Virus blocks access to antivirus Web sites

A new variant of the Crowt worm blocks an infected user's browser from accessing certain antivirus vendors' Web sites.

Crowt.D -- first discovered on Wednesday last week -- opens up the Google News site upon infection and then alters the computer's HOST file to manipulate access to specific Web sites. According to antivirus firm Trend Micro, the worm restricts access to sites including trendmicro.com, kapersky-labs.com, sophos.com, symantec.com and us.mcafee.com.

Adam Biviano, senior systems engineer at Trend Micro, said Crowt.D can redirect users' regardless of which browser they use.

"It uses the Windows associations to launch a file, so it will open your default browser," said Biviano.

Biviano said the virus is noteworthy because it has the potential to send a victim to a phishing Web site even when they have manually typed in a Web address, which is especially dangerous when using an online banking service.

"Banks are telling their customers to type their specific Web site address into the browser. However, if the host file has been compromised then even if the URL is typed in, the browser will still go to the phishing Web site," said Biviano.

DNS poisoning is another method that is being used by hackers to try and redirect Internet users to fraudulent Web sites. On Wednesday, Microsoft advised users of its server software to reconfigure their setting to avoid such attacks.

Advertisement

Talkback 3 comments

    HELP!Anonymous -- 06/12/08

    I'm very sure I have somehow gotten this virus. How do I get rid of it?

    HELP!Anonymous -- 25/12/08 (in reply to #320118118)

    Everybody is trying to get rid of it, please!

    Format the hard disk and all the partitions!Anonymous -- 13/01/09

    It worked for me! don`t run any of the exe files you save ... the only thing worth saveing are pictures and some txt files ! it`s a **** of a virus! I installed Vista after that ... i`ll keep u posted :) thx

Add your opinion


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured