On The Insider: Jackson Memorial Confirmed
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jan 12, 2006 1:20:00 AM

Symantec has released an update to its popular Norton SystemWorks to fix a security problem that could be abused by cybercriminals to hide malicious software.

In the PC-tuning application, a feature called the Norton Protected Recycle Bin creates a hidden directory on Windows systems. The feature is meant to help people restore modified or deleted files, but the hidden folder might not be scanned during scheduled or manual virus scans, Symantec said in an advisory released Tuesday.

"This could potentially provide a location for an attacker to hide a malicious file on a computer," Symantec said. The Cupertino, Calif., security provider is not aware of any attempts by hackers to conceal malicious code in the folder. "This update is provided proactively to eliminate the possibility of that type of activity," it said.

Symantec's alert has echoes of Sony BMG Music Entertainment's recent PC security fiasco. The record label was found to be shipping copy-protected compact discs that planted so-called rootkit software on the computers that played them. The rootkit technology also offered a hiding place for malicious software.

When the recovery feature was first introduced, hiding the directory helped ensure that a user would not accidentally delete the files in it, Symantec said.

"In light of current techniques used by malicious attackers, Symantec has re-evaluated the value of hiding this directory," the company said in its advisory.

Security monitoring company Secunia rates the issue "not critical." Symantec itself deems the risk impact "low."

Symantec credits Mark Russinovich, the Sysinternals researcher who also investigated the Sony rootkit, and F-Secure, a Finnish security company that has a rootkit detection product, for helping it address the SystemWorks issue.

The Norton update will display the previously hidden "NProtect" directory in the Windows interface, which will allow it to be scanned by antivirus products, Symantec said. The new version is available through the Symantec LiveUpdate service. Installing the software will require a system reboot.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 80 Talkback(s)
rnav2004
i need this file please can you send me it(rnav2004)for email???? please (Read the rest)
Posted by: canarilla Posted on: 10/13/06 You are currently: a Guest | | Terms of Use
What kind of hiding?  fivetalentguy | 01/11/06
Hiding  adsanders@... | 01/12/06
as far as i can tell...  linuxoverwindows | 01/12/06
Not hidden to the kernel  BrewMan01 | 01/12/06
Why allow hiding?  fizzmaster | 01/11/06
Well put...  techboy_z | 01/12/06
Windows XP boots faster  duclod | 01/12/06
or...  linuxoverwindows | 01/12/06
Not an OS issue  Interfecus | 01/12/06
It is an OS issue  Leria | 01/16/06
Erm... Dude  EdwardT | 01/12/06
The real WHY...  Wolfie2K3 | 01/12/06
Those people are stupid  Leria | 01/16/06
Bloatware hiding in bloatware  zmud | 01/12/06
Not me. Their recycle bin was the end  jinko | 01/12/06
go with avast  Jeff Spicoli | 01/12/06
I want a second opinion  IceTheNet@... | 01/12/06
here  Jeff Spicoli | 01/12/06
Oh well that is easy then  IceTheNet@... | 01/12/06
A second opinion  Dave F_z | 01/12/06
AVG vs. Avast  Quiet_Type | 01/12/06
Spicoli Now Star in Czechoslovakia  PMC-CON | 01/17/06
Now You are Really Showing Your Ignorance  HiBeamR_z | 01/12/06
Re: Now You are Really Showing Your Ignorance  snakesc | 01/14/06
Norton Antivirus isn't the right product  Leria | 01/16/06
need link 2please  moses_z | 01/23/06
it's really crap!  pikeman666@... | 01/12/06
The disc might have been defective  Leria | 01/16/06
dud is Symantec, dudley  moses_z | 01/23/06
Early reporting of possible hacker attacts  skip_fraker | 01/12/06
Given the nature of the feature...  techboy_z | 01/12/06
Bet the Black Hats Knew it Before ZDNet Posted This  tbbrickster_z | 01/12/06
Annoying 'feature' anyway  voyager529 | 01/12/06
100% agree  jinko | 01/12/06
Option to not install/or uninstall parts of NSW  cglrcng@... | 01/13/06
Recovery Bin Uses  adsanders@... | 01/12/06
There is a good purpose  Leria | 01/16/06
Any Tools to completely remove Norton?  OldTimer1 | 01/12/06
Yes  Ralfthedog | 01/12/06
Maybe  moonbr | 01/12/06
Tools to remove Norton  smcc_z | 01/12/06
Removing Norton  prushworth@... | 01/12/06
Any Tools to completely remove Norton  a8a09923@... | 02/05/06
Completely remove Symantec Norton Antivirus  tschrock | 03/12/06
ISO original RNAV.EXE  glnz | 05/28/06
Norton protected files  frank_s | 01/12/06
Norton is still the name?  IT Scion | 01/12/06
what is TMIS  IceTheNet@... | 01/12/06
re:what is TMIS  monkey_poop | 01/12/06
What else is new?  Lorenzo1950 | 01/12/06
and furthermore  Lorenzo1950 | 01/12/06
Nortons firewall is no good either  IceTheNet@... | 01/12/06
Have You Tried Tiny Personal FW?  tbbrickster_z | 01/12/06
Not so sure about that...  Wolfie2K3 | 01/12/06
The firewall isn't the problem  Leria | 01/16/06
That is a script warning...  cglrcng@... | 01/13/06
Look at that list!!  s_gamgee | 01/13/06
Hiding the world  JenBell | 01/12/06
what about hidden files in chip  IceTheNet@... | 01/12/06
Only Some Really faaa-REAKY "People" at Redmond... (nt)  tbbrickster_z | 01/12/06
Content.IE5  Wolfie2K3 | 01/12/06
Rabbit Hole...  cglrcng@... | 01/13/06
re: Rabbit Hole...  ray.pating | 01/13/06
You can see that directory  Leria | 01/16/06
Yep - we use Windows  EJHonda | 01/12/06
NOD32  alex@... | 01/12/06
??? CNET: has Microsoft's passed Winfix_ F-Secure  Pop 3 | 01/12/06
Who'da thunk,,,  preacherx | 01/12/06
Q. How much software contains rootkits?  Betelgeuse58 | 01/12/06
Yes! RNAV 2004.exe & SYMCLN.EXE  cglrcng@... | 01/13/06
ISO original RNAV.EXE  glnz | 05/28/06
rnav2004  canarilla | 10/13/06
Sensationalistic lies?  Dukhalion | 01/13/06
Norton fell since 2002  pegassus | 01/14/06
Turn it OFF  Pegasus1 | 01/15/06
"FYI"  Pegasus1 | 01/15/06
Let's keep things balanced  FNicodem | 01/16/06
Symantec didn't close off hacker hiding place  Boot_Agnostic | 01/16/06
what else then  road runner_z | 01/28/06
ISO original RNAV.EXE  glnz | 05/28/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Smartphones

  • Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they're arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
  • Designed for
    bold living.
  • blackberry bold
  • Edit Word docs, check email, even listen to iTunes® playlists. Do more and do it faster with the BlackBerry® Bold™.Learn more
  • blackberry logo
advertisement
Click Here