Jump to content

My virus not completed remove after Norton Scan, Need help on editing


page
 Share

Recommended Posts

Hi,

My computer being attacked by W32.Spybot.Worm.

Symptom seem to cause my Laptop heat's generate way up high, slowing my operation & IE connection, and my Norton Firewall keep poping-up similar traffice rule for the specific program ie. plccd.exe & system.exe (Doesn't help after I block and remove the rule many times from Firewall configuration.)

2_plscd_execrop.jpg 3_system_execrop.jpg

After which I performed Norton Antivirus full-scanning and give me the result. (code tag inclucded my error registry.)

1_NortonScanResultcrop.jpg

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsUpdate->DoNotAllowXPSP2:0

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\StandardProfile->EnableFirewall:1

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\DomainProfile->EnableFirewall:1

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCom:Y

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update->AUOption:3

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Control->WaitToKillServiceTimeout:20000

HKEY_CLASSES_ROOT\.Key->regfile

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINNT\system32\winsvc32.exe

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINDOWS\system32\winsvc32.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservice->DRam prosessor

HKEY_USERS\S-1-5-21-3723053430-561953684-2661041586-1005\SOFTWARE\Microsoft\OLE->DRam prosessor

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->DRam prosessor

I went Symantec sites, look up self-removal topic regards to W32.Spybot.Worm and follow the instructions accordingly.

[below was the site, I facing problem on that guide step.4.

(Highlighted in red means I got problem)

4nortonhelpcrop.jpg

Some Registry left unfixed cos I don't know what is the default setting, whether to delete or do create. shown below

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsUpdate->DoNotAllowXPSP2:0 (not Found)

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\StandardProfile->EnableFirewall:1 (Not Found)

HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\POlicies\Microsoft\WindowsFirewall\DomainProfile->EnableFirewall:1 (not Found)

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2 (found and change to 4)

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3 (found and change to 4)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCom:Y (found but regedit set as 'N')

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update->AUOption:3 (found but regedit set as 4)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0 (Found but no idea what action to change/delete)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0 (Found but no idea what action to change/delete)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0 (Found but no idea what action to change/delete)

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Control->WaitToKillServiceTimeout:20000 (Found but no idea what action to change/delete)

HKEY_CLASSES_ROOT\.Key->regfile (Found but no idea what action to change/delete)

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->
C:\WINNT\system32\winsvc32.exe (Not Found)

HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->
C:\WINDOWS\system32\winsvc32.exe (Not Found)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservice->DRam prosessor (deleted)

HKEY_USERS\S-1-5-21-3723053430-561953684-2661041586-1005\SOFTWARE\Microsoft\OLE->DRam prosessor (deleted)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->DRam prosessor (deleted)

After I done, I shut down and restart then PLSCD.EXE, SYSTEM.EXE and Win32.spybot.worm poping-up again!!!! :censored: :(

Any one can help???

Link to comment
Share on other sites

Does my Norton antivirus allow me to installing Trendmicro before I reboot to Safe Mode with Networking?

You're not installing anything. TrendMicro Housecall is an online virus scan, which is run through ActiveX controls on your browser. Norton will not affect it.

Safe mode with networking allow Wireless coverage?

No. http://support.microsoft.com/kb/305616

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy