Earlier I randomly noticed the Police Pro, pop-up on my desktop and immediately attempted to run McAfee, since it was what's on this laptop. Seeing as it wouldn't load up I rebooted to safe mode and found this site after attempting to do various things and failing.

I deleted desote.exe, hopped into regedit through "as Administrator" and edited the required entry, as well as deleting any others that I could find that had to do with desote or WPPro. I wanted to just keep going with any steps to check things. McAfee did find a trojan file that it deleted. A random name type of thing I believe. I also ran the Win32kDiag? Here is the Log:

Log file is located at: C:\Users\Michael\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'...


Cannot access: C:\Windows\bthservsdp.dat

[1] 2009-09-09 23:08:20 12 C:\Windows\bthservsdp.dat ()


Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl

[1] 2009-09-10 00:09:17 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl ()


Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl

[1] 2009-09-10 00:08:48 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl ()


Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl

[1] 2009-09-10 00:08:48 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl ()


Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl

[1] 2009-09-10 00:08:48 64 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl ()


Finished!


Any further info would be appreciated. And sorry if I've forgotten anything, I was tired long before this happened.

Dani AI

Generated

Quick summary and context: OP has already removed the visible dropper (desote.exe) and edited the .exe association, and McAfee removed a trojan — good first moves, but Windows Police/Police Pro is a known “rogue” (scareware) family that purposely hijacks .exe handling and installs multiple moving parts so it often comes back or leaves behind damage. The behaviour you reported (desote.exe, fake Windows Security UI, blocked AV installers) matches published analyses of Windows Police Pro. MyAntiSpyware removal notes and a SANS writeup document the common tricks (respawning processes, .exe hijack). (myantispyware.com)

Actionable next steps (in roughly this order): isolate the PC (disconnect network), avoid logging into accounts, boot Safe Mode (or use bootable rescue media) and run a current anti‑malware scan (Malwarebytes and similar on-demand scanners are effective; if the infection blocks in‑OS tools, run a bootable offline scanner such as Microsoft Defender Offline or a vendor rescue disk). Use Sysinternals Autoruns to find and remove persistent autostart entries (Run/RunOnce, Services, Scheduled Tasks, Startup shortcuts) and inspect %AppData%, ProgramData and the Start Menu for leftover folders/links. Submit unknown executables to VirusTotal before re‑running or deleting them. (learn.microsoft.com)

Notes about the Win32kDiag output and system repair: the “Cannot access …\LogFiles\WMI\RtBackup\EtwRT*.etl” lines are commonly seen on many systems because those ETL files/folders are locked to the SYSTEM account and don’t necessarily indicate malware — they’re usually normal for a live scan. After removing malware components, run Windows image/system repairs to restore any altered system files and handlers (DISM then SFC). Example commands to run from an elevated prompt:

DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow

See Microsoft documentation for details. (learn.microsoft.com)

Final cautions and cleanup: don’t use the infected machine to change important passwords — change credentials only from a known‑clean device and monitor financial accounts. If the infection keeps reappearing or Windows remains unstable after thorough cleaning, a full reinstall (or restore from a verified clean image) is the safest option. Helpers sometimes recommend powerful removal tools (as suggested), but those should be used carefully and ideally with guidance; always back up data first. For quick file checks, use VirusTotal and follow government guidance on post‑incident steps (disconnect, preserve evidence, change passwords from clean hosts). (virustotal.com)

Recommended Answers

All 3 Replies

Any further info would be appreciated. And sorry if I've forgotten anything, I was tired long before this happened.

Hi Xiados,

Please download and Extract the FindIt folder to your desktop.
-- Inside the folder, you'll see RunThis.bat - DoubleClick it and let it run. (10-20 seconds)
A log should pop up - please post that for me.


I will check back as time permits.

PP :)

Thanks for any time you have! Here's the find it results:

Looking for cngaudit.dll

C:\WINDOWS\SYSTEM32\
cngaudit.dll Thu Nov 2 2006 5:46:04a A.... 11,776 11.50 K

C:\WINDOWS\WINSXS\X8D921~1.163\
cngaudit.dll Thu Nov 2 2006 5:46:04a A.... 11,776 11.50 K

D:\WINDOWS\SYSTEM32\
cngaudit.dll Thu Nov 2 2006 5:46:04a A.... 11,776 11.50 K

D:\WINDOWS\WINSXS\X81D05~1.180\
cngaudit.dll Sat Jan 19 2008 4:51:16a A.... 11,776 11.50 K

4 items found: 4 files, 0 directories.
Total of file sizes: 47,104 bytes 46.00 K


Looking for eventlog.dll

C:\PROGRA~1\FINGER~1\
eventlog.dll Tue Apr 17 2007 1:06:36a A.... 33,280 32.50 K

C:\WINDOWS\SYSTEM32\NDF\
eventlog.etl Tue Aug 25 2009 11:56:50a A.... 327,680 320.00 K

2 items found: 2 files, 0 directories.
Total of file sizes: 360,960 bytes 352.50 K


Looking for logevent.dll

No matches found.


Looking for netlogon.dll

C:\WINDOWS\SYSTEM32\
netlogon.dll Sat Apr 11 2009 2:28:24a A.... 592,896 579.00 K

C:\WINDOWS\WINSXS\X8834C~1.180\
netlogon.dll Sat Apr 11 2009 2:28:24a A.... 592,896 579.00 K

C:\WINDOWS\WINSXS\X8EB3B~1.180\
netlogon.dll Sun Jan 20 2008 10:24:06p A.... 592,384 578.50 K

D:\WINDOWS\SYSTEM32\
netlogon.dll Sat Jan 19 2008 3:35:38a A.... 592,384 578.50 K

D:\WINDOWS\WINSXS\X8EB3B~1.180\
netlogon.dll Sat Jan 19 2008 4:51:18a A.... 592,384 578.50 K

5 items found: 5 files, 0 directories.
Total of file sizes: 2,962,944 bytes 2.82 M


Looking for scecli.dll

C:\WINDOWS\SYSTEM32\
scecli.dll Sat Apr 11 2009 2:28:26a A.... 177,152 173.00 K

C:\WINDOWS\WINSXS\X84EB9~1.180\
scecli.dll Sun Jan 20 2008 10:24:52p A.... 177,152 173.00 K

C:\WINDOWS\WINSXS\X8FE87~1.180\
scecli.dll Sat Apr 11 2009 2:28:26a A.... 177,152 173.00 K

D:\WINDOWS\SYSTEM32\
scecli.dll Sat Jan 19 2008 3:36:20a A.... 177,152 173.00 K

D:\WINDOWS\WINSXS\X84EB9~1.180\
scecli.dll Sat Jan 19 2008 4:52:46a A.... 177,152 173.00 K

5 items found: 5 files, 0 directories.
Total of file sizes: 885,760 bytes 865.00 K

Thanks for any time you have! Here's the find it results:

Happy to try to help :)

Let's try this:

If you already have combofix on your machine, DELETE it.

Then follow the instructions in the link below to DL a fresh Combofix and run it:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

What I want you to do, though, is this:
When you download it and it asks you to "Save File As," rename combofix to Zappafix.exe and then download it to your desktop as that and follow the instructions in the linky very carefully to run Combofix and then post the Combofix log for me.

Let me know if you have trouble with that. I'll be back tonight.

PP :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.