<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emsisoft New Malware Blog &#187; Windows Police Pro</title>
	<atom:link href="http://www.anti-malware-blog.com/tag/windows-police-pro/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anti-malware-blog.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Wed, 25 Jan 2012 06:47:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WindowsPolicePro Adware Removal Instructions</title>
		<link>http://www.anti-malware-blog.com/2009/09/15/windowspolicepro-adware-removal-instructions/</link>
		<comments>http://www.anti-malware-blog.com/2009/09/15/windowspolicepro-adware-removal-instructions/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 11:38:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Alerts]]></category>
		<category><![CDATA[Removal Help]]></category>
		<category><![CDATA[Rogue]]></category>
		<category><![CDATA[Windows Police Pro]]></category>

		<guid isPermaLink="false">http://www.anti-malware-blog.com/post.aspx?id=b9ad8141-b4e8-4516-9c42-5493ae8fc1d6</guid>
		<description><![CDATA[The Emsi Software malware research team has discoverd a new outbreak for the Adware.Win32.WindowsPolicePro. WindowsPolicePro is a rogue security program that: Show False warning messages. Show Misleading scan results. Show fake Windows Security Center. Show fake error svchost.exe. And it&#8217;s Browser Helper Objects The main installer of this malware seem like packed with EXECryptor, and [...]]]></description>
			<content:encoded><![CDATA[<p>The Emsi Software malware research team has discoverd a new outbreak for the <a href="http://www.emsisoft.com/en/malware/?Adware.Win32.WindowsPolicePro" target="_blank">Adware.Win32.WindowsPolicePro</a>.</p>
<p>WindowsPolicePro is a rogue security program that:</p>
<ul>
<li>Show False warning messages.</li>
<li>Show Misleading scan results.</li>
<li>Show fake Windows Security Center.</li>
<li>Show fake error svchost.exe.</li>
<li>And it&#8217;s Browser Helper Objects</li>
</ul>
<p>The main installer of this malware seem like packed with EXECryptor, and it extract several files to:</p>
<ul>
<li>%ProgramFiles%\Windows Police Pro\msvcm80.dll</li>
<li>%ProgramFiles%\Windows Police Pro\msvcp80.dll</li>
<li>%ProgramFiles%\Windows Police Pro\msvcr80.dll</li>
<li>%ProgramFiles%\Windows Police Pro\windows Police Pro.exe</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\dbsinit.exe</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\wispex.html</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\i1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\i2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\i3.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\j1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\j2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\j3.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\jj1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\jj2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\jj3.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\l1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\l2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\l3.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\pix.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\t1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\t2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\up1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\up2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\w1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\w11.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\w2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\w3.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\w3.jpg</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\wt1.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\wt2.gif</li>
<li>%ProgramFiles%\Windows Police Pro\tmp\images\wt3.gif</li>
<li>%SystemRoot%\ppp3.dat</li>
<li>%SystemRoot%\ppp4.dat</li>
<li>%SystemRoot%\svchasts.exe</li>
<li>%SystemRoot%\system32\bennuar.old</li>
<li>%SystemRoot%\system32\dddesot.dll</li>
<li>%SystemRoot%\system32\desote.exe</li>
<li>%SystemRoot%\system32\sysnet.dat</li>
<li>%UserProfile%\Desktop\PC_protect.exe</li>
<li>%UserProfile%\Desktop\Windows Police Pro.lnk</li>
<li>%UserProfile%\Start Menu\Programs\Windows Police Pro\Windows Police Pro.lnk</li>
</ul>
<p>And create new registry entries:</p>
<ul>
<li>HKEY_CURRENT_USER\software\Windows Police Pro</li>
<li>HKEY_CURRENT_USER\software\Windows Police Pro\windows Police Pro</li>
<li>HKEY_CURRENT_USER\software\Windows Police Pro\windows Police Pro\Registration</li>
<li>HKEY_CURRENT_USER\software\Windows Police Pro\windows Police Pro\setdata</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\Win Police Pro</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AntipPro2009_100</li>
<li>HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{76DC0B63-1533-4ba9-8BE8-D59EB676FA02}</li>
</ul>
<p>This malware also try to connect to core2634.newdomainagain.com.</p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPolicePro_GUI.png" alt="WindowsPolicePro graphical user interface" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPolicePro_Buy.png" alt="WindowsPolicePro price" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPolicePro_SecurityCenter.png" alt="Show fake Windows Security Center" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPolicePro_FakeError.png" alt="Show fake error svchost.exe" width="400" /></p>
<p><img src="http://www.anti-malware-blog.com/wp-content/uploads/2009/9/WindowsPolicePro_Register.png" alt="User must register to enable removal feature." width="400" /></p>
<p><strong><span style="font-size: small;">How to remove the infection of Adware.Win32.WindowsPolicePro?</span></strong></p>
<p>To delete this malware infection, please download and install <a href="http://www.emsisoft.com/en/software/antimalware/">a-squared Anti-Malware</a>. Run a full scan on all drives and move all detected items to the quarantine</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.anti-malware-blog.com/2009/11/16/control-center-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Center Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/04/14/control-components-adware-removal-instructions/" rel="bookmark" class="crp_title">Control Components Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/06/acommander-adware-removal-instructions/" rel="bookmark" class="crp_title">ACommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2010/05/07/pcommander-adware-removal-instructions/" rel="bookmark" class="crp_title">PCommander Adware Removal Instructions</a></li><li><a href="http://www.anti-malware-blog.com/2009/11/17/personal-protector-adware-removal-instructions/" rel="bookmark" class="crp_title">Personal Protector Adware Removal Instructions</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.anti-malware-blog.com/2009/09/15/windowspolicepro-adware-removal-instructions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

