av.exe AND win32.exe terrible issues, please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by FreeStyle_Wave, Mar 7, 2010.

  1. FreeStyle_Wave

    FreeStyle_Wave Private E-2

    First off, welcome Major Geeks. I made an account in the hopes that I could get some help from my irritating problem.
    I am running Windows Vista.
    Just today I was getting annoying pop-ups from an obviously fake Windows Security Center, telling me a bunch of garbage, doing fake scans, and whatnot. After closing the program through task manager it came back, so I found the file location, and noticed that it was hidden. To remove the irritating program I made a .bmp file, renamed it to av.exe, and put it in the folder. When I put it in it asked me if I wanted to replace it, and I said OK. Then, no more problems, no av.exe on my task manager, and it didn't come back. Then the second I tried to open up an application it told me, "(app) is not a valid win32.exe application", or something like that. So I searched for a resolution to this problem on the internet. I went through your 'read first' and installed many programs and whatnot only to be sad upon realizing that none of them could be opened. Some 30 minutes later I had a hunch to delete the new 'av.exe' in my Appdata/local folder, and when I did that I had some new freedom. When I want to run Notepad.exe, for example, instead of saying it is not a valid win32.exe app, it gives me the 'Choose the program you want to use to open this file' box. So i Browse for Notepad, wherever it is, and run Notepad.exe with Notepad.exe, and it comes up. So I was relieved but not finished. I tried to open a program that I downloaded, called FindyKill, for example, but when I browse for it in my download file that is pointless. Because it just asks the same question again and again. Seems I can't download anything....
    I'm guessing its a combination of two viruses, but I am unsure.
    Help would be greatly appreciated. Thanks in advance.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell us if you have tried running the scans from the Read and Run First instructions? What happened when you tried to run:
    SAS
    MBAM
    RootRepeal
    ComboFix
    C:\MGTools.exe

    Can you change the extension to .com and make them run?

    Have you tried safe mode to run them?

    Please be specific as to what errors or problems you are currently having.

    Does this work:
    http://www.dougknox.com/xp/file_assoc.htm ---> item #9.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds