Computing.Net > Forums > Security and Virus > Norton disabled (by virus?)

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Norton disabled (by virus?)

Reply to Message Icon

Name: Ken Jones
Date: June 21, 2004 at 11:16:05 Pacific
OS: Windows XP Home
CPU/Ram: P4/512K
Comment:

Just got a brand new machine(Windows XP Home). Installed Norton Antivirus 2003 and ran Live Update. Instead of the normal update window a Symantec message appeared saying that an intruder has changed some settings. This message won’t go way, and any attempt to use Norton again closes it down.
Symantec advises running Live Update but it won’t let me ! Uninstalled and reinstalled Norton but same thing happens. Uninstalled again and tried to install AVG instead. AVG also closed down after a few seconds. Tried in safe mode but same again. Noticed that when on line I am sending as much as receiving…odd surely? Presumably a virus but since can’t use a virus checker I don’t know which one. Anyone any ideas how to get out of this mess ?

Thanks.

Ken



Sponsored Link
Ads by Google

Response Number 1
Name: GIS_tech
Date: June 21, 2004 at 11:56:47 Pacific
Reply:

Ken,

I had a similar problem with a friend's laptop. This is what I found:

1. He had many viruses (virii) in his machine. Namely, Nachi worm, Gaobot.A.; Gaobot.B, and some others cannot remember.

2. Gaobot (or some variation of this) was causing the antivirus (norton)to be disable as soon as boot up time.

My solution:

1. Detach machine from Lan/internet
2. use any other antivirus(other than norton) or use the free tool "stinger" from network associates
3. Clean the machine using the above tool
4. Install a firewall (sygate personal is free)
5. Install your antivirus
6. connect to lan/internet and download all security patches for ms xp.


notes: some of these viruses are pretty nasty with some replacing files such as svchost for SCVHOST (NOTICE THE SWITCHED V AND C). For some of the variants you might have to go to the registry and delete some entries manually.

Good luck!

Post back if more help needed.

GIS_tech


0

Response Number 2
Name: Tufenuf
Date: June 21, 2004 at 12:36:28 Pacific
Reply:

Ken, GIS_tech gave you good advice. You may also want to follow the instructions under "Do this first: Step 1: Check a Windows file" for Windows XP at the link below because I'd be willing to bet that your hosts (no extension) has been altered and is the reason you can't update your Norton AV program.

Norton Live Update Problems

The hosts (no extension) file you want to check is located in your C:\Windows\System32\drivers\etc directory (folder). Below is what it should look like.
____________________________________________
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

____________________________________________

Open it in notepad and remove any entries below 127.0.0.1 localhost

DO NOT REMOVE THE 127.0.0.1 localhost

Close notepad and save the changes.

Hope This Helps,
Tufenuf



0

Response Number 3
Name: murve
Date: June 21, 2004 at 12:46:35 Pacific
Reply:

hi ken,
all the above is good advice and should be followed.
try this also if you wish:
disable your system restore to flush out your system. go to www.hauriusa.net and install the VIrobot anti-virus, get the latest defs.
reboot into safe mode, scan with hauri anti-virus, also if you have spybot, adaware and a trojan scanner such as a free 30 day trial of trojan hunter, it would be a good idea to scan with them also. delete all files that they come up with, clean your cache, temp files, history and cookie folder and recycle bin.
reboot your computer into normal mode, and re-enable your system restore.
all the best,
murve


0

Response Number 4
Name: GIS_tech
Date: June 21, 2004 at 13:26:33 Pacific
Reply:

Resources:

STINGER
http://vil.nai.com/vil/stinger/

PANDA QUICK REMOVER:

http://www.pandasoftware.com/download/utilities/

good luck!!!

GIS_tech


0

Response Number 5
Name: swanplant
Date: June 21, 2004 at 14:12:58 Pacific
Reply:

Trojans that kill AV programs and Firewalls use a cyclic process killer. They look for the av process every 10 seconds or so and kill any found. You need to kill the trojan process, i would suggest using a good process killer like winpatrol.

Once the trojan process has been killed, reinstall your av software and it will be able to remove the trojan

for more help on trojans visit
http://www.anti-trojan.org


0

Related Posts

See More



Response Number 6
Name: Ken Jones
Date: June 22, 2004 at 14:17:26 Pacific
Reply:

Thanks all. In the event nothing worked. It was the Gaobot virus. So resorted to format c and started over. Why oh why do people do this !!!!!


0

Response Number 7
Name: dstart
Date: July 11, 2004 at 03:11:56 Pacific
Reply:

I had a very similar problem (which also stopped me accessing the internet at all, grrrr). Norton was disabled, but I managed to run AVG, which didn't find anything. After a while or monitoring my internet traffic with the firewall booted up high I discovered it was being caused by dxrss.exe in windows/ system32, which I then deleted. All is back to normal except I can't run Norton live update on even viist the Norton website. Is this something I need to fix in the 'hosts' file as given above?


0

Response Number 8
Name: Tufenuf
Date: July 11, 2004 at 05:54:13 Pacific
Reply:

Daniel, It very well could be that your hosts file has been altered by the virus/trojan. Follow the instructions in my Response Number 2 above.

Tufenuf


0

Sponsored Link
Ads by Google
Reply to Message Icon

atl.dll - spyware removal Missing bridge.dll file o...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Norton disabled (by virus?)

virus which disables anti-virus www.computing.net/answers/security/virus-which-disables-antivirus/27751.html

Excel File locked password by virus www.computing.net/answers/security/excel-file-locked-password-by-virus/25849.html

Looking for a freeware firewall www.computing.net/answers/security/looking-for-a-freeware-firewall/4385.html