also @ TechSpot: Amazon wants to build a trio of biospheres in downtown Seattle

(Any antivirus.exe) not a valid win32 Application in Vista

Discussion in 'Virus and Malware Removal' started by bennychains, Jan 22, 2008.

  1. sahara Newcomer, in training

    I eventually managed to get the Kaspersky online scan to run and complete without crashing, and the report listed a lot of "Object is locked" and:
    "C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of "
    I tried removing the file, but got an error that says "Cannot delete mdelk: Cannot read from the source file or disk".
    The online help files about the file suggested uninstalling it first, but it isn't showing up in my program list. Neither is it in my task manager's process list either.

    I'll try to get the full version of Kaspersky and see if I've any luck with it.

    By the way, thanks vistaboy2, I managed to get wifi working again following your instruction.

    Edit Installed Kaspersky trial, and then restarted into command prompt, removed the mdelk.exe file there, but when I restart I still have the same old problem of Kaspersky "is not a valid Win32 application"...
  2. jigjag Newcomer, in training

    Same Issue

    Just to brief things up, antivirus didnt recognize it(nod32), tried installing the trial of kaspersky, avg etc, nothing worked. same old error, however did an online virus scan, managed to recognize 6 virus, said it cleaned them, but left 1 behind, rebooted, voila - problem still persists.

    problems inlcude: cant boot up in safe mode, wireless disabled, even tried to overwrite my system files by 'upgrading windows' (windows xp)

    what i can recommend is, get a windows disk that boots up from a CD, use an antivirus program in that os and scan for issues and then reboot again

    else

    clean format your pc.

    unfortunately i dont have a Windows Cd boot up thing-a-ma-jig.

    im just saying thats an idea...
  3. DanielKatz Newcomer, in training

    I'm experiencing the same disturbances too

    It's also started with blue screen, and followed by disabling any security systems I had… including the system services that supports security.
    I solved the issue by reinstalling the operation system, but because it's obviously a new virus (only one more match on Google) I very interested on any evolvement on the subject.
  4. temir Newcomer, in training Posts: 87

  5. sahara Newcomer, in training

    Good news, I've managed to (I think) fix my computer :)
    I followed bloo2k's reply on
    nivas.hr/blog/2008/01/13/biohazard-outbreak-of-wintemsexe-28-hours-later-how-to-get-rid-of-a-virus-if-you-cant-boot-to-safe-mode-and-your-computer-keeps-deleting-anti-virus-software
    - basically, download something that doesn't need installation (Rootkit UnHooker, IceSword, ComboFix), save it as something .bak/txt/whatever instead of a exe, so the virus won't recognize it, and then change the file to read only before renaming it to .exe and run it.
    With that method, I managed to avoid the "not a valid win32 application" error messages. And I used Rootkit UnHooker to kill the wintem.exe and hldrrr.exe processes, and then use IceSword, ComboFix, BitDefender online scanner and Kaspersky online scanner to delete all remaining traces of the virus.

    Looks like all the old firewall and antivirus/spyware programs will need reinstalling, but so far everything I've installed works.
  6. diishen Newcomer, in training

    sahara,
    could you clarify what you mean as "remaining traces of the virus"?
    I used Rootkit UnHooker like bloo2k did and deleted wintem.exe and hldrrr.exe but bloo2k only mentioned about srosa.sys in Icesword. Is there any other that I should manually delete?