Reply
Visitor
MrBrateee
Posts: 5
Registered: ‎02-01-2012

Norton AntiVirus 19.1.0.28 blocks attack!

A few days ago we are reported that Norton blocks of constant attacks. Somewhere on the internet  I read that hackers had retrieve the source code. Can you tell me what is this?

SendOfJive
Posts: 9,899
Kudos: 4,190
Solutions: 706
Registered: ‎02-07-2009

Re: Norton AntiVirus 19.1.0.28 blocks attack!

[ Edited ]

Hi MrBrateee,

 

Can you tell us the name of the threat that Norton says it is blocking?  It should appear in the alert itself  or in one of the entries in the Intrusion Prevention logs in Norton History.

 

It is not related to the reports of the source code theft, which only affects users of pcAnywhere.

Visitor
MrBrateee
Posts: 5
Registered: ‎02-01-2012

Re: Norton AntiVirus 19.1.0.28 blocks attack!

IPS Alert Name: OS Attack: MS PRCSS Attack CVE-2004-01162

Visitor
MrBrateee
Posts: 5
Registered: ‎02-01-2012

Re: Norton AntiVirus 19.1.0.28 blocks attack!

Is there stealing source code and, am I safe if install Norton again?

Visitor
MrBrateee
Posts: 5
Registered: ‎02-01-2012

Re: Norton AntiVirus 19.1.0.28 blocks attack!

My problem is not solved. :(

SendOfJive
Posts: 9,899
Kudos: 4,190
Solutions: 706
Registered: ‎02-07-2009

Re: Norton AntiVirus 19.1.0.28 blocks attack!

[ Edited ]

Hi MrBrateee,

 

OS Attack: MS PRCSS Attack CVE-2004-01162 is an exploit of an old vulnerability that was patched by Microsoft in 2004, so you are not likely to be susceptible to this specific attack unless you are running an OS that was not patched as listed here:

 

http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=20386

 

If you are seeing these only occasionally, especially when you are visiting a particular website, it may just be that the site is compromised and Norton is successfully preventing an exploit hosted there from running on your computer.  On the other hand, an OS attack is serious business, and if you are getting these repeatedly it may indicate something already on your system that is connecting out to launch the exploit.   When you look in your IPS logs, do you see any entries that list the threat as "System Infected?"  If so, you may wish to post to one of the free malware removal forums where trained experts can run tools to find any hidden malware that may be on your PC:

 

http://www.bleepingcomputer.com

http://www.geekstogo.com/forum/

http://www.cybertechhelp.com/forums/

http://forums.whatthetech.com/

 

Again, this has absolutely nothing to do with the stolen code from 2006, so persuing that angle will not be very productive.