hosts file to look like this adding

127.0.0.1 gen-webserver.local www.gen-webserver.local # gen digital helper server
1.2.3.4 redirector.gen-webserver.local www.redirector.gen-webserver.local # gen digital helper server at the bottom.

If you do clean the file using Norton it will delete the hosts file. Then when you restart your computer it will make a new hosts file that looks like this.

It was my understanding that malware usually modifies this file causing Antivirus software to flag it. Since there is no workaround why isn’t Norton making this a top priority?

The code that’s added

127.0.0.1 gen-webserver.local www.gen-webserver.local # gen digital helper server
1.2.3.4 redirector.gen-webserver.local www.redirector.gen-webserver.local # gen digital helper server

1.2.3.4 is a real IP address is it even safe for us to use our computers seeing how our traffic is being routed through these 2 new entries?

The only solution I can think of and it’s not good because if you restart your computer you get the Norton Code back is to restore the hosts file and never restart your computer and never run a virus scan.

Did you restart your computer after you restored the file? Then ran the scan again? Restoring the original hosts file will work but upon a reboot norton will add it’s code back in the hosts file.

I restored the file that norton detected the first time. It keeps the microsoft text but also still has the norton add ons. I have started restarted a few times and the contents remain. It just doesnt set off the scan anymore. By comparison when i tried this trick last night it gave the same warning and quarantine. Are others still getting warnings?

This happened with my laptop last night. I restored the file using Norton quarantine and it did not detect malware but the hosts file still had those Norton entries at the end of the file. I think this was the second time I had restored the file.

Then I decided to replace the hosts file with a new one (that had the MS code in it) restarted my computer and Norton had put it’s code back in and upon a full scan it came back as malware. There must be a issue with restoring the file that makes it immune to being caught again? (I don’t know I am just speculating)

Make sure you do a full system scan because this is not picked up on a quick scan.

I really want to update Windows as it’s patch Tuesday but a little unsure because I don’t want to brick my PC while Norton are having these issues.

Here’s what I did. This post is a little longwinded, but still.

Went on my main laptop around 9PM, did a smart scan got the malware warning and it quarantined. Panicked checked the other computers, same issue. Restarted a few times, saw that norton replaced the file with their own hosts files. Removed theirs and put the quarantined file back in, scanned that file, still got warnings and requarantined. Some of the tests I didn’t restart computer, i just scanned it got quarantined i added back in, scanned agian, bam quarantined again.

This morning around 6AM, added quarantined file back to computer after removing norton one, scanned, got warning. Removed the norton created hosts file after a restart, added the quarantine file back and still got a warning. Left to do errands. Came back around 12PM, scanned, lo and behold the quarantined file after another test like I described. (that has the microsoft and norton text) didn’t get marked as malware. Added the quarantined back to the other two computers, and again, they did not scan as malware.

It would also come up as a virus during explorer scans whether I scanned the etc folder or just the file itself.

But the hosts file still have the Norton stuff at the bottom? That should not be there. If so we still have the same problem.

In all three instances now, yes, the file contains both the microsoft instructions and the norton additiond

I am doing a system restore to roll back my computer to an earlier date and see if anything changes. I did a restore also last night and this morning on both the other two computers, which did roll the hosts back to their original incarnations before scanning and quarantine but norton did add their additions to the hosts files. During those experiments once restored the files were scanned again and got quarantined again

Based upon what AI has told me my own opinion is that these entries are harmless and flow back into the Norton 360 UI.

This text represents a standard configuration for a hosts file (typically located at /etc/hosts on Linux/macOS or C:\Windows\System32\drivers\etc\hosts on Windows).

It maps specific domain names to local or remote IP addresses, overriding standard DNS lookups.

Breakdown of the Configuration

  • 127.0.0.1 gen-webserver.local www.gen-webserver.local

    • IP Address: 127.0.0.1 (The local machine / localhost).

    • Domains: gen-webserver.local and www.gen-webserver.local.

    • Result: Typing either domain into a browser on this machine routes traffic directly to a web server running locally on the same computer.

  • 1.2.3.4 redirector.gen-webserver.local www.redirector.gen-webserver.local

    • IP Address: 1.2.3.4 (A specific remote public or private IPv4 address).

    • Domains: redirector.gen-webserver.local and www.redirector.gen-webserver.local.

    • Result: Traffic intended for these subdomains is routed to the specific server at 1.2.3.4.

  • Comments (# gen digital helper server)

    • Text following the # symbol is ignored by the system.
  • Of course AI can make mistakes but since no one from Norton is jumping in here I am going to assume these additions are not malicious. I also assume that since the hosts file has been altered that the virus scan flags the file as a trojan.

1 Like

I agree adding their own code into the file is fine but they are deleting the file and replacing it with their own. That is not necessary and I think it’s malicious to delete microsoft’s own code. Someone from Norton should clarify what’s going on here. This is one of the worst issues I have seen with Norton.

Unless they plan to have nothing in the hosts file except their own code. Then they need to say that.

I agree.

Norton should respond here to clear up this whole thing.