| 1. |
Solve : Error Msg- C:\Windows\System32\ekrn.exe is not a valid Win32 application? |
|
Answer» hi, and thanks in advance for any help you can give me. Important: Some malware camouflage themselves as ekrn.exe, particularly if they are located in c:\windows or c:\windows\system32 folder. Thus check the ekrn.exe process on your pc whether it is pest. You could search your registry for an entry which is attempting to start ekrn.exe and, if found, delete it. Hi, Thanks for the replies. I did as you all suggested. Looked for any other antivirus program (there isn't any). Under msconfig startup there is ekrn.exe I unchecked it (both in safe mode and not) and it doesn't stay that way when rebooted. It reverts back to checked. I went into the registry and searched for instances of ekrn.exe and when found (there were two of them) I BACKED them up and then deleted them. I rebooted and the same issue is there. I start the system, the error msg comes up. But NOW when I go into the task manager, it shows up under applications (it did not previously) so I hit end task from there, and it stops coming up. If I do not do that and just hit 'OK' in the popup it will continue popping up about every 5 seconds. The instances of ekrn in the registry were under search assist and one came up with a reference to mininova. I am still trying to uninstall the mininova (it conveniently did not come with a utility for that). So, that is what I have done up to this point. Thanks again for your help. Quote The instances of ekrn in the registry were under search assist and one came up with a reference to mininova. I am still trying to uninstall the mininova Aha, the revenge of the Torrents strikes again. LOL DOWNLOAD HijackThis: http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download Click on Download HijackThis Installer Post HijackTHis log.Here you go: log is attached also, I got the toolbar off my browser (firefox 3) but it still has taken over my firefox homepage. I'm pretty sure at this point that the mininova toolbar is where the problem came from. thanks again for helping me out. [recovering disk space -- attachment deleted by admin]Well, as this entry shows: - O4 - HKCU\..\Run: [NOD32] C:\WINDOWS\system32\ekrn.exe you had Eset NOD32 Antivirus installed, at some point. Go to Add\Remove, and see, if it's listed there. If so, uninstall it. If it's not listed there, let me know.Hi, Just looked again, and no Eset, no Nod32 in Add/Remove. MaryThat's fine. Since I don't see any infection present, I won't be sending you to "Malware removal" section. Simply open HJT, and checkmark: - O4 - HKCU\..\Run: [NOD32] C:\WINDOWS\system32\ekrn.exe Click "Fix checked" button, and it should take care of your problem. Restart computer. Did it. Clicked "Fix Checked" on that line, restarted, and its still doing the same thing. Ran HJT again and the same line is still there. - O4 - HKCU\..\Run: [NOD32] C:\WINDOWS\system32\ekrn.exe Mary Hmmm....interesting Go Start>Run, type in: regedit Click OK. Registry Editor will open. Navigate to: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run In RIGHT pane, you'll see NOD32 entry. Right click on it, click Delete. Restart computer. |
|