Hjt

Status
Not open for further replies.
i have the firewall and the antivirus on, norton is disabled. o_o; and its still freaking around with its live update.
 
I`m not sure what you mean by your computer doesn`t have safe mode.

Go to add remove programmes and uninstall Liveupdate and anything else to do with Symantec. Just a quick question. Your computer wouldn`t happen to be a Compaq by any chance, would it?

Regards Howard :)
 
its a dell... live update uninstallation doesnt work. Live update is stuck and wont die.
Dell 2400 O_o'
uh how do you get into safe mode i cant get in it...
it says in the start up
press f2 for setup (i fixed my ram to run full capacity)
press f12 for boot selections
f12 doesnt have anything near safemode
 
Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

Symantec Core LC
Symantec SPBBCSvc (SPBBCSvc)
Symantec Network Drivers Service (SNDSrvc)
ScriptBlocking Service (SBService)
SAVScan
Norton AntiVirus Auto-Protect Service (navapsvc)
LiveUpdate
ISSvc (ISSVC)
Symantec Settings Manager (ccSetMgr)
Symantec Password Validation (ccPwdSvc)
Symantec Network Proxy (ccProxy)
Symantec Event Manager (ccEvtMgr)
Automatic LiveUpdate Scheduler
Symantec NetDriver Monitor
ccApp

Close the services window.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

ccApp.exe
SNDMon.exe
ALUSchedulerSvc.exe
ccEvtMgr.exe
ccProxy.exe
ccPwdSvc.exe
ccSetMgr.exe
ISSVC.exe
LUCOMS~1.EXE
navapsvc.exe
SAVScan.exe
symlcsvc.exe
SPBBCSvc.exe
SNDSrvc.exe
SBServ.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab

O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab

O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab

O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Click on the fix checked button.

Close HJT.

Now go to add remove programmes in your control panel and uninstall anything to do with(if there).

Symantec
Norton
Liveupdate.

Reboot your computer and go back to add remove programmes and check if there`s any of the above left. If there is, uninstall it. Keep doing this untill all the Symantec/Norton/liveupdates entries have gone.

Post a fresh HJT log.

Regards Howard :)

This thread is for the use of Kaorichan2002 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
did all you said cant delete the main program, it wants me to log on. and i cant... i deleted all its start up scripting.
 
Please post a fresh HJT log.

Regards Howard :)

This thread is for the use of Kaorichan2002 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Will not work its norton 2005 o_o; that and... it says it doesnt support the repair feature please uninstal and reinstall
 
Bloody hell.

Now you know why I hate Symantec/Norton.

There has to be a way of getting rid of that crap of of your system. problem is, I don`t know how, other than what I`ve already suggested and that`s obviously not worked.

Regards Howard :)
 
The problem is, not all of it`s disabled.

Ok, let`s have one more go at killing this sucker. Follow these instructions very carefully.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

Go to add remove programmes in your control panel and uninstall anything to do with(if there).

GCN

BroadJump\Client Foundation

Also check for anything Symantec/Norton and try and uninstall it.

Close control panel.

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

SPBBCSvc

Symantec Network Drivers Service (SNDSrvc)

ScriptBlocking Service (SBService)

Norton AntiVirus Auto-Protect Service (navapsvc)

ISSvc (ISSVC)

Symantec Settings Manager (ccSetMgr)

Symantec Password Validation (ccPwdSvc)

Symantec Network Proxy (ccProxy)

Symantec Event Manager (ccEvtMgr)

Automatic LiveUpdate Scheduler

Close the services window.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

GCN.exe

CFD.exe

ccSetMgr.exe

SPBBCSvc.exe

SNDSrvc.exe

SBServ.exe

navapsvc.exe

ISSVC.exe

ccPwdSvc.exe

ccProxy.exe

ccEvtMgr.exe

ALUSchedulerSvc.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html

O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe

O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Program Files\GCN

C:\Program Files\BroadJump

C:\Program Files\Common Files\Symantec Shared

C:\Program Files\Norton Internet Security

C:\Program Files\Symantec

Reboot into normal mode and turn system restore back on.

Post a fresh HJT log.

Regards Howard :)
 
why gcn? its a chat program.
could the problem be the corrupt .dll files?
I did actually have a problem with those when i dumped the comp. O_o;
 
If you`re sure GCN.exe is safe, then by all means keep it.

I`m not sure what you mean by corrupt .dll files. Can you be specific please?

Just try the above and see what happens.

Regards Howard :)
 
Status
Not open for further replies.
Back