954,242 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

windows police,help

I got hit with the windows police pro virus,and it has locked up everything,i cant get into control panel,task manager,hell not even the calculator,i have tried every command listed for restarting task manager or regedit,but cannt get access,i cant even log into safe mode,i dont know what else to try,now im posting on an old computer,I am completely stumped here,i was able to run a virus program that has deleted a lot of viruses,but I am still locked out please any help would be great,thanks

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 

-- Do you have a flash drive to transfer tools and scanlogs between computers?

-- Can you get a command prompt on ill machine?
START > RUN > type cmd > OK
or
START > RUN > type command.com > OK

Let me know.

PP :)

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

-- Do you have a flash drive to transfer tools and scanlogs between computers?

-- Can you get a command prompt on ill machine?
START > RUN > type cmd > OK
or
START > RUN > type command.com > OK

Let me know.

PP :)


yes to both questions

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 

yes i can get the command promt and have a flash drive

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
yes to both questions


Allrightythen!

You'll need to put these tools on your flash drive:

http://ad13.geekstogo.com/Win32kDiag.exe
http://swandog46.geekstogo.com/avenger.zip
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
With combofix, what I want you to do, though, is this:
When you download it and it asks you to "Save File As," rename combofix to Combo-Fix and then download it to working compy and put it on the flash drive.
FindWPP.zip
DDS by sUBs
http://download.sysinternals.com/Files/Junction.zip
http://www.raktor.net/exeHelper/exeHelper.com
http://download.bleepingcomputer.com/sUBs/MiniFixes/Inherit.exe
SysProt Anti-Rootkit


Then, see if you are able to copy these to the desktop:
-- FindWPP.zip
-- Win32kDiag.exe
-- Combo-fix.exe

Let me know how you fare.

PP :)

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

ok they are there,

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
ok they are there,


With the three tools now on the Desktop, try this:

-- See if combofix will run. If not, try RightClick on it andRun As Administrator.

If it runs, let it finish and post the log.

If no combofix, then Extract the FindWPP folder from the FindWPP.ZIP
In the folder you'll find RunThis.bat
Run it and post me the log.

Let me know how you fare.

PP :)

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

With the three tools now on the Desktop, try this:

-- See if combofix will run. If not, try RightClick on it and Run As Administrator.

If it runs, let it finish and post the log.

If no combofix, then Extract the FindWPP folder from the FindWPP.ZIP
In the folder you'll find RunThis.bat
Run it and post me the log.

Let me know how you fare.

PP :)


ok doing it now

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 

with both i get a message saying registry edit is disabled by administrator,

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
with both i get a message saying registry edit is disabled by administrator,


Open a command prompt and type %userprofile%\desktop\combo-fix.exe /KillAll ENTER
Note ther is a space here --> .exe/KillAll

EDIT: Try using command.com to open prompt if that fails.

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

says combo-fix.exe is not a recognizeable command

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
says combo-fix.exe is not a recognizeable command


Is combo-fix.exe on the desktop? You did rename it and it is not combofix (w/out dash)?

Click START > Run > type command.com to open the command prompt and then type:

cd %userprofile%\desktop ENTER
then type
combo-fix.exe /KillAll ENTER (or combofix.exe if not renamed)

It should run - let me know.

PP :)

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

yea its there,hang on ill try that

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 

now it says installation files for combofix are corrupted,i cannot get it to install at all

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
now it says installation files for combofix are corrupted,i cannot get it to install at all


OK - let's try something else for the time being:
RightClick on FindWPP.ZIP and Extract the FindWPP folder from the ZIP to the desktop.
In the FindWPP folder you'll find RunThis.bat
Run it and post me the log.

With any luck, that will work ok...

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

nope get a message saying registry editinf has been disabled by the administrator,this is making me feel dumb

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
nope get a message saying registry editinf has been disabled by the administrator,this is making me feel dumb


This is the worst malware I've seen in 6+ years of volunteering in forums . . . and I've seen some doozies!

-- Were you able to extract the FindWPP folder from the ZIP?
If so:
Click START > Run > type command.com to open the command prompt and then type:cd %userprofile%\desktop\FindWPP ENTER
then type
RunThis.bat ENTER


If that doesn't work:
Click START > Run > type command.com to open the command prompt and then type:

cd %userprofile%\desktop ENTER
then type
Win32kDiag.exe ENTER

If that runs, allow it to run until it finishes (it will say "finished")
Post the log.

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

If no joy with any of the above, move Inherit.exe from your flash drive to the Desktop.
Then, drag and drop Win32kDiag.exe onto Inhereit.exe on the desktop. After a few seconds, a dialog box should pop up saying "OK"
If that works, try to run Win32kDiag.exe again.

PP :)

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

ok ill try that,lol told ya this was bad

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 
ok ill try that,lol told ya this was bad


I've seen a lot of this baddie - It comes in different flavors and different degrees of difficulty.
Most of the compys I see this on have a lot of P2P apps.....

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

Win32kDiag ran,but didnt list anything,just said warning could not get backup privileges and dragging and dropping onto inhereit did nothing at all

mike34
Newbie Poster
18 posts since Oct 2009
Reputation Points: 10
Solved Threads: 0
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You