<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Update sites or spyware scams. in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20570#M6342</link>
    <description>&lt;blockquote&gt;&lt;hr /&gt;bullhorn wrote: &lt;br /&gt;   Why can i not find this message in the listings for 28-8-08 entries&lt;hr /&gt;&lt;/blockquote&gt;&lt;p&gt; The threads in the board listings are ordered by the most recent post.&amp;nbsp; This is the common protocol found on internet forums, new content on top.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To always be able to locate your own threads, click your posting name 2 lines above the search box in the upper left section of the screen.&amp;nbsp; On the page that loads you can see your 5 most recent postings, underneath which is a link to view all your prior posts. &lt;/p&gt;</description>
    <pubDate>Fri, 29 Aug 2008 18:36:27 GMT</pubDate>
    <dc:creator>Allen_K</dc:creator>
    <dc:date>2008-08-29T18:36:27Z</dc:date>
    <item>
      <title>Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20427#M6305</link>
      <description>&lt;p&gt;My norton internet security asked my permission to remove host file entries 'tc.symantec.com' and 'om.symantec.com'&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;as it needs those sites to update........It seems going by other sources that these sites are spyware sites...has Norton got it wrong?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;seems to be some confusion of information......I wonder if Norton would clarify?&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Quote&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;These are sites used by Norton internet security to update&amp;quot;&lt;br&gt;Not really ... they just want you to think that ...&lt;br&gt;&lt;br&gt;Symantec detects a possible malicious entry in the HOSTS file&lt;br&gt;&lt;a href="http://msmvps.com/blogs/hostsnews/archive/2007/08/08/symantec-detects-a-possible-malicious-entry-in-the-hosts-file.aspx" target="_blank"&gt;http://msmvps.com/blogs/hostsnews/archive/2007/08/08/symantec-detects-a-possible-malicious-entry-in-the-hosts-file.aspx&lt;/a&gt;&lt;br&gt;[or]&lt;br&gt;Why does Symantec (Norton 2007) detect a possible malicious entry in the&lt;br&gt;HOSTS file?&lt;br&gt;&lt;a href="http://www.mvps.org/winhelp2002/hostsfaq.htm#Norton_2007" target="_blank"&gt;http://www.mvps.org/winhelp2002/hostsfaq.htm#Norton_2007&lt;/a&gt;&lt;br&gt;[or]&lt;br&gt;Symantec detects suspicious entries in the MVPS HOSTS file&lt;br&gt;&lt;a href="http://msmvps.com/blogs/hostsnews/archive/2007/11/14/1309806.aspx" target="_blank"&gt;http://msmvps.com/blogs/hostsnews/archive/2007/11/14/1309806.aspx&lt;/a&gt;&lt;br&gt;[or]&lt;br&gt;&lt;a href="http://www.mvps.org/winhelp2002/hostsfaq.htm#Norton_360" target="_blank"&gt;http://www.mvps.org/winhelp2002/hostsfaq.htm#Norton_360&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;                                                                   anyone with any information?   bullhorn&lt;br&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 28 Aug 2008 23:49:45 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20427#M6305</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-08-28T23:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20548#M6335</link>
      <description>&lt;p&gt;I did not read in detail the links you provided, so this may not directly answer your question, but it may help you understand what is happening here.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;When you tell your internet browser to go to &lt;a href="http://www.google.com/" target="_blank"&gt;www.google.com&lt;/a&gt; one of the first things that has to happen is that your computer has to turn that nice address for google.com into an IP address. An IP address looks like this:  74.125.XX.XX  (which is one choice for google).&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;So how does your computer translate &lt;a href="http://www.google.com/" target="_blank"&gt;www.google.com&lt;/a&gt; to a number?   It uses DNS (Domain Name Service) to lookup the IP address, much like you would lookup a phone number in a phone book.  You type google and your computer 'lookups' the number for google (and google is big enough that it has more than one 'number' that might be found--but that issue isn't relevant here:smileywink:).   DNS servers for most home users are usually provided by your ISP, and anymore the whole process is really quite transparent to the end user.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Thats the simple version of the explaination.  Now to expand on that without getting really to technical, for the sake of speed and minimizing network traffic your comuter has a variety of places it may 'look first' for the number before consulting the DNS server. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;First off a check in a local address cache, this is a place that holds recently 'looked up' IPs.  If we just looked up google recently and we need it again now, its faster if we can find it on our own internal 'scratchpad' than asking the DNS server for it.&lt;/li&gt;&lt;li&gt;Next the computer will check the HOSTS file.  The HOSTS file isn't actually used in practice much anymore.  But it's still there, and still checked as part of the process.  If a domain name is listed with and address here, the computer will use that address to contact the domain.&lt;/li&gt;&lt;li&gt;What happens next is dependent on your configuration, but in most home user cases is a query to the DNS server provided by your ISP. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;So in your case what has happened is that a piece of malware has modified your HOSTS file to include entries for 'tc.symantec.com' and 'om.symantec.com'.  