Re: not a valid Win32 application - warning. Can't run antivirus apps



Its possible that you still may have a computer virus still on your system. Try
use avg or a nother virus scanner and see what happens?



From: "The Real Truth MVP" <toidi@xxxxxxxx>

Are you still having problems? Is system restore on or off? Now you need to us
a boot disk to manually remove the files.

--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/




"Nehmo" <nehmo54@xxxxxxxxxxx> wrote in message
news:a721ebf0-6852-439d-9a98-a8f1e32e9016@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
On Nov 15, 5:47 pm, "The Real Truth MVP" <to...@xxxxxxxx> wrote:
On the Tools menu in Windows Explorer, click Folder Options.
Click the View tab.
Under the Hidden files and folders heading select Show hidden files and
folders.
Uncheck the Hide protected operating system files (recommended) option
Click ok.
Can you see those files now? send me a copy of the MBAM log

I already have "Hide protected operating system files (Recommended)"
with an un-checked box. I also have "Hidden files and Folders" set
with a dotted circle to the option "Show hidden files and folders".

The file isn't there. Yet I continually get DriveSentry popups saying
winfilse.exe is trying to write to either Temporary Internet files ie
content or Cookies. These popups are loged by DriveSentry.

The Malwarebytes (MBAM) log is short enough to just post here. MBAM
deleted Winterms.exe (see near the end of the log). That was the other
file I couldn't find.

The MBAM log:
Malwarebytes' Anti-Malware 1.30
Database version: 1400
Windows 5.1.2600 Service Pack 3

11/15/2008 5:15:53 PM
mbam-log-2008-11-15 (17-15-53).txt

Scan type: Full Scan (C:\|)
Objects scanned: 179546
Time elapsed: 3 hour(s), 7 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 46

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\drivers\downld (Trojan.Agent) -> Quarantined and
deleted successfully.
C:\Documents and Settings\Owner\Application Data\m (Trojan.Agent) ->
Delete on reboot.

Files Infected:
C:\WINDOWS\system32\drivers\downld\161671.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\177296.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\198265.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\204656.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\304546.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\314578.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\330921.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\346953.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\348453.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\366687.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\380140.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\388250.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\416312.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\464687.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\475625.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\501265.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\517921.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\581171.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\594640.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\677359.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\682593.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\689375.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\692750.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\695250.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\705703.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\707609.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73636734.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73704218.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73712703.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73734921.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73741343.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73771890.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73777218.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73804890.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73871015.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73877390.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73880187.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\73937937.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\74020203.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\762484.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\76625.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\downld\795109.exe (Trojan.Agent) ->
Quarantined and deleted successfully.
C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and
deleted successfully.
C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Quarantined and
deleted successfully.
C:\Documents and Settings\Owner\Application Data\m\flec006.exe
(Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\srosa.sys (Rootkit.Bagle) -> Quarantined
and deleted successfully.

--
~~ Nehmo

--- BBBS/LiI v4.01 Flag
* Origin: bbs.cyberchatnet.com Vienna, VA (8:8/703)
.



Relevant Pages

  • Re: .dbx folder - does not show in OE6 window
    ... Just an FYI. Manually compacting all folders in the manner Gerry explained /does/ reset the registry counter back to zero. ... Fortunately, once the scan is complete, it offers the opportunity "Continue Anyway" which allows the user an opportunity to examine its' findings and copy specific Registry details to the clipboard. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Ron Sommer My Reply Need more info on the System Restore
    ... Moving the rules and blocked senders will require going into the Registry. ... "Ron Sommer" wrote: ... Replacing the dbx files with dbx files from another Identity should work. ... If you import .dbx files will that also create the folders in my ...
    (microsoft.public.windowsxp.general)
  • Re: Twaintec.dll and the Transponder Gang
    ... Hopefully the below steps will help you clean your ... from your system caused from TWAINTEC. ... Use the "Search for Files and Folders" feature in Windows. ... You will now have to clean up the System Registry. ...
    (microsoft.public.windowsxp.general)
  • Re: NetworkService and LocalService accounts
    ... system accounts, took ownership and reset perms on the folders. ... To display Hidden files and folders... ... Hide protected operating system files, ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: All files disappeared from my PC!
    ... Sounds as though you removed more than just McAfee files via the registry. ... All files and folders my cousin created in the past ... > for the CD that was used to install them. ...
    (microsoft.public.windowsxp.general)