Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Bad Image

  • 03-12-2010 10:23pm
    #1
    Posts: 3,518 ✭✭✭


    Hi I'm getting this error message when I open something such as Chrome/Firefox and I get loads on startup. When I scan with AVG there's 34 files that are broken and it won't repair.
    I ran TFC and it didn't remove anything. Rebooted and scanned with DDS and Malwarebytes.
    If anyone has the time to read the logs and suggest something I'd be very grateful. Thanks in advance :)
    Logs
    DDS:

    Run by Joe at 22:16:43.88 on 03/12/2010
    Internet Explorer: 8.0.6001.18975
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.353.1033.18.3002.1622 [GMT 0:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\STacSV.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_827e372d\aestsrv.exe
    C:\Windows\System32\svchost.exe -k Akamai
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Application Updater\ApplicationUpdater.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\spool\DRIVERS\W32X86\3\lxdvserv.exe
    C:\Windows\system32\lxdvcoms.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\SMINST\BLService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Lexmark X5400 Series\lxdvmon.exe
    C:\Program Files\Lexmark X5400 Series\lxdvamon.exe
    C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\IDT\WDM\sttray.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Users\Joe\AppData\Local\Google\Update\GoogleUpdate.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\OpenOffice.org 3\program\soffice.bin
    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Windows\system32\conime.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Joe\AppData\Local\Google\Chrome\Application\chrome.exe
    c:\program files\windows defender\MpCmdRun.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\vssvc.exe
    C:\Windows\System32\svchost.exe -k swprv
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\Joe\Downloads\dds (3).com

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://google.atcomet.com/m/
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ie&c=91&bd=Presario&pf=cnnb
    uInternet Settings,ProxyOverride = <local>;*.local
    uURLSearchHooks: H - No File
    BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: AOL Toolbar BHO: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll
    TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
    TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [Google Update] "c:\users\joe\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
    uRun: [<NO NAME>]
    uRun: [NokiaOviSuite2] c:\program files\nokia\nokia ovi suite\NokiaOviSuite.exe -tray
    uRun: [DAEMON Tools Net Agent] "c:\program files\daemon tools net\DTAgent.exe" -autorun
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
    mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
    mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
    mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
    mRun: [lxdvmon.exe] "c:\program files\lexmark x5400 series\lxdvmon.exe"
    mRun: [lxdvