** is not a valid win32 application

Discussion in 'Malware Help (A Specialist Will Reply)' started by killurass, Oct 16, 2009.

  1. killurass

    killurass Private E-2

    Hey, i have a very annoying problem and i hope you could help me!

    Since yesterday, everything i download and try to open is "not a valid win32 application", while all archives i try to open are "either in unknown format or damaged"(archives that i download), and every torrent i download is not a valid torrent file!

    i can open everything except the files i downloaded yesterday and today.

    i read about a bagle, or beagle or something like that. i was thinking it might be it, or just another stupid bug

    i'm using 32 bit vista home premium 6 build 6001

    the files i tried to open are definitely not corrupted! i tried to download vuze, a new version of msn, about 20 different torrents and so on. nothing works.

    also another thing i noticed, is that sometimes firefox stops at 3 kb/s or 2 kb/s and just freezes the download. i wonder if it's related?


    thanks!
     
  2. killurass

    killurass Private E-2

    Uhm...someone?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. killurass

    killurass Private E-2

    umm well i was kind of in a hurry, so i read the stickies only a few days later.

    and i did read the special removal procedures sticky, but the link to the software that is suppose to remove bagle is broken, not to mention i can't open anything i downloaded anyways.

    but thanks for replying.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the secondary link I just added to the procedure. Download it on another PC if necessary and copy to this PC. This program has typical run even when others will not. Try it in safe mode if necessary. Shutdown ALL other programs before running. And also make sure you have disabled UAC and rebooted after disabling it before you try to run the fix.

    Also try the below just in case your problem is not really Bagle. Are you getting Google Redirections?


    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then doube click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the c:\avplog.txt file that is will hopefully create as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)


    Now download and Run exeHelper
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


    Also please try running the below online scan:

    http://www.superantispyware.com/onlinescan.html

    Reboot immediately after scanning if it finds and removes anything. Let me know if anything was found. See if you can save a log with it.


    Then try running these instructions: Using MGtools

    Attach the below logs when finished with all of the above:
    • C:\avplog.txt - from AVPfind
    • a log from online SAS scan if you could make one
    • log.txt - from exeHelper
    • C:\MGlogs.zip - from MGtools
    The C:\ assumes that drive C is you Windows boot drive. If you boot from another drive, then use the correct drive letter above.
     
    Last edited: Oct 22, 2009
  6. killurass

    killurass Private E-2

    Thanks for the reply!
    i downloaded on a different computer, and copied to mine. I added all of the logs.
    i also have ad-aware, although it could not find anything.

    and what do you mean by a Google Redirection?
     

    Attached Files:

    Last edited by a moderator: Oct 24, 2009
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would know if you had one. ;) It means when you do a search on Google and then click on one of the given links, you don't go where the link should take you.

    You did not have a Bagle infection and you do not have a Windows Police Pro type infection. The only real problems your logs show are that you are downloading, installing, and running illegal/cracked software and are even doing this for your protection software which is extremely contrary to the purposes of having protection. In addition we do not provide help on systems using illegal software. Please read the below sticky:

    Warning about Porn, Keygens, Cracks, and other Illegal Software

    You need to begin by uninstalling the below and any other illegal software an go legit:
    Code:
    ################## | Cracks / Keygens / Serials |
    "C:\Users\Liam\Downloads\Crack_ESET_byMike_.exe"  
    21/08/2009 11:46 |Size 9455320 |Crc32 d6f4630b |Md5 71255fc232210aeb5e12dd220b64c0a4  
     
    "C:\Users\Liam\Software\Spyware Doctor v6.1.0.447 [2009] + Serial [h33t] - CaZoR\sdsetup.exe"  
    28/07/2009 14:05 |Size 26146032 |Crc32 5ff4eeca |Md5 fff6899b42d9427bb91f3ab90517110e  
     
    ################## | ! End of report # FindyKill V6.002 ! |
    Once you have removed all of the illegal software, then put your PC into Normal Startup mode with MSconfig. Then get a new log from MGtools and attach it. We will not continue until then.
     
  8. killurass

    killurass Private E-2

    I've removed my illegal protection software.

    The new MGtools log is attached.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    Java(TM) 6 Update 15
    Java(TM) SE Runtime Environment 6 Update 1
    NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKCU\..\Policies\Explorer\Run: [] 0
    O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe
    O23 - Service: WinCam - Unknown owner - C:\Windows\TEMP\jemtvrtkst.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\Temp
    C:\Users\Liam\AppData\Local\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds