Technology news and Jobs arrow Information Technology News arrow Symantec gets spoofed by virus purveyor
Symantec gets spoofed by virus purveyor E-mail
by Stan Beer   
Wednesday, 19 April 2006

In the ultimate slap in the face, the world's largest anti-virus vendor Symantec has had its identity spoofed by a virus purveyor. A high risk malicious email, which appears to be a Symantec virus advisory, but actually is an e-mail that contains a payload that disables anti-virus updates, was discovered by another internet security services provider.

UK-based internet security specialist SurfControl has alerted customers to the threat. The email has a spoofed “From” address that indicates the message is from Symantec’s Norton Anti-Virus division; and it indicates the user’s machine is infected with a virus called This e-mail address is being protected from spam bots, you need JavaScript enabled to view it email directs the user to a “cleaner” link that will eliminate the infection. However, when a user clicks on the link in the suspect virus notification, an executable file is downloaded, and upon execution it modifies the user’s host file.

The changed host file disables the user’s anti-virus software updates, leaving the user susceptible to further malicious activity. The anti-virus killer technique has been seen before, but this the latest iteration, according to SurfControl.

The malicious file was located on a free hosting service but the Web site mirrored a Symantec update site. The site has now been suspended by the Web host.{moscomment}

Please enable JavaScript in your browser to post your comment!


Get stories like this delivered daily - FREE - subscribe now
 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
Suscribers
904,266
13,751
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff
Subscribe to our free e-newsletter