If you think that the Canadian Police have no business investigating your online activity, you will be shocked to find a truly intimidating notification sent by the Association Canadienne des Policiers virus. All information presented to you through this alert is bogus; however, the professionally developed interface and intimidating credentials attached to the warning have already helped schemers fool thousands of Windows users. You should not allow cyber crooks fool you too, and if you apply Association Canadienne des Policiers virus removal tips presented in the report, soon enough you will be able to run your PC ordinarily.
The virus that misleadingly uses the CPA ACP logo has been discovered to travel through the security backdoors exposed by ransom Trojans, and it can be spread into Windows systems using drive-by download protocols. Once Association Canadienne des Policiers virus is activated within your computer, you will notice extremely irritating system functionality disturbances. In the worst case scenario, your system will be locked and all of your administrative privileges will be removed. This is caused to make you desperate for a quick fix. If you pay attention to the seemingly intimidating alert, you might start thinking that you will restore your system only after you pay a 100 dollar fine. Here is what you will be forced to believe in:
Your computer is locked! […]
1. Your computer has been used to view banned Web sites
2. Your computer has been used to view Web sites containing child pornography.
3. Your computer has been used to illegal information, software.
4. Your computer has been used for storing / viewing pirated content. […]
According to “Information Security and Control Act 2012”, you are required to pay a fine of 100 Canadian dollars.
The presented Information Security and Control Act 2012 does not enable governmental agencies and Police departments to lock down systems and demand fine payments made through Ukash or Paysafecard. These systems are completely legitimate but do not require identification, which is why they would never be linked to any law enforcement departments. What is more, these money transfer systems have been used by schemers who have developed the infamous Cuerpo Nacional de Policía virus, Polizei österreich Virus, Dutch Police Virus and a number of other so-called Ukash viruses.
It is clear that you need to delete Association Canadienne des Policiers virus; however, if you think you will be able to succeed with manual removal, we remind you that the infection could be running alongside other PC infections. Do not risk the integrity of your operating Windows system and implement automatic removal tools to delete the virus. Here is how you can do it:
Instructions for Windows XP users:
| # | File Name | File Size (Bytes) | File Hash |
|---|---|---|---|
| 1 | puozlkmyj.dll | 356352 bytes | MD5: a36b0b1c2a6c4ad06418ab137b62ee6c |
| 2 | rool0_pk.exe | 134144 bytes | MD5: a363c25160f5bb09bdaee0e03d85278c |
| 3 | m2PythonLoader.exe | 135680 bytes | MD5: d8dab211e0db20f00118f25ad64be90c |
| 4 | brenasa.exe | 45056 bytes | MD5: a626c9a877af7d078e67be021a5baf28 |
| 5 | crack.exe | 306176 bytes | MD5: ab5af9b01941bff73068abf9c7def3bd |
| 6 | dtkmujvo.exe | 87040 bytes | MD5: b8d2f2fb25bc89994c96079e6079a3ec |
| 7 | n. | 46592 bytes | MD5: 61a29236fee6568908a9bc629b8ada22 |
| 8 | ieudator.dll | 55808 bytes | MD5: bfe953f0f96438290914369a7797cf84 |
| 9 | scvhost.exe | 231936 bytes | MD5: 2dc8b92985e96aabc9ab0937f1018ff7 |
| 10 | JfCqQ5JC.exe | 270336 bytes | MD5: 023829e50c93205ac81dd27009762620 |
| 11 | %ALLUSERSPROFILE%\Application Data | ||
| 12 | mplayer2.exe | 403456 bytes | MD5: a01f673216f9a83cb352028319809f2f |
| 13 | NTServiceManager.exe | 666624 bytes | MD5: 8e931cb28a92d7ee1a7f146b7f6c4664 |
| 14 | iner.exe | 674816 bytes | MD5: 6b485eb86c32deca15b26e47e66a94e7 |
| 15 | ex3b.dll | 1792000 bytes | MD5: 992d5e68d52b908e744f0ea1db1deb89 |
| 16 | msn.exe | 675840 bytes | MD5: a403f9d53ad6a07073c9236842dd865e |
| 17 | TimeDateMUICallback.exe | 87552 bytes | MD5: 2d108d8f3d914658f74768a8eb120dde |
| 18 | Piranha.exe | 449161 bytes | MD5: eb0f419c0a98b065271effae67c4920f |
| 19 | wahneaqa.exe | 102912 bytes | MD5: dfd58427f8741b480eae4d9535a1e5f3 |
| 20 | wlsidten.dll | 155648 bytes | MD5: 26ca88d3fc9175797365a8553eb6948d |
| 21 | DA0B.exe | 61440 bytes | MD5: 15279561b4232d0600f4cede0d7de174 |
| 22 | %LOCALAPPDATA%\lollipop | ||
| 23 | %APPDATA%\system | ||
| 24 | msqjrothu.pif | 35800 bytes | MD5: 414a57fdd1a951035df9c09614ee8623 |
| 25 | opera.dll | 192232 bytes | MD5: 02f0e5b598be8c2ceabb17a965e6e67c |
| 26 | 50E1.exe | 340992 bytes | MD5: 0e337ac9e0242482503a3c31559ed661 |
| 27 | xlqbteeb.exe | 64512 bytes | MD5: 5f2861537c90cd2d3ec9620e67b91de7 |
| 28 | %CommonProgramFiles% | ||
| 29 | install_0_msi.exe | 118272 bytes | MD5: 68f337adbfbdaad81faa7ea3ec22da0b |
| 30 | skype.dat | 65024 bytes | MD5: 13985f6b7ca5c771b28dbf42aef80984 |
| 31 | comeo.exe | 3581440 bytes | MD5: 17b063d029da62b8afc715880c0ae047 |
| 32 | rvcbcyks.exe | 103424 bytes | MD5: e63bdd7e5eb894ca59900f155ad62158 |
| 33 | msdtmsrd.exe | 224256 bytes | MD5: acf3959bb985b616f9b221ae15d252eb |
| 34 | acuvzomo.exe | 61440 bytes | MD5: 64d6b4385310293e6ca81631c1652d59 |
| 35 | ACEIEAddOn.dll | 204800 bytes | MD5: f42778c8d316a0e2f45844f8051242ff |
| 36 | msshell.exe | 18432 bytes | MD5: 0e9e0b2092e1c643f103d93f4a04b82a |
| 37 | wgsdgsdgdsgsd.exe | 144896 bytes | MD5: 3a8e4b69add412fd66d11c7ace416421 |
| 38 | 00qbipeq.exe | 108032 bytes | MD5: b46bec93ed0cbf470b7a4e5421c30655 |
| 39 | csrsss.exe | 83928 bytes | MD5: c41898f24d84a4ada9fe9b71e94ccd64 |
| 40 | svchost.exe | 417792 bytes | MD5: 805c3831ce41e9f7123398409d6b5c40 |
| 41 | secproc_isv.exe | 108544 bytes | MD5: 25595c5104cafc7c667c73d1e2c74447 |
| 42 | 00b5d693.exe | 282112 bytes | MD5: 4dd835b5b72613c8f7fa71aed486b6c7 |
| 43 | %WINDIR%\system32 | ||
| 44 | pmstcdjwz.exe | 97344 bytes | MD5: dc30b025294d0ed58a16141e64942ff7 |
| 45 | yaiiwockc.dll | 483328 bytes | MD5: 9460de1c3485d5f3cc9f5fa1d4a09708 |
| 46 | Americana Dreams.exe | 179712 bytes | MD5: e909c36e06e0c978655389e89e6f1e76 |
| 47 | 3511172082012Build.exe | 297984 bytes | MD5: 835c431d44e546ac46f899466acff0e1 |
| 48 | %TEMP% | ||
| 49 | VSD3DRefDebug.exe | 124416 bytes | MD5: 0cc8134e81ff99e54ea1844888ec8f56 |
| 50 | Task Scheduler.exe | 122368 bytes | MD5: b923b9094635464cb81a245716d2d932 |
| 51 | ssntvs.exe | 103415 bytes | MD5: 863c2d694dc3cf82711420aa089e16e4 |
| 52 | obvwo.exe | 129024 bytes | MD5: e5893ac27c4ee6817f380e3607a3664c |
| 53 | %APPDATA%\Task Scheduler | ||
| 54 | aPr0hY9.exe | 45558 bytes | MD5: 100b8f04f2bff5c49052173dc231eea1 |
| 55 | gcrwcoak.exe | 108544 bytes | MD5: 095507587859038b638fe1c0d6c0c74c |
| 56 | taskhost.exe.exe | 15872 bytes | MD5: 8cdc3a6a50af07cbdc4a1193e45f8721 |
| 57 | yybiwwhj.exe | 86016 bytes | MD5: 3ec42e48033e3543bb0dc85b880363c1 |
| 58 | %LOCALAPPDATA%\Temp | ||
| 59 | 2084473.dll | 92672 bytes | MD5: 4b53eef2de438858d7cc1360feb3c6c2 |
| 60 | %AppData% | ||
| 61 | C87C.exe | 79360 bytes | MD5: efe25f747cdc17ebebc22604c4cdd209 |
| 62 | SyncHostps.exe | 94208 bytes | MD5: 286f4c7e06c1c467e58426b916985567 |
| 63 | Firewallservice.exe | 423424 bytes | MD5: 8f4305c63693259f648f33c59370978c |
| 64 | %WINDIR%\Temp | ||
| 65 | jucheck.dll | 212992 bytes | MD5: afd39fda07129ea22b7963b77c58ff53 |
| 66 | administration.exe | 5242880 bytes | MD5: f3e4e59a27b1ed11ebf0330b02b408f7 |
| 67 | bvhylsviw.exe | 98560 bytes | MD5: 4b1c6c2aabc0314f7558151834b63717 |
| 68 | wpbt0.dll | 225280 bytes | MD5: 3dfd93b751a0f9168739a7e668d14023 |
| 69 | pYunY8m4VL3qLc.exe | 286822 bytes | MD5: 3415bcb9153afa1e0c1400b2f7fa1335 |
| 70 | setex.exe | 38759 bytes | MD5: 01da942199a8e606a09889a23f7d27b5 |
| 71 | questscan.dll | 1019904 bytes | MD5: 0965f3611e919838ad794fcf11db43cf |
| 72 | sqlncli.exe | 75264 bytes | MD5: 1b8b3b51d8b52bed7a7bc0b05bdafbcb |
| 73 | najeoxtt.exe | 105984 bytes | MD5: d0761e37cdef392ee249e24c84f0a66c |
| 74 | %APPDATA%\updates | ||
| 75 | %UserProfile% | ||
| 76 | videotwisterSA.exe | 746496 bytes | MD5: a72b74832ff54293504f3c1b441db398 |
| 77 | %SystemDrive%\???????????? | ||
| 78 | oygqyunapnp.exe | 78336 bytes | MD5: acdd61209ba5a132915c565f669b0d81 |
| 79 | wlsidten.exe | 111616 bytes | MD5: 1f2052c6529cd8a76a20ce858f080e68 |
| 80 | WinSyncMetastore.exe | 83456 bytes | MD5: b7614742cc2adf0264a038267d35a78a |
| 81 | OmaSG21e.exe | 107520 bytes | MD5: 27baf21f123fe80b8e0bf2a3d0a9c91e |
| 82 | idiokbbrv.exe | 98448 bytes | MD5: 3cd07724cf408fc515a711042d4a0524 |
| 83 | DLL321.dll | 191712 bytes | MD5: bd6c2627b0f2e007d371f71edc0762a4 |
| 84 | MWSBAR.DLL | 376901 bytes | MD5: 8d23a39be47954dc43fcbb0114ce2a55 |
| 85 | Nbt.exe | 643072 bytes | MD5: 90f72d0a2cc6956c07c46b47f6a3d40e |
| 86 | ifgxpers.exe | 331648 bytes | MD5: 4765da2ba43a0ce9206d29c4c7aa76b6 |
| 87 | xmlfilter.exe | 115200 bytes | MD5: 0ecf7e220a38e4fd86a5d67e8ce7c88a |
| 88 | MusicCollector.exe | 6901936 bytes | MD5: 42d5f1c904eae88de63cabeaa6a4bf50 |
| 89 | dyjdl.exe | 194560 bytes | MD5: 5b94a572fd15f5416c4a88d02f406189 |
| 90 | %ALLUSERSPROFILE% | ||
| 91 | Updating.exe | 1517520 bytes | MD5: e5d532e96f42229d89993da562fbb5b4 |
| 92 | systemcpl.exe | 100352 bytes | MD5: de7c781205d31f58a04d5acd13ff977d |
| 93 | 锿³•桌é¢ç¬¬ä¸‰æ–¹ä¸»é¢˜ç ´è§£è¡¥ä¸V1.1.exe | 188416 bytes | MD5: 5252ca014813b18c517ff44951628329 |
| 94 | autoosk.dll | 60928 bytes | MD5: a64e4dfb484bebb96f1bbf91c813200a |
| 95 | 96dddda4.dll | 3303936 bytes | MD5: 522cb91f694f6866568b91b7a11f5802 |
| 96 | Q3d38543.exe | 33280 bytes | MD5: 67f05820f38cf6ce319d92b55bae0956 |
| 97 | UpgradeHelper.exe | 289792 bytes | MD5: 70f2dfab3a93558fec4dbc2d4b9d8a31 |
| 98 | msuyqa.cmd | 64512 bytes | MD5: 55b337b9741df50dbdbec29aba6bae91 |
| 99 | zqmkrehUkpoKfsafsaZg.exe | 33012 bytes | MD5: 461caa595d898e273656853c337d81c4 |
| 100 | VaultSysUi.exe | 62464 bytes | MD5: e6922b3d1e2a74fa8620c4e004224a71 |
| 101 | flashplayer.dll | 186456 bytes | MD5: c92c7c8c57363a2996d0ceb731cef6ba |
| 102 | UpdatePriv.exe | 65536 bytes | MD5: a29c0d8665033ec58739bebd1693727e |
| 103 | uenovfiu.exe | 100864 bytes | MD5: 47ebbd7f529d71b8eac53b7ca0f7eeaa |
| 104 | bhoclass.dll | 400896 bytes | MD5: 00f4e6542235cc34958a1778a93d2bfb |
| 105 | msnmsgrr.exe | 1427968 bytes | MD5: 49300637db06b13f0bc0ee3b742e6399 |
| # | Process Name | Process Filename | Main module size |
|---|---|---|---|
| 1 | rool0_pk.exe | rool0_pk.exe | 134144 bytes |
| 2 | m2PythonLoader.exe | m2PythonLoader.exe | 135680 bytes |
| 3 | brenasa.exe | brenasa.exe | 45056 bytes |
| 4 | crack.exe | crack.exe | 306176 bytes |
| 5 | dtkmujvo.exe | dtkmujvo.exe | 87040 bytes |
| 6 | scvhost.exe | scvhost.exe | 231936 bytes |
| 7 | JfCqQ5JC.exe | JfCqQ5JC.exe | 270336 bytes |
| 8 | mplayer2.exe | mplayer2.exe | 403456 bytes |
| 9 | NTServiceManager.exe | NTServiceManager.exe | 666624 bytes |
| 10 | iner.exe | iner.exe | 674816 bytes |
| 11 | msn.exe | msn.exe | 675840 bytes |
| 12 | TimeDateMUICallback.exe | TimeDateMUICallback.exe | 87552 bytes |
| 13 | Piranha.exe | Piranha.exe | 449161 bytes |
| 14 | wahneaqa.exe | wahneaqa.exe | 102912 bytes |
| 15 | DA0B.exe | DA0B.exe | 61440 bytes |
| 16 | 50E1.exe | 50E1.exe | 340992 bytes |
| 17 | xlqbteeb.exe | xlqbteeb.exe | 64512 bytes |
| 18 | install_0_msi.exe | install_0_msi.exe | 118272 bytes |
| 19 | comeo.exe | comeo.exe | 3581440 bytes |
| 20 | rvcbcyks.exe | rvcbcyks.exe | 103424 bytes |
| 21 | msdtmsrd.exe | msdtmsrd.exe | 224256 bytes |
| 22 | acuvzomo.exe | acuvzomo.exe | 61440 bytes |
| 23 | msshell.exe | msshell.exe | 18432 bytes |
| 24 | wgsdgsdgdsgsd.exe | wgsdgsdgdsgsd.exe | 144896 bytes |
| 25 | 00qbipeq.exe | 00qbipeq.exe | 108032 bytes |
| 26 | csrsss.exe | csrsss.exe | 83928 bytes |
| 27 | svchost.exe | svchost.exe | 417792 bytes |
| 28 | secproc_isv.exe | secproc_isv.exe | 108544 bytes |
| 29 | 00b5d693.exe | 00b5d693.exe | 282112 bytes |
| 30 | pmstcdjwz.exe | pmstcdjwz.exe | 97344 bytes |
| 31 | Americana Dreams.exe | Americana Dreams.exe | 179712 bytes |
| 32 | 3511172082012Build.exe | 3511172082012Build.exe | 297984 bytes |
| 33 | VSD3DRefDebug.exe | VSD3DRefDebug.exe | 124416 bytes |
| 34 | Task Scheduler.exe | Task Scheduler.exe | 122368 bytes |
| 35 | ssntvs.exe | ssntvs.exe | 103415 bytes |
| 36 | obvwo.exe | obvwo.exe | 129024 bytes |
| 37 | aPr0hY9.exe | aPr0hY9.exe | 45558 bytes |
| 38 | gcrwcoak.exe | gcrwcoak.exe | 108544 bytes |
| 39 | taskhost.exe.exe | taskhost.exe.exe | 15872 bytes |
| 40 | yybiwwhj.exe | yybiwwhj.exe | 86016 bytes |
| 41 | C87C.exe | C87C.exe | 79360 bytes |
| 42 | SyncHostps.exe | SyncHostps.exe | 94208 bytes |
| 43 | Firewallservice.exe | Firewallservice.exe | 423424 bytes |
| 44 | administration.exe | administration.exe | 5242880 bytes |
| 45 | bvhylsviw.exe | bvhylsviw.exe | 98560 bytes |
| 46 | pYunY8m4VL3qLc.exe | pYunY8m4VL3qLc.exe | 286822 bytes |
| 47 | setex.exe | setex.exe | 38759 bytes |
| 48 | sqlncli.exe | sqlncli.exe | 75264 bytes |
| 49 | najeoxtt.exe | najeoxtt.exe | 105984 bytes |
| 50 | videotwisterSA.exe | videotwisterSA.exe | 746496 bytes |
| 51 | oygqyunapnp.exe | oygqyunapnp.exe | 78336 bytes |
| 52 | wlsidten.exe | wlsidten.exe | 111616 bytes |
| 53 | WinSyncMetastore.exe | WinSyncMetastore.exe | 83456 bytes |
| 54 | OmaSG21e.exe | OmaSG21e.exe | 107520 bytes |
| 55 | idiokbbrv.exe | idiokbbrv.exe | 98448 bytes |
| 56 | Nbt.exe | Nbt.exe | 643072 bytes |
| 57 | ifgxpers.exe | ifgxpers.exe | 331648 bytes |
| 58 | xmlfilter.exe | xmlfilter.exe | 115200 bytes |
| 59 | MusicCollector.exe | MusicCollector.exe | 6901936 bytes |
| 60 | dyjdl.exe | dyjdl.exe | 194560 bytes |
| 61 | Updating.exe | Updating.exe | 1517520 bytes |
| 62 | systemcpl.exe | systemcpl.exe | 100352 bytes |
| 63 | 锿³•桌é¢ç¬¬ä¸‰æ–¹ä¸»é¢˜ç ´è§£è¡¥ä¸V1.1.exe | 锿³•桌é¢ç¬¬ä¸‰æ–¹ä¸»é¢˜ç ´è§£è¡¥ä¸V1.1.exe | 188416 bytes |
| 64 | Q3d38543.exe | Q3d38543.exe | 33280 bytes |
| 65 | UpgradeHelper.exe | UpgradeHelper.exe | 289792 bytes |
| 66 | zqmkrehUkpoKfsafsaZg.exe | zqmkrehUkpoKfsafsaZg.exe | 33012 bytes |
| 67 | VaultSysUi.exe | VaultSysUi.exe | 62464 bytes |
| 68 | UpdatePriv.exe | UpdatePriv.exe | 65536 bytes |
| 69 | uenovfiu.exe | uenovfiu.exe | 100864 bytes |
| 70 | msnmsgrr.exe | msnmsgrr.exe | 1427968 bytes |