something blocking AV programs - can't reinstall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rickir, Apr 14, 2008.

  1. rickir

    rickir Private E-2

    Hi,

    Two days ago I noticed that my WinPatrol "exe" file seemed to be renamed. At the same time, my anti-virus program and firewall did not appear in the taskbar. I could not manually start them - I got a "not valid win32 app" message - nor could I reinstall them.

    I went through the steps before posting as directed. SuperAntiSpyware installed, but my computer reboots when I try to run it. Spybot can't be installed and ComboFix gets the same "not valid win32 app" as noted above.

    I can install and run Malwarebytes, which identified some viruses and trojans, particularly "wintems" and "hldrrr." Those two keep popping up.

    I hope the information is sufficient and clear. Anything you can do would be appreciated!

    RR
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please attach the logs from MalwareBytes and the MGTools log (C:\MGLogs.zip) when you have done them.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. SUPERAntiSpy

    SUPERAntiSpy Private E-2

    If SUPERAntiSpyware is rebooting, that means there is a faulty kernel driver (probably the infection) - we have addressed this in our upcoming 4.1 version - for now, assuming you are running the 4.0.1154 version - uncheck the Kernel Direct options under the Scanning Control Preferences of SUPERAntiSpyware and then peform your scan again and it won't reboot and should detect and remove the problem.

    If not, we (with MajorGeeks permission) can run a diagnostic on your system that will see everything and we can update the SUPERAntiSpyware definitions to remove the problem.

    Nick Skrepetos
    SUPERAntiSpyware.com
     
  4. rickir

    rickir Private E-2

    Here are the log files as requested...

    Thanks,
    RR
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have some items in your browser trusted zone that should not be there....let's do this:

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now what are these:
    C:\Documents and Settings\rickir\Desktop\322756.exe
    C:\Documents and Settings\rickir\Desktop\Dog Site

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 5"
    Java 2 Runtime Environment, SE v1.4.2_05"
    Java(TM) SE Runtime Environment 6 Update 1

    Now reboot and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Tell me how things are running.
     
  6. rickir

    rickir Private E-2

    I am unable to run analyse.exe It starts, and I can click "system scan only," but at that point it seems to freeze up and then suddenly disappears.

    I was able to delete the various Java programs as you instructed. I have not installed Java Runtime 6 yet.

    As to the files you asked about, I deleted 322756.exe, but the other - Dog Site - is a website I am working on.

    Thanks,
    RR
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do the reg. patch? Can you do the analyse.exe in safe mode?
     
  8. rickir

    rickir Private E-2

    By reg patch, I assume you mean "DisableUAC.reg" in the MGtools folder. I did double click this and got a message that it was added to the registry. I do not get the "Windows needs your permission to continue" message.

    I am unable to boot into Safe mode. Once I choose Safe Mode, it begins to run various files and then kicks me back to the options screen.

    Sorry this is so difficult.
    RR
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No...I meant the fixME.reg that I posted to you ....please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  10. rickir

    rickir Private E-2

    For some reason, I am now able to run analyze.exe as previously suggested. I did so, and then ran the "fixme.reg" file. Following that I ran MBtools and have now attached the latest log file.

    Thanks,
    RR
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you getting prompts from Deep Freeze when you do these fixes?

    You need to remove these from your browser trusted zones:
    O15 - Trusted Zone: *.doginhispen.com
    O15 - Trusted Zone: *.whataboutadog.com

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Tell me what problems you are having and re-scan with MWBytes and attach the log.
     
  12. rickir

    rickir Private E-2

    No, I am not getting any messages from Deep Freeze.

    I ran analyze.exe, but none of the items were listed except
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Start%20Page/MyPage.html G (without the G)

    I ran MalwareBytes, rebooted as suggested and this is the logfile. WinPatrol pointed out two programs/drivers that were trying to run: wintemps and hldrrr. I've seen this before and even though I click "no" they obviously load anyway.

    Thanks,
    RR
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...that scan with MalwareBytes indicates it deleted them ...so attach a new MGLogs.zip and lets be sure.
     
  14. rickir

    rickir Private E-2

    Here you go....still picking up on 2 of the 4 that are constantly showing up.

    RR
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you not have it fix them?
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also attach a new MWB's log after doing the above.

    What are the "other two" files ---> the exact path.
     
  16. rickir

    rickir Private E-2

    My apologies. I think I saved a logfile before rebooting as suggested by Malwarebytes. I ran Malwarebytes again and have attached the logfile. Once again, I rebooted and Winpatrol picked up this file: C:\WINDOWS\system32\drivers\hldrrr.exe, which Malwarebyte was trying to delete by rebooting. This happens time and again. This was the only file that was caught by Winpatrol.

    We have not yet discussed Avenger.exe. I searched for it on your website and found a link, but I get the same error message as when trying to install other programs, like AVG: "not a valid win32 file." Basically, it locks up and I have to use the task manager to close it.

    Thanks for your patience.
    RR
     

    Attached Files:

  17. rickir

    rickir Private E-2

    BTW, Winpatrol also notifies me that some unnamed program is trying to edit my win.ini file. I keep saying no to this, but is there any possibility that this is Malwarebytes trying to edit the file?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know...thought I doubt it. But I am also thinking that deep freeze is booting you back to where you started after each attempt to remove those files. Can you use windows explorer to find and manually delete them? What happens?
     
  19. rickir

    rickir Private E-2

    Sorry for the delay - I've been out of town.

    I've not been able to find the files, even though my folders are set to show hidden files. I did discover a subfolder of /windows/system32 called something like "dwnld" that was full of "EXE" files. I don't see them right now, but I suspect it will be back once I reboot.

    RR
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please tell me what is in that folder if it returns ....can you do a screen capture?
     
  21. rickir

    rickir Private E-2

    I can and will. It goes without saying that it doesn't show up right now; in fact, even though I have the folders view set to display hidden files, my system32 folder doesn't show at all. I have to type in the address, but even then that "download" folder isn't showing up.

    RR
     
  22. rickir

    rickir Private E-2

    I ran a program called "catchme" and here is the log. Note the list of files in the c:\windows\system32\drivers\downld folder.



    RR
     

    Attached Files:

    Last edited by a moderator: Apr 21, 2008
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Using cracks and keygens will do that to you....

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
     
  24. rickir

    rickir Private E-2

    Message received.

    Unfortunately, I cannot run Avenger. I get the same message as when I try to run AV programs: "not a valid win32 application."

    Any other ideas?

    TIA,
    RR
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open Notepad and copy/paste the text in the below quote box into it:
    * Save the above as ComboFix-Do.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * Now use your mouse to drag ComboFix-Do.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  26. rickir

    rickir Private E-2

    I get the same error message as with Avenger - "not a valid win32 applcation."

    RR
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  28. rickir

    rickir Private E-2

    Yes, I meant ComboFix. I have deleted all of the files and folders using Unlocker......

    RR
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things now?

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  30. rickir

    rickir Private E-2

    It's running pretty much the same as it has in the last few days. Still can't install AV programs, etc...

    Here is the log...

    Thanks
    RR
     

    Attached Files:

  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You at one time had AVG7 and Avast installed.....in fact one of your startup keys is for AVG7

    What are these on your desktop:
    C:\Documents and Settings\rickir\Desktop\ave1060full.exe
    C:\Documents and Settings\rickir\Desktop\TEXAS_D
    C:\Documents and Settings\rickir\Desktop\texas_d.zip?

    Use windows explorer to find and delete:
    C:\WINDOWS\unins000.dat
    C:\WINDOWS\unins000.exe
    C:\WINDOWS\unins001.dat
    C:\WINDOWS\unins001.exe
    C:\WINDOWS\system32\1.exe

    Lets remove those items in the registry:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
    Last edited: Apr 26, 2008
  32. rickir

    rickir Private E-2

    Yes, I still have AVG installed on my machine but it doesn't work - meaning it doesn't show up in the toolbar and if I right click a file to "scan with avg," literally nothing happens. I cannot start the program by double clicking the EXE file and I cannot reinstall (not a valid win32 file message).

    One of the files/folders on my desktop was an Avenger program, but it was the wrong program and I never installed it. The other two are a Texas Hold'em game that I got off your website. I deleted it last night as it's too easy to win.

    I could not find the various C:\uninstall files. I ran "Cleanup!" yesterday before receiving your message, so perhaps they have been deleted already? I used Windows Search and I searched for them using the Command Prompt, but still found nothing.

    I was able to get the new fixME.reg file to be added to the registry.

    I was not able to run bitdefender. When I click on "start scan," it stops and says it cannot update the virus definitions, but gives me the option to scan anyway. When I do so, it immediately stops and says only that it cannot scan my computer. I downloaded the free home version, but it stopped during installation and said I should verify whether or not I have sufficient privleges to install the program. I cannot get any further than that and had to cancel the installation.

    Sorry this is so troublesome. I hope you can continue to help.

    RR
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok...we missed a few ....my bad :eek:
    Use the Unlocker to remove them.

    It also looks like you once had ClamWin Anti-virus....can you run it or put it on a thumb drive and run it from there?
     
  34. rickir

    rickir Private E-2

    Well, it goes without saying that none of the files showed up using Explorer. I used the command prompt again and even though they didn't show up, I still went through the old Dos delete commands just in case. I also checked attributes of the files, but none of the files showed up.

    I tried using ClamAV a week ago as I already had it on my thumb drive, but it wouldn't run. I may try it again by downloading ClamAV from a different computer on a different thumb drive.

    In the meantime, I appreciate any further suggestions.

    RR
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file. I want to be sure they are gone and that I didn't miss anything else. :(
     
  36. rickir

    rickir Private E-2

    Here is the latest logfile. I could not load ClamAV on a thumb drive and run it - same message as with others "not a valid win32 file."
     

    Attached Files:

  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have no idea as to what is happening with your system...your logs are full of inconsistancy...The CatchMe log indicated the three files I wanted you to remove....

    Yet your logs state this:
    You also started that you looked for and could not find certain files to delete...yet they are clearly in your most recent logs:
    You have searchindexer.exe in your sys32 files..which relates to The Ultimate Troubleshooter ....something you once used?

    I see AVG Rootkit revealer and GMER installed ...do they not run also?

    I would advise you to copy your important files and data to a cd and consider a reformat.
     
  38. rickir

    rickir Private E-2

    First of all, I finally found those three "unins*" files and deleted them. The rest, however, I haven't been able to locate. As to AVG Rootkit revealer and GMER - no, they do not run.

    So, we're up to the word I dreaded - reformatting. Are there any other choices, like trying to reload Windows or do a repair?

    Again, thanks for your help and if a reformat is the only option, I'll go ahead with that.

    RR
     
  39. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would try a repair install first ...and see if that allows you to run some of the scans for us....it won't remove any of your files or programs (or malware), but it may give you a chance to run some cleaning programs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds