Question about Microsoft Windows XP Professional With Servise Pack 2 (e8503040) for PC

1 Answer

Win32 hi, recently i had virus in my comp called win32.worm.autorun.MQ i restored my windows through restore after cleaning up when i click on my drive it gives me error saying "resycled\boot.com is not valid win32 application" when i right click the drive the frist option is autorun is use to be open ....the 2nd option is open..when i click open option i get error win32 is not valid application ..3rd option is search n 4th is explorer however i can acces my drive through explore option .. can anyone plss tell how can i restore this plssssss

Posted by on

  • hopkinzer jay May 11, 2010

    first thing you need to check if you are still noinfected with virus to check it

    1)Explore any drive
    2)goto Tool >Folder options > then View and Make sure show hidden files and folder is checked if its not selected select it click ok

    2) check if you can see hidden folder and files in system

    if your hidden folders and files are displayed we can move for the solution if not we need to first remove virus from your system



  • Anonymous Mar 16, 2014

    after I click all the menu in boots options, none of the option is working. all option after I click one by one , I get this error status Status:0xc0000001.

×

1 Answer

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    MVP:

    An expert that gotĀ 5 achievements.

    Governor:

    An expert whose answer gotĀ voted for 20 times.

    Scholar:

    An expert who has written 20 answers of more than 400 characters.

  • Expert
  • 34 Answers

Hello,
Hopefully this will get your system back up and running well.  First download from malwarebytes.org their free anti-malware program. Then follow the steps below.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. 
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally(not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.

I hope that this helps you out, and that you are able to restore your system back to running condition.
Ken

Posted on Jan 06, 2009

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

The Dorkbot.A worm changed my files into TMP files, ESET NOD32 cleaned the virus. How do I restore the TMP files to my files and folders?


The hard drive was corrupted but the worm virus. Worms will eat data and can change the data to what it wants (to destroy anything). If you can not do an open with to open your data with the correct program.

Dec 12, 2011 | Western Digital My Passport Essential...

Tip

How to remove the scvhost.exe Virus.


Svchost.exe is the name of a generic host process for services that run from dynamic link libraries (DLLs). A variety of worm malware programs spread a similarly named file <b>Scvhost.exe </b>via Yahoo! Messenger that blocks the Task Manager and Registry Editor, as well as use of the command prompt.<br /> <br /> <b><u>Warning</u></b><br /> Manual removal of Scvhost.exe may be very difficult as the removal process requires knowledge of the Operating System's command prompt and Registry Editor. If not performed properly, your computer system might experience permanent damage. Consequently, manual removal might be best for experienced users. Less experienced users might want to consider using an automatic spyware removal application, such as that offered by Trend Micro. This worm duplicates itself to different locations of shared folders. The duplicated program uses a folder icon that has an .exe file extension. DO NOT double click on any of these folders.<br /> <br /> <b><u>Follow these step by step instructions to remove the scvhost.exe virus.</u></b><br /> <b></b> <br /> <b><u>Step 1 (Turning off System Restore)</u></b><br /> This is so that if you ever need to use System Restore after you have removed the virus, it doesn't restore the virus aswell.<br /> <br /> If the operating system of the infected computer is either Windows Me or Windows XP, turn off System Restore while this fix is being implemented. To turn off System Restore within Windows Me, click <b>Start &gt; Settings &gt; Control Panel</b>. Double-click <b>System</b>. Select F<b>ile System</b> from the Performance tab. Left click the <b>Troubleshooting</b> tab and check the <b>Disable System Restore</b> box. Click <b>OK</b>. <br />To turn off System Restore within Windows XP, log in as Administrator and click <b>Start</b>. Right click <b>My Computer</b>" and select <b>Properties</b> from the shortcut menu. Check the <b>Turn off System Restore</b> option for each drive on the System Restore tab. Left click <b>Apply</b> and <b>Yes</b> to confirm when prompted. Click <b>OK</b>.<br /> <b></b> <br /> <b><u>Step 2 (Run in safe mode)</u></b><br /> Restart your computer in Safe Mode and log in as Administrator. Press <b>F8</b> after the first beep occurs during start up, before the display of the Microsoft Windows logo. Select the first option, to run Windows in Safe Mode from the selection menu.<br /> <b></b> <br /> <b><u>Step 3 (Accessing Command prompt)</u></b><br /> Access the command prompt. Click <b>Start &gt; Run</b>. Type <b>cmd</b>. Click <b>OK</b>. Then in the command prompt type <b>cd </b>to<b> </b>change directory then press the space bar. <br />Type the name of the full directory path of the folder containing your Windows system files. It will be either <b>C:\Windows\System </b>or<b> C:\Windows\System 32</b><br /> <b></b> <br /> <b><u>Step 4</u></b><br /> From the command prompt, type the following to unprotect the files for removal:<br /><b>attrib -h -r -s scvhost.exe</b> and press <b>Enter</b>;<br /><b>attrib -h -r -s blastclnnn.exe </b>and press<b> "Enter</b>;<br /><b>attrib -h -r -s autorun.inf</b> and press <b>Enter</b>.<br /> <br /> <b><u>Step 5</u></b><br /> Delete the files by typing the following from the command prompt:<br /><b>del scvhost.exe</b> and press <b>Enter</b>;<br /><b>del blastclnnn.exe</b> and press <b>Enter</b>;<br /><b>del autorun.ini</b> and press <b>Enter</b>.<br /> <b></b> <br /> <b><u>Step 6</u></b><br /> Type "<b>cd\</b>" to return to the main Windows directory.<br />Unprotect and delete the Autorun.inf file by typing the following from the Windows directory command prompt:<br /><b>attrib -h -r -s autorun.inf</b> and press <b>Enter</b>;<br /><b>del</b> <b>autorun.inf</b> and press <b>Enter</b>;<br />Type <b>regedit</b> and press <b>Enter</b> to open the Registry Editor.<br /> <b></b> <br /> <b><u>Step 7</u></b><br /> Locate the following entry:<br /><b>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</b>.<br />Delete the incorrectly spelled Yahoo! Messenger entry with the value<br /><b>c:\windows\system32\scvhost.exe.</b><br /> <b></b> <br /> <b><u>Step 8</u></b><br /> Locate the following key:<br /><b>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</b>.<br />Within the key, there is a <b>shell</b> entry with the value of <b>explorer.exe, scvhost.exe</b>. Edit the entry to remove the reference to Scvhost.exe, leaving Explorer.exe as the remaining value in the registry entry.<br /> <br /> <b><u>Step 9</u></b><br /> Locate the following key:<br /><b>HKEY_LOCAL_MACHINE&gt;SYSTEM&gt;CurrentControlSet&gt;Services&gt;<br /></b>Delete the following subkeys from the left panel:<br /><b>RpcPatch</b><br /><b>RpcTftpd <br /></b>Exit the command prompt and return to the operating system. Type <b>Exit</b>, and press <b>Enter</b>.<br /> <br /> <b><u>Step 10</u></b><br /> Reboot the PC.<br />If Scvhost.exe still resides on the computer, repeat these steps or try using an automatic removal program from McAfee or Symantec.<br /> <br /> <br /> <br />

on Feb 25, 2011 | Computers & Internet

1 Answer

Worm.win32.autorun.blw virus appear in my system i already use kesper sky, but not solved. please advise a solution. thanx


When the executable is run on the victim's machine, the worm copies itself to the following locations:
  • %Application Data%\remove.exe (Copy of itself)
  • %Application Data%\autorun.inf
Where %Application Data% = c:\Documents and Settings\All Users\Application Data
Autorun.inf has following command
Exp: [autorun]
shellExecute=remove.exe
The worm adds a Run entry in registry so that it executes itself at every startup:
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    "(Default)" = "%Application Data%\remove.exe"
Symptoms -
  • Presence of above mentioned files.
  • Presence of registry entries mentioned above.
Method of Infection Method of Infection - This worm spreads by using autorun.inf on shared drives and removable devices.
Removal - A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.


Thanks for using fixya..

Sep 14, 2009 | Computers & Internet

3 Answers

My computer has an email worm and am unsure about fixing it.


What this will do is reset your computer back to factory defaults like you had just got it out of the box. This would fix the problem for sure. Of course you could also go here as well and download the win32.brontok removal tool. http://www.bitdefender.com/VIRUS-157247-en--Win32.Brontok.A@mm.html This program will remove any instance of the worm on your computer and get rid of it. This way you won't have to restore your computer back to factory defaults.

Jun 04, 2009 | E-Machines (T2958) PC Desktop

1 Answer

Hi, recently i had virus in my comp called win32.worm.autorun.MQ i restored my windows through restore after cleaning up when i click on my drive it gives me error saying "resycled\boot.com is not valid...


This is a solution i found at another site that i think could help you with your probem

Hi

If you still need help with this please do following:

Download and install TrendMicro HijackThis
* Once installed open HijackThis by clicking Start > Programs > HijackThis and click the button labeled
Do a system scan only

* Click the scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
* Once the scan is complete the scan button will now read save log. Click this button to save the log file to your PC. Once you select where you would like to save the file it will open in your systems default text editor. Typically this application is Notepad. Post the log here.

The link:http://www.techsupportforum.com/security-center/virus-trojan-spyware-help/hijackthis-log-help-inactive/306207-resycled-boot-com-not-valid-win32-application.html

Please let me know if you need more help with this problem

Jan 06, 2009 | Computers & Internet

1 Answer

Removal of win32mode of hard drives


While researching this problem, it seems that the most likely cause is a virus called FUNNY UST SCANDAL.....it is mostly an annoyance, not too evil, they say.

Please back up your data!

Some people recommend using a noob killer program to kill the virus, but when searching online for one, I come up with very sketchy sites, use at your own risk!

Others have recommended the following site for answers:
http://www.edmartechguide.com/2007/11/funny-ust-scandal-aviexe-remover.html

Then there are these anti virus programs to try, one is free, other a trial, both good:
http://www.eset.com/download/free_trial_download_eav.php

http://www.avast.com/eng/download-avast-home.html

FINALLY.......I found a jumble of instructions to try to fix the problem, and they are as follows.
I have not had this problem myself, but it looks like a messy one, good luck!



Go to Start/Run and type :

reg.exe add "HKCRDriveshell" /ve /d "none" /f

then type:

regsvr32 shell32.dll

If this doesn't work - try this

Problem

when you open any drive letter from your pc it gives the following error

c: application can not run in Win32 mode
d: application can not run in Win32 mode

Solution

To correct and solve this error follow this procedure

Run Task Manager (Ctrl-Alt-Del or right click on Taskbar)

Stop wscript.exe process if available by highlighting the process name and clicking End Process.

Then terminate explorer.exe process.

In Task Manager, click on File -> New Task (Run…).

Type “cmd” (without quotes) into the Open text box and click OK.

Type the following command one by one followed by hitting Enter key

del c:autorun.* /f /q /a
del d:autorun.* /f /q /a
del e:autorun.* /f /q /a

c, d, e each represents drive letters on Windows system. If thereare more drives or partitions available, continue to command byaltering to other drive letter. Note that you must also clean theautorun files from USB flash drive or portable hard disk as theexternal drive may also be infected.

In Task Manager, click on File -> New Task (Run…).

Type “regedit” (without quotes) into the Open text box and click OK.

Navigate to the following registry key

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon

Check if the value name and value data for the key is correct (thevalue data of userint.exe include the path which may be different thanC drive, which is also valid, note also the comma which is also needed)

“Userinit”=”C:WINDOWSsystem32userinit.exe,”

If the value is incorrent, modify it to the valid value data.

Dec 30, 2008 | Microsoft Windows XP Professional for PC

2 Answers

How do i get rid of a W32.SillyFDC virus


The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
  1. Disable System Restore (Windows Me/XP).
  2. Update the virus definitions.
  3. Run a full system scan.
  4. Delete any values added to the registry.

For specific details on each of these steps, read the following instructions.

1. To disable System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:

Note: When you are completely finished with the removal procedure and are satisfied that the threat has been removed, reenable System Restore by following the instructions in the aforementioned documents.

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article: Antivirus Tools Cannot Clean Infected Files in the _Restore Folder (Article ID: Q263455).

2. To update the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
  • Running LiveUpdate, which is the easiest way to obtain virus definitions.

    If you use Norton AntiVirus 2006, Symantec AntiVirus Corporate Edition 10.0, or newer products, LiveUpdate definitions are updated daily. These products include newer technology.

    If you use Norton AntiVirus 2005, Symantec AntiVirus Corporate Edition 9.0, or earlier products, LiveUpdate definitions are updated weekly. The exception is major outbreaks, when definitions are updated more often.


  • Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted daily. You should download the definitions from the Symantec Security Response Web site and manually install them.

The latest Intelligent Updater virus definitions can be obtained here: Intelligent Updater virus definitions. For detailed instructions read the document: How to update virus definition files using the Intelligent Updater.

3. To run a full system scan
  1. Start your Symantec antivirus program and make sure that it is configured to scan all the files.

    For Norton AntiVirus consumer products: Read the document: How to configure Norton AntiVirus to scan all files.

    For Symantec AntiVirus Enterprise products: Read the document: How to verify that a Symantec Corporate antivirus product is set to scan all files.


  2. Run a full system scan.
  3. If any files are detected, follow the instructions displayed by your antivirus program.
  4. Delete the autorun.inf file from writeable removable devices, if necessary.
Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.


After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the threat may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

4. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
  1. Click Start > Run.
  2. Type regedit
  3. Click OK.

    Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

  4. Navigate to the following registry subkeys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"load"

  5. In the right pane, delete any values associated with the worm.


  6. Exit the Registry Editor.

Dec 18, 2008 | Microsoft Computers & Internet

6 Answers

How can i remove virus worm/autoit permanently


its simple guys..!!!
if it asks for permission to access outlook..don't permit it because it is a smart virus and is going to spread it to all the people on your contact list...!!!
simply open task manager and end process tree of KHATRA.exe , gHost.exe , xplorer.exe and OUTLOOK.exe seperately...!!
then run your anti virus or download one if you don't have one..!!!
run a complete computer scan in detail..!!
then delete all files which are infected by the virus because the results contain only duplicate files which are created by the virus

Feb 04, 2008 | Acer TravelMate 2300 Notebook

2 Answers

Funny UST Scandal


hi my friend got that last week to... ehat you need to do is download kaspersky. after running kaspersky. that will be gone. you can download kaspersky @ majorgeeks.com Here are some examples of autorun viruses which rely on the autorun function of Windows to infect PC’s and flash drives. Funny UST Scandal.avi.exe Autorun.vbs win32.autorun.k copy.exe imgkulot taga lipa are autorun.vbs recycler FS6519.dll.vbs strawberry from baguio W32/Perlovga (copy.exe | host.exe) VBS_RESULOWS.A Bha.dll.vbs w32automa worm (Autorun.vbs) Trojan.Win32.VB.atg | Win32/Dzan | Worm_vb.bnr (tel.xls.exe | mmc.exe) W32/RJump.worm (RavMonE) Worm.Win32.Delf.bf | W32.Fujacks (spoclsv.exe) W32.Fujacks.BH (****.vbs) WORM_AGENT.PGV (soundmix.exe) W32/Hakaglan.worm (RVHost.exe) Trojan.Win32.VB.ayo [AVP] (Macromedia_Setup.exe) Trojan.VBS.DeltreeY.b#1 (Destrukto!!! | destrukto.vbs) if you want to manually delete it... Solution is here: 1. Start Notepad [Start Menu-All Programs-Accessories-Notepad] or right-click any empty space in your desktop then select New-Text Document 2. Copy the following text. (note: Everything in between the square brackets should be in one line) REGEDIT4 [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIniFileMappingAutorun.inf] @="@SYS:DoesNotExist" 3. Save the file with a name (anything) like DisableAutoRun.reg (The extension .reg is the important part) 4. Double Click your newly created registry file. Choose yes or continue to the warning that will appear. hope this helps

Jan 24, 2008 | Computers & Internet

Not finding what you are looking for?
Microsoft Windows XP Professional With Servise Pack 2 (e8503040) for PC Logo

94 people viewed this question

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

micky dee

Level 3 Expert

2642 Answers

Les Dickinson
Les Dickinson

Level 3 Expert

18346 Answers

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...