windows police,help

Reply

Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster

windows police,help

 
0
  #1
Oct 21st, 2009
I got hit with the windows police pro virus,and it has locked up everything,i cant get into control panel,task manager,hell not even the calculator,i have tried every command listed for restarting task manager or regedit,but cannt get access,i cant even log into safe mode,i dont know what else to try,now im posting on an old computer,I am completely stumped here,i was able to run a virus program that has deleted a lot of viruses,but I am still locked out please any help would be great,thanks
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,006
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #2
Oct 21st, 2009
-- Do you have a flash drive to transfer tools and scanlogs between computers?

-- Can you get a command prompt on ill machine?
START > RUN > type cmd > OK
or
START > RUN > type command.com > OK

Let me know.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster
 
0
  #3
Oct 21st, 2009
Originally Posted by PhilliePhan View Post
-- Do you have a flash drive to transfer tools and scanlogs between computers?

-- Can you get a command prompt on ill machine?
START > RUN > type cmd > OK
or
START > RUN > type command.com > OK

Let me know.

PP
yes to both questions
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster
 
0
  #4
Oct 21st, 2009
yes i can get the command promt and have a flash drive
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,006
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #5
Oct 21st, 2009
Originally Posted by mike34 View Post
yes to both questions
Allrightythen!

You'll need to put these tools on your flash drive:

http://ad13.geekstogo.com/Win32kDiag.exe
http://swandog46.geekstogo.com/avenger.zip
http://www.bleepingcomputer.com/comb...o-use-combofix
With combofix, what I want you to do, though, is this:
When you download it and it asks you to "Save File As," rename combofix to Combo-Fix and then download it to working compy and put it on the flash drive.
FindWPP.zip
DDS by sUBs
http://download.sysinternals.com/Files/Junction.zip
http://www.raktor.net/exeHelper/exeHelper.com
http://download.bleepingcomputer.com...es/Inherit.exe
SysProt Anti-Rootkit


Then, see if you are able to copy these to the desktop:
-- FindWPP.zip
-- Win32kDiag.exe
-- Combo-fix.exe

Let me know how you fare.

PP
Last edited by PhilliePhan; Oct 21st, 2009 at 7:53 pm. Reason: The Usual. . . .
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster
 
0
  #6
Oct 21st, 2009
ok they are there,
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,006
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #7
Oct 21st, 2009
Originally Posted by mike34 View Post
ok they are there,
With the three tools now on the Desktop, try this:

-- See if combofix will run. If not, try RightClick on it and Run As Administrator.

If it runs, let it finish and post the log.

If no combofix, then Extract the FindWPP folder from the FindWPP.ZIP
In the folder you'll find RunThis.bat
Run it and post me the log.

Let me know how you fare.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster
 
0
  #8
Oct 21st, 2009
Originally Posted by PhilliePhan View Post
With the three tools now on the Desktop, try this:

-- See if combofix will run. If not, try RightClick on it and Run As Administrator.

If it runs, let it finish and post the log.

If no combofix, then Extract the FindWPP folder from the FindWPP.ZIP
In the folder you'll find RunThis.bat
Run it and post me the log.

Let me know how you fare.

PP
ok doing it now
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 18
Reputation: mike34 is an unknown quantity at this point 
Solved Threads: 0
mike34 mike34 is offline Offline
Newbie Poster
 
0
  #9
Oct 21st, 2009
with both i get a message saying registry edit is disabled by administrator,
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,006
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer
 
0
  #10
Oct 21st, 2009
Originally Posted by mike34 View Post
with both i get a message saying registry edit is disabled by administrator,
Open a command prompt and type %userprofile%\desktop\combo-fix.exe /KillAll ENTER
Note ther is a space here --> .exe<space>/KillAll

EDIT: Try using command.com to open prompt if that fails.
Last edited by PhilliePhan; Oct 21st, 2009 at 9:18 pm. Reason: Added info
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Reply

Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 2058 | Replies: 34
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC