Cannot Access Symantec website

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boroboynz, Oct 6, 2007.

  1. boroboynz

    boroboynz Private E-2

    My system has recently been infected by a Trojan Horse (Generic 8). I have managed to get rid of the offending file but now I cannot access the symantec website.

    Below is my Hijackthis scan.

    Can anyone help me out?
     
    Last edited by a moderator: Oct 6, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    What do you mean you cannot access the Symantec website? What message do you get? And is this the only site you cannot access? What about other security/antivirus sites?


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. boroboynz

    boroboynz Private E-2

    Since the virus infection I cannot access Symantec or Macafee, I get the "Page cannot be displayed" error message. It is only from this machine my others are good.

    Did not run Counterspy, run AVG Antispyware - this found no problems.

    Bitdefender could not be run

    Have attached Panda Scan, runkey, newfiles and Hijackthis logs
     

    Attached Files:

  4. boroboynz

    boroboynz Private E-2

    Hijackthis scan attached
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? And how can you day they did not find any problems if they were not run???

    What happended?

    First goto Add/Remove programs and uninstall this: LiveUpdate 2.5 (Symantec Corporation)

    Now let's also remove a left over service from Symantec.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Oct 7, 2007
  6. boroboynz

    boroboynz Private E-2

    I removed liveupdate 2.5

    stopped SymWMI

    Ran HJ and and did delete NT Service, error message stated this was crirical and could not be deleted. When HJ closed it did not prompt me to restart.

    Ran HostXpert

    Fixed the selected lines in HJ

    Ran ATF Cleaner

    Still get an error of page cannot be displayed on Symantec and Mcafee

    Attached HJ and shownew logs
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the new logs!

    Which browser are you using to try and connect to those sites and what URLs are you using? Also make sure you are not blocking them in your firewall and that they are not in your Restricted Zone.
     
  8. boroboynz

    boroboynz Private E-2

    I am currently using IE 6.

    The two sites are not being blocked by the firewall and are not in the restricted zone list.

    The result is the same whether I use Symantec.com or if I navigate to it through a search engine, same for Mcafee.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install Mozilla FireFox browser and see if you can connect to those same two sites using FireFox.
     
  10. boroboynz

    boroboynz Private E-2

    I downloaded and installed Mozilla Firefox, everything was good, I was able to connect to the Symantec and Mcafee sites.

    Went and tried IE and could not connect, same error as previous.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that is what I expected would happen. It does not sound like you are having malware problems. It seems like you are blocking those sites in IE some how.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.xtramsn.co.nz/0SEENNZ/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.xtramsn.co.nz/0SEENNZ/SAOS01?FORM=TOOLBR
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=Q305&bd=presario&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.xtramsn.co.nz/0SEENNZ/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://securityresponse.symantec.com/

    After clicking Fix, exit HJT.
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now please download DelDomainsand unzip it to your desktop. Do not run it yet.

    Find the files from deldomains.zip on your Desktop and RightClick on the deldomains.inf file and select Install.

    (Now you will need to "Immunize" with Spybot again because deldomains will remove all of the sites Spybot adds.)


    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Did that change anything?
     
  12. boroboynz

    boroboynz Private E-2

    Carried out the last set of instructions, still the same.

    Sorry to be a pest.

    Have included HJ and Shownew logs
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see no malware related reasons why you cannot access those two websites so there must be something configured on your PC that is blocking access to those sites when you use IE. You will have to hunt around to find out what. You can in the meantime just use FireFox to access the sites.

    Let's address a few issues that I do see though. On of which is that Norton Security Center seems to be still installed and you are using AVG. Also some other software needs to be uninstalled and/or updated.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Norton Security Center

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds