Norton modify hosts file and says it’s malware

Have you removed the entries, saved hosts file and set its attributes to “read only”, restarted and rechecked? Those are my settings.

SA

Good morning!

No I haven’t, Soul, my friend, at least not yet. It’s like one of your earlier posts. I want to be careful in case it compromises my machines safety. So I can tell you, if you have norton set normally and have left the hosts file alone, when you fully uinstall the lines go. When you reinstall, they come back.

I do have serious privacy issues with these lines, but at this point, Norton likely added these posts for Safe Web and if it was malicious as in someone sabotaged the liveupdates to install malware, I believe Norton would have already acted faster than it currently is.

Here is more pertinent info about hosts and software writing to it: *Malicious or not these entries should not have been written in the first place. That is my opinion, and I want to make it clear as a bell, I DO NOT speak for Norton nor Gen Digital as I am not an employee.

AI Overview

Programs do not write invisible entries into the Windows hosts file, but they can write visible entries that go unnoticed if you do not open and read the file. The hosts file is a plain text file, meaning any text added to it is fully readable, though malicious software or legitimate apps can append lines silently in the background if they have administrator rights. [1, 2, 3, 4, 5]

How Programs Modify the Hosts File

  • Plain Text Format: Every entry inside the hosts file requires standard text characters showing an IP address followed by a domain name. There is no coding method to hide text on a specific line so that a text editor cannot display it. [1, 2, 3]

  • Blank Space Tricks: Programs or malicious actors sometimes push unauthorized entries far down the page using numerous blank lines or carriage returns. This forces the text out of the immediate viewing window when you first open the file, making it look empty unless you scroll down. [1]

  • Silent Writing: Software with elevated administrative permissions can modify system files automatically without prompting you with a visible notification. [1, 2]

Why Entries Go Unnoticed

  • Lack of Visibility: Users rarely inspect the hosts file during routine computer use.

  • No Native Alerts: Windows does not display a pop-up warning alert every time an application edits the hosts file

SA

Today update from 26.6.11052 to 26.7.11086 (versie 26.7.11086.990)

I also use GlassWire, which provides me with information when an application edits the host file.

The host file now only changes at startup.
With the previous version 26.6.11052, during startup and shutdown.

@Feelgood I have asked whether any of you have your hosts file attributes set to read only. I have mine set that way, hosts is NOT being over written on my machines.

SA

Hi SoulAsylum,

I have not installed the latest version yet and will set the host file to read only.

What concerns me is the altercation to the host file.

For curiousity, I asked AI Norton why the host file was altered.

Here is the response on Offficial Norton TM Support, therefore it still leaves a huge question mark on my mind. What else could it be doing to the device?

If your host file contains entries like 127.0.0.1 gen-webserver.local or 1.2.3.4 redirector.gen-webserver.local, these are not standard entries and suggest that your host file has been modified. While Norton products are designed to protect your system, they do not typically add such entries to your host file. These modifications could be due to malware, other software installations, or even a misconfiguration. It’s recommended to restore your host file to its default state to ensure proper system function and security.

Understanding Host File Entries

  • Purpose of the Host File: The host file is a plain text file in an operating system that maps hostnames to IP addresses.

    It’s used to translate human-friendly domain names into numerical IP addresses that computers use to identify each other on a network. For example, 127.0.0.1 localhost is a standard entry that directs your computer to itself when you try to access “localhost”.

  • Non-Standard Entries: The entries you’ve provided, such as gen-webserver.local and redirector.gen-webserver.local, are not part of the default Windows host file.

    The presence of these entries, especially those pointing to 127.0.0.1 (your own computer) or other specific IP addresses, indicates that some program or process has altered your host file. This could be legitimate software, but it’s also a common tactic used by malware to redirect web traffic or block access to certain sites.

  • Restoring the Default Host File: To ensure your system is functioning correctly and securely, it’s best to revert your host file to its original, default state. This involves renaming the altered file and creating a new one with the standard Windows content. This process helps eliminate any potentially malicious or unwanted redirections that might be present in the modified host file.

It is Norton adding the lines.

It started during the evening of July 13th with Norton adding two lines (gen-webserver and redirector), and a lot of us noticed it due to Norton flagging the hosts file as malware. But by Tuesday afternoon it finished flagging it and left it alone.

Then on July 21st, when Norton upgraded to 26.7, they added a third line (revocation).

When you fully delete Norton, the lines go away. If Norton wasn’t the cause, this wouldn’t happen. It’s up for debate why Norton added them, but until and if Norton tells us, we won’t know for sure. They’re more than likely part of Safe Web.

Now Soul edited his host file and marked it as read only which means Norton can’t edit the file.

Hello All,

We would like to clarify on the recent questions regarding temporary hosts file updates by Norton Safe Web.

In some cases, Norton may temporarily add entries to the Windows hosts file when certain web protection features are enabled.

Examples of possible entries:
127.0.0.1 gen-webserver.local www.gen-webserver.local # gen digital helper server
1.2.3.4 redirector.gen-webserver.local www.redirector.gen-webserver.local # gen digital helper server
127.0.0.1 revocation.gen-webserver.local www.revocation.gen-webserver.local # gen digital helper server

These entries support specific Norton browser-security functions, such as Safe Web warning and related protection experiences. They are limited to Norton-controlled destinations used by those features and are not used to redirect your normal browsing to unrelated third-party websites.

Because some security tools monitor the hosts file for unexpected changes, you may occasionally see an alert when Norton adds or removes these entries. If the change relates to a Norton-managed entry associated with this feature, the behavior is expected and does not by itself, indicate that your device is compromised.

When the relevant feature is disabled or no longer active, Norton removes the associated entries.

Thank you for keeping your trust with Norton !

4 Likes

Going forward on my side. The Windows hosts file on ALL my machines are set to “read only”. The issue is resolved for me personally. If anything gets written into hosts going forward there will be a new issue.

Regards,
SA

Thank you for your reply Selvakumar. At the present time I use safe web and have set the hosts file to read only. Will this interfere with my using Norton Safe Web for the home page and will I still see the green check marks on the search pages?

Hi SoulAsylum,

At the present time I use safe web and have set the hosts file to read only. Will this interfere with my using Norton Safe Web for the home page and will I still see the green check marks on the search pages? I will be installing the new version this weekend. Thanks.

@Win7and10 Its not interfering with things my side. Although I don’t have the Safe Web extension installed on Edge nor Opera GX, Safe Web still runs within Norton 360. That part is active. The hosts entries do not make any difference on my machines to date. I don’t expect that to change going forward. :wink:

Each one of you, have individual and personal decisions to make about the hosts issue. Mine is, setting hosts to read only and leaving it that way. No software I have ever installed has edited nor attempted to edit hosts. And I have used Norton for a very long time, this is a first for Norton.

Safe Web was working just fine before, it doesn’t need to add hosts entries and redirect my surfing data to any servers for detections or other purposes. That is a privacy issue I learned the hard way about years ago. This all sounds lovely from a one sided perspective, its not from where I sit.

Regards,
SA

3 Likes

AI sourced content may make mistakes

2 Likes

As stated the host file amendment is an optimization, however isn’t it a report back to Norton? I’d rather play it safe and keep the host file read only. So many variables. I’m not trying to discredit Norton. Just error on the side of caution. Perhaps others can comment on their product performance as well. :smiling_face_with_three_hearts:

2 Likes

fwiw ~ Norton EAP 26.8.11103
I tried cycling Safe Web engine and a cold start and still no gen-webserver.local entries.
I tried Repair Norton and a cold start and still no gen-webserver.local entries.

==========

AI sourced content may make mistake

==========

Edit: now with 26.7.11086 – I’m finding:
127.0.0.1 gen-webserver.local www.gen-webserver.local # gen digital helper server
1.2.3.4 redirector.gen-webserver.local www.redirector.gen-webserver.local # gen digital helper server
127.0.0.1 revocation.gen-webserver.local www.revocation.gen-webserver.local # gen digital helper server

1 Like

For those who still have the hosts entries from Norton you can open an elevated command ( run as admin ) type is netstat -r and have a look at your routing tables on the specific device you are using. Take note of whether there are “persistent routes” or none in the table.

SA


1 Like

Not seeing any persistent routes is good. Nothing is sending outbound traffic that shouldn’t be going out.

SA

==========

==========

==========

==========

AI sourced content may make mistakes

Ahh!! AI rules the day. That is a personal decision everyone has to make. Given the track record of AI, I choose not to trust it. Your mileage will vary and experience with it as well. Not looking to go down that AI rabbit hole anytime soon on my part. Closed domains are not something a security company should be adding to an OS profile regardless of the intention. Just my dime on the issue. :wink:

EDIT: I am also very aware of what hosts is for and what it does. My side the conversation that continues via AI about it is moot. Others may see things in a different light.

A “Zero Sum Game” is a concept from game theory, which analyzes competitive interactions where one party’s gain is directly offset by another party’s loss . This concept suggests that resources are finite, and individuals or groups are in constant competition for them—be it money, power, or status.

Regards,
SA