I don't know what those specific sub-domains are for but if I had to guess I would bet they are related to liveupdate and/or virus definitions.   Whats happening here is that when liveupdate runs instead of your computer being properly routed to valid symantec servers, it gets re-directed to talk to the 'wrong number'.  The computer that answers at the 'wrong number' tho can lie and say hello i'm symantec and then download false or empty virus definitions, and or more malware.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The prompt by NIS telling you it wants to remove these entries from HOSTS is a tamper protection.  NIS says 'hey i'm about to update, let me check and make sure I think I'm going to get to the correct server to get my update'  So it performs some tests and says 'oops, there is something in the HOSTS file thats going to prevent me from getting to the correct server'.  So NIS then asks your permission to remove these entries before it updates.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="1" color="#ff0000"&gt;[mod note: Broke IP address (even tho it is google and most likely alwasy will be).]&lt;/font&gt;&lt;/strong&gt; &lt;/p&gt;&lt;div class='message-edit-history'&gt;&lt;span class='edit-author'&gt;Message Edited by Allen_K on &lt;/span&gt;&lt;span class='local-date'&gt; 08-29-2008&lt;/span&gt;&lt;span class='local-time'&gt; 05:12 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Fri, 29 Aug 2008 22:12:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20548#M6335</guid>
      <dc:creator>4runner</dc:creator>
      <dc:date>2008-08-29T22:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20563#M6340</link>
      <description>Why can i not find this message in the listings for 28-8-08 entries</description>
      <pubDate>Fri, 29 Aug 2008 18:12:03 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20563#M6340</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-08-29T18:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20565#M6341</link>
      <description>Further added, the links if read suggest links to DNS hijackers and advert vendors</description>
      <pubDate>Fri, 29 Aug 2008 18:23:21 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20565#M6341</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-08-29T18:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20570#M6342</link>
      <description>&lt;blockquote&gt;&lt;hr /&gt;bullhorn wrote: &lt;br /&gt;   Why can i not find this message in the listings for 28-8-08 entries&lt;hr /&gt;&lt;/blockquote&gt;&lt;p&gt; The threads in the board listings are ordered by the most recent post.&amp;nbsp; This is the common protocol found on internet forums, new content on top.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To always be able to locate your own threads, click your posting name 2 lines above the search box in the upper left section of the screen.&amp;nbsp; On the page that loads you can see your 5 most recent postings, underneath which is a link to view all your prior posts. &lt;/p&gt;</description>
      <pubDate>Fri, 29 Aug 2008 18:36:27 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20570#M6342</guid>
      <dc:creator>Allen_K</dc:creator>
      <dc:date>2008-08-29T18:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20609#M6353</link>
      <description>Allen_K  thanks for the info</description>
      <pubDate>Fri, 29 Aug 2008 21:23:17 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20609#M6353</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-08-29T21:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20683#M6366</link>
      <description>&lt;p&gt;i have seen these in my net connections log on and off,but nis has not asked me about them.is this the same as above?should i worry or not?thanks&lt;/p&gt;&lt;p&gt;mo&lt;/p&gt;</description>
      <pubDate>Sat, 30 Aug 2008 06:24:06 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20683#M6366</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2008-08-30T06:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20716#M6373</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;bullhorn wrote:&lt;br&gt;Further added, the links if read suggest links to DNS hijackers and advert vendors&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;yea if you read my earlier post that essentially what i explained... malware uses your HOSTS file to at the very least prevent liveupdate from working.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;blockquote&gt;&lt;hr&gt;mo wrote:&lt;br&gt;&lt;p&gt;i have seen these in my net connections log on and off,but nis has not asked me about them.is this the same as above?should i worry or not?thanks&lt;/p&gt;&lt;p&gt;mo&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;probably don't need to worry... they should appear in the logs.   In bullhorns case he had some malware that was attempting to redirect or hijack how his norton installed software phoned home for updates...  You can check your HOSTS file if you want...just open it in notepad... remember that for any line that starts with a # the rest of the line is ignored or considered a comment.   The single normal entry to have point localhost to 127.0.0.1   if you have anything else (on lines that DON'T start with a #) post it for comment.&lt;/p&gt;</description>
      <pubDate>Sat, 30 Aug 2008 14:32:44 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20716#M6373</guid>
      <dc:creator>4runner</dc:creator>
      <dc:date>2008-08-30T14:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20723#M6374</link>
      <description>&lt;p&gt;quote from [color=red]4runner[/color]&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;[quote]The prompt by NIS telling you it wants to remove these entries from HOSTS is a tamper protection. NIS says 'hey i'm about to update, let me check and make sure I think I'm going to get to the correct server to get my update' So it performs some tests and says 'oops, there is something in the HOSTS file thats going to prevent me from getting to the correct server'. So NIS then asks your permission to remove these entries before it updates[/quote]&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;No, I'm afraid you've got that the wrong way around a screen came up over Norton protectection centre screen warning that Norton&lt;/p&gt;&lt;p&gt;could not proceed to update unless it removed two sites from my host file, these sites were already routed to 127.0.0.1&lt;/p&gt;&lt;p&gt;so the prompt asked me if it could remove them.....a yes or no screen...I selected yes and then made inquiries with host sites&lt;/p&gt;&lt;p&gt;in other words it was a [u]no go place[/u] ..When removed it was a go place.  I discovered later that my Google had a lot of guff added to it in the way of adverts........this is DNS hijacking by way of browser cookies....I had to clear my DNS cache to get rid of them&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;You are twisting what I had originally stated in my first post.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;I intend to take screen shots if it occurs again and will post them here as evidence if possible..........bullhorn.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;ps. i dont know if BBcode is enable on this board as there is no review option.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 30 Aug 2008 16:08:18 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20723#M6374</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-08-30T16:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20770#M6385</link>
      <description>&lt;blockquote&gt;&lt;hr&gt;bullhorn wrote:&lt;br&gt;&lt;p&gt;'tc.symantec.com' and 'om.symantec.com'&lt;/p&gt;&lt;hr&gt;&lt;/blockquote&gt;&lt;p&gt;Ok... so those two domains were pointed at 127.0.0.1 (also known as localhost)&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#ff0000"&gt;so that means&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;any requests being made by software (liveupdate) to those two domains will be redirected back to your own computer &lt;font size="1"&gt;(and the requests are most likely blocked at the firewall as requests to an unknown port -- &lt;strong&gt;after all your computer isn't a symantec server is it?  so why would it be set up to do anythiing but disregard requests like that&lt;/strong&gt;.)&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;at anyrate.. NIS found the tamper, and told you it had to remove it to phone home &lt;/font&gt;&lt;font size="1"&gt;(which it did, because your computer was told to ask itself)&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="1"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt; &lt;/font&gt;&lt;/p&gt;&lt;hr&gt;&lt;p&gt;Page 2:  The Hosts file can also be used in another way... and that is to redirect you to fake / ad / malicious sites...  Thats the direction this thread was headed in... sorry for the confusion... things became clear when you mentioned 127.0.0.1&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;hr&gt;&lt;p&gt;you can use the toolbar above the message editor window... or you can click 'edit as html' and use your on HTML. &lt;font color="#999999" size="1"&gt;&lt;strong&gt;(not all HTML is supported)&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description>
      <pubDate>Sat, 30 Aug 2008 21:34:39 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/20770#M6385</guid>
      <dc:creator>4runner</dc:creator>
      <dc:date>2008-08-30T21:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/21045#M6491</link>
      <description>&lt;p&gt;Thanks 4runner&lt;/p&gt;&lt;p&gt;I started another thread and got my answer by a Symantec employee,totally different from bullhorns problem.Appreciate your reply to my inquiry.&lt;/p&gt;&lt;p&gt;regards mo&lt;/p&gt;</description>
      <pubDate>Mon, 01 Sep 2008 11:44:08 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/21045#M6491</guid>
      <dc:creator>mo</dc:creator>
      <dc:date>2008-09-01T11:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Update sites or spyware scams.</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/25525#M8559</link>
      <description>&lt;p&gt;Yes, well now it's happened again!&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img src="http://img227.imageshack.us/img227/8377/20080919230127ah8.jpg" border="0" width="528" height="360" /&gt;&lt;/p&gt;&lt;p&gt;Shot at 2008-09-20&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;although this time it had a muliple choice box, and a  'Backdoor.tidserv' virus was soon thereafter  reported&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;by Norton anti-virus ..............which required manual removal&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;so the question still remains what have these two update sites got to do with norton update?..........bullhorn&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="1" color="#ff0000"&gt;[edit: added screenshot to post&lt;/font&gt;&lt;/strong&gt;&lt;strong&gt;&lt;font size="1" color="#ff0000"&gt;]&lt;/font&gt;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div class='message-edit-history'&gt;&lt;span class='edit-author'&gt;Message Edited by Tony_Weiss on &lt;/span&gt;&lt;span class='local-date'&gt; 09-20-2008&lt;/span&gt;&lt;span class='local-time'&gt; 07:29 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Sat, 20 Sep 2008 23:29:46 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Update-sites-or-spyware-scams/m-p/25525#M8559</guid>
      <dc:creator>bullhorn</dc:creator>
      <dc:date>2008-09-20T23:29:46Z</dc:date>
    </item>
  </channel>
</rss>

