Windows Police Pro
» If you can't view the screen shot, you may have to click the screen shot when you put the mouse over the it.
» Dependant upon your browser settings.
This sleek program is another to watch out for. So be don't be tricked.
It appears
that the client was browsing facebook.com, when their Google Chrome browser was hijacked and redirected to
another site. The client was duped into installing this program.
Below are entries found in the Registry(If you are unfamiliar with the registry...Leave this page NOW)
and files associated with the program.
-
Key Name: HKLM\SOFTWARE\Microsoft\ESENT\Process\Windows Police Pro
Class Name:
Last Write Time: 10/19/2009 - 6:42 PM
-
Key Name: HKLM\SOFTWARE\Microsoft\ESENT\Process\Windows Police Pro\DEBUG
Class Name:
Last Write Time: 10/19/2009 - 6:42 PM
Value 0
Name: Trace Level
Type: REG_SZ
Data:
-
Key Name: HKEY_USERS\....\Software\Windows Police Pro
Class Name:
Last Write Time: 10/19/2009 - 3:26 PM
-
Key Name: HKEY_USERS\....\Software\Windows Police Pro\Windows Police Pro
Class Name:
Last Write Time: 10/19/2009 - 3:26 PM
-
Key Name: HKEY_USERS\....\Software\Windows Police Pro\Windows Police Pro\Registration
Class Name:
Last Write Time: 10/19/2009 - 3:26 PM
-
Key Name: HKEY_USERS\....\Software\Windows Police Pro\Windows Police Pro\setdata
Class Name:
Last Write Time: 10/19/2009 - 9:52 PM
Value 0
Name: scantime
Type: REG_SZ
Data: 20.10.2009 0:52:51
Value 1
Name: scncnt
Type: REG_DWORD
Data: 0x1c
Value 2
Name: check9
Type: REG_DWORD
Data: 0x1
Value 3
Name: check10
Type: REG_DWORD
Data: 0
Value 4
Name: check11
Type: REG_DWORD
Data: 0x1
Value 5
Name: check12
Type: REG_DWORD
Data: 0x1
Value 6
Name: check13
Type: REG_DWORD
Data: 0
Value 7
Name: check14
Type: REG_DWORD
Data: 0x1
Value 8
Name: check15
Type: REG_DWORD
Data: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Windows Police Pro.exe"
You will find shortcuts to the program on the
- Desktop,
- on the Quick Launch
- in the Program Groups (i.e. Start » All Programs) »
Windows Police Pro
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following is a list of files you may find in the:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"C:\Program Files\Windows Police Pro" Folder
Size
Name
- 479,232 bytes » msvcm80.dll
- 548,864 bytes » msvcp80.dll
- 626,688 bytes » msvcr80.dll
- 9,171,464 bytes » Windows Police Pro.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The following is a list of files you may find in the:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"C:\Windows\System32" Folder
Size
Name
- 235 bytes » windows
- 508,416 bytes » pump.exe
- 567,808 bytes » plugie.dll
- 4 bytes » bincd32.dat
- 145 bytes » tempie.html
- 9 bytes » nuar.old
- 36 bytes » skynet.dat
- 108 bytes » wwp.html
Next, you will need to find the "schtml" Folder, where you will find these files
- 137,703 bytes » dbsinit.exe
- 508,416 bytes » pump.exe
- 8,551 bytes » wispex.html
- images FOLDER
Remember to always check here:
C:\WINDOWS\Prefetch
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-

-
