I GIVE UP-WINDOWS POLICE PRO has computer locked down tight-can anyone help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by homescool, Sep 22, 2009.

  1. homescool

    homescool Private E-2

    I give up - so far 5 computers infected with WIndows Police Pro - was able to save 3 and get Kaspersky on them. One I can't get Kaspersky to complete install - talked with them and they were to instantly email help - that was 6 hrs ago!
    The other Dell is locked up tighter than a drum. It won't load anything other than the infected screen - it runs in a loop. No task bar, no start menu, can't do anything in ANY Safe mode. If I try regedit or any commands it either says it has been infected or stopped by the admin - I am the admin and I have NO passwords set. Besides, the "warnings" look fake. I have tried to get past this blank-blank virus/trojan but nothing has worked. I have spent days doing research and trying all suggestions but nothing works because I can't get it to run in safe mode etc.
    PLEASE - I know there is someone here 10 times smarter than the @$$-wipe that created this thing! PLEASE HELP!! Thank you!

    Paula
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First, you need to start a thread for each computer you want assistance with. Now, pick one for this thread and please then tell me exactly what you can and can not do. Can you get into normal mode, if so, what can you do there? Does safe mode work, and if so, what can you do there?
    Can you transfer anything via cd?

    Can you try doing both of these:
    Win32KDiag - How to run

    Using Inherit to correct program execution permissions issues
     
  3. homescool

    homescool Private E-2

    I did start a thread for both computer problems.
    Here they are.
    http://forums.majorgeeks.com/showthread.php?t=199331&goto=newpost-this is the Dell.
    http://forums.majorgeeks.com/showthread.php?t=198946&goto=newpost
    -this is the Emachine T2240.-THIS IS MY MOM'S COMPUTER - She had to purchase another as she lives 4 states away from me and I could not fix it over the phone - the virus corrupted windows - we tried a clean install with a windows CD -she had the KEY (Emachines DOES NOT send the recovery CD with their computers or at least with 3 that I know of)
    We tried 3 different CD's - would load to a certain point then instead of letting her reinstall windows it would go to partition the HD. She still needs to fix or get the info off the HD - however wouldn't it be infected? Wouldn't you need to clean it up before putting the info on a new computer?

    Most of the info or at least the gist of the info is in the threads but I will summarize the Emachine one for you.
    Dell OptiPlex 170 infected with the Vundo virus or some mutant form - Windows Police Pro error message to start with.
    Tried running Malwarebytes - would install and start for 2 seconds then quit.
    Tried installing and running Kaspersky, Fix-It Utilities, System Mechanic Pro and Registry Mechanic, AVG Anti Virus and a few others - none would even install - Fit It would start from cd but only diagnose HD - it said it was fine.
    This computer only uses F2-setup - useless - can't do much in here.
    F8 - Start in different modes etc but NO reset to factory settings option
    F12 - Boot order - was already set to CD ROM.
    I did DAYS of research and spend DAYS looking for the virus, trying to remove and and trying to load programs to help navigate or remove virus.
    I followed the directions here and on several other tech support sites for removing the virus, trying to work around computer virus not letting you boot in normal and install the software etc.
    I don't care what the norm is this virus has mutated to SAFE MODE. I kept being told it would not interfere with SAFE MODE - HA I say!
    1. Looks like it boots to normal mode but only see wallpaper - no icons no start button - nothing. any attempt to bring up the task bar gets an error message "The task bar has been blocked my the administrator - NOT! We NEVER used the admin and I checked - nothing was blocked.
    2.Will boot in safe mode with command prompts but EVERY command gives the error message - "Bad file name or invalid file name"
    3. Safe mode with networking - black screen - no internet connection
    4. all other choices boot to a black screen with a flashing cursor but you can type nothing.
    5. Safe mode(plain) o ctr-alt-del will bring up the task bar. You can navigate thru file/run browse and look thru files etc. This is where I deleted registry keys associated with this bugger, removed files etc.
    6.I tried many fixes, found and deleted over 10 reg keys,files,etc that wre infected or had the virus name attached to them.
    7. Each time I would try Malwarebytes or the other anti virus programs but still would not install or run.
    8. I tried to run UBUNTU from the cd but it would not load or run.
    9. I tried getting into the system recovery to wipe the HD and once again was blocked by you don't have access to this file or can't be run in Safe Mode.
    10. When I try to run any .exe program it gives me the you don't have access or file won't run in Safe Mode crap.
    11. I tried saving with another name and it changes it back.
    12. I GAVE UP!! - I DO NOT GIVE UP EASILY but this has me whipped!:cry:cry:(:confused

    OH - I followed the instructons for the fix with INHERIT from Bleeping Computer - won't run any program - says I don't have permission to access this program and sometimes it will say this program can not be accessed in safe mode.
    Thanks,

    Paula
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One thread is in software and the other was with me. You chose to take one to a repair shop. The other appears as though you are getting assistance with doing a reformat of the windows partition and then a new installation.

    Was there something you wanted us to help you with in this thread?

    Did you follow these instructions for using Inherit:
    Using Inherit to correct program execution permissions issues ?
     
  5. homescool

    homescool Private E-2

    Dear Tim,
    I am not sure what you are asking me. I posted 2 seperate problems in 2 seperate threads -I listed them in my previous post and if you click on the 2 links they are 2 different problems. This thread is my 3rd(is there a limit I am not aware of?)
    I really appreciate your help however, you ask "Was there something you wanted us to help you with in this thread?
    I started this thread because I NEEDED HELP. I thought that was what these forums were for. I HAD NOT taken the machine to a repair shop until a few days AFTER I posted my question. I was hoping someone could assit me in fixing the Dell with the Windows Police Pro virus(Vundo) problem as I tried every tip/help posted here. Before I posted and bothered anyone with any problem I did hours/days of research and tried all of the fixes they had so I am not just posting without knowledge or forthought. I did not get an answer to my question for a few days - we needed the computer so I ended up taking it to a repair shop.
    You replied to my post AFTER I took it to the shop. I apologize for not immediately posting back to close the thread and possibly wasting your time.
    I did try your suggestions as I had already read about those particular fixes on Bleeping computer site. Thank you for the info.
    I appreciate all your help. As there is nothing further that can be done at this site please close this thread.

    P.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My question was because ( as your two links showed ) I didn't know what you were wanting. One link as I stated was the one where you had taken a computer to a repair shop because you needed more immediate assistance then the malware forum could provide you.

    Your second link was to a thread in the software forum where you were seeking advice on reformatting and doing a clean install.

    So my question still is what are you seeking assistance with? Are you still trying to remove the virus on the Dell? Or have you chosen to reformat and reinstall?
     
  7. homescool

    homescool Private E-2

    Dear Tim,

    I think I am confused-you are confused or we both are:confused.
    My original thread and post was about my mom's EMachine-infected with the Vundo strain virus or at least that is what we think.- That was this link-http://forums.majorgeeks.com/showthr...6&goto=newpost
    She had the phony security alert- windows was corrupt-we bought a CD that got as far as the partition HD -which we did not want to do and did not get the repair windows option-
    I was told this means windows is so corrupt you have to do a clean install. She got a Windows CD and attempted to do a clean install-she has the key form the computer. This did not work - would not load the CD - we checked the boot order many times and it was set to CD Rom. We tried several other fixes and ideas presented here to us, however nothing was working. We tried 2 other Windows CD's and gto to the same partition the HD point but were never given the repair option.
    Emachines did not send cd with this computer and when contacted they said it was too old and they could not make one.
    As she needed a computer she had to go purchase another one.
    She would love to be able to clean this one up and transfer the files but it is not a major loss if she can't - if this can't be done she would like to wipe the HD COMPLETELY and give the computer to a local group that provides computers for the needy. -Her are my questions for this problem.
    QUESTION - Any way to access the files and put on new computer without infecting new computer?
    QUESTION - If not - how to wipe HD completely so computer can be donated?
    My second post was about my son's Dell - here is that thread -http://forums.majorgeeks.com/showthr...o=newpost
    Same virus but I could not run/install ANY virus program or ANY other program or fix. I could not boot and work in any mode but Safe and then only through task mgr.
    Every time I tried something I was stopped by this virus with "Access denied" "You do not have permission to access this file" "File not a valid file" "Task mgr blocked by the Administrator" and several other errors.
    I tried every fix offered more than one time and after a week or more of working on/researching it etc I was wiped out so I started THIS thread.
    That was on 9-22. I kept trying things people here and elsewhere suggested but no luck. I had no response to my thread HERE so on 9-26 I gave up - much to my dismay and took it to a repair shop.:cry
    You were kind enough to answer my post here on 9-27.
    Your answer was confusing as you asked me to start a thread for each computer- I had - or so I thought -
    The Emachine thread was in software as it was windows that was corrupt.
    The Dell thread was in Malware.
    This thread is about the Dell - Maybe I should have added it to my original post but it had already been answered - I did not know anyone would even look at it again - I had a new problem - I was being locked out or blocked from EVERYTHING - Hence the I GIVE UP thread in malware.
    SO - As this computer is in the repair shop I guess this thread should be closed?
    I would REALLY like to know though if there was any way to access this computer and beat this virus - I know this is juvenile but this darned thing has me frustrated - I don't like to admit defeat and was hoping to beat it.
    I could not get into the computer to do system restore, to take it back to factory setting or even to reformat the HD - Every time I tried I was told by the computer/virus it could not be done in Safe Mode!:(
    Once again - THANK YOU from the bottom of my heart for all of you help and everyone else.
    This is the BEST help site on the net by far and I REALLY appreciate it!:major

    Thank you,

    Paula
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could slave the HD to the new computer. But you must have the new computer well protected and all protection up to date. Then you may be able to run the scanning tools on that computer, and let us help you remove the malware from that HD. Then you could transfer your files.

    Check this in the software forum, but I believe that once you have slaved the drive, you can format it. It has been too long a time since I last did that.

    You may have noticed that we are running days behind. This usually happens when a new virus attack is hitting a lot of people. So our response time, working the queue from last to first order, is being stretched these days.
    We do not close threads.....unless the poster has violated one of the forum rules.

    All of our procedures will usually work. It really is a matter of us being able to get information. It is rare that a system gets so badly corrupted that we can't fix it. But it does happen. That is why we always have people read this --> How to Protect yourself from malware!

    You are most welcome. I am sorry that we could not help you and in a timely fashion. Please do avail yourself of the software forum for additional guidance.
     
  9. homescool

    homescool Private E-2

    Thank you. FYI, I have the computer back from repair shop - working fine and YES it is well protected now! :-o - BTW, the repair tech said this was the by far the sickest, most infected computer he has worked on in his 20+ years. It thwarted him art every turn as he tried several repairs/fixes prior to wiping the HD. I am sure you are aware, but this virus is a new and improved strain of the old virus - it duplicates itself everywhere! Too bad these poor, lonely, pathetic, socially inept individuals who create these "things" would not use their obvious talents for the good of humanity!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are aware of this new strain and is very difficult to remove unless caught fairly early. Once it has managed to spawn itself into all exe's and system files, there is little hope of repairs.

    Good to know you are at least back up and running.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds