awake Posted June 21, 2004 Report Share Posted June 21, 2004 I'm looking at a Windows XP Home laptop with a wierd problem:The PC had a virus (can't remember name) which has been removed with a norton AV tool. Norton Internet Security 2004 was then loaded.Noticed norton wouldn't get any liveupdates from symantec. So, checked the web connection - ok (blueyonder cable broadband).I then tried a different web site which it loaded ok. In fact, it will happily load any web site that dowsn't belong to symantec, ie, www.symantec.com, liveupdate.symantecliveupdate.com, www.symantec.co.uk, etc are all unaccessable with a standard 'Unable to load this page' (404 error, I think) error message.Thought this was some rule setup in Norton, so checked and no firewall rules are setup. Then uninstalled, turned off sys restore, reinstalled, updated virus definitions manually and scanned to find no sign of any virus / threat, but still the PC wouldn't load a symantec website.Then disabled norton internet security, but got the same results !?So, did some more checking: XP firewall is switched off and with all IE privacy/content settings at their minimum the problem still exists.So, something (maybe the virus ?) has altered a setting either in IE or the registry to prevent all symantec web sites from being loaded.Putting up this post in the vague hope that someone has heard of this, before I start trawling through the registry, or reloading XP.Any thoughts on this appreciated. Quote Link to comment Share on other sites More sharing options...
Chris Posted June 21, 2004 Report Share Posted June 21, 2004 Click Start, Run, Copy and paste:notepad %systemroot%\system32\drivers\etc\hostsClick OK.Do you see symantec.com or a bunch of numbers [An I.P] other than 127.0.0.1 localhost ? Quote Link to comment Share on other sites More sharing options...
awake Posted June 21, 2004 Author Report Share Posted June 21, 2004 Haven't got the PC in front of me, but I will have a look.Thanks for that. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 21, 2004 Report Share Posted June 21, 2004 A lot of viruses will disable AV software, such as disabling updates, automatic scans, and so on.The virus has probably done something like this, and after being removed, the "trail of destruction", as I like to call it was left behind. This means any files, reg keys or values etc that were altered by the virus are usually not undone by a removal tool.So, you may need to format, but I'm sure there is an easier fix, I'm just not sure of how :) good luck Quote Link to comment Share on other sites More sharing options...
expertec Posted June 21, 2004 Report Share Posted June 21, 2004 Go to here and download 'Hijack This!'. Unzip/extract to a new folder, doubleclick HijackThis.exe, and hit "Scan".When the scan is finished, the "Scan" button will change into a "Save Log" button.Press that, save the log somewhere, and please copy and paste its contents into a post here.Most of what it lists will be harmless or even required, so do NOT fix anything yet.Someone here will help you analyze the results.With ME and XP simply right click the zipped folder, select Extract All, this will create a folder Hijackthis, inside will be Hijackthis.exe. Quote Link to comment Share on other sites More sharing options...
awake Posted June 28, 2004 Author Report Share Posted June 28, 2004 Following is 'HijackThis' log from the laptop in question - I'd be grateful if someone could look at it pls.Logfile of HijackThis v1.97.7Scan saved at 16:55:21, on 26/06/2004Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exeC:\WINDOWS\system32\slserv.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINDOWS\System32\igfxtray.exeC:\WINDOWS\System32\hkcmd.exeC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\vsnpstd.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Sony Corporation\Image Transfer\SonyTray.exeC:\Program Files\blueyonder IST\bin\mpbtn.exeC:\Program Files\Outlook Express\msimn.exeC:\WINDOWS\System32\wuauclt.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Documents and Settings\FIONA JOHNSON.FIONA.003\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.blueyonder.co.uk/O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dllO2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1629.0\en-gb\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [OemReset] %systemroot%\OPTIONS\OEMRESET.EXE /AUDITO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exeO4 - Global Startup: Image Transfer.lnk = ?O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.htmlO8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.htmlO8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.htmlO8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.htmlO9 - Extra button: Related (HKLM)O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Messenger (HKLM)O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0555360ef53290...ip/RdxIE601.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...38104.194837963O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl...ArcadeRdxIE.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab Quote Link to comment Share on other sites More sharing options...
Redhat Posted June 28, 2004 Report Share Posted June 28, 2004 Open this file in notepad : c:\windows\system32\drivers\etc\hosts and see if symantec.com has been edited in. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 28, 2004 Report Share Posted June 28, 2004 The only thing in your log that I don't recognise is thisO4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exedo you know what it is? Could you find it and right click on it and tell me what it says in properties?There is an excellent hosts file reader and editor here, written and developed by Gladiator's toadbee.You could download it and run it and click on the button that says copy to clipboard, then paste as a reply to this thread. Quote Link to comment Share on other sites More sharing options...
expertec Posted June 28, 2004 Report Share Posted June 28, 2004 If Symantec had been added to Hosts, wouldn't it have shown up in HJT? (That was what I was thinking) Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 28, 2004 Report Share Posted June 28, 2004 I would have thought so expertec.... but I never take anything for granted these days.It might be an idea for awake to do an online virus scan too! Click on the Panda link at the top of this board. Quote Link to comment Share on other sites More sharing options...
awake Posted June 30, 2004 Author Report Share Posted June 30, 2004 I think we've found the source of the problem. Finally got hold of the 'hosts' file (the PC isn't mine) and it contains the following:==================================================# Copyright © 1993-1999 Microsoft Corp.## This is a sample HOSTS file used by Microsoft TCP/IP for Windows.## This file contains the mappings of IP addresses to host names. Each# entry should be kept on an individual line. The IP address should# be placed in the first column followed by the corresponding host name.# The IP address and the host name should be separated by at least one# space.## Additionally, comments (such as these) may be inserted on individual# lines or following the machine name denoted by a '#' symbol.## For example:## 102.54.94.97 rhino.acme.com # source server# 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost 127.0.0.1 www.symantec.com127.0.0.1 securityresponse.symantec.com127.0.0.1 symantec.com127.0.0.1 www.sophos.com127.0.0.1 sophos.com127.0.0.1 www.mcafee.com127.0.0.1 mcafee.com127.0.0.1 liveupdate.symantecliveupdate.com127.0.0.1 www.viruslist.com127.0.0.1 viruslist.com127.0.0.1 viruslist.com127.0.0.1 f-secure.com127.0.0.1 www.f-secure.com127.0.0.1 kaspersky.com127.0.0.1 www.avp.com127.0.0.1 www.kaspersky.com127.0.0.1 avp.com127.0.0.1 www.networkassociates.com127.0.0.1 networkassociates.com127.0.0.1 www.ca.com127.0.0.1 ca.com127.0.0.1 mast.mcafee.com127.0.0.1 my-etrust.com127.0.0.1 www.my-etrust.com127.0.0.1 download.mcafee.com127.0.0.1 dispatch.mcafee.com127.0.0.1 secure.nai.com127.0.0.1 nai.com127.0.0.1 www.nai.com127.0.0.1 update.symantec.com127.0.0.1 updates.symantec.com127.0.0.1 us.mcafee.com127.0.0.1 liveupdate.symantec.com127.0.0.1 customer.symantec.com127.0.0.1 rads.mcafee.com127.0.0.1 trendmicro.com127.0.0.1 www.trendmicro.com==================================================!!!!!!!!So, will perform some 'surgery' on this file and let you know how it goes ! Quote Link to comment Share on other sites More sharing options...
nellie2 Posted June 30, 2004 Report Share Posted June 30, 2004 Looks like something doesn't want you to have any access to AV protection! :huh: Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 30, 2004 Report Share Posted June 30, 2004 A lot of viruses will disable AV software, such as disabling updates, automatic scans, and so on.The virus has probably done something like this, and after being removed, the "trail of destruction", as I like to call it was left behind. This means any files, reg keys or values etc that were altered by the virus are usually not undone by a removal tool.So, you may need to format, but I'm sure there is an easier fix, I'm just not sure of how :) good luckI agree nellie............. Quote Link to comment Share on other sites More sharing options...
awake Posted July 26, 2004 Author Report Share Posted July 26, 2004 Problem resolved - thanks for everyone's help. Edited the hosts file and removed all except the local host entry and all's well ! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.