XP Police Antivirus
Malware - Rogues
XP Police Antivirus is a rogue application, which is distributed by one or more sites such as xp-police.com, It tries to disable the Task Manager, registry tools and the windows "Security Center" on the infected computer. Creates folders and files inside windows and the system folder, and generates a lot of registry entries. You will find all the necessary details in this article. [ This article is written such that any person with basic knowledge of computers can eliminate the malware problem without having to purchase anything. Videos demonstrating steps are also embedded where ever possible. If you want you can watch them in larger size from the links  given at the end of this article. All the tools/ software mentioned in this article are fully functional freeware. You are welcome to add a comment if you have any questions or suggestions or if you do not understand something ]
Check your security  and your browsing habits: Click here to read more

 
Preparation: Search for and keep the windows operating system disk ready, if you got one with your computer. Or check if there is a Restore Partition on your hard disk, in that case you won't require an extra disk. It is advisable to have a functioning antivirus application on your computer. You will also need to install CCleaner, and a Firewall application, you can choose one of the firewall applications listed at the end of this article.
Turn system restore off :You should do this in order to remove the virus files that may be stored inside the system restore backup files, you can turn it back to ON after the computer is cleaned . Click here to read more...

If you are unable to open Task Manager

This malware disables Task Manager and the Registry tools. So if you find that you are not able to open the task manager, there are several polpular free tools available on the internet to solve this problem.  I will list them here, see which one helps you. Click here to read more...

Using the command window: If the Task Manager is disabled and if you can still open the command prompt, then you can use a command to terminate the processes. First Click on Start > All Programs > Accessories > Command Prompt. The Command window will open. Now use the following commands.
For windows XP Home / Professional: tskill xppolice.exe and press Enter
For windows Professional:  taskkill /im xppolice.exe /f  and press Enter
 

  Remove Processes from Task Manager
Press Ctrl Shift Esc to open Task Manager. See in the list of the processes for a processes named xppolice.exe select if found and press the End Process button. It will prompt you , say yes, and then close the Task Manager. Although the file names may differ. There may be more processes belonging to this malware.This malware stops the "security center" , so beware of the fake security center. The process may be named as "winscenter.exe" or similar.

If you use a freeware tool called "Zenturi program checker"  You may be able to see the path of a process in the task manager, and from the list of malware files given in this article you may be able to locate the malware processes from windows genuine processes .

 
 Removing a Program from windows startup: The system configuration utility can be started in xp and in vista by typing msconfig in the run box. The run box can be opened in xp by clicking on Start > run
The best part of windows startup is that the setting is reversible, therefore you can check / uncheck any entry from windows startup any number of times. So do not hesitate to uncheck anything that you find doubtful. You can always check it back if you later come to know that it is something useful. 

After the system configuration utility window is open, Click on the Startup tab, that will list all the programs that are scheduled to start when you turn your computer On. Expand the middle column using your mouse pointer so that you can see the path of the program on the hard disk, that will give you a clear idea, what program that is. Locate and uncheck the entries if  found
"C:\Program Files\XPPoliceAntivirus" (look for any suspicious name) Uncheck the boxes in front of these entries. Also look at other entries, if you find an entry  of any of the malware files listed in this article, uncheck that too. This step is very important. The further cleaning depends on cleaning this list. Press Apply , Press Close/Ok , at the next prompt select "Restart the computer". 

 
 View Hidden files and folders : You may need to enable to view hidden files and folders if you can not see the hidden folders. Click here to read more...
 Boot in safe mode :  You may require to boot in safe mode if the virus files and folders are not getting deleted , and you are getting a "file in use" or "permission denied" message. Click here to read more...

Searching andd Deleting the Folders / files on the hard disk 

 

After restarting the computer, use the windows search utility to search for "XPPoliceAntivirus". This search will find all its folders on the hard disk , delete the folders from the hard disk. You may find the folder in more than one location. Delete its all instances.

  C:\Windows\System32\Plugins
  C:\Windows\System32\sounds
(it creates above folders, delete if found)

C:\Windows\System32\AVCoreFn.dll
C:\Windows\System32\bdconf.cfg
C:\Windows\System32\Core.dll
C:\Windows\iehost.dll
(it creates above files, delete if found)

 

 

 Manually removing malware entries from  Registry  : 

If you want to know more about manual registry editing. Click here to read more...

Remove the registry keys

  • The following Registry Keys were created:
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\InprocServer32
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\ProgID
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\Programmable
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\TypeLib
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\VersionIndependentProgID
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\0
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\0\win32
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\FLAGS
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\HELPDIR
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe\CLSID
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe\CurVer
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe.1
    • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe.1\CLSID
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6b571fb-b71d-449c-ad70-82e966328795}
    • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
  • The newly created Registry Values are:
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\VersionIndependentProgID]
      • (Default) = "WinApp.WinSafe"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\TypeLib]
      • (Default) = "{16406580-14ce-4441-b904-ad56cc8064ca}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\ProgID]
      • (Default) = "WinApp.WinSafe.1"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}\InprocServer32]
      • (Default) = "%Windir%\iehost.dll"
      • ThreadingModel = "Apartment"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795}]
      • (Default) = "WinSafe Class"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib]
      • (Default) = "{16406580-14CE-4441-B904-AD56CC8064CA}"
      • Version = "1.0"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32]
      • (Default) = "{00020420-0000-0000-C000-000000000046}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid]
      • (Default) = "{00020420-0000-0000-C000-000000000046}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}]
      • (Default) = "_IBhoAppEvents"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib]
      • (Default) = "{16406580-14CE-4441-B904-AD56CC8064CA}"
      • Version = "1.0"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32]
      • (Default) = "{00020424-0000-0000-C000-000000000046}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid]
      • (Default) = "{00020424-0000-0000-C000-000000000046}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}]
      • (Default) = "IBhoApp"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\0\win32]
      • (Default) = "%Windir%\iehost.dll"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\HELPDIR]
      • (Default) = "%Windir%\"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0\FLAGS]
      • (Default) = "0"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{16406580-14CE-4441-B904-AD56CC8064CA}\1.0]
      • (Default) = "WinSafe 1.0 Type Library"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe\CurVer]
      • (Default) = "WinApp.WinSafe.1"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe\CLSID]
      • (Default) = "{b6b571fb-b71d-449c-ad70-82e966328795}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe]
      • (Default) = "WinSafe Class"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe.1\CLSID]
      • (Default) = "{b6b571fb-b71d-449c-ad70-82e966328795}"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinApp.WinSafe.1]
      • (Default) = "WinSafe Class"
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      • AntiVirusDisableNotify = "1"
      • FirewallDisableNotify = "1"
      • UpdatesDisableNotify = "1"

    • to disable notification of firewall, antivirus and/or update status through the Windows Security Center
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6b571fb-b71d-449c-ad70-82e966328795}]
      • NoExplorer = 0x00000001
    • [HKEY_CURRENT_USER\Control Panel\don't load]
      • scui.cpl = "No"
      • wscui.cpl = "No"
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      • DisableTaskMgr = "1"
      • DisableRegistryTools = "1"

    • to prevent users from starting Task Manager (Taskmgr.exe)
      to disable the Windows registry editors (Regedt32.exe and Regedit.exe)
  • The following Registry Value was deleted:
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      • AntiVirusDisableNotify = 0x00000001
      • FirewallDisableNotify = 0x00000001
      • UpdatesDisableNotify = 0x00000001

 


Use CCleaner:  CCleaner is a freeware temp files and registry cleaner. Click here to read more...

 

Using the Antivirus: The Antivirus application on your computer can also help you to remove some parts of the malware, particularly the virus processes in the memory. Click here to read more.... 

 Using Online Virus Scanner: This option can be explored if you already have paid for an antivirus and you want to keep it. Click here to read more...

 

Using the system file checker: Follow this step if you notice trouble in the normal functioning of windows. Click here to read more...

If you are unable to access one or more sites during the repair process

- if possible use another computer to download the software needed for repairing your computer, and then copy and transfer it to the infected computer using any available means like a pen drive.
- if you are using only internet explorer, and if it is blocked from visiting some of the security related sites, try to download/ install Firefox browser, and see if you can use it for the same purpose. 

Using Firewall to block unsolicited communication
Use a standalone firewall to block any unwanted communication to and from your computer. The malware contacts these urls (89.149.194.188/setup.dat) (216.240.151.112/setup.dat) block if found in the firewall.

(Reference with permission from ThreatExpert)
Comments
Add New Search
Ivan  - Thank You!!   |96.250.54.xxx |2009-02-09 23:50:43
Man did I panic when I suddenly got this darn program on my laptop. Thank god
for this guide, now I'm virus free once again. Thanks a lot man. Your
instructions were very detailed and helpful.

10/10
Sanjay  - you are welcome   |121.246.33.xxx |2009-02-11 12:38:08
All the articles on this site are Updated regularly with the latest information
available. So please check the site again if you have an unresolved issue. I
also welcome your questions/ problems in this regard
Stef  - Thank You - A couple of questions...     |58.179.99.xxx |2009-02-11 18:25:58
thanks for the help! I found you thru youtube.

I've got a couple of
questions...

In the blue section it says "The newly created Registry Values
are" - am I s'posed to removed them??

And where it says "The following
Registry Value was deleted" do I just make sure they're there - cause they
are.

I'm just a little confused cause up the top it says... "Remove the
registry keys" so it looks like you have to remove ALL the info below that
in the blue section.

It's so good of you to put up help like this - much
appreciated!
sanjay   |115.109.9.xxx |2009-02-12 00:35:17
you need to remove all the registry keys. The first block lists the keys, and
the second block lists the values assigned to the keys. Just make sure that it
is the same key as listed
sanjay   |115.109.9.xxx |2009-02-12 00:46:16
and the "following registry keys were deleted" is the handywork of the
malware. It will get restored once you manage to eliminate the malware
Kyle   |78.148.138.xxx |2009-02-11 18:57:38
Thanks for this - probably the most comprehensive help guide I've come across.
sanjay   |115.109.9.xxx |2009-02-12 00:40:14
:) Yes, it is the most comprehensive help guide on the net. And it is not
static. Updated when new information becomes available. So you may find more
info the next time you visit the same page
RjbsNXT  - AWESOME !   |81.159.72.xxx |2009-02-14 16:59:17
THANKYOU !!!!!!!!!

Jees i was scared :0 when my antivirus software didn't
remove it. I searched the web for 'XPPoliceAntivirus' and was relieved when i
realised i was not alone. :side: This is by far the best guide to remove it
i've found. :D
All set to roam the web again. :silly:


***** 5 stars,
any day :woohoo:
Chris  - Thank you!   |70.215.24.xxx |2009-02-15 09:46:05
You are awesome Sanjay! Thank you so much!
JJJKKKLLL   |97.123.11.xxx |2009-02-16 01:56:11
:angry: agh! I got the version where it disables the task manager, what exactly
should i do?
sanjay   |121.246.34.xxx |2009-02-16 05:41:56
:idea: Use one of the tools mentioned in this article, even copy/pasting the
tool as explained should help. Use the tools one after the other, till the task
manager is back in action.
JJJKKKLLL   |97.123.11.xxx |2009-02-18 00:51:55
:side: I tried using a free anti-malware program called Malwarebytes'
Anti-Malware to remove the rogue malware. the program quarantined two files and
the task manager started working again. Which instructions do you suggest I look
at to remove the leftover files from the malware from my computer?
JJJKKKLLL   |97.123.11.xxx |2009-02-18 00:58:31
:cheer: oh yeah, you mentioned the program above, just noticed.
brr   |98.198.192.xxx |2009-02-18 16:54:43
thank you for this guide!
you saved my desktop. (:
Anonymous   |76.64.36.xxx |2009-02-22 21:12:24
:s
First of all thanks so much for this guide, it is very useful. however, I
have a question about the registry keys/values.

I couldn't find any of the
ones that you said were made by the malware program, and the ones you said were
deleted,

* AntiVirusDisableNotify = 0x00000001
* FirewallDisableNotify =
0x00000001
* UpdatesDisableNotify = 0x00000001

,seem to be there. I did
download and run, before looking at the registry, the CCleaner program that you
recommended above, including the registry part. I'm not sure that maybe fixed
it? I'm new at doing stuff with the registry though, although I'm not an idiot,
so probably I'm just doing something wrong. Oh, and I'm using vista. Hope you
can help,

Ianthe
sanjay   |121.246.35.xxx |2009-02-23 01:54:17
see if you can Click on the security link in control panel, and if that opens
the windows security center, then everything is alright .
Ianthe   |76.64.36.xxx |2009-02-23 10:00:01
When I click on "security" it opens up a list which has windows
firewall, windows update, windows defender, internet options, and parental
controls. Is this the security center you are talking about?
sanjay   |121.246.35.xxx |2009-02-23 10:48:25
:) yes, if that is working , then those registry entries are unaltered, and you
need not worry about them
Ianthe   |76.64.36.xxx |2009-02-23 12:14:19
:cheer: Hey, thanks soooo much, I almost freaked out when I first saw that I had
this virus, mostly because a friend of mine got one recently (called spygaurd
2008) and he had to reformat his computer. Anyway, thanks again!
Silvan  - Programs doesn't work   |83.137.142.xxx |2009-05-06 05:08:19
Heee i followed your whole guide ..
But many programs won't work anymore, and i
can't even visit some websites like hotmail!

How can i fix this?
sanjay   |115.109.11.xxx |2009-05-06 06:09:07
you need to reinstall the programs that are not working. And you need to check
your hosts file and see if it is altered
Silvan   |83.137.142.xxx |2009-05-07 04:08:18
O i should reinstall it anyway?!
Okay, thank u .. !
Write comment
Name:
Email:
 
Title:
 

3.26 Copyright (C) 2008 Compojoom.com / Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

 
Privacy Policy