Program.exe is not a valid Win32 application

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Psychedea, Jul 31, 2009.

  1. Psychedea

    Psychedea Private E-2

    My family computer is a desktop PC running Windows Vista with McAfee. I make sure to run all updates ASAP. My updates are current through yesterday. When I tried to update my computer this morning, the updates failed with an unknown error. "Error(s) found: code 80070103 Windows Update encountered an unknown error"

    This morning, I turned on the computer to find that McAfee has been disabled, Windows Defender has been disabled, and that I cannot turn them back on. Additionally, I cannot run any programs. Invariably, I get the response "program.exe is not a valid Win32 application" regardless of whether I run the program from the C drive or a USB.

    Neither Internet Explorer nor Firefox are working; I can only access the internet by opening windows explorer and typing an address into the address bar in that window.

    I have tried running McAfee in safe mode, but get the same message. I tried the "repair computer" function when I boot the computer, but it insists that I have another drive attached (though I have unplugged the camera, flash drvie, external hard drive)... There is nothing attached (except for the keyboard and mouse). I have tried restoring my computer to a previous restore point only to be told by the computer that there are no restore points.

    I started Googling and thought that it may be the Bagle virus because of the "is not a valid Win32 application" but found none of the files listed on the Removing Bagle Infections page.

    I looked at the thread titled “x:\ is not a valid Win32 application” which led me to a dead link: http://support.microsoft.com/Default.aspx?kbid=303395&sd=RMVP .

    I have read and followed the instructions on the READ AND RUN ME FIRST and Vista Cleaning Procedure threads, but to no avail. I could not download the files on the infected computer, and so I used my personal laptop to download the scans to a flash drive. I plugged the flash drive into the infected computer and tried to run each scan as instructed by the threads. I have no logs to attach as the scans could not run. I took the following notes:

    • Could not open McAfee to empty quarantine folder. “c:\Windows\system32\rundlll32.exe is not a valid Win32 application”
    • Could not run CCleaner. “F:\C Cleaner.exe is not a valid Win32 application”
    • Could not be sure Msconfig was set for normal startup. “C:\Windows\system32\msconfig.exe is not a valid Win32 application”
    • Could not follow Step 4; link to “Uninstall Malware via Add/Remove Programs” did not work
    • Could not download Root Repeal because “The bandwidth or page view limit for this site has been exceeded and the page Could not be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.”
    • Could not install/ run SUPERAntiSpyware. “F:\SUPERAntiSpyware.exe is not a valid Win32 application”
    • Could not install Malware Bytes. “F:\mb.exe is not a valid Win32 application”
    • Could not run/ install ComboFix. “C:\Users\Onixill\Desktop\ComboFix.exe is not a valid Win32 application” and “F:\ComboFix.exe is not a valid Win32 application”
    • Could not run/ install MGtools. “C:\MGtools.exe is not a valid Win32 application”

    To get a better idea of what I’m dealing with, I ran Kaspersky’s online scanner. It found the following threats:

    (My apologies for not attaching a log; the report was made on the infected computer and my [limited] experience workign with computers has taught me not to pull something off of an infected computer to put onto a clean one)
    • File- C:\Program Files\2wire\sst\VNC\MotVNC.exe
      Name- “not-a-virus:RemoteAdmin.Win32.WinVNC-based.b”
      There are 2 reported objects infected by this virus.
    • File: C:\Program Files\Windows Antivirus Pro\Windows Antivirus Pro.exe
      Name: “not-a-virus:Fraud Tool.Win32.AntiVirusPro.nf”
      There is 1 object reported infected by this one.
    • File: C:\ProgramData\19195324\19195324.exe
      Name: “Packed.Win32.Krap.r”
      There is 1 object reported as infected by it.
    • File: C:\Users\All Users\19195324\19195324.exe
      Name: “Packed.Win32.Krap.r”
      There is 1 object reported as infected by it.
    • File: C:\Users\Onixill\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1ITK5PR2\Setup[1].exe
      Name: Trojan-Downloader.Win32.FraudLoad.wmxc
      There is 1 object reported as infected by it.


    I hope that I have been thorough enough. Any help would be greatly appreciated! Thank you. :)
     
    Last edited: Jul 31, 2009
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Psychedea

    Step 1:
    Let's see if one of these online scanners can remove enough for you to then run our tools.

    Using BitDefender Online Scan

    TrendMicro HouseCall

    Step 2:
    Make sure that you transfer the tools to the instructed directories given in the R & R Me FIRST
    • Both SAS & MBAM should be saved to C:\Downloads.. then installed to C:\Program Files
    • Once installed, open each application and update their definitions databases before running a "Quick scan".

    Step 3:
    Then re-name MGTools.exe to MGTools.com and see if it will run.

    Step 4:
    Attach these logs to your reply -
    • bdscan.txt
    • TM Housecall results
    • MGLogs.zip
    • SASlog.txt
    • mbamlog.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Aug 3, 2009
  3. Psychedea

    Psychedea Private E-2

    Sun Java was not already installed on the computer and so I did not need to remove the program. I could not download Sun Java; I received an error message: “C:\Users\Onixill\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1M7YKNST\jre-6u15-windows-i586(1).exe is not a valid Win32 application”

    I proceeded (as instructed by R&R ME FIRST)

    When I tried to run BitDefender, the computer told me that “Internet Explorer is not running with administrative privileges so BitDefender Online Scanner will not work properly. Please run IE as administrator”. I clicked on the “more info” and told the computer to “allow” the scan to run. I’m not sure if this allowed it administrative privileges or not..

    I clicked “start scan” and a screen flashed quickly with two red bars that read “fail” above them; I could not make out the rest of the text even after repeating to see it. Next a screen popped up. It said “Update Failed. Continue?” in the title bar. The text: “BitDefendere failed to update the virus definitions. Although it might be possible to check for viruses, the result will probably not be 100% accurate.

    Do you want to start scanning?” I selected “Yes” The next window: “Scan Failed!” Could not check the computer for viruses.” The last window said that my computer has no viruses, but likely because it did not scan…


    Moved on to Housecall. When I clicked to agree to the Terms of Use and launched Housecall, it told me that [an error occurred when transferring information from the internet] something to that effect; I missed the exact text. I selected “scan complete computer” but the program seemed to jump directly to past step 2 (“scanning local and computer and connected components”) to step 3 (“listing and removing detected infections and vulnerabilities”). It reported that “Housecall did not find any potential threats to your computer.”

    On the off chance that something was fixed, I tried again to download Sun Java. Same result as posted above. So far as I can tell, there has been no change.. :(
     
  4. Psychedea

    Psychedea Private E-2

    I found that an unused User account existed on the computer and was able to run the scans. Attached are the logs; below I will edit in the problems which I encountered. They must be edited in because the logs are on the infected computer while the notes were taken on a computer which was not scanning.

    Problems encountered while scanning:

    Running Combofix. As soon as it starts: “Parasites found!! The following files were trying to attach to Combofix. They shall be disabled.

    C:\Program Filed\iZ3D Driver\Win32\S3DInjector.dll
    C:\Program Filed\iZ3D Driver\Win32\S3DInjector.dll”
    (same file twice?)

    While I was disabling McAfee (before running Combofix) Combofix detected “Rootkit!! Combofix has detected rootkit activity and needs to reboot the machine.

    C:\Program Files\iZ3d Driver\Win32\S3DInjector.dll”

    After reboot, “NirCmd.cfexe- Bad Image

    C:\Program Files\iZ3d Driver\Win32\S3DInjector.dll is either not designed to run on Windows or it contains an error. Try installing the program again using the original installation media or contact your system administrator or the software vendor for support.

    Exact same message pops up over and over after I click “ok” with the following titles in place of “NirCmd.cfexe”:
    Attrib.exe, grep.cfexe (cam up multiple times), Attrib.cfexe, grep.cfexe, SWREG.cfexe, chcp.com, hidec.exe, PING.exe, PV.cfexe, sed.cfxex, pev.cfexe, CF15904.exe, gsar.exe, regt.cfexe, eRUNT.exe, sort.exe, dumphive.cfexe, setpath.cfexe, FINDSTR.cfexe, moveex.cfexe,

    Combofix in the background says it is preparing to run; kept clicking “ok” in the hopes that it would continue. Blue screen disappeared; black screen. Kept clicking “ok”, got to disclaimer. Clicked “ok”, Bad Image screens persist through attempting to create a system restore point and scan.

    Kept clicking “ok”; scan seemed to pause when I was not clicking. Particularly hard to get through stages 1,2,3, 36A, 42

    Combofix rebooted; error messages started popping up on startup.
    Combofix reported: “The system cannot find the file whitedir01” Errors continued through log creation and when the log opened up. Saved log; closed it. Errors ceased.

    Moved on to RootRepeal; Bad Image result pops up once when I open RootRepeal Zip and program; The same message appears with “rootrepeal.exe-Bad Image” as the title. I select the file tab and click scan, but the program stops responding. I left it for 30 minutes, but no response.

    Moved on to MGTools. Same message with “MGTools.exe” in the title, then again with “cmd.exe”. Error pop-ups persist through installerand scan, but scan completed and yielded a log.

    The message persists when I try to use other programs on the computer (enable User Control, open Internet Explorer, sign on after rebooting)

    Attempts to run TrendMicro HouseCall and BitDefender Online Scan yielded the same results as before.

    Thanks so much for your help!
     

    Attached Files:

    Last edited: Aug 5, 2009
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Psychedea

    I'm sorry for the delay in getting back to you.

    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up this account's Desktop [ iC:\Users\Joey\Desktop ] immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

    *Comment: Giving all users of this pc "Adminstrator Accounts" is bound to lead to problems.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run this tool > re-boot > run it a second time.
    Norton Removal Tool (SymNRT) 2009.0.5.26

    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 5:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp

    Step 6:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 7:
    Now install the latest Sun Java Runtime Environment

    Step 8:
    There is a new version of SUPERAntiSpyware released.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.

    Step 9:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • updated SASlog.txt
    • C:\MGlogs.zip
    • C:\combofix.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds