MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 04-21-08, 22:22
Youri Youri is offline
Private E-2
 
Join Date: Apr 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Getting message "file"exe is not a valid Win32 application

Hi, Geeks,

Looks like you have an answer to any question....

After carefully checked all messages on board, and do some homework have decided to put down by problem.
Received exe. file made my computer stoped proper functioning: pop-ups, slow speed, lost control over operation. Indeed, the classical example of spyware / malware....

Symptoms are:

1. Running HijackThis, Avenger, Spyware Doctor, Spybot S&D and Avira Antivirus have the same message: "...is not a valid Win32 application"
2. Safe Mode does not work.
3. System Restore does not work.
4. Spyware Terminator, SmitFraudFix, A-Squared Free, Malware Sweeper, CCleaner surprisingly work but with no much of end result.
5. Running MGTools giving the following information (in attachment):

Processes running:

Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Also, I have found insteresting information in "new files" log:

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Locating all files created in C:\WINDOWS\System32\drivers\etc within the last 90 days.

"C:\WINDOWS\system32\drivers\etc\"
hosts Apr 21 2008 716 "hosts"

1 item found: 1 file, 0 directories.
Total of file sizes: 716 bytes 0.70 K
******************************************************************************

Locating all files in C:\WINDOWS\System32\inf This is not a normal Win folder

No matches found.
******************************************************************************

Locating all files created in C:\WINDOWS\Driver Cache\I386 within the last 360 days.

No matches found.
******************************************************************************

Locating C:\WINDOWS\TEMP files created with in the last 90 days.

"C:\WINDOWS\temp\"
mpcmdrun.log Apr 21 2008 1690 "MpCmdRun.log"

1 item found: 1 file, 0 directories.
Total of file sizes: 1,690 bytes 1.65 K
******************************************************************************

Locating C:\Documents and Settings\Owner\Local Settings\TEMP files created within the last 90 days.

"C:\Documents and Settings\Owner\Local Settings\Temp\"
getunkey.txt Mar 8 2008 306882 "GetUnKey.txt"
KAVUPD~1 Apr 21 2008 "KAV Updater update files"
lastscan.txt Apr 21 2008 3596 "LastScan.txt"
msid9d8b.log Apr 21 2008 526 "MSId9d8b.LOG"
perfli~1.dat Apr 21 2008 16384 "Perflib_Perfdata_5f4.dat"
~df1d22.tmp Apr 21 2008 16384 "~DF1D22.tmp"
~df1d2d.tmp Apr 21 2008 512 "~DF1D2D.tmp"

7 items found: 6 files, 1 directory.
Total of file sizes: 344,284 bytes 336.21 K

xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

System is XP Home with SP-2 (above noted...), installed at Best Buy, hence no bootable disk or like.

Now the question to professionals: What to do?

Many thanks,

Youri
Ontario, Canada
Attached Files
File Type: zip MGlogs.zip (46.7 KB, 3 views)

Last edited by chaslang; 04-22-08 at 00:04..
Reply With Quote
Sponsored links
  #2  
Old 04-22-08, 00:18
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,259
Thanks: 61
Thanked 7,623 Times in 4,105 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Welcome to Major Geeks!

Please do not post any logs inline. We do not need you to attach HijackThis logs either.

You need to uninstall Java 2 Runtime Environment, SE v1.4.2_03 as requested in step 1 of the READ ME and then install the current version as requested.

Also per step 1 of the READ ME, run MSconfig and put your system into Normal Startup mode.

I also noticed that you have Iolo System Mechanic Pro installed which includes an antivirus application, but you also have AVG Antivirus installed (which by the way is out of date. The current version is 7.5). As stated in the READ ME, only one antivirus should be installed. However I'm not even sure that either of these are running properly. I suggest that you uninstall both of them right now and then reboot. After reboot download and install/update this: AVG Free Edition

You also have too many antispyware tools installed:
  • Ad-aware 6 Professional - this is way too out of date to be useful
  • Malware Sweeper 2.3.0.1 - did you purchase this?
  • Spyware Doctor - is this a trial that you just installed that does not fix anything?
  • Spyware Terminator
  • Windows Defender
The information that you highlighted from newfiles.txt is nothing important.

You need to attach the other logs that were requested in the READ ME from
  • SuperAntiSpyware
  • Malwarebytes Anti-Malware
  • ComboFix.
Based on your newfiles.txt log, you never even installed them. You need to complete all steps in the READ ME in the order written and then attach all of the logs. MGtools must be run after the other tools so you will have to attach a new MGlogs.zip file after the other tools have been run.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #3  
Old 04-22-08, 12:01
Youri Youri is offline
Private E-2
 
Join Date: Apr 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Chaslang,

1. Java 2 Runtime is removed by "Add and Remove program" option.
2. Where to get "READ ME" file to follow?
3. As instructed, System Mechanic is uninstalled.
4. System does not allow to run ComboFix (after re-naming it to cf.exe) giving the same message: "is not a valid Win32 application"
Reply With Quote
  #4  
Old 04-22-08, 22:14
Youri Youri is offline
Private E-2
 
Join Date: Apr 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Chaslang,

Appreciate your help.

Ad-aware 6 Professional - removed.
Iolo System Mechanic Pro - removed.
Spyware Doctor - removed.
AVG 7.5 removed.
Java removed.
Malware Sweeper 2.3.0.1 - did you purchase this? - It's a Free Version.


As instructed, run as follows:

SuperAntiSpyware-O.K. - removed some viruses.
Malwarebytes Anti-Malware - O.K. - removed some viruses.
ComboFix. - system not allowed to run.
-----------------------------------------------
After this AVG Free Edition installed.
------------------------------------------------
Then, I run AVG Free Edition and removed a lot of viruses.
This allowed to start and run HjackThis. File is in attachment.
ComboFix still can not be opened and shows: "is not a valid Win32 application".
Then, Malwarebytes Anti-Malware and SuperAntiSpyware did not find any viruses or like.
I run the "MGlogs" and file is in attachment.

Please instruct for the next step.

Thank you again,

Youri
Attached Files
File Type: log hijackthis.log (5.9 KB, 1 views)
File Type: zip MGlogs.zip (48.8 KB, 0 views)
Reply With Quote
  #5  
Old 04-23-08, 01:39
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,259
Thanks: 61
Thanked 7,623 Times in 4,105 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Quote:
Originally Posted by Youri View Post
2. Where to get "READ ME" file to follow?
You are supposed to be follow the instructions in the sticky thread given below and seen on all pages in the forum:

READ & RUN ME FIRST. Malware Removal Guide


You still need to start at the beginning of the above and complete all instructions in the order gievn and this also still means anothe MGlogs.zip file since you have again attached it before running the other steps in the READ & RUN ME FIRST.

I repeat again, we do not need you to run HijackThis and attach logs from it. We need you to run the above!

Does the free version of Malware Sweeper, fix anything? If not, uninstall it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Sponsored links
  #6  
Old 04-23-08, 12:11
Youri Youri is offline
Private E-2
 
Join Date: Apr 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Wow, Chaslang,

Looks like all nice and clean. No pop-ups, no messages. Nothing wrong...
I just followed what was in "Read & Run Me First" Guide.

Attaching is MGlogs file for your consideration. Is it O.K.?

Thanks,

Youri
Attached Files
File Type: zip MGlogs.zip (47.3 KB, 6 views)
Reply With Quote
  #7  
Old 04-23-08, 22:00
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,259
Thanks: 61
Thanked 7,623 Times in 4,105 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Sorry but you definitely are still not clean; but I cannot finish helping you since you still have not followed instructions. You need to run ALL steps in the READ & RUN ME. You must run all of the scanners and attach ALL of the logs. MGtools is the very last thing to run but it is the only log you have been attaching which is not what we have been requesting. Please run ALL steps in the READ ME from beginning to the end and then attach the below logs as requested in the READ ME:
  • SUPERAntispyware
  • Malwarebytes Anti-Malware
  • C:\ComboFix.txt
  • C:\MGlogs.zip - this needs to be a new log after the above have been run.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
  #8  
Old 04-24-08, 14:55
Youri Youri is offline
Private E-2
 
Join Date: Apr 2008
Posts: 5
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Sorry for being not accurate, will do my best.
Thank you.
Reply With Quote
  #9  
Old 04-25-08, 22:57
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,259
Thanks: 61
Thanked 7,623 Times in 4,105 Posts
Default Re: Getting message "file"exe is not a valid Win32 application

Once you attach all of the logs we will be able to help you.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
"windows.exe is not a valid win32 application." Help! toocool_sashi Software 0 02-24-08 09:03
get either "file corrupted" or "i/o error message" sable51 Software 1 01-07-07 01:37
keep getting "not a valid win32 application" error adamxsquared Software 1 12-24-06 01:16
getting "not a valid win32 application " message massiveheart Software 1 03-07-05 13:03
CD-ROM ""F:/ Is not a valid Win32 application" Message Matt8789 Software 9 01-13-05 16:50


All times are GMT -5. The time now is 04:12.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger