Norton Internet Security Anomoly
Saturday, April 30, 2005 by starkers | Discussion: Windows Software
This is an anomoly I've not encountered before, and Symantec provided no answers either, so if anyone can shed any light on this it would be most useful for future reference and muchly appreciated. Whilst no trojan or virus was detected on my system by subsequent scans, my browser appeared to be hijacked and other applications malfunctioned during this (now seemingly false) alert. A 4th system scan just gave another all clear. Strange! Answers anyone?
Reply #2 Saturday, April 30, 2005 9:45 AM
| The only thing I can think of is that you have your *Nortons preferences set to delete threats as they appear? or perhaps the threat is in your quarantine files..they wont show up once they are there.. |
Ditto ....
Reply #3 Saturday, April 30, 2005 10:11 AM
MAC (Media Access Control) addresses are used to identify hardware in a network (for instance a NIC card in your computer). A trojan would allow someone or something to identify this hardware address, then access it and your connection activity.
I am not a Network specialist at present, so this is the best information I can currently offer.
Hopefully, the - 'had a "macip" trojan on my computer' - indicated in your opening comments means that Norton was telling you it found the trojan and disposed of it.
Good luck.

Reply #4 Saturday, April 30, 2005 10:26 AM

Reply #5 Saturday, April 30, 2005 10:39 AM
I have been running Norton Internet Security Pro 2003, Ad-Aware, and Spybot for a couple years now - no issues so far.
Also, depending whether your Norton has the same function or not, you might want to go to "status & settings pane > select firewall > configure firewall > program control > program scan" to make sure firewall identifies all programs designed to access internet.
I think that's it for me.

Reply #6 Saturday, April 30, 2005 7:09 PM
| My Nortons preferences are set to delete threats as they appear, but the security alert said that the problem could not be repaired. |
Nothing unusual about that Starkers, what it means is that the Virus/trojan or whatever *Corky says it was..LoL.."Could not be repaired" the only course of action for Nortons to take was deletion and thats exactly what happened..Nortons deleted the threat after checking to see if it could be repaired..if you had your prefs set to quarantine, then the threat would have been nuetralized and stored in your Nortons quarantine file so that you could send it to Symantec for further study..
I believe thats exactly how it works..but..I could be wrong, this is my understanding of the program though.
Zero.
Reply #7 Saturday, April 30, 2005 11:20 PM
The point, however, apart from resolving my own issue, was to report the event for others to be aware of it. When the Nortons alert window was on screen, there was no access to IE, Documents or Documents and Settings, etc. IE could not be closed, Ctrl, Alt, Del was ineffective and the Web page could not be manually changed, though the page was altering itself. The alert window constantly reappeared after repeatedly closing it and I could not close my system down using the normal method. Only when I shut it down at the box did I regain full control of my computer, which could indicate IE.was hijacked and the threat only existed while it was open. Perhaps?
Hopefully this explains the event more clearly for others, should it ever happen to them. Also, apart from the advice given here, I was also advised to restart in safe mode to disable suspicious browser add-ons, then do a system restore before deleting cookies and Temporary Internet Files to remove all traces.
All is well now, thanks again guys.
Reply #8 Sunday, May 1, 2005 5:34 AM
| the Web page could not be manually changed, though the page was altering itself. The alert window constantly reappeared after repeatedly closing it and I could not close my system down using the normal method. |
....playing on the darkside of the net
You might also want to look at https://netfiles.uiuc.edu/ehowes/www/resource.htm IE-SPYAD, basically what it does is sets up which sites are in the restricted zone in IE to keep them from doing malicious stuff when you visit them. The list is pretty restrictive, but can be edited or an eye-opener when you find a site that you frequented is now blocked. They also make https://netfiles.uiuc.edu/ehowes/www/resource6.htm "Enough is Enough!" which is extreme lockdown....
Reply #9 Sunday, May 1, 2005 9:43 AM
Apparently, according to other advice and a MS error report, my problem was caused by an obnoxious IE browser add-on, which most probably was covertly installed by an EXE file when I downloaded some MSStyles to port with Skin Studio. The reason I could not access my documents was because they were being used remotely, according to MS, which raises further issues and questions.
In another recent thread, Jafo said that avoiding these EXE files was in fact theft through revenue deprivation, that he did not advocate making the means to do this public. Now after being burgled some time ago, I no more condone theft than Jafo, but if one can sidestep such malicious software to protect their own interests, should one not do so? Is it not theft in itself to covertly access another's private information and illegally take control of their property? Yes, these EXE files give you the option not to install this additional software, but that's not truthful as I always select those options and still found some of the deselected software on my computer after this incident forced me to investigate more thoroughly. The practice of covertly installing this software, knowing its capabilities, is theft and should be avoided.
Furthermore, I should add that MS advise that these browser add-ons can avoid detection when trying to remove or disable them in Normal Mode. To do so, restart in Safe Mode, go to Contol Panel> Internet Options> Programs> Manage Add-Ons, then disable those you do not recognise or are suspicious. After doing this I've had no problems.
Hope this is helpful to others - safe and happy computing everyone, starkers
Reply #10 Sunday, May 1, 2005 2:30 PM
The problem users run into in many cases, is the fact that he/she did not actually read the full "EULA" - which is binding. I am guilty of not reading the "EULA", and just thinking "I agee to install this on just one computer".
Glad to hear you feel reasonably safe now. The real bummer is that the MAC address is hard-coded in the hardware. Maybe some day, the manufacturer will offer a utility to change the address in cases like these.
Have a better day.

Reply #11 Sunday, May 1, 2005 10:43 PM
When checking my browser add ons in safe mode, I found 2 that I did not recognise, each containing just a random set of numbers and no company name or author to otherwise identify them. I can only conclude they were still bundled with my selected items and covertly installed to serve an agenda other than my own.
My hope here is to inform others of such practices so they don't have to learn the hard way like I did.

Reply #12 Sunday, May 1, 2005 11:09 PM
| but is bundled with themes, walls and MS Styles,etc in an EXE file. |
Just keep away from 'that site'.
I do....
Reply #13 Sunday, May 1, 2005 11:11 PM
| the software I've referred to is not part of a purchased item but is bundled with themes, walls and MS Styles,etc in an EXE file. |
Starkers, unfortunately that is what really killed Win98 themes, Artists would upload their creations to a site that would host them but in doing so the artist agreed to have h/her work bundled with "harmless optional software" in return for being hosted. For users that really had no clue, that artist would gain a bad reputation and become the subject of numerous "flames" to the point of the artist simply giving up their hobby. It really was a sad thing, the artists really asked for nothing in return for sharing their works, much like the artists here at WC, but they became the subjects of unwarranted hatred due to the malware that was being added to their themes. *ThemeXP is a site that seems to be doing that as well these days.
Wincustomize is a great place for WB/Theme.etc..etc artists to be hosted on due to the fact that WC does not follow the same miserable habits of other sites that host the hard work of the artists..
It costs money to run a site, and if your doing it by yourself for no profit other than an occassional "Thanks" or "Great Job" it can add up in the long term, thats why so many artists sought "Hosting" alternatives..unfortunately those hosts were the ruin of some very talented people..
So, I suppose my point is..be very careful where you get your WB's/Themes and other goodies of that nature because more times than not you will be getting some sort of "Malware" as well..
Not in every case, but there is a TON of it out there..
I usually download a couple items from a site and check them out, you can usually tell before you install, because it asks you if you agree to install (insert name here) *Yes or No* I just cancel the installation at that point and get that trash off my PC..:laughs::
Zero.
Reply #14 Sunday, May 1, 2005 11:34 PM
I just noticed I can't quote anymore.
Reply #15 Sunday, May 1, 2005 11:43 PM
I agree - if it installs after you say no = "Not Good".
Peace.

Reply #16 Monday, May 2, 2005 12:48 AM
Not as convienent..but it works..::laughs::
Zero.
Reply #17 Monday, May 2, 2005 10:47 AM

Reply #19 Monday, May 2, 2005 8:06 PM
And yes, Jafo, I'll be steering a wide berth from now on - you just don't know what you're going to get. My step-daughter and I were looking at dolphin walls on moment, and the next we were hijacked to a site that hosts porn as well as themes. We were not impressed! It's bad enough to be inundated with a multitude of every day products, but that's unacceptable. It also poses the question: is it legal to connect restricted or offensive material with software that targets everyone including minors?
What I fail to understand is why my anti-spyware programs and Nortons didn't detect this malware. All are permanently enabled, and by rights, they should have notified me of its presence and didn't. Now that's a worry: if malware can now be diguised to appear as valid software. What a scary thought - and such a wonderous technology, being used for commercial and evil practices. More is the pity its designers didn't inadvertantly give us access to their bank accounts so we could donate the money to charity,
Now back to the Nortons. With no log entries to show a virus/trojan was deleted or quarantined, could it be that the threat was eliminated before it entered my computer or a false alarm? I could find nowhere on the Symantec site to pose such questions and it would be useful to know for future reference, should a similar event occur.
Cheers guys, and thank God for Wincustomize

Reply #20 Monday, May 2, 2005 9:11 PM
With the high-jacking of your browser and the Norton message occuring at the same time, it was in all probability the software gaining access to your NIC by way of the MAC address - it was probably just waiting until you invoked it by using the browser (especially if the plug-in you mentioned was part of that browser, and was indeed the software that fell in Norton's definition of a Trojan).
The behavior you describe in comment #7 would indicate that Norton was trying to stop the programs activity to allow you to take some action, and was unable to do so. By shutting down, you removed all programs loaded in memory and were therefore able to restore some measure of control.
Norton may have allowed it to install as an authorized plug-in, and did not do anything until the software started behaving like a trojan. Perhaps some rules for plug-ins need to be either created or updated by the powers that be?
If you were able to perform a successful System Restore to a point before installing the offending software, you should be fine. Especially if you can now browse without a warning or having your browser take a trip to some unrequested site.
Glad you kept this thread open for a while, as I agree whole-heartedly that others may benefit from your experience - and indeed, WC is a wonderful place.
Best of luck in the future.

Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Saturday, April 30, 2005 9:12 AM
The only thing I can think of is that you have your *Nortons preferences set to delete threats as they appear? or perhaps the threat is in your quarantine files..they wont show up once they are there..
Take a look through Nortons logs and in the quarantine, other than that..im stumped!..LoL
Zero.