Invalid Win32 Trojan!!

Discussion in 'Science, Technology & Car Chat' started by Great Sage Equal of Heaven, Mar 2, 2008.

  1. its not faster.. nor do I have an extra external hdd layin around..


    thas so like punkin' away from the hackers.. Don't be a PUNK!
     
  2. Ok I think if someone can someone create a rescue disk with anti-virus I may be able to get rid of this thing..

    in the midst of trying to install anti-viruses.. I found a cleanapi.exe process.. however there wasn't much info i can find online..
     
  3. Kachi_no_Kemuri

    Kachi_no_Kemuri Well-Known Member

    529
    68
    0
    Dont bother with AVG. I used it and it is worthless. Like you, Norton is fuked up on my comp and i cant uninstall it neither can i use it which sux.

    anyways down to business.

    Go to Cnet and download Avast. Thats a good anti-virus software.

    Because its been a while since i set up Avast. Upon installing i think you need to update the virus definition. Once done it will ask you whether or not you would like to scan your computer upon start up. Click yes and once your computer reboots it will undergo a full scan of the computer b4 Window starts.

    If it doesnt ask you to update it's virus definiton, i think it will skip to scanning the comp b4 window is booted up.

    If that all fails, then Hijack this is your only hope. Im quite surprised it cant be used. Why?
     
  4. Ouch man at the very least you can still pull up your task manager, check your startup programs by going into Run --> msconfig in the startup tabs uncheck any malicious programs that you can see, save and reboot, try to stop explorer.exe right on startup, and see if you can just run things through your task manager.

    Sometimes this method works but every case is different.... i had to do this once... worse came to worse i burned everything onto dvds...... and reformatted....
     
  5. ItsRobertttt

    ItsRobertttt Well-Known Member

    105
    41
    0
    dont reformat... just get a new hard drive xD
    btw try to get a program that scans your registry... the trojan could be hiding in there =x if you just try to disinfect your system32 files you'll end up deleting some of 'em
     
  6. bbes

    bbes Incredible

    hey ecko, what is this trojan actually doing btw?
     
  7. Knoctur_nal

    Knoctur_nal |Force 10 from Navarone|

    16,563
    662
    29
    Did the Avast and Nod32 install, as you never gave us an update on that.
    Also, to get a better understanding of what process are running, install Process Explorer:http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
    It will give you a break down and associated program to each process.
    Peculiar that only Trend has this Trojan registered, although, i do see it floating around in a few variations.
    Also, can you try using a a piece of software that looks specifically for Trojans. Check her for a review:http://www.anti-trojan-software-reviews.com/review-ewido.htm and it can be downloaded here:http://www.ewido.net/en/download/
    Note, ewido anti-spyware 4.0 has been replaced by AVG Anti-Spyware 7.5 and it states it still looks for Trojans.
    Keep us posted.

    Knoc
     
  8. jacklui45

    jacklui45 Active Member

    40
    231
    0
    try installing the program you mentioned eariler in this thread on a laptop or another pc, then take the whole folder from the drive u installed it on and then copy it all over to a pen drive. then run it on ur current pc.. i duno if it works tho
     
  9. ItsRobertttt

    ItsRobertttt Well-Known Member

    105
    41
    0
    reinstall windows whatever you have... not format just reinstall the system files so that it overwrites the current system files cause some of those files are infected... then you gotta delete the trojan in the registry cause thats probably the main place where its hiding...
     
  10. yea.. thing is.. I can get some of those registry scanners to install and run.. but just can't get any type of anti-virus to run.. always gets not valid win32 error..

    it's not doing anything obvious.. but last time I checked.. my emailed showed that it tried to send emails to pple in my contact list.. and only reason I found out was because some of those emails were invalid so I got the sent error..
    I've since signed out of the email account.. hopefully it wont cause any more trouble..

    avast installed but can't get working.. Nod32 won't even install.. get some kinda service failed to start error..

    that in theory could work.. although I'm not sure what kinda anti-virus would work like that..


    Alright.. so after close examing.. I think that the cleanapi.exe is part of the Kaspersky install process.. I don't think it was a virus that this one site claimed it to be...

    I'ved installed that process explorer and everything seems to be in order.. cept some times a red process would flash then disappear..


    So I've been thinking about creating those anti-virus bootcds.. but so complicated.. I have no idea how to do it even after reading about it.. I've tried deleting it, but dunno if its gone for good.

    my other option would be to give access to a laptop and let the laptop scan my computer.. but is that possible? And also I think it might get too technical..
     
  11. tonkachi

    tonkachi Well-Known Member

    1,271
    86
    0
    i'm actually suprised that you couldn't get the trend micro house call to get rid of it....the one thing that i did that fixed the registry when i was getting the not valid win32 program was to run www.ccleaner.com and use their registry cleaner. it cleaned up a lot of gunk in the system and fixed issues of installing programs. I would isolate the computer to make sure u don't get it spreading to other computers

    also there is very little documentation for this virus so it's hard to put a hold as to how to clear it up. The other i noticed is your registry is pretty corrupted so your safest bet maybe to backup your important files and do a full reinstall of windows
     
  12. Kid

    Kid Well-Known Member

    85
    31
    0
    well, if ur internet speed is very fast. U might want to try to download a copy of linux(ubuntu,mepis,Knoppix choose anyone)

    Make sure u download a live cd version so it runs on startup
    After u download, burn it to a cd/dvd.
    Go bios and set cd/dvd drive as primary and restart again.
    After that, u should get into linux OS.
    From there, try to scan using the AV.(if not provided, u can download from the net and do the scaning.)

    I'm pretty sure that the trojan that runs on windows platform will not work on linux since they run on different platform.

    Good luck.
     
  13. ooh.. I think I can give that a go.. is there any linux version more ideal for vista?

    Never played with linux before.. so I have no clue how are it is to set up..
     
  14. Knoctur_nal

    Knoctur_nal |Force 10 from Navarone|

    16,563
    662
    29
    Hes suggesting a live cd.
    A chance it might work. Rip, burn, boot.
    You basically boot from the cd and run the os from the cd itself.
    Here is a list of distros to check: http://www.frozentech.com/content/livecd.php
    I'd personally recommend Knoppix.
    Note, do your readings on this.

    Knoc
     
  15. BigC

    BigC Well-Known Member

    702
    68
    0
    Why not try a system restore to a earlier date before the prob???
     
  16. It does not work...


    aight.. so the concept of running it off the cd is understandable.. but I don't understand how Imma install the antivirus on there??

    does any one have a cd ready for me to make my life easier? :D
     
  17. Knoctur_nal

    Knoctur_nal |Force 10 from Navarone|

    16,563
    662
    29
    The os on the cd should come with AV already installed. Once you boot form the cd, it loads an environment with tools, including av, to use.
    AV in Knoppix, F-Prot installer package.
    You can also look into Ultimate BootCD: http://www.ultimatebootcd.com/
    Also, virus scanning in Knoppix: http://www.enterprisenetworkingplanet.com/netsecur/article.php/10952_3389801_2

    Knoc
     
  18. Ecko if you never played with Linux before i wouldn't suggest at a time like this to try it....... your life would be made easier if you just give into the trojan (there is no shame) and just back up your harddrive and reformat....

    But Good Luck in which ever fix you decide in the end
     
  19. Kid

    Kid Well-Known Member

    85
    31
    0
    ecko have try many ways to get rid of the trojan using windows platform method, none works so should give linux a try.
    livecd is perfectly save for everyone.

    1) it runs from cd, not on ur hdd drive
    2) its doesnt mess up ur windows folder because nothing is install

    everything will run back to normal when u take out the cd and reboot. this is why livecd is invented.
     
  20. The_Jelly

    The_Jelly NSFW? :P

    Install your AV and Hijacthis on a UBS drive, then run it from there.