This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ERROR - "Sophos Firewall detected malicious traffic: 'C2/Generic-C' at 'C:\Windows\System32\svchost.exe' (Technica..."

I am getting the error status on 1 or 2 computers each day 

"Sophos Firewall detected malicious traffic: 'C2/Generic-C' at 'C:\Windows\System32\svchost.exe' (Technica..."

What is this?



This thread was automatically locked due to age.
  • Hello Paul Dunn,

    the analysis for C2/Generic-C is rather vague. What's in the endpoints' Anti-Virus log (%ProgramData%\Sophos\Sophos Anti-Virus\logs\SAV.txt)? Is indeed the client firewall (SCF) installed, if so please check its log for possible details. See also Dealing with a C2 detection.

    Christian

  • Hey Paul,

    did you find something? We are getting this error on some computers here too. I found the URL which is responsible for the threat: "sync.header.direct".

    Is it the same for you?

    I'm not that knowledgeable about domains. Is this a safe domain and the Sophos popup wrong?

     

    Kind regards

    Marc

     

  • Marc

    Haven't found anything yet.  Been a little busy.  All I do know is I am very disappointed with Sophos Central and all the problems we are having with it.  It does not seem to be working at all on about 40% of our machines (either it's giving so many false positives or just not running)

    We are truly sorry we purchased this software and 3 years of contract.  Seems like it is just a waste of money and we should have gone with a more reliable working solution.

    But now we are stuck :-(

  • Hi Marc,

    We are getting the exact same reports as you are across multiple machines all to the URL "sync.header.direct" It just started out of the blue a week or so ago and no matter what I try I cant confirm that it is actually malicious and not a false positive.

    Have you heard back from Sophos?

    Thanks

    Steve

  • Of course I do not see anything useful or helpful in the log file :-(

     

    I 'tailed' the file, do you see anything useful?

     

    20171221 140943 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'.
    20171221 140943 Virus/spyware 'C2/Generic-C' is not removable.
    20171221 140950 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 140950 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 140951 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 140955 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'.
    20171221 140955 Virus/spyware 'C2/Generic-C' is not removable.
    20171221 141006 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 141006 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 141007 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.
    20171221 141011 File "C:\Windows\System32\svchost.exe" belongs to virus/spyware 'C2/Generic-C'.
    20171221 141011 Virus/spyware 'C2/Generic-C' is not removable.
    20171221 172504 Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15341575 items.
    20171221 232504 Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15341598 items.
    20171222 042504 Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15341629 items.
    20171222 082505 Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15341640 items.
    20171222 122504 Using detection data version 5.46 (detection engine 3.70.2). This version can detect 15341646 items.

  • We are getting the messages now all over the place and no help from Sophos :(

  • Hello Paul,

    indeed there's no further information - the odd thing though is the Threat ID: 0. It shouldn't be zero unless it's a double-generic detection - but then on what observations does it base its assessment. Did you open a ticket with Support?

    Christian

  • Yes, I opened a ticket with support

     

    thanks

  • We are seeing similar issues since 12/18 with a number of machines:

    20171218 174443 File "C:\program files (x86)\Google\Chrome\application\chrome.exe" belongs to virus/spyware 'C2/Generic-C'. Threat ID: 0. No action taken.

    Is this a false positive issue with an update?

    Greg

  • We have also this issues for aaprox. 10 machines per week.

    It is connected to sync.header.direct or sync-eu.headre.direct.

    We are sure, that the svchost.exe on these machines are 100% O.K. (on disc NTFS system - we cannot by sure in memory).