1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[Solved] Cannot connect to symantec

Discussion in 'Virus & Other Malware Removal' started by Scottp7, Apr 28, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    I have asimilar problem to Migh that you have already helped and am wondering if I can follow his solution from you?

    I cannot connect to Symantec and my Norton shows my auto protect off and cant be reset/my e-mail cscan off as well and my virus definitions cannot be updated. When I try to updae it tells me i'm not connected to internet which I am!

    I also then get these messages:
    1) RUNDLL
    error loading & the sopecified module cannot be found

    2) error loading
    microsoft visual C++runtime library
    runtime error
    program:c:\programfile\common\symantecshared\ccEvtMgr.exe
    R6025 - pure virtual function

    I can do eveything else normally except now have no virus protection. You come highly recommended and i'm hoping you can help

    Thanks

    Scott
     
  2. TOGG

    TOGG

    Joined:
    Apr 2, 2002
    Messages:
    5,897
  3. TOGG

    TOGG

    Joined:
    Apr 2, 2002
    Messages:
    5,897
    Also, take a look at the threads by arthodyd and luvmynails further down this page.

    Running the anti adware tools referred to in those threads, plus a HijackThis scan, could be useful in your case although you will have to wait for one of the experts here to interpret HJT for you.
     
  4. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    Thanks,

    it asppears adware is what has screwed things up for me. So I want be using that.
     
  5. TOGG

    TOGG

    Joined:
    Apr 2, 2002
    Messages:
    5,897
    Perhaps I didn't make myself clear in my last post.

    The Spybot and AdAware programs are supposed to remove spyware/adware and should be run before any HJT scan. Or are you saying that you know that AdAware caused your current problems?

    Were you able to get to Symantec Knowledgebase and try the fix for the R6025 error suggested in that article?
     
  6. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    Hey Togg,

    I can run a scan with my Norton and get 7 files listed that are infected and they are all from adware ... I can't delete them with Norton or manually they just reappear when I restart?

    I tried the url you gave and had already tried it the file it has me search for to rename is not being found when I search for it? I also tried searching for the file "hos" and don't seem to get anywhere there either. I'm getting stumped every way I turn here! Frustrating cause I can do everything else on it except I have no protection! ( no pun intended)

    I can't access spybot as it stops me from connecting.
     
  7. TOGG

    TOGG

    Joined:
    Apr 2, 2002
    Messages:
    5,897
    There seem to be a lot of people on here with problems that sound similar to yours.

    NAV is not a dedicated spyware remover even though they do include some in their definitions. One or both of the other programs I mentioned would be much better.

    Check this thread as the problem seems to have been resolved here;
    http://forums.techguy.org/t224666.html
     
  8. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Please do this. Click here to download Hijack This. Click on the Hijackthis.exe.

    Click the "Scan" button when the scan is finished the scan button will become "Save Log" click that and save the log.

    Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.

    DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required. Someone here will be glad to advise you on what to fix.

    *Note: When you download Hijack This Do Not download it to a temp folder or to the desktop. Create a permanent folder somewhere like in My Documents and name it Hijack This and put it in that folder.
     
  9. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    Flrman1, Gald I found you but when I click on the link I now get this message:
    C:\docum~1\scott\locals~1\temp\ryc9kwpe.exe could not be saved, because the source file could not be read.
    try again later or contact server administrator.
    Now i'm rally confused here as I knwo youv'e helped people this way and now what do do?
    Please help

    Thanks

    Scott
     
  10. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Ok I'm attaching Hijack This to this post as hijackthis.txt. Download it and save it to it's own permanent folder and then rename it to hijackthis.exe. Run it according to my previous instructions and post the log.
     
  11. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    Flrman1,

    Ypu most definately are the man! It still wouln't let me save it so what I did was went to my laptop downloaded as you said and the e-mailed it to my home it appeared to work and this is what I got. Hope you cna keep helpin from here alyjough I ge the feeling you can.

    Thanks

    Scott



    Logfile of HijackThis v1.97.7
    Scan saved at 5:10:35 PM, on 29/04/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Samsung Multimedia Keyboard\MMKBD.EXE
    C:\PROGRA~1\WinFax\WFXSWTCH.exe
    C:\WINDOWS\System32\wfxsnt40.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\wt\updater\wcmdmgr.exe
    C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    C:\Program Files\Common files\updmgr\updmgr.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\PopupDummy!\PopupDummy! 2.5.EXE
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    C:\Program Files\Netscape\Netscape 6\Netscp.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Documents and Settings\Scott\My Documents\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myt/
    R3 - URLSearchHook: PerfectNavBHO Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~2.DLL
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.canada.com/vancouver/"); (C:\Program Files\Netscape\Users\ebonvan\prefs.js)
    O2 - BHO: NavErrRedir Class - {0428FFC7-1931-45b7-95CB-3CBB919777E1} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~2.DLL
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_22-1.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Multimedia Keyboard] "C:\Program Files\Samsung Multimedia Keyboard\MMKBD.EXE"
    O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\ACDSee\CAMDET~1.EXE
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
    O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 ΓΈ,NewDotNetStartup
    O4 - HKLM\..\Run: [scvhost.exe] scvhost.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Startup: PopupDummy!.lnk = C:\Program Files\PopupDummy!\PopupDummy! 2.5.EXE
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
     
  12. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    We are going to have to do this in several steps so we can get you to where you can connect to these sites to download some tools.

    First run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"

    O4 - HKLM\..\Run: [scvhost.exe] scvhost.exe

    O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe


    Restart to safe mode.

    How to start your computer in safe mode

    First in safe mode click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
    Click "Apply" then "OK"

    Now find and delete:

    The C:\WINDOWS\System32\scvhost.exe file

    Also in safe mode navigate to the C:\Documents and Settings\scott\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


    The next thing you need to do is navigate to the C:\Windows\System32\Drivers\etc folder. Locate the HOSTS file. Right click it and rename it to HOSTS.txt. Now doubleclick it and it will open in notepad. Now you should see a bunch of entries like this:

    127.0.0.1 www.sophos.com
    127.0.0.1 sophos.com
    127.0.0.1 www.mcafee.com
    127.0.0.1 mcafee.com
    127.0.0.1 liveupdate.symantecliveupdate.com
    127.0.0.1 www.viruslist.com
    127.0.0.1 viruslist.com
    127.0.0.1 viruslist.com
    127.0.0.1 f-secure.com
    127.0.0.1 www.f-secure.com
    127.0.0.1 kaspersky.com
    127.0.0.1 kaspersky-labs.com
    127.0.0.1 www.avp.com
    127.0.0.1 www.kaspersky.com
    127.0.0.1 avp.com
    127.0.0.1 www.networkassociates.com
    127.0.0.1 networkassociates.com
    127.0.0.1 www.ca.com
    127.0.0.1 ca.com
    127.0.0.1 mast.mcafee.com
    127.0.0.1 my-etrust.com
    127.0.0.1 www.my-etrust.com
    127.0.0.1 download.mcafee.com
    127.0.0.1 dispatch.mcafee.com
    127.0.0.1 secure.nai.com
    127.0.0.1 nai.com
    127.0.0.1 www.nai.com
    127.0.0.1 us.mcafee.com
    127.0.0.1 rads.mcafee.com
    127.0.0.1 trendmicro.com
    127.0.0.1 www.trendmicro.com
    127.0.0.1 www.grisoft.com
    127.0.0.1 www.symantec.com
    127.0.0.1 securityresponse.symantec.com
    127.0.0.1 symantec.com
    127.0.0.1 www.sophos.com
    127.0.0.1 sophos.com
    127.0.0.1 www.mcafee.com
    127.0.0.1 mcafee.com
    127.0.0.1 liveupdate.symantecliveupdate.com
    127.0.0.1 www.viruslist.com
    127.0.0.1 viruslist.com
    127.0.0.1 viruslist.com
    127.0.0.1 f-secure.com
    127.0.0.1 www.f-secure.com
    127.0.0.1 kaspersky.com
    127.0.0.1 kaspersky-labs.com
    127.0.0.1 www.avp.com
    127.0.0.1 www.kaspersky.com
    127.0.0.1 avp.com
    127.0.0.1 www.networkassociates.com
    127.0.0.1 networkassociates.com
    127.0.0.1 www.ca.com
    127.0.0.1 ca.com
    127.0.0.1 mast.mcafee.com
    127.0.0.1 my-etrust.com
    127.0.0.1 www.my-etrust.com
    127.0.0.1 download.mcafee.com
    127.0.0.1 dispatch.mcafee.com
    127.0.0.1 secure.nai.com
    127.0.0.1 nai.com
    127.0.0.1 www.nai.com
    127.0.0.1 update.symantec.com
    127.0.0.1 updates.symantec.com
    127.0.0.1 us.mcafee.com
    127.0.0.1 liveupdate.symantec.com
    127.0.0.1 customer.symantec.com
    127.0.0.1 rads.mcafee.com
    127.0.0.1 trendmicro.com
    127.0.0.1 www.trendmicro.com
    127.0.0.1 www.grisoft.com


    Delete all the lines there, but this one:

    127.0.0.1 localhost

    Close the file and answer Yes to confirm the change. Now rename HOSTS.txt back to HOSTS.

    Boot back to normal.


    Next I highly recommend you get rid of Kazaa if you still have it. It is full of spyware and the source of many problems. A lot of the problems you have now are from the garbage that comes bundled with Kazaa and is installed on your PC without your knowledge.

    Go here and get KazaaBegone and run it to get rid of Kazaa.


    Go here:

    http://www.newdotnet.com

    Scroll to the bottom of the page to Precedure 4 and download and run the New.Net removal tool.


    Go here and download Adaware 6 Build 181

    Install the program and launch it.

    First in the main window look in the bottom right corner and click on Check for updates now and download the latest referencefiles.

    Make sure the following settings are made and on -------ON=GREEN

    From main window :Click Start then Activate in-depth scan (recommended)

    Click Use custom scanning options then click Customize and have these options selected: Under Drives and Folders put a check by Scan within archives and below that under Memory and Registry put a check by all the options there.

    Now click on the Tweak button in that same window. Under Scanning engine select Unload recognized processes during scanning and under Cleaning Engine select Let windows remove files in use at next reboot

    Click proceed to save your settings.

    Now to scan just click the Next button.

    When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

    Restart your computer.


    Then go here and download Spybot Search & Destroy.

    Install the program and launch it.

    Before scanning press Online and Search for Updates .

    Put a check mark at and install all updates.

    Click Check for Problems and when the scan is finished let Spybot fix/remove all it finds marked in RED.

    Restart your computer.

    Come back here and post another Hijack This log and we'll get rid of what's left.
     
  13. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    lfrman1,

    I did all the steps and was left over with the file CvdLineExt03: access denied, I logged onto Kazaabegone and cant access the file to down load I sill get this error:

    C:\Documents~1\Scottlocals~1\Temp\ta42kyh9.zip could not be saved ,because the source file could not be read.

    Is there something I did wrong? Should I follow the steps again and repeat them?

    Hope you can help.

    Thanks

    Scott
     
  14. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    Did you do everything except run KazaaBegone?
     
  15. Scottp7

    Scottp7 Thread Starter

    Joined:
    Apr 28, 2004
    Messages:
    20
    yes,

    when I tried to download Kazaabe gone I got the meesage.
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - [Solved] Cannot connect
  1. KendraDit
    Replies:
    0
    Views:
    680
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/224724

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice