Hi everyone,
I’ve noticed something odd with my Windows hosts file recently. An entry for gen-webserver.local keeps appearing out of nowhere, and I’m pretty sure Avast is behind it.
I ran Process Monitor to track down what was modifying the file, and the logs point directly to AvastSvc.exe. Here’s a snippet of what I captured:
08:49:31.9045476 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,151, Length: 81, Priority: Normal
08:49:31.9077107 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,232, Length: 2, Priority: Normal
08:49:31.9079909 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,234, Length: 103
08:49:39.5613875 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,151, Length: 81, Priority: Normal
08:49:39.5629975 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,232, Length: 2, Priority: Normal
08:49:39.5631528 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,234, Length: 103
08:51:26.6864544 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,151, Length: 81, Priority: Normal
08:51:26.7065280 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,232, Length: 2, Priority: Normal
08:51:26.7067785 AvastSvc.exe 3552 WriteFile C:\Windows\System32\drivers\etc\hosts SUCCESS Offset: 8,234, Length: 103
For reference, here’s my system info:
OS Name: Microsoft Windows 11 Pro
OS Version: 10.0.26200 N/A Build 26200
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Workstation
OS Build Type: Multiprocessor Free
And the Avast version I’m currently running:
DisplayName REG_SZ Avast Free Antivirus
DisplayVersion REG_SZ 26.7.11086.3745
As you can see, AvastSvc.exe is writing to the hosts file repeatedly within a short timeframe. The entry being added is gen-webserver.local.
Has anyone else experienced this? I’m not sure if this is part of some Avast feature (like Web Shield, a local network scanner, or perhaps a captive portal detection mechanism) or if it’s something I should be concerned about.
A few questions:
-
Is this expected behavior from Avast?
-
If so, what is the purpose of adding
gen-webserver.local? -
Can this be disabled without turning off core protection features?
Any insights would be much appreciated. Thanks in advance!


