<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : Omniture 2o7.net</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/Omniture+2o7.net/default.aspx</link><description>Tags: Omniture 2o7.net</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Symantec LiveUpdate Security Warning revisited</title><link>http://msmvps.com/blogs/hostsnews/archive/2008/08/30/1646253.aspx</link><pubDate>Sat, 30 Aug 2008 05:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646253</guid><dc:creator>winhelp2002</dc:creator><slash:comments>1</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2008/08/30/1646253.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ve blogged about this several times ...[&lt;a target="_blank" href="http://www.mvps.org/winhelp2002/hostsfaq.htm#Norton_2007"&gt;here&lt;/a&gt;] [&lt;a target="_blank" href="http://msmvps.com/blogs/hostsnews/archive/2007/08/08/symantec-detects-a-possible-malicious-entry-in-the-hosts-file.aspx"&gt;here&lt;/a&gt;]&amp;nbsp;however as I am frequently asked about this (false) prompt (mostly from new MVPS HOSTS users) I thought I would address this again ... especially after seeing a response from one of their (very) uninformed commenters on &lt;a target="_blank" href="http://community.norton.com/norton/board/message?board.id=nis_feedback&amp;amp;message.id=6341"&gt;their Forum&lt;/a&gt; ...&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;I did not read in detail the links you provided, so this may not directly answer your question, but it may help you understand what is happening here.&amp;quot;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Then why bother ... if you are not going to &amp;quot;read in detail the links&amp;quot; ...&lt;/p&gt;
&lt;p&gt;And then goes on to say:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&amp;quot;So in your case what has happened is that a piece of malware has modified your HOSTS file to include entries for &amp;#39;tc.symantec.com&amp;#39; and &amp;#39;om.symantec.com&amp;#39;.&amp;quot;&lt;/em&gt; ... talk about mis-informed ... &lt;strong&gt;duh!&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you had bothered to read the links then you would not (hopefully) make such a truly false statement.&lt;br /&gt;Here is&amp;nbsp;a typical&amp;nbsp;prompt Symantec users see ...&lt;/p&gt;
&lt;p&gt;&lt;img width="615" src="http://www.mvps.org/winhelp2002/liveupdate.jpg" height="382" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;If Symantec users click the drop-down arrow there is an option for:&lt;br /&gt;&lt;strong&gt;&lt;em&gt;&amp;quot;Leave the entry in the hosts file (do not warn me about them later)&amp;quot; &lt;/em&gt;&lt;/strong&gt;(then this is no longer an issue ...)&lt;/p&gt;
&lt;p&gt;Let me be very clear ... these are &lt;strong&gt;NOT&lt;/strong&gt; entries from Symantec ... although they try to disguise them as such ... they both are 3rd party entries from &lt;a target="_blank" href="http://en.wikipedia.org/wiki/Omniture" title="Wikipedia description of Omniture"&gt;Omniture&lt;/a&gt; ... and they do &lt;strong&gt;NOT&lt;/strong&gt; prevent Symantec products from updating themselves ...&lt;/p&gt;
&lt;p&gt;&lt;img width="439" src="http://mvps.org/winhelp2002/blog/symanteccom1.gif" height="342" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see &amp;quot;&lt;em&gt;&lt;strong&gt;om.symantec.com&lt;/strong&gt;&lt;/em&gt;&amp;quot; is actually an alias for &amp;quot;&lt;em&gt;&lt;strong&gt;symanteccom.112.2o7.net&lt;/strong&gt;&lt;/em&gt;&amp;quot; and the IP addresses are all controlled by Omniture.&lt;/p&gt;
&lt;p&gt;&lt;img width="722" src="http://mvps.org/winhelp2002/blog/symanteccom2.gif" height="409" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Even when you run a traceroute you can see above where it ends ... below is just a partial list of the Omniture entries and the IP addresses ... which shows that some sites prefer the &amp;quot;2o7.net&amp;quot; while others prefer to hide their identity as in the case with Symantec ...&lt;/p&gt;
&lt;p&gt;&lt;img width="425" src="http://mvps.org/winhelp2002/blog/symanteccom3.gif" height="403" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;strong&gt;Note&lt;/strong&gt;: it appears that Symantec is no longer using &amp;quot;&lt;em&gt;tc.symantec.com&lt;/em&gt;&amp;quot; on their site ... most likely after I &lt;a target="_blank" href="http://msmvps.com/blogs/hostsnews/archive/2007/08/08/symantec-detects-a-possible-malicious-entry-in-the-hosts-file.aspx"&gt;exposed this issue last time&lt;/a&gt; ... where they were using the Privacy policy from a 3rd party (Omniture) and not their own. So this entry will be removed and will reflect in the next update ...&lt;/p&gt;
&lt;p&gt;&lt;img width="450" src="http://mvps.org/winhelp2002/blog/touchclarity.gif" height="84" style="border:1px solid black;" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;Folks I can not control these false-positive prompts from Antispyware/Antivirus products ... believe me I&amp;#39;ve tried ... but they refuse alter their scanning techniques, so all I can do is try to explain why these entries exist ... then you can decide for yourself if you have a malware infection ... or a poorly writen scanner detection. There is no such thing as a infection that only alters the HOSTS file ... so if that&amp;#39;s all that shows up in a scan then check it out or ask ... I will gladly assist in determining the cause ...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1646253" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Omniture+2o7.net/default.aspx">Omniture 2o7.net</category></item></channel></rss>