Virus blocks access to antivirus Web sites

A new variant of the Crowt worm blocks an infected user's browser from accessing certain antivirus vendors' Web sites.

Crowt.D -- first discovered on Wednesday last week -- opens up the Google News site upon infection and then alters the computer's HOST file to manipulate access to specific Web sites. According to antivirus firm Trend Micro, the worm restricts access to sites including trendmicro.com, kapersky-labs.com, sophos.com, symantec.com and us.mcafee.com.

Adam Biviano, senior systems engineer at Trend Micro, said Crowt.D can redirect users' regardless of which browser they use.

"It uses the Windows associations to launch a file, so it will open your default browser," said Biviano.

Biviano said the virus is noteworthy because it has the potential to send a victim to a phishing Web site even when they have manually typed in a Web address, which is especially dangerous when using an online banking service.

"Banks are telling their customers to type their specific Web site address into the browser. However, if the host file has been compromised then even if the URL is typed in, the browser will still go to the phishing Web site," said Biviano.

DNS poisoning is another method that is being used by hackers to try and redirect Internet users to fraudulent Web sites. On Wednesday, Microsoft advised users of its server software to reconfigure their setting to avoid such attacks.

Advertisement

Talkback 3 comments

    HELP! Anonymous -- 06/12/08

    I'm very sure I have somehow gotten this virus. How do I get rid of it?

    HELP! Anonymous -- 25/12/08 (in reply to #320118118)

    Everybody is trying to get rid of it, please!

    Format the hard disk and all the partitions! Anonymous -- 13/01/09

    It worked for me! don`t run any of the exe files you save ... the only thing worth saveing are pictures and some txt files ! it`s a **** of a virus! I installed Vista after that ... i`ll keep u posted :) thx

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured