This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Not a valid Win32 application

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is not letting me download any programs. I tried downloading an anti virus program a couple times and the "not a valid Win32 application" popped up. I believe my computer is infected with some sort of virus. If any one could help me if would be appreciated! -Bri
Hi Bri,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Then


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please describe how your computer behaves at the moment.
Hi thanks Tomk for your help! I tried to download all the programs you told me to but when I clicked on it to run it said not valid Win32 application.
here is my hijack this log if that helps any. I did this log last week though. I was able to download this program and run it but this was the only one since then.






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:15:55 PM, on 11/26/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Toshiba\TOSHIBA Service Station\TSS.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\Internet Explorer\IEUser.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Users\family\AppData\LocalLow\CyberDefender\cdmyidd.dll (file missing)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Users\family\AppData\LocalLow\CyberDefender\cdmyidd.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Users\family\AppData\LocalLow\CyberDefender\cdmyidd.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\TSS.exe" /hide
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\The Print Shop 23\Remind.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 8733 bytes
Bri,

OK. Let's try a few things.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Please either print out these instructions for reference or copy/paste them in notepad and save to your desktop for access when in safe mode

We must disable certain protection programs that may interfere with our fix:
http://forums.whatthetech.com/How_to_Disab…ams_t89859.html


  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
      R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
      O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
      O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.


Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them (if still present):
C:\PROGRAM FILES\MYWEBSEARCH <–This folder

Don't be concerned if you don't find these folders. It just means that it was already removed in a previous step.

Then please try to run exehelper again. If it still will not work…

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

If MBAM will not work…

We Now Need To Boot Into Safemode

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.

Now try exehelper and mbam again.
exeHelper by Raktor Build 20091122 Run at 23:06:49 on 12/02/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– ok I was able to download the exehelper….what is next.
Bri,

I realize that this is may be a little frustrating but I'm going to have you try running different tools in different ways until we can get through with something. :wacko:


Download this TDSSKiller.zip & extract TDSSKiller.exe onto your Desktop

Then create this batch file to be placed next to TDSSKiller
Open NOTEPAD.exe and copy/paste the text in the quotebox below into it:
@ECHO OFF
START /WAIT TDSSKILLER.exe -l Logit.txt -v
START Logit.txt
del %0
Save this as fix.bat Choose to "Save type as - All Files"
It should look like this:[external image: Posted Image]
Double click on fix.bat & allow it to run (you will probably have to press any key to continue)
Logit.txt should open. Post that information here.
Host Name: FAMILY-PC OS Name: Microsoftr Windows VistaT Home Basic OS Version: 6.0.6001 Service Pack 1 Build 6001 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Workstation OS Build Type: Multiprocessor Free Registered Owner: family Registered Organization: Toshiba Product ID: 89572-OEM-7332166-00152 Original Install Date: 2/6/2009, 5:13:22 AM System Boot Time: 12/3/2009, 12:12:32 AM System Manufacturer: TOSHIBA System Model: Satellite L305D System Type: X86-based PC Processor(s): 1 Processor(s) Installed. [01]: x64 Family 15 Model 124 Stepping 2 AuthenticAMD ~800 Mhz BIOS Version: Insyde Corp. 1.70 , 9/16/2008 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume2 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (GMT-06:00) Central Time (US & Canada) Total Physical Memory: 1,917 MB Available Physical Memory: 1,161 MB Page File: Max Size: 4,075 MB Page File: Available: 3,007 MB Page File: In Use: 1,068 MB Page File Location(s): C:\pagefile.sys Domain: WORKGROUP Logon Server: \\FAMILY-PC Hotfix(s): 104 Hotfix(s) Installed. [01]: {2B939677-2FFD-48F6-9075-7BF48CB87C80} [02]: {2B939677-2FFD-48F6-9075-7BF48CB87C80} [03]: KB905866 [04]: KB935509 [05]: KB937287 [06]: KB938371 [07]: KB938464 [08]: KB941693 [09]: KB947562 [10]: KB947864 [11]: KB948590 [12]: KB948609 [13]: KB948610 [14]: KB948881 [15]: KB950126 [16]: KB950582 [17]: KB950759 [18]: KB950760 [19]: KB950762 [20]: KB950974 [21]: KB951066 [22]: KB951072 [23]: KB951376 [24]: KB951698 [25]: KB951978 [26]: KB952004 [27]: KB952069 [28]: KB952287 [29]: KB952709 [30]: KB952714 [31]: KB953155 [32]: KB953733 [33]: KB953838 [34]: KB953839 [35]: KB954154 [36]: KB954155 [37]: KB954211 [38]: KB954366 [39]: KB954459 [40]: KB955020 [41]: KB955069 [42]: KB955302 [43]: KB955430 [44]: KB955519 [45]: KB955839 [46]: KB956390 [47]: KB956391 [48]: KB956572 [49]: KB956744 [50]: KB956802 [51]: KB956841 [52]: KB957095 [53]: KB957097 [54]: KB957200 [55]: KB957321 [56]: KB957388 [57]: KB958481 [58]: KB958483 [59]: KB958623 [60]: KB958624 [61]: KB958644 [62]: KB958687 [63]: KB958690 [64]: KB958869 [65]: KB959108 [66]: KB959130 [67]: KB959426 [68]: KB959772 [69]: KB960225 [70]: KB960715 [71]: KB960803 [72]: KB961371 [73]: KB961501 [74]: KB963027 [75]: KB967723 [76]: KB968389 [77]: KB968537 [78]: KB968816 [79]: KB969947 [80]: KB970238 [81]: KB970653 [82]: KB970710 [83]: KB971486 [84]: KB971557 [85]: KB971657 [86]: KB971961 [87]: KB972036 [88]: KB972145 [89]: KB972260 [90]: KB973346 [91]: KB973507 [92]: KB973525 [93]: KB973540 [94]: KB973565 [95]: KB973687 [96]: KB974455 [97]: KB974469 [98]: KB974571 [99]: KB975467 [100]: KB975517 [101]: KB976098 [102]: KB976470 [103]: KB976749 [104]: 940157 Network Card(s): 2 NIC(s) Installed. [01]: Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) Connection Name: Local Area Connection Status: Media disconnected [02]: Atheros AR5007EG Wireless Network Adapter Connection Name: Wireless Network Connection DHCP Enabled: Yes DHCP Server: 192.168.2.1 IP address(es) [01]: 192.168.2.3 [02]: fe80::4407:2efd:4883:38a5 0:25:34:826 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 main: Driver KLMD successfully dropped 0:25:48:195 2212 main: Driver KLMD successfully loaded 0:25:48:195 2212 Scanning Registry … 0:25:48:195 2212 ScanServices: Searching service UACd.sys 0:25:48:195 2212 ScanServices: Access denied, trying to reopen with REG_OPTION_BACKUP_RESTORE 0:25:48:195 2212 DeleteEvilService: Access denied, trying to reopen with REG_OPTION_BACKUP_RESTORE 0:25:48:195 2212 DeleteEvilService: UACd.sys: ImagePath = C:\Windows\system32\drivers\uacoxttnmtrfuxsbne.sys 0:25:48:195 2212 File C:\Windows\system32\drivers\uacoxttnmtrfuxsbne.sys will be deleted on next reboot 0:25:48:195 2212 RegNode SYSTEM\CurrentControlSet\Services\UACd.sys will be deleted on next reboot 0:25:48:195 2212 ScanServices: Searching service TDSSserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service gaopdxserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service gxvxcserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service MSIVXserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 Scanning Kernel memory … 0:25:48:195 2212 KLMD_OpenDevice: Trying to open KLMD device 0:25:48:195 2212 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk 0:25:48:195 2212 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 0:25:48:195 2212 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 847B3748 0:25:48:195 2212 DetectCureTDL3: KLMD_GetDeviceObjectList returned 1 DevObjects 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847C5208 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847C5208 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847B68B0 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847B68B0 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847A4BA0 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847A4BA0 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x847A4BA0[0x38] 0:25:48:195 2212 DetectCureTDL3: DRIVER_OBJECT addr: 83997F38 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x83997F38[0xA8] 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x846D8810[0x208] 0:25:48:195 2212 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi 0:25:48:195 2212 DetectCureTDL3: IrpHandler (0) addr: 807390FC 0:25:48:195 2212 DetectCureTDL3: IrpHandler (1) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (2) addr: 807390FC 0:25:48:195 2212 DetectCureTDL3: IrpHandler (3) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (4) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (5) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (6) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (7) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (8) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (9) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (10) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (11) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (12) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (13) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (14) addr: 807279D6 0:25:48:195 2212 DetectCureTDL3: IrpHandler (15) addr: 807279A8 0:25:48:195 2212 DetectCureTDL3: IrpHandler (16) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (17) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (18) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (19) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (20) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (21) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (22) addr: 80727A04 0:25:48:211 2212 DetectCureTDL3: IrpHandler (23) addr: 80734B70 0:25:48:211 2212 DetectCureTDL3: IrpHandler (24) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (25) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (26) addr: 81C2EFE3 0:25:48:211 2212 TDL3_FileDetect: Processing driver file: C:\Windows\system32\Drivers\atapi.sys 0:25:48:211 2212 KLMD_CreateFileW: Trying to open file C:\Windows\system32\Drivers\atapi.sys 0:25:48:242 2212 Completed Results: 0:25:48:242 2212 Infected / Cured drivers in memory: 0 / 0 0:25:48:242 2212 Infected / Cured drivers on disk: 0 / 0 0:25:48:242 2212 Files deleted on next reboot: 1 0:25:48:242 2212 Registry nodes deleted on next reboot: 1 0:25:48:242 2212
Host Name: FAMILY-PC OS Name: Microsoftr Windows VistaT Home Basic OS Version: 6.0.6001 Service Pack 1 Build 6001 OS Manufacturer: Microsoft Corporation OS Configuration: Standalone Workstation OS Build Type: Multiprocessor Free Registered Owner: family Registered Organization: Toshiba Product ID: 89572-OEM-7332166-00152 Original Install Date: 2/6/2009, 5:13:22 AM System Boot Time: 12/3/2009, 12:12:32 AM System Manufacturer: TOSHIBA System Model: Satellite L305D System Type: X86-based PC Processor(s): 1 Processor(s) Installed. [01]: x64 Family 15 Model 124 Stepping 2 AuthenticAMD ~800 Mhz BIOS Version: Insyde Corp. 1.70 , 9/16/2008 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume2 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (GMT-06:00) Central Time (US & Canada) Total Physical Memory: 1,917 MB Available Physical Memory: 1,161 MB Page File: Max Size: 4,075 MB Page File: Available: 3,007 MB Page File: In Use: 1,068 MB Page File Location(s): C:\pagefile.sys Domain: WORKGROUP Logon Server: \\FAMILY-PC Hotfix(s): 104 Hotfix(s) Installed. [01]: {2B939677-2FFD-48F6-9075-7BF48CB87C80} [02]: {2B939677-2FFD-48F6-9075-7BF48CB87C80} [03]: KB905866 [04]: KB935509 [05]: KB937287 [06]: KB938371 [07]: KB938464 [08]: KB941693 [09]: KB947562 [10]: KB947864 [11]: KB948590 [12]: KB948609 [13]: KB948610 [14]: KB948881 [15]: KB950126 [16]: KB950582 [17]: KB950759 [18]: KB950760 [19]: KB950762 [20]: KB950974 [21]: KB951066 [22]: KB951072 [23]: KB951376 [24]: KB951698 [25]: KB951978 [26]: KB952004 [27]: KB952069 [28]: KB952287 [29]: KB952709 [30]: KB952714 [31]: KB953155 [32]: KB953733 [33]: KB953838 [34]: KB953839 [35]: KB954154 [36]: KB954155 [37]: KB954211 [38]: KB954366 [39]: KB954459 [40]: KB955020 [41]: KB955069 [42]: KB955302 [43]: KB955430 [44]: KB955519 [45]: KB955839 [46]: KB956390 [47]: KB956391 [48]: KB956572 [49]: KB956744 [50]: KB956802 [51]: KB956841 [52]: KB957095 [53]: KB957097 [54]: KB957200 [55]: KB957321 [56]: KB957388 [57]: KB958481 [58]: KB958483 [59]: KB958623 [60]: KB958624 [61]: KB958644 [62]: KB958687 [63]: KB958690 [64]: KB958869 [65]: KB959108 [66]: KB959130 [67]: KB959426 [68]: KB959772 [69]: KB960225 [70]: KB960715 [71]: KB960803 [72]: KB961371 [73]: KB961501 [74]: KB963027 [75]: KB967723 [76]: KB968389 [77]: KB968537 [78]: KB968816 [79]: KB969947 [80]: KB970238 [81]: KB970653 [82]: KB970710 [83]: KB971486 [84]: KB971557 [85]: KB971657 [86]: KB971961 [87]: KB972036 [88]: KB972145 [89]: KB972260 [90]: KB973346 [91]: KB973507 [92]: KB973525 [93]: KB973540 [94]: KB973565 [95]: KB973687 [96]: KB974455 [97]: KB974469 [98]: KB974571 [99]: KB975467 [100]: KB975517 [101]: KB976098 [102]: KB976470 [103]: KB976749 [104]: 940157 Network Card(s): 2 NIC(s) Installed. [01]: Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0) Connection Name: Local Area Connection Status: Media disconnected [02]: Atheros AR5007EG Wireless Network Adapter Connection Name: Wireless Network Connection DHCP Enabled: Yes DHCP Server: 192.168.2.1 IP address(es) [01]: 192.168.2.3 [02]: fe80::4407:2efd:4883:38a5 0:25:34:826 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 ForceUnloadDriver: NtUnloadDriver error 2 0:25:34:842 2212 main: Driver KLMD successfully dropped 0:25:48:195 2212 main: Driver KLMD successfully loaded 0:25:48:195 2212 Scanning Registry … 0:25:48:195 2212 ScanServices: Searching service UACd.sys 0:25:48:195 2212 ScanServices: Access denied, trying to reopen with REG_OPTION_BACKUP_RESTORE 0:25:48:195 2212 DeleteEvilService: Access denied, trying to reopen with REG_OPTION_BACKUP_RESTORE 0:25:48:195 2212 DeleteEvilService: UACd.sys: ImagePath = C:\Windows\system32\drivers\uacoxttnmtrfuxsbne.sys 0:25:48:195 2212 File C:\Windows\system32\drivers\uacoxttnmtrfuxsbne.sys will be deleted on next reboot 0:25:48:195 2212 RegNode SYSTEM\CurrentControlSet\Services\UACd.sys will be deleted on next reboot 0:25:48:195 2212 ScanServices: Searching service TDSSserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service gaopdxserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service gxvxcserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 ScanServices: Searching service MSIVXserv.sys 0:25:48:195 2212 ScanServices: Open/Create key error 2 0:25:48:195 2212 Scanning Kernel memory … 0:25:48:195 2212 KLMD_OpenDevice: Trying to open KLMD device 0:25:48:195 2212 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk 0:25:48:195 2212 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 0:25:48:195 2212 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 847B3748 0:25:48:195 2212 DetectCureTDL3: KLMD_GetDeviceObjectList returned 1 DevObjects 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847C5208 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847C5208 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847B68B0 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847B68B0 0:25:48:195 2212 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 847A4BA0 0:25:48:195 2212 KLMD_GetLowerDeviceObject: Trying to get lower device object for 847A4BA0 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x847A4BA0[0x38] 0:25:48:195 2212 DetectCureTDL3: DRIVER_OBJECT addr: 83997F38 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x83997F38[0xA8] 0:25:48:195 2212 KLMD_ReadMem: Trying to ReadMemory 0x846D8810[0x208] 0:25:48:195 2212 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi 0:25:48:195 2212 DetectCureTDL3: IrpHandler (0) addr: 807390FC 0:25:48:195 2212 DetectCureTDL3: IrpHandler (1) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (2) addr: 807390FC 0:25:48:195 2212 DetectCureTDL3: IrpHandler (3) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (4) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (5) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (6) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (7) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (8) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (9) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (10) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (11) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (12) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (13) addr: 81C2EFE3 0:25:48:195 2212 DetectCureTDL3: IrpHandler (14) addr: 807279D6 0:25:48:195 2212 DetectCureTDL3: IrpHandler (15) addr: 807279A8 0:25:48:195 2212 DetectCureTDL3: IrpHandler (16) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (17) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (18) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (19) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (20) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (21) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (22) addr: 80727A04 0:25:48:211 2212 DetectCureTDL3: IrpHandler (23) addr: 80734B70 0:25:48:211 2212 DetectCureTDL3: IrpHandler (24) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (25) addr: 81C2EFE3 0:25:48:211 2212 DetectCureTDL3: IrpHandler (26) addr: 81C2EFE3 0:25:48:211 2212 TDL3_FileDetect: Processing driver file: C:\Windows\system32\Drivers\atapi.sys 0:25:48:211 2212 KLMD_CreateFileW: Trying to open file C:\Windows\system32\Drivers\atapi.sys 0:25:48:242 2212 Completed Results: 0:25:48:242 2212 Infected / Cured drivers in memory: 0 / 0 0:25:48:242 2212 Infected / Cured drivers on disk: 0 / 0 0:25:48:242 2212 Files deleted on next reboot: 1 0:25:48:242 2212 Registry nodes deleted on next reboot: 1 0:25:48:242 2212

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI