Norton Internet Security Anomoly

Earlier, I was getting some walls for my step-daughter (only using "save as"), and i got a Nortons Anti-virus alert so say I had a "macip" trojan on my computer and that it could not be repaired. At this point my computer began to behave strangely and I couldn't close IE. I immediately ran internet security and anti-virus to locate and nullify this offender. However, when doing a full system scan and checking the alert tracker, Nortons found no evidence of the trojan on my system. I then went to live update to confirm I had the most recent definitions, which I had, so did an online security check to discover the source of the problem. Again, no evidence of a trojan, so did a selective scan of "my pictures" where the walls were stored, and again no trojan, yet the alert window repeatedly reappeared when it was closed.
This is an anomoly I've not encountered before, and Symantec provided no answers either, so if anyone can shed any light on this it would be most useful for future reference and muchly appreciated. Whilst no trojan or virus was detected on my system by subsequent scans, my browser appeared to be hijacked and other applications malfunctioned during this (now seemingly false) alert. A 4th system scan just gave another all clear. Strange! Answers anyone?
4,496 views 21 replies
Reply #1 Top
Hey there Starkers,
The only thing I can think of is that you have your *Nortons preferences set to delete threats as they appear? or perhaps the threat is in your quarantine files..they wont show up once they are there..

Take a look through Nortons logs and in the quarantine, other than that..im stumped!..LoL

Zero.
Reply #2 Top
The only thing I can think of is that you have your *Nortons preferences set to delete threats as they appear? or perhaps the threat is in your quarantine files..they wont show up once they are there..


Ditto ....
Reply #3 Top
If I am not mistaken, the warning was telling you it identified a "MAC/IP" trojan.

MAC (Media Access Control) addresses are used to identify hardware in a network (for instance a NIC card in your computer). A trojan would allow someone or something to identify this hardware address, then access it and your connection activity.

I am not a Network specialist at present, so this is the best information I can currently offer.

Hopefully, the - 'had a "macip" trojan on my computer' - indicated in your opening comments means that Norton was telling you it found the trojan and disposed of it.

Good luck.
Reply #4 Top
My Nortons preferences are set to delete threats as they appear, but the security alert said that the problem could not be repaired. That's why I ran the scans, to manually resolve it, and they revealed nothing. The strange thing is that the event log only shows the trojan's appearance, nothing more. So if it was not deleted or quarantined, and subsequent system scans show no evidence of it, where did it go? The only thing I can think of is that it was only present while IE was open, and once it was closed the threat was negated. Maybe? It's still a mystery, but thanks guys for your thoughts
Reply #5 Top
If you have not already done so, you might want to install and run Ad-Aware, Spybot, and perhaps Microsoft's spyware tool (beta) - to eliminate the possibility of any programs running without your knowledge or consent that would be able to transmit your MAC/IP address.

I have been running Norton Internet Security Pro 2003, Ad-Aware, and Spybot for a couple years now - no issues so far.

Also, depending whether your Norton has the same function or not, you might want to go to "status & settings pane > select firewall > configure firewall > program control > program scan" to make sure firewall identifies all programs designed to access internet.

I think that's it for me.
Reply #6 Top
My Nortons preferences are set to delete threats as they appear, but the security alert said that the problem could not be repaired.



Nothing unusual about that Starkers, what it means is that the Virus/trojan or whatever *Corky says it was..LoL.."Could not be repaired" the only course of action for Nortons to take was deletion and thats exactly what happened..Nortons deleted the threat after checking to see if it could be repaired..if you had your prefs set to quarantine, then the threat would have been nuetralized and stored in your Nortons quarantine file so that you could send it to Symantec for further study..

I believe thats exactly how it works..but..I could be wrong, this is my understanding of the program though.

Zero.
Reply #7 Top
Thanks guys, I have taken the recommended steps and feel the threat no longer exists. However, given there are no log events to say how it was dealt with, it still remains a mystery as to how it was eliminated. Great sighs of relief, regardless!
The point, however, apart from resolving my own issue, was to report the event for others to be aware of it. When the Nortons alert window was on screen, there was no access to IE, Documents or Documents and Settings, etc. IE could not be closed, Ctrl, Alt, Del was ineffective and the Web page could not be manually changed, though the page was altering itself. The alert window constantly reappeared after repeatedly closing it and I could not close my system down using the normal method. Only when I shut it down at the box did I regain full control of my computer, which could indicate IE.was hijacked and the threat only existed while it was open. Perhaps?
Hopefully this explains the event more clearly for others, should it ever happen to them. Also, apart from the advice given here, I was also advised to restart in safe mode to disable suspicious browser add-ons, then do a system restore before deleting cookies and Temporary Internet Files to remove all traces.
All is well now, thanks again guys.
Reply #8 Top
the Web page could not be manually changed, though the page was altering itself. The alert window constantly reappeared after repeatedly closing it and I could not close my system down using the normal method.


....playing on the darkside of the net

You might also want to look at https://netfiles.uiuc.edu/ehowes/www/resource.htm IE-SPYAD, basically what it does is sets up which sites are in the restricted zone in IE to keep them from doing malicious stuff when you visit them. The list is pretty restrictive, but can be edited or an eye-opener when you find a site that you frequented is now blocked. They also make https://netfiles.uiuc.edu/ehowes/www/resource6.htm "Enough is Enough!" which is extreme lockdown....
Reply #9 Top
Thanks, Essencay, for the link to SPYAD> It's just the thing for even more peace of mind, as is AGNIS, available from the same link, which adds more to Nortons default list of restricted sites. After this scary experience, I have become more security conscious than ever, especially since I forked out over #3500 Aus for my set up.
Apparently, according to other advice and a MS error report, my problem was caused by an obnoxious IE browser add-on, which most probably was covertly installed by an EXE file when I downloaded some MSStyles to port with Skin Studio. The reason I could not access my documents was because they were being used remotely, according to MS, which raises further issues and questions.
In another recent thread, Jafo said that avoiding these EXE files was in fact theft through revenue deprivation, that he did not advocate making the means to do this public. Now after being burgled some time ago, I no more condone theft than Jafo, but if one can sidestep such malicious software to protect their own interests, should one not do so? Is it not theft in itself to covertly access another's private information and illegally take control of their property? Yes, these EXE files give you the option not to install this additional software, but that's not truthful as I always select those options and still found some of the deselected software on my computer after this incident forced me to investigate more thoroughly. The practice of covertly installing this software, knowing its capabilities, is theft and should be avoided.
Furthermore, I should add that MS advise that these browser add-ons can avoid detection when trying to remove or disable them in Normal Mode. To do so, restart in Safe Mode, go to Contol Panel> Internet Options> Programs> Manage Add-Ons, then disable those you do not recognise or are suspicious. After doing this I've had no problems.
Hope this is helpful to others - safe and happy computing everyone, starkers
Reply #10 Top
If the software does not offer an option not to install, or it is not stated in the "EULA" that the installation of the "subversive" software is required for installation of the intended software - then I believe that is illegal, and the company probably has to refund the purchase price.

The problem users run into in many cases, is the fact that he/she did not actually read the full "EULA" - which is binding. I am guilty of not reading the "EULA", and just thinking "I agee to install this on just one computer".

Glad to hear you feel reasonably safe now. The real bummer is that the MAC address is hard-coded in the hardware. Maybe some day, the manufacturer will offer a utility to change the address in cases like these.

Have a better day.
Reply #11 Top
Hi Corky, the software I've referred to is not part of a purchased item but is bundled with themes, walls and MS Styles,etc in an EXE file. The problem is that although the file gives you the option not to install the additional items, such as browser helpers, etc, the deselected items can still find their way into your computer. My point is this: if you opt not to have these items, and by design they are covertly installed on your computer to collect information and hijack browsers, etc, then it is deceit, fraud and theft. The option not to install the additional software should mean just that, and not: "ok then, we'll come through the backdoor" so to speak.
When checking my browser add ons in safe mode, I found 2 that I did not recognise, each containing just a random set of numbers and no company name or author to otherwise identify them. I can only conclude they were still bundled with my selected items and covertly installed to serve an agenda other than my own.
My hope here is to inform others of such practices so they don't have to learn the hard way like I did.
Reply #12 Top

but is bundled with themes, walls and MS Styles,etc in an EXE file.

Just keep away from 'that site'.

I do....

Reply #13 Top
the software I've referred to is not part of a purchased item but is bundled with themes, walls and MS Styles,etc in an EXE file.


Starkers, unfortunately that is what really killed Win98 themes, Artists would upload their creations to a site that would host them but in doing so the artist agreed to have h/her work bundled with "harmless optional software" in return for being hosted. For users that really had no clue, that artist would gain a bad reputation and become the subject of numerous "flames" to the point of the artist simply giving up their hobby. It really was a sad thing, the artists really asked for nothing in return for sharing their works, much like the artists here at WC, but they became the subjects of unwarranted hatred due to the malware that was being added to their themes. *ThemeXP is a site that seems to be doing that as well these days.

Wincustomize is a great place for WB/Theme.etc..etc artists to be hosted on due to the fact that WC does not follow the same miserable habits of other sites that host the hard work of the artists..
It costs money to run a site, and if your doing it by yourself for no profit other than an occassional "Thanks" or "Great Job" it can add up in the long term, thats why so many artists sought "Hosting" alternatives..unfortunately those hosts were the ruin of some very talented people..

So, I suppose my point is..be very careful where you get your WB's/Themes and other goodies of that nature because more times than not you will be getting some sort of "Malware" as well..
Not in every case, but there is a TON of it out there..

I usually download a couple items from a site and check them out, you can usually tell before you install, because it asks you if you agree to install (insert name here) *Yes or No* I just cancel the installation at that point and get that trash off my PC..:laughs::

Zero.
Reply #14 Top
I agree fully with DZ - if it comes with other stuff, it's just gone.




I just noticed I can't quote anymore.
Reply #15 Top
starkers,

I agree - if it installs after you say no = "Not Good".

Peace.
Reply #16 Top
Hey Bichur, I have been running into the quote issue quite often of late.. You can still quote if you Copy/paste and manually add the tags.. quote and /quote surrounded of course with the brackets [ ]
Not as convienent..but it works..::laughs::

Zero.
Reply #17 Top
Thanks DZ - I couldn't remember what went the the bracks.
Reply #18 Top
Bichur is the coolest dude alive! - anon



testing
Reply #19 Top
You're right there, Zero, this malware situation harms much more than the end user. I just read an article agreeing with you that many good artists have had their reputations tarnished by "bundling" and that they have stopped sharing their works. That's a crime in itself! Perhaps the analogy here is somewhat exaggerated, but isn't that tantamount to defacing the Mona Lisa? Furthermore, some of this malware disables Desktop Architect, the very tool for applying the 98 themes, which perhaps is the reason its no longer updated.

And yes, Jafo, I'll be steering a wide berth from now on - you just don't know what you're going to get. My step-daughter and I were looking at dolphin walls on moment, and the next we were hijacked to a site that hosts porn as well as themes. We were not impressed! It's bad enough to be inundated with a multitude of every day products, but that's unacceptable. It also poses the question: is it legal to connect restricted or offensive material with software that targets everyone including minors?

What I fail to understand is why my anti-spyware programs and Nortons didn't detect this malware. All are permanently enabled, and by rights, they should have notified me of its presence and didn't. Now that's a worry: if malware can now be diguised to appear as valid software. What a scary thought - and such a wonderous technology, being used for commercial and evil practices. More is the pity its designers didn't inadvertantly give us access to their bank accounts so we could donate the money to charity,

Now back to the Nortons. With no log entries to show a virus/trojan was deleted or quarantined, could it be that the threat was eliminated before it entered my computer or a false alarm? I could find nowhere on the Symantec site to pose such questions and it would be useful to know for future reference, should a similar event occur.

Cheers guys, and thank God for Wincustomize
Reply #20 Top
starkers,

With the high-jacking of your browser and the Norton message occuring at the same time, it was in all probability the software gaining access to your NIC by way of the MAC address - it was probably just waiting until you invoked it by using the browser (especially if the plug-in you mentioned was part of that browser, and was indeed the software that fell in Norton's definition of a Trojan).

The behavior you describe in comment #7 would indicate that Norton was trying to stop the programs activity to allow you to take some action, and was unable to do so. By shutting down, you removed all programs loaded in memory and were therefore able to restore some measure of control.

Norton may have allowed it to install as an authorized plug-in, and did not do anything until the software started behaving like a trojan. Perhaps some rules for plug-ins need to be either created or updated by the powers that be?

If you were able to perform a successful System Restore to a point before installing the offending software, you should be fine. Especially if you can now browse without a warning or having your browser take a trip to some unrequested site.

Glad you kept this thread open for a while, as I agree whole-heartedly that others may benefit from your experience - and indeed, WC is a wonderful place.

Best of luck in the future.
Reply #21 Top
Thanks, Corky, it seems you hit the nail on the head. A rather knowledgeable friend just informed me that these browser hijackers can innoccously sit in your computer until the user inadvertantly does something to activate the code which executes a trojan/virus, etc. It would be wise for anyone experiencing unusual browser activity to investigate their browser add-ons bt the aforementioned method to disable and remove unwanted paraphenalia.

Safe computing to all and be ever vigilant for peace of mind, starkers