Symantec Corp acknowledged that it was deliberately hiding a directory from Windows APIs as a feature to stop customers from accidentally deleting files. Symantec's Norton System Works used a root-kit type feature that could have have been used by hackers.
Norton SystemWorks contains a feature called the Norton Protected Recycle Bin, which resides within the Microsoft Windows Recycler directory. The Norton Protected Recycle Bin includes a directory called NProtect, which is hidden from Windows APIs. Files in the directory might not be scanned during scheduled or manual virus scans. This could potentially provide a location for an attacker to hide a malicious file on a computer.
Symantec is not aware of any attempts by hackers to conceal malicious code in the NProtect folder. Symantec product engineers have developed and released an update for products affected by this exposure. The update is available through Symantec LiveUpdate by running a manual update.
|