Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows Police Pro [Solved]


  • This topic is locked This topic is locked

#1
dustincm1100

dustincm1100

    Member

  • Member
  • PipPip
  • 46 posts
I have a Dell Dimension 5150 and I apparently have a problem with a virus. When I start my computer it loads windows and has no problem pulling up the desktop. However thats where I have my problems. There is a permanent Danger sign on my desktop, it reads "Danger your computer is INFECTED! Attention!!! (there are some more words but I cant read them) then it says PROTECT YOURSELF! DELETE SPYWARE FROM YOUR COMPUTER RIGHT NOW!

I have a new program that has installed itself on my computer it is called Windows Police Pro.

When I try to run any programs that might help me fix my computer they won't run at all. When I click on system restore, Mbam, erunt setup, or TFC a command prompt box pops up for a second and then dissapears and nothing else happens.

When i open up a new web page i also get a popup for Windows Anti-Virus Pro.

Any help you guys can give me would be greatly appreciated.
Thanks
  • 0

Advertisements


#2
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
Hi,

Can you still access your Task Manager?

(Ctrl + Alt + Delete)


Go into Task manager > Processes tab

check the checkbox labeled Show processes from all users bottom left of the Task Manager window.

Find the process Windows Police Pro.exe and left-click on it once so it becomes highlighted.

Now click on the End Process button

Task manager will ask you if you are sure - say YES

Now scroll through the list of processes until you find the svchast.exe process.

end this process as well by clicking on the End Process button and confirming that you want to end it.

note the spelling svchAst.exe there are legitimate files spelt svchOst < do not end process on those.

NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


Posted Image
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.

    Posted Image
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Edited by CatByte, 05 September 2009 - 07:15 AM.

  • 0

#3
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hey thanks for the fast reply, I was able to access my task manager however there was no windows police pro process in my list. I did find the svchast process and ended it but that did not enable my programs to start up. Would the police pro process maybe have a different name? I did remember to click the show all processes check box too.
  • 0

#4
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
It may have a different name...give me a list of the suspicious looking processes in task manager and I'll see
  • 0

#5
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
I'm sorry but I am not computer savvy enough to know what processes are suspicious looking, I will send them all to you.
taskmgr.exe
iexplore.exe
alg.exe
CALMAIN.EXE
svchost.exe
jqs.exe
svchost.exe
ctfmon.exe
explorer.exe
wmpnetwk.exe
mDNSResonder.exe
AppleMobileDeviceService.exe
brss01a.exe
spoolsv.exe
ati2evxx.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
  • 0

#6
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
Hi,

no, those are all good processes so you must have something else on board as well.

Please navigate to C:\Documents and Settings\All Users\Application Data which is a hidden folder, so you will need to show hidden files and folders:

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.


Once you are in the Application data Folder look for a folder that has a random number of 8 digits

If you find one - drag the folder to your desktop (do not delete it) (you will need to make your window smaller so you can access the desktop too)

Once you have that folder on the desktop - reboot - go back into task manager - end process on svchast.exe again - then try MBAM and the other tools

Edited by CatByte, 05 September 2009 - 07:33 AM.

  • 0

#7
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Ok I tried to access "My computer" but it also would not open up. I rebooted the computer in safe mode and was able to access the folder that you told me too and there was one file with a bunch of numbers {3276BE95_AF08_429F_A64F_CA64CB79BCF6}

Anyways I moved this folder to my desktop (while still in safe mode) and then rebooted my computer. After ending the svchast process I am still unable to run any programs on my computer.

Also when I boot up in normal mode I do not see that folder that I had moved to my desktop. Could this be because I am unable to access my files in normal mode and therefore am unable to check "show all hidden folders"?
  • 0

#8
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
Hi,

That wasn't the folder I was after - the folder in question has 8 digits.

OK, we move on.

Please run this program:

Download SREng

  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that have an Error status click [Repair]
  • Refer to this image for an example:

    Posted Image
  • Close SREng now.

NOTE: you may need to rename it it IEXPLORE.EXE to get it to run or SREng.com


NEXT:


Please download Sysprot Antirootkit from >>>HERE<<<

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select ALL ITEMS
  • Look near the bottom left, and Check Hidden Objects Only
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.

Again: you may need to rename this to svchost.exe to get it to run

NEXT


Download and run Win32kDiag:


Again try renaming to Winlogon.exe to run

Edited by CatByte, 05 September 2009 - 07:58 AM.

  • 0

#9
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Ok those programs seemed to work for me, the Syspro is scanning my root drive now and I will post the log when it is finished, thanks for helping me out with this.
  • 0

#10
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Ok here are the logs that the two programs generated. By the way I clicked on the MBAM program and it will run now, do you think I should go ahead and run it?

Attached Files


  • 0

Advertisements


#11
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
Yes please
  • 0

#12
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Ok MBAM is running now, although when I told it to check for updates it gave me an error message. I went ahead and told it to scan (hopefully I didn't mess up doing that), it is scanning now and I will post the results when it is finished and then I will proceed through the next steps that you posted for me. (By the way it was already found 20 infected objects)
  • 0

#13
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Just wanted to post a quick update and let you know that Mbam is done the DDS program is done and I am waiting on GMER, once it finishes I will post all of the logs. Thanks again for your help
  • 0

#14
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Ok all of the programs have finished scanning my computer and here are the logs that they generated.

Attached Files


  • 0

#15
dustincm1100

dustincm1100

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Here is what DDS found.

Attached Files


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP