Endpoint Protection

 View Only
Expand all | Collapse all

SONAR Configuration for Host File change

Migration User

Migration UserSep 05, 2013 10:10 PM

  • 1.  SONAR Configuration for Host File change

    Posted Sep 05, 2013 06:30 AM

    On our SEPM, under SONAR settings

    DNS change = log

    HOST FILE change = log

     

    result: we keep receiving single risk notification for microsoft svchost.exe and other applications.

    Question: is the hostfile SONAR referring to is the one on C:\Windows\System32\drivers\etc??

    or is there any other hostfile location?

     



  • 2.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 06:35 AM

    - What SEP/SEPM versions are running?

    - Correct, the hostfile is the one from C:\Windows\System32\drivers\etc

    - Have a look at the following KB for the svchost.exe notifications:

    Error: "Security Risk Found! Hosts File Change in File: c:\windows\system32\svchost.exe by: SONAR scan"

    Article:TECH164391  |  Created: 2011-07-12  |  Updated: 2012-04-24  |  Article URL http://www.symantec.com/docs/TECH164391

     



  • 3.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 06:40 AM

    it should be from your application and device control?

    Hardening Symantec Endpoint Protection (SEP) with an Application and Device Control Policy to increase security

     

    http://www.symantec.com/business/support/index?page=content&id=TECH132337

     



  • 4.  RE: SONAR Configuration for Host File change

    Trusted Advisor
    Posted Sep 05, 2013 06:51 AM

    Hello,

    What version of SEP are you running?

    Check these Articles:

    Error: "Security Risk Found! Hosts File Change in File: c:\windows\system32\svchost.exe by: SONAR scan"

    http://www.symantec.com/docs/TECH164391

    Symantec Endpoint Protection 12.1: Blocked System Change Events produce unexpected messages

    http://www.symantec.com/docs/TECH161646

    Creating an DNS or Host File Change Exception in Symantec Endpoint Protection Manager 12.1 RU1 MP1 and above.

    https://www-secure.symantec.com/connect/articles/creating-dns-or-host-file-change-exception-symantec-endpoint-protection-manager-121-ru1-mp1

    Hope that helps!!



  • 5.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 07:09 AM

    Hi All,

     

    Thanks for the prompt reply.

    We are running 12.1 RU3. If that's the location it's pertaining to.. Does it mean that my svchost.exe or chrome.exe change my hostfile that's why I received single risk notification. Even my backup application has been detected as single risk. Is there a way for me to check how this application change something on my hostfile

     

    Hi Rafeeq,


    It's under SONAR settings, because if I check my SONAR logs on monitor. Those detected application will be listed down from there.



  • 6.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 08:35 AM

    This is likely harmless as the backup location may just be trying to open/read the HOSTS file. The only way would be to take a backup and than do a compare between the two files.

    You could also use a tool like procmon to what read/writes the application is attempting.



  • 7.  RE: SONAR Configuration for Host File change

    Broadcom Employee
    Posted Sep 05, 2013 10:56 AM

    Hi,

    Thank you for posting in Symantec community.

    I would be glad to answer your query.

    Question: is the hostfile SONAR referring to is the one on C:\Windows\System32\drivers\etc??

    --> Yes, that's the correct location.

    or is there any other hostfile location?

    --> No, there is not any other hostfile location.

    Check this article: Creating an DNS or Host File Change Exception in Symantec Endpoint Protection Manager 12.1 RU1 MP1 and above.

    http://www.symantec.com/docs/TECH194108



  • 8.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 09:42 PM

    Hi Brian,

     

    the sonar will create risk log if the application did changes on the host/dns file only right? But if it open/read only, will it still create log?



  • 9.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 09:47 PM

    It should only happen if a "change" of some sort is detected.



  • 10.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 10:10 PM
      |   view attached

    dllhost.exe is related to hostfile correct



  • 11.  RE: SONAR Configuration for Host File change

    Posted Sep 05, 2013 10:38 PM

    svchost.exe is. check here:

    http://www.symantec.com/docs/TECH164391



  • 12.  RE: SONAR Configuration for Host File change

    Posted Sep 06, 2013 01:45 AM
      |   view attached

    If svchost.exe is changing my hostfile..then why my hostfile modified date is still 2009 and never change.



  • 13.  RE: SONAR Configuration for Host File change

    Posted Oct 09, 2013 03:28 AM

    exclude svchost.exe for nth time using dns and host file change but still thesame. I still received notifications.