このフォーラムスレッドには解決策が必要です。
拍手0

Norton360 breaks windows firewall

Hi. Recently, my windows firewall breaks because of norton out of nowhere! And that breaks the norton firewall also so i cant enable the firewall in norton, no uninstall and reinstall worked, only solution is a Windows 10 in place upgrade, but if i install norton again and update it, i get the same issue again. This is the error "0x6d9 Error in Windows Defender Firewall " the snap in breaks, and the Windows firewall service breaks so you can't enable the service, it won't let me. Something has happened, i think its because of an update in norton. 
Here is an article about it, but nothing works i tried everything. https://appuals.com/how-to-fix-windows-defender-firewall-error-code-0x6d9/

Here is a picture 

ラベル: Firewall, Windows 10

返信

拍手1 統計

Re: Norton360 breaks windows firewall

Has running the administrative command ( command prompt, run as admin ) sfc / scannow and DISM provided a different result? If not. Have you, performed a system restore to restore previous settings? Has the system been scanned for malware in a safe mode configuration? Norton doesn't break or even shut down the Windows firewall because its required for Windows Updates to function properly. There is a different issue at hand causing Windows services to not run. Actually running Windows Defender and Norton so they both start at boot-time can cause the issue you are seeing. 

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手1 統計

Re: Norton360 breaks windows firewall

Your post is a little unclear.  When do you see this alert?  With Norton installed, the Windows Firewall should never be running.  The Windows Firewall Service should always be running.

拍手0

Re: Norton360 breaks windows firewall

The firewall service break and wont start ever again. i get that snap in error also as you see in my picture whilst i did not get that issue ever before. And because of that firewall in norton breaks so its off and there is no way to enable it again it gets greyed out and it vanishes from the context menu when you right-click the norton toolbar, there is no "Disable firewall" option any longer. I am about to install in again and i will post picture of the error i get when trying to start the windows firewall service that stops running. I have been without norton now for 24 hours and i have no issue with firewall service, but im about to install norton now and maybe 10 min after that it will break again and i will have to restore everything again.

I will leave norton UN-updated for a while and see if firewall breaks, if it won't break ill update and then see how long it takes before it breaks.

拍手0

Re: Norton360 breaks windows firewall

No issues found with DISM or SFC. I think windows defender is off while norton is on. i have not changed anything this issue came out of nowhere, i have been using norton for years now on this setup and no issue apart from the bug from some update some months ago that made my C: drive usage to 100% all the time after an update that you after many complaints from people fixed.

Now it seems like an update again is causing this new problem, but I've not seen anyone else here talk about it though. I'm about to update norton again, i just installed it again. But ill leave it unpatched to see how long i can go without it breaking windows firewall service. And then update and see how long it takes for it to break. 

拍手0

Re: Norton360 breaks windows firewall

Yep! It's confirmed! As soon as I update it breaks! 

And here you can see more of the issue. 

拍手0

Re: Norton360 breaks windows firewall

I was able to fix it with "Tweaking.com - Windows Repair" i choose repair firewall and reset permission in registry and permission on services. Im glad i dont need to restore windows again, i was so tired of it. BUT still remains why updating norton broke it in the first place. I hope it wont happen again. Its been 10 min and another restart and its still working, ill be back if another update that comes out later will break it again. 

拍手0

Re: Norton360 breaks windows firewall

This time it took more than 24 hours, but it happened again out of nowhere! I used the same software to repair, and it's ok now again. Why is this keep happening?

拍手0

Re: Norton360 breaks windows firewall

Are you, using an administrator account on this machine? Have you gotten ALL the updates for your product that are offered, not just one update? 

Edited: Run registry checks on your machine following this article. https://support.microsoft.com/en-us/topic/description-of-the-windows-reg...

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

Yes i this is an admin account. Yes its all of the updates from when i installed it and even after, now it says "no updates found" . ok ill try with regfix.

Edit: i dont have scanreg on my windows. Where do i find it? im using windows 10 pro x64 latest version and updates

oh "Apparently Microsoft has pulled the plug on scanreg.exe and scanregw.exe. They have discontinued it since Windows Vista (or maybe even since XP, they don't say on their Knowledge Base website)"

拍手0

Re: Norton360 breaks windows firewall

Yes, I didn't see the scanreg was removed either. My apologies although the intent was legitimate on my part to help further. DISM should have picked up and repaired anything that was found, the sfc /scannow command should as well. In system services, check for Remote Procedure Call ( RPC) and running. Also check for DCOM running as it also can cause issues with the Defender A/V itself. Screenshots below.

What is your EXACT Windows version and build? IE as mine is Windows 10 Pro x 64 version 21H2 / build 19044.1741

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

DCOM is running and i have the exact same version of windows as you even build number. When i use "Tweaking.com - Windows Repair" and choose the "fix firewall" it fixes the problem, but some time later it breaks. But i think its because im under attack! Someone is controlling this to disable my firewall i think, because its random when it happens, and mostly why i think this is because zemana antilogger caught a fileless WMI trojan just 1 day ago! Norton and malwarebytes missed this one. No other scan found it. Someone is using fileless to bypass things, i think.  
Here is information i found: To begin with, WMI based malware requires a degree of sophistication not seen in your "run of the mill" malware. As such, it is usually reserved for advanced persistent threats. Below is an excerpt from a FireEye article about APT29 that I will refer to. Notable are the following:

1. To perform the WMI class registrations you referred to requires administrator privileges. If malware has acquired those, it can do much more than just manipulate WMI.

2. In the case of APT29, it used WMI to create a backdoor. Creating the backdoor itself was useless until it was utilized to execute a malicious PowerShell script/commands. On Win 10, Eset monitors Powershell script execution utilizing the AMSI interface.

拍手0

Re: Norton360 breaks windows firewall

Leave the computer OFF-LINE and run the repair again. Keep it off line, Norton should alert you to traffic requests in and out of the device. That is the best way to tell if there is malware calling to a C/C server. Your internet modem/router is also most likely compromised. 

Edited: I would factory reset your modem and/or router, DO NOT use the factory admin log-in name or its default password other than to initially setup the devices. Change them both and reboot both devices at the same time. 

https://media.defense.gov/2020/Jul/16/2002457639/-1/-1/0/NCSC_APT29_ADVI...

Microsoft Safety Scanner may help, downloaded via a non-compromised machine and ran via a USB drive on the affected machine while OFF-LINE. https://docs.microsoft.com/en-us/microsoft-365/security/intelligence/saf...

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

IMA, file-less malware is  LOL, living off the land infestation. It will use legit Windows files/processes with powershell. In the long run a full sanitization IE: OS reinstall, coupled with complete formatting of all HD partitions may be the only way to garner the system clean. 

https://us.norton.com/internetsecurity-malware-what-is-fileless-malware....

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

I will do the scan like you said when I can. Yes I have been thinking i have LOL and been under attack under a long time now, now it's confirmed. I'm glad because I have been trying to prove it a long time in forums but nothing was found, of course because it hides behind legit files. I have nuked my windows' disk before. But I suspect either is a deep-rooted rootkit that someone put in while having physical access to my pc, or it's because it's in some of my no-OS drives that I never nuked, so I keep getting infected. 

I have disabled WMI. I know some things break when doing that, would it make me safer having it disabled? Because I had infected WMI so if I disable it they can't use that technique again?

拍手0

Re: Norton360 breaks windows firewall

I used WmiLister and it found something and deleted it, please review! 

拍手0

Re: Norton360 breaks windows firewall

Oh no! It's just because I installed this script! https://www.reddit.com/r/Windows10/comments/9t5be1/automatically_disable... it might be a false positive, and I'm in no danger! Can you look at the script and verify it's no danger? It supposedly only disables full-screen optimization

拍手0

Re: Norton360 breaks windows firewall

I would REINSTALL Windows on this computer ASAP. OFFLINE!! That will provide a clean registry. If the compromise persists that is an indication your UEFI/BIOS/FIRMWARE has also been compromised. There isn't any way to remove this other than attempts to update the BIOS/UEFI firmware and have successful results. An added note. Using third party software on a continual basis is many times a receipt for disaster. 

Edited: Please take serious note that a CLEAN Windows install is paramount. NOT from a backup.

https://answers.microsoft.com/en-us/windows/forum/all/can-i-reset-my-win...

As suggested earlier, I would factory reset your modem and/or router, DO NOT use the factory admin log-in name or its default password other than to initially setup the devices. Change them on both devices, and reboot both devices at the same time. Make sure both devices are using their latest firmware updates, manually check both. 

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

Thanks for the reply! But i know what caused it, it was a false positive. This is what i wrote "Oh no! It's just because I installed this script! https://www.reddit.com/r/Windows10/comments/9t5be1/automatically_disable...(link is external) it might be a false positive, and I'm in no danger! Can you look at the script and verify it's no danger? It supposedly only disables full-screen optimization"

Here is the script:
 

<# :: Note that you can skip a program if you manually set another flag for it like the Override DPI            reddit .com/9t5be1
@set v=2019.09.29 ||: run admin rights required section as scriptblock - should now work on systems it previously failed 
@title Automatically Disable Fullscreen Optimizations and DPI Override - AveYo - v%v%                
@color 1e & echo off & echo. & powershell -nop -c "iex ([System.IO.File]::ReadAllText('%~f0'));" &exit/b
#>$main = {
# CHOICE TEXT - &X IS OPTIONAL TO ACTIVATE KEYBOARD SHORTCUTS           # CHOICE VALUE                           # DEFAULT:1 #>
$t  = @()                                                            ;  $v  = @()                             ;  $d  = @()
$t += '&1  Disable Fullscreen optimizations                         ';  $v += 'DISABLEDXMAXIMIZEDWINDOWEDMODE';  $d += 1
$t += '&2  Program DPI from main display when I signed in to Windows';  $v += 'PERPROCESSSYSTEMDPIFORCEOFF'   ;  $d += 0
$t += '&3  Program DPI from main display when I open this program   ';  $v += 'PERPROCESSSYSTEMDPIFORCEON'    ;  $d += 0
$t += '&4  High DPI scaling override by Application                 ';  $v += 'HIGHDPIAWARE'                  ;  $d += 0
$t += '&5  High DPI scaling override by System                      ';  $v += 'DPIUNAWARE'                    ;  $d += 0
$t += '&6  High DPI scaling override by System [Enhanced]           ';  $v += 'GDIDPISCALING DPIUNAWARE'      ;  $d += 0
$t += '&7  CLEAR MANUAL DEFINITIONS                                 ';  $v += ''                              ;  $d += 0
$t += '&8  UNINSTALL                                                ';  $v += ''                              ;  $d += 0

# SHOW CHOICES DIALOG FROM EXTENDED TEXT $t (INSTEAD OF VALUES $v) WITH DEFAULTS $d SELECTED - OUTPUTS INDEXES LIKE '1,3,4'
$all = $t -join ','; $def = (($d -split "`n") | Select-String 1).LineNumber -join ','; $selected = @($false) * $t.length
$result = Choices $all $def 'GlobalAppCompatFlags'; if($result){ $result -split ',' | % { $selected[[int]$_ - 1] = $true } }

# QUIT IF NO CHOICE MADE
if(!$result){ write-host -fore Red "`n No choice selected, exiting.. "; timeout /t 3 >$null; exit }

# VALIDATE SELECTION WITH RULES LIKE 'IF GDIDPISCALING SELECTED THEN HIGHDPIAWARE MUST BE UNSELECTED' ETC.
$uninstall=$false; $clear=$false
if($selected[2]){$selected[1]=$false} <# SINGLE CHOICE FOR Program DPI (2 OR 3) AND High DPI (4 OR 5 OR 6) #>
if($selected[5]){$selected[3]=$false; $selected[4]=$false}; if($selected[4]){$selected[3]=$false; $selected[5]=$false}
if($selected[6] -and $selected[7]){$clear=$true; $uninstall=$true; $selected=@($false) * $t.length} <# CLEAR, UNINSTALL #>
if($selected[6]){$clear=$true; $selected[6]=$false}; if($selected[7]){$uninstall=$true; $selected=@($false) * $t.length}

# COMPUTE THE FLAGS VARIABLE APPLIED AUTOMATICALLY TO HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
$values = @(); (($selected -split "`n") | Select-String $true).LineNumber | % { if([int]$_){$values += $v[[int]$_ - 1]} }
$flags = '~ ' + $values -join ' '
#if ($flags -eq '~ ') { $uninstall=$true } 

#  IF SELECTED, CLEAR PREVIOUS FLAGS FOR ALL PROGRAMS ONCE - FIY: AUTOMATIC HANDLER DOES NOT OVERRIDE EXISTING ENTRIES
if($clear){
  write-host -fore Red "`n Clearing existing flags in registry for all programs.. "; timeout /t 3 >$null
  Remove-Item -Path 'HKCU:\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers' -EA 'silentlycontinue' -Force
}

# INSTALLING AND UNINSTALLING THE PERSISTENT WMI HANDLER REQUIRES ADMIN RIGHTS
if (-not ([Security.Principal.WindowsPrincipal] [Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole(544)) {
  write-host -fore Black -back Yellow  "`n PERMISSION DENIED! Asking for admin rights..  "; timeout /t 3 >$null
  start powershell -Verb RunAs -ArgumentList "-nop -NoExit -C & { $($RunAsAdmin -replace '"', '\"') } '$flags' '$uninstall'"; exit
} else { & $RunAsAdmin "$flags" "$uninstall" }

} # $main Done!

$RunAsAdmin = { param($Flags, $Uninstall) 
$script = {
  cmd /c color 1e; write-host -Fore Black -Back Gray "`n Flags: $flags "
  # UNINSTALL PERSISTENT WMI HANDLER IF SELECTED
  if($Uninstall -eq [bool]::TrueString){
    write-host -Fore Red "`n Uninstalling GlobalAppCompatFlags.. "
    RemoveGlobalAppCompatFlags; timeout /t -1; exit
  }
  # INSTALL PERSISTENT, NON-PULLING, HIGH PERFORMANCE FILTERED WMI HANDLER TO ADD FLAGS FOR USER PROGRAMS ON SECOND LAUNCH
  write-host -Fore Red "`n Installing GlobalAppCompatFlags.. " #timeout /t 3 >$null
  AddGlobalAppCompatFlags $Flags
  write-host "`n DONE! All programs - old and new - will have above flags applied after being run once "
  write-host "`n INFO: To prevent this for a program, manually adjust another flag like Override DPI for it "
  write-host "`n INFO: If only CLEAR MANUAL DEFINITIONS is selected then flags are cleared automatically instead "
  timeout /t -1; exit
}
function RemoveGlobalAppCompatFlags(){
  $ns = 'root\subscription'
  gwmi __eventFilter -Namespace $ns -filter "name='GlobalAppCompatFlags'"| Remove-WmiObject
  gwmi activeScriptEventConsumer -Namespace $ns -filter "name='GlobalAppCompatFlags'" | Remove-WmiObject
  gwmi __filtertoconsumerbinding -Namespace $ns -filter "Filter = ""__eventfilter.name='GlobalAppCompatFlags'"""| Remove-WmiObject
}
function AddGlobalAppCompatFlags($newflags){
  $GlobalAppCompatFlags_script_embedded_in_WMI_database = @"
' Add GlobalAppCompatFlags automatically after launching user processes - applies on the second launch of the same program
' Yes it does it via the "infamous" WMI persistence - but are we really not gonna use legit super light methods out of fear now?
' Why vbs, though? For no other reason than shitty lazy AVs going indiscriminately ham on any js because it can run on the web..
Dim oldflags : newflags = "$newflags"
Const HKU = 2147483651 : Const SEMISYNCHRONOUS = 48
layerskey = "Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers"
querytext = "SELECT ExecutablePath FROM Win32_Process WHERE ProcessID=" & TargetEvent.ProcessID
Set mExec = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\CIMv2").ExecQuery(querytext,,SEMISYNCHRONOUS)
Set rProv = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv")
Set regEx = New RegExp : regEx.Global = False : regEx.IgnoreCase = True
filterprg = "^.:\\Program Files(?:\\| \(x86\)\\)(Common |dotnet|Microsoft |Windows |WindowsApps|MSBuild)"
regEx.Pattern = "^.:\\Windows\\|^.\\ProgramData\\Package |\\AppData\\Local\\Temp\\|\\AppData\\Local\\Microsoft\\|" & filterprg
For Each process in mExec
  If Not IsNull(process.ExecutablePath) And Not regEx.Test(process.ExecutablePath) Then
    process.GetOwnerSid sid : compatkey = sid & "\\" & layerskey
    ret = rProv.GetStringValue(HKU, compatkey, process.ExecutablePath, oldflags)
    If (ret <> 0) Then
      rProv.CreateKey HKU, compatkey : rProv.SetStringValue HKU, compatkey, process.ExecutablePath, newflags
    ElseIf (newflags = "~ ") Then
      rProv.DeleteValue HKU, compatkey, process.ExecutablePath
    End If
  End If
Next
"@
  $EvtQuery = "SELECT * from Win32_ProcessStartTrace WHERE SessionID!=0"
  $nospam = @('cvtres','csc','svchost','DllHost','RuntimeBroker','backgroundTaskHost','rundll32','find','findstr','reg',
'PING','timeout','taskkill','Conhost','cmd','cscript','wscript','powershell','explorer','OpenWith','SearchProtocolHost',
'SpeechRuntime','browser_broker','MicrosoftEdgeCP','firefox','chrome','steamwebhelper')
  foreach ($n in $nospam){ $EvtQuery += " AND ProcessName!='"+$n+".exe'" }
  RemoveGlobalAppCompatFlags # Clear previous before new event subscription
  $EvtFilter = Set-WmiInstance -Class __EventFilter -NameSpace 'root\subscription' -Arguments @{
Name='GlobalAppCompatFlags';EventNameSpace='root\cimv2';QueryLanguage='WQL';Query=$EvtQuery } -ErrorAction Stop
  $EvtCon = Set-WmiInstance -Class ActiveScriptEventConsumer -Namespace 'root\subscription' -Arguments @{
Name='GlobalAppCompatFlags';ScriptingEngine='VBScript';ScriptText=$GlobalAppCompatFlags_script_embedded_in_WMI_database }
  Set-WmiInstance -Class __FilterToConsumerBinding -Namespace 'root\subscription' -Arguments @{Filter=$EvtFilter;Consumer=$EvtCon}
}
& $script } # $RunAsAdmin Done! 

# Choices dialog snippet - parameters: 1=allchoices, 2=default; [optional] 3=title, 4=textsize, 5=backcolor, 6=textcolor
function Choices($all, $def, $n='Choices', [byte]$sz=12, $bc='MidnightBlue', $fc='Snow', $saved='HKCU:\Environment'){
  [void][System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms'); $f=New-Object System.Windows.Forms.Form
  $a=$all.split(','); $s=$def.split(','); $reg=(Get-ItemProperty $saved).$n; if($reg.length){ $s=$reg.split(',') };
 function rst(){ $cb | %{ $_.Checked=0; if($s -contains $_.Name){ $_.Checked=1 } } }; $f.Add_Shown({rst; $f.Activate()})
  $cb=@(); $i=1; $a | %{ $c=New-Object System.Windows.Forms.CheckBox; $cb+=$c; $c.Text=$_; $c.AutoSize=1;
 $c.Margin='8,4,8,4'; $c.Location='64,'+($sz*3*$i-$sz); $c.Font='Tahoma,'+$sz; $c.Name=$i; $f.Controls.Add($c); $i++}
  $bt=@(); $j=1; @('OK','Reset','Cancel') | %{ $b=New-Object System.Windows.Forms.Button; $bt+=$b; $b.Text=$_; $b.AutoSize=1;
 $b.Margin='0,0,72,20'; $b.Location=''+(64*$j)+','+(($sz+1)*3*$i-$sz); $b.Font='Tahoma,'+$sz; $f.Controls.Add($b); $j+=2 }
  $v=@(); $f.AcceptButton=$bt[0]; $f.CancelButton=$bt[2]; $bt[0].DialogResult=1; $bt[1].add_Click({$s=$def.split(',');rst});
 $f.Text=$n; $f.BackColor=$bc; $f.ForeColor=$fc; $f.StartPosition=4; $f.AutoSize=1; $f.AutoSizeMode=0; $f.FormBorderStyle=3;
 $f.MaximizeBox=0; $r=$f.ShowDialog(); if($r -eq 1){$cb | %{if($_.Checked){$v+=$_.Name}}; $val=$v -join ',';
 $null=New-ItemProperty -Path $saved -Name $n -Value $val -Force; return $val }
} # Let's Make Console Scripts Friendlier Initiative by AveYo - MIT License -          Choices '&one, two, th&ree' '2,3' 'Usage'
& $main
<#_#>

拍手0

Re: Norton360 breaks windows firewall

I'm confused a bit with the solution. Does Norton now function correctly and Defender firewall enable in services? If you haven't checked those services and validated them as running the issue persists. Although you suggest you have a solution, I invite you to re-read the txt file / log you posted earlier that suggests compromise. We are here if you need us going forward.

Regards,

SA

MS Certified Professional : Windows 11 Home/Pro 22H2 x 64 build 22621.2715 / Windows 10 Pro x 64 version 22H2 / build 19045.3693 / Norton Security Ultra - Norton 360 Deluxe ver. 22.23.10.10 / Opera GX LVL5 (core: 104.0.4944.70) 64 bit-Early Access w/Norton Chrome Extensions
拍手0

Re: Norton360 breaks windows firewall

The firewall has not been disabled again since last time, but if it does, i can just use windows tweak to fix it. The wmi fileless it found was not a real fileless, it was false-posetive. But if firewall service break too often, ill be back. I cleared the solution because i dont know if firewall will break again

This thread is closed from further comment. Please visit the forum to start a new thread.