Network Management
SolarWinds.BusinessLayerHost.exe Deleting Files from MachineKeys Folder
SolarWinds.BusinessLayerHost.exe’s routine deletion of temporary certificate files in the Windows MachineKeys folder can trigger security alerts—such as McAfee ePO Exploit Prevention or Windows Audit logs—flagging “Windows EFS abuse,” but this behavior is expected and not malicious.
First published date
Last published date
Overview
Customers may report security alerts from McAfee ePO Exploit Prevention or other security tools indicating that SolarWinds.BusinessLayerHost.exe is deleting files from the MachineKeys folder, triggering a "Registry violation detected: Windows EFS abuse" or similar alert. This behavior is part of normal SolarWinds certificate management operations and is not malicious. Such activity may also be visible in Windows Security Audit logs.
Symptoms
- Security alerts or blocks triggered by SolarWinds.BusinessLayerHostx64.exe accessing or deleting files under:
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ - Alerts may appear as "Malware Behavior: Windows EFS abuse," "Registry violation detected," or similar in McAfee ePO or other endpoint protection tools.
- Corresponding events may also be logged in Windows Security Audit logs under file or registry access events.
- The process SolarWinds.BusinessLayerHostx64.exe is signed by "SOLARWINDS WORLDWIDE, LLC".
Product section
Cause
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\Resolution
- Process: SolarWinds.BusinessLayerHostx64.exe
- Process MD5 Hash: [Use the specific hash from your environment]
- Process Signer: SOLARWINDS WORLDWIDE, LLC
- Target Path:
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\* - Access Type: Change Permissions, Delete