page Posted March 14, 2007 Report Share Posted March 14, 2007 Hi,My computer being attacked by W32.Spybot.Worm.Symptom seem to cause my Laptop heat's generate way up high, slowing my operation & IE connection, and my Norton Firewall keep poping-up similar traffice rule for the specific program ie. plccd.exe & system.exe (Doesn't help after I block and remove the rule many times from Firewall configuration.) After which I performed Norton Antivirus full-scanning and give me the result. (code tag inclucded my error registry.)HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsUpdate->DoNotAllowXPSP2:0HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\StandardProfile->EnableFirewall:1HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\DomainProfile->EnableFirewall:1HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCom:YHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update->AUOption:3HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Control->WaitToKillServiceTimeout:20000HKEY_CLASSES_ROOT\.Key->regfileHKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINNT\system32\winsvc32.exeHKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINDOWS\system32\winsvc32.exeHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservice->DRam prosessorHKEY_USERS\S-1-5-21-3723053430-561953684-2661041586-1005\SOFTWARE\Microsoft\OLE->DRam prosessorHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->DRam prosessorI went Symantec sites, look up self-removal topic regards to W32.Spybot.Worm and follow the instructions accordingly.[below was the site, I facing problem on that guide step.4.(Highlighted in red means I got problem)Some Registry left unfixed cos I don't know what is the default setting, whether to delete or do create. shown belowHKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsUpdate->DoNotAllowXPSP2:0 (not Found)HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\Microsoft\WindowsFirewall\StandardProfile->EnableFirewall:1 (Not Found)HKEY_LOCAL_MACHINE\SOFTWARE\POlicies\POlicies\Microsoft\WindowsFirewall\DomainProfile->EnableFirewall:1 (not Found)HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry->Start:2 (found and change to 4)HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\TlntSvr->Start:3 (found and change to 4)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole->EnableDCom:Y (found but regedit set as 'N')HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update->AUOption:3 (found but regedit set as 4)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->UpdatesDisableNotify:0 (Found but no idea what action to change/delete)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->AntiVirusOverride:0 (Found but no idea what action to change/delete)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center->FirewallOverride:0 (Found but no idea what action to change/delete)HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Control->WaitToKillServiceTimeout:20000 (Found but no idea what action to change/delete)HKEY_CLASSES_ROOT\.Key->regfile (Found but no idea what action to change/delete)HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINNT\system32\winsvc32.exe (Not Found)HKEY_LOCAL_MAcHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplicattions\List->C:\WINDOWS\system32\winsvc32.exe (Not Found)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservice->DRam prosessor (deleted)HKEY_USERS\S-1-5-21-3723053430-561953684-2661041586-1005\SOFTWARE\Microsoft\OLE->DRam prosessor (deleted)HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run->DRam prosessor (deleted)After I done, I shut down and restart then PLSCD.EXE, SYSTEM.EXE and Win32.spybot.worm poping-up again!!!! :( Any one can help??? Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted March 14, 2007 Report Share Posted March 14, 2007 You should boot into safe-mode with networking and run an online virus scanner. A good one is provided by Trend Microhttp://housecall.trendmicro.com/ Quote Link to comment Share on other sites More sharing options...
page Posted March 14, 2007 Author Report Share Posted March 14, 2007 You should boot into safe-mode with networking and run an online virus scanner. A good one is provided by Trend Microhttp://housecall.trendmicro.com/Thank you ScarecrowDoes my Norton antivirus allow me to installing Trendmicro before I reboot to Safe Mode with Networking?Safe mode with networking allow Wireless coverage? Quote Link to comment Share on other sites More sharing options...
rong Posted March 14, 2007 Report Share Posted March 14, 2007 Trendmicro is an online scan so it shouldn't be a problem Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted March 14, 2007 Report Share Posted March 14, 2007 Does my Norton antivirus allow me to installing Trendmicro before I reboot to Safe Mode with Networking?You're not installing anything. TrendMicro Housecall is an online virus scan, which is run through ActiveX controls on your browser. Norton will not affect it.Safe mode with networking allow Wireless coverage?No. http://support.microsoft.com/kb/305616 Quote Link to comment Share on other sites More sharing options...
page Posted March 14, 2007 Author Report Share Posted March 14, 2007 hi,Housecall trend-micro doesn't seem to work on registry area.do u have any housecall alike to cater on registry issues?tks Quote Link to comment Share on other sites More sharing options...
page Posted March 15, 2007 Author Report Share Posted March 15, 2007 Virus still remain and repeat the same pop-up messege. Quote Link to comment Share on other sites More sharing options...
page Posted March 15, 2007 Author Report Share Posted March 15, 2007 can anyone solve my problem? Quote Link to comment Share on other sites More sharing options...
andsome Posted March 15, 2007 Report Share Posted March 15, 2007 It appears from an online search that this could have been picked up with downloads from a P2P site, do you indulge in this foolish habit?Info and possible removal here Quote Link to comment Share on other sites More sharing options...
nellie2 Posted March 15, 2007 Report Share Posted March 15, 2007 Adaware should remove it for you, download it, install it and update it then boot into safe mode and run a full system scan Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.