Question about Symantec Norton Internet Security 2009
Manual Method:
Kill Process
--------
1. Press CTRL+SHIFT+ESC
2. Windows Task Manager should pop up
3. Go to "Processes" tab
4. Kill "WP345d.exe", "eb.exe", "fix.exe", "ppal.exe" by ending the process. (There may only be one of these listed)
5. A warning prompt will come up, Click Yes to End anyway.
6. To confirm the spyware is no longer running, the icon should dissapear when you hover your mouse over the system tray in the lower right. (The icon is a red brick wall)
Remove Registry Keys
--------
1. Press WIN+R (The WIN key is the key between CTRL and ALT that looks like a Windows logo)
2. In the run box, type "regedit"
3. Windows Registry Editor will pop-up. *Be cautious when editing the registry*
4. Navigate to the following folder on the left-hand pane, and delete the listed items below:
------------------------
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WP345d.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=201&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "UID" = "201"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "89770891803"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows PC Defender"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows PC Defender"
------------------------
Registry Locations may vary, If you can not locate a certain item, use Edit > Find and type in the name of the key in quotes, For example:
To find...
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows PC Defender"
Search for "Windows PC Defender" without quotes.
4. Delete the Folders
Navigate to the following folders through My Computer, and delete the listed items.
C:\Documents and Settings\All Users\Application Data\
Delete the folder "3ad5ffe"
c:\Documents and Settings\All Users\Application Data\
Delete the folder "345d567" (This is a randomly generated set of numbers/letters)
c:\Documents and Settings\All Users\Application Data\
Delete folder "WPCDSys"
%UserProfile%\Application Data\ (Copy-Paste into Explorer's Address bar)
Delete folder "Windows PC Defender"
5. Reboot the PC and then refer to Step 1 to finish clean-up with MalwareBytes if necessary.
Posted on Mar 04, 2011
102 views
Usually answered in minutes!
×