windows police pro- giant problem

Thread Solved

Join Date: Dec 2006
Posts: 959
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 46
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: windows police pro- giant problem

 
1
  #41
Aug 31st, 2009
Originally Posted by Atecks View Post
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe tapi.nfo beforeglav
F2 - REG:system.ini: UserInit=C:\WINDOWS.0\system32\userinit.exe,C:\WINDOWS.0\system32\sdra64.exe,
So sorry to be the bearer of bad news, but you have a nasty backdoor trojan with rootkit components.
This thing is far worse than Windows Police Pro - If you do any sort of online banking, there is a good chance your info has been compromised. Definitely check your banks, credit cards, etc. and change any passwords.

In cases such as this, I generally recommend a re-format because, even if we are able to clean the machine, you'll never be able to trust it......

PP
Last edited by PhilliePhan; Aug 31st, 2009 at 10:55 pm.
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 23
Reputation: Atecks is an unknown quantity at this point 
Solved Threads: 0
Atecks Atecks is offline Offline
Newbie Poster

Re: windows police pro- giant problem

 
0
  #42
Sep 1st, 2009
well, that blows; I have a bunch of sensitive info as well as a bunch of online transactions, however everything seems the same

I'm going to change everything on another computer, and then re-format this one whenever I find the disk

Thanks alot for your help, and everyone else that helped too
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 959
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 46
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: windows police pro- giant problem

 
0
  #43
Sep 1st, 2009
Originally Posted by Atecks View Post
Thanks alot for your help, and everyone else that helped too
Happy to help

I may have been a bit premature in calling for you to format - I am finding that these infections tend to have all sorts of rootkit components.

If you like, we can try to clean it. But I still stand by my last post and the severity of the infection shown.

Be very careful putting things on another compy
- I'm not sure that is a good idea, given the nature of this baddie.


Are you able to get combofix to run as per the linky below?
http://www.bleepingcomputer.com/comb...o-use-combofix

Try that and post a log, if possible.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2009
Posts: 23
Reputation: Atecks is an unknown quantity at this point 
Solved Threads: 0
Atecks Atecks is offline Offline
Newbie Poster

Re: windows police pro- giant problem

 
0
  #44
Sep 1st, 2009
I already formatted(I pretty much needed to already, the computer was cluttered, blue screening very often, etc.) I backed up everything important, and this time I'm gonna keep everything secure. Right now, I'm just trying to set up my internet access(on my PC) since it seems to have been removed or something(I'm gonna go seek help on the appropriate board/forum)
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 959
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 46
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Posting Shark

Re: windows police pro- giant problem

 
0
  #45
Sep 1st, 2009
All things considered, that is probably for the best because the rootkit on your machine is one of the nastier ones - I am not seeing it on the other machines with similar problems, so you very well may have picked that up some time ago.

Best Luck
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC