This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infection that turns installation .exe into invalid win32 application

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I would like to inform you that additional to ESET Online Scanning, I have used the Microsoft Malware Remover. A.K.A: MRT.exe. Which has been already in my computer. However it still has a very outdated malware database :pullhair: I wonder why Microsoft doesn't show some interest in this basic tool.. Results of MRT was zero: No suspicious file found.. This is a very good day, NoodleTech. Waking up at 10 AM and returning from the swimming pool at 5 PM, heh, sounds an excellent program especially in the sacred Muslim month: Ramadan.. Fasting is healthy! Report to be forwarded soon..
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=edd90f904d290048b734ce7e06349ab4 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-30 11:09:16 # local_time=2012-07-31 12:09:16 (+0100, Afr. centrale Ouest) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 16775129 100 98 12293 279960462 86594913 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 2800178 2800178 0 0 # scanned=229657 # found=13 # cleaned=0 # scan_time=10488 C:\Documents and Settings\too\Mes documents\Downloads\Non confirmé 54899.crdownload a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\too\Mes documents\Downloads\Non confirmé 9173.crdownload Win32/Adware.1ClickDownload.C application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\MDickie DB Toolbar Toolbar\UninstallToolbar.exe Win32/Somoto application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Symantec\LiveUpdate\LUALL.EXE probably a variant of Win32/Patched.NAE trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\too\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\UninstallToolbar.exe.vir Win32/Somoto application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP926\A1172738.lnk Win32/Dorkbot.D worm (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP926\A1172739.lnk Win32/Dorkbot.D worm (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP926\A1172740.lnk Win32/Dorkbot.D worm (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP926\A1172741.lnk Win32/Dorkbot.D worm (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP926\A1172742.lnk Win32/Dorkbot.D worm (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP936\A1190843.exe a variant of Win32/Remtasu.Y trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{2CA1AAC8-474C-47BD-B65C-7CA5D410B6D4}\RP964\A1254097.exe Win32/Somoto application (unable to clean) 00000000000000000000000000000000 I C:\WINDOWS\ed4.exe a variant of Win32/Rozena.AM trojan (unable to clean) 00000000000000000000000000000000 I
Hi Daniel14,

I'm glad you're having a good day :). I noticed you have not installed service pack 3 yet. Can you please do?

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?showtopic=123738&st=45

Collect::
C:\WINDOWS\ed4.exe
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe



Then post the results log using Copy / Paste
Should I update to SP3 after running the script or before? Also, does updating to SP3 makes me lose all information on my computer and like we say start over?
Hi Daniel, .crdownload files are incomplete downloads. ESET did not detect them as malware. It just detected third party software that was bundled with the software you were trying to download. Nothing to worry about.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI