Windows Security jacked...norton autoprotect disabled, can't reenable

Logfile of HijackThis v1.99.1
Scan saved at 9:19:25 PM, on 4/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\ofps.exe
C:\WINDOWS\system32\RadioSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Bond\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe Acrobat Control for ActiveX - {CA8A9780-280D-11CF-A24D-444553540000} - C:\PROGRA~1\Adobe\ACROBA~1.0\Acrobat\ActiveX\pdf.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: OmniForm Printer - Unknown owner - C:\WINDOWS\System32\ofps.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe


I did everything...........here is my hijack log. I'm out of resolutions. I'm an avid user of adaware/spybod/hijackthis. Now I'm done. I dunno what to do. I cannot turn on and off my firewall, norton will not allow for automatic protection to be turned on. Turns on, then off after like 3 seconds. What is going on. I already did the basics and the advanced stuff that I'm used to. I need someone that can really really help me. Like a super advanced user. So please help me.

Comments

  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited April 2006
    There is nothing visible in your log, but there is a tool to remove the Chod D worm which is known to disable AV's and firewalls.

    Please Download MsnVirRem.exe to your desktop from one of the following mirrors.
      [*]First close any other programs you have running as this will require a reboot
      [*]Double click MsnVirRem.exe to run it
      [*]Once open, click the button labelled "Search and Destroy"
      <<Your computer will now be scanned for Infected Files>>
      [*]When scanning is finished you will be prompted to reboot only if infected, Click OK
      [*]Now click the "REBOOT" Button.
      [*]After the Reboot, you WILL receive file not found errors (usually 4) please acknowledge them and continue.
      [*]A Message should popup from MsnVirRem if not, double click the program again and it will finish
      Please Post the contents of C:\msnvirrem.log along with a fresh HijackThis log

      If that doesn't fix it, you may have to uninstall then reinstall Norton.
    • edited April 2006
      It didn't find any infected files..... I uninstalled norton and now I'm still dealing with my Windows security crap. It shows the firewall is on, but when I go down to manage security settings for "Windows firewall" it shows that it's off. msnvirrem Log shows no infections and I've still got the same hijackthis log. Any other suggestions?
    • CrunchieCrunchie Mandurah. Western Australia. Member
      edited April 2006
      If you have your XP CD you may be able to fix it using the 'repair' option.
      Another option would be to go to Start>Run and type in 'sfc /scannow' (without the quotes) and hit ok. Further details here; http://www.updatexp.com/scannow-sfc.html
    Sign In or Register to comment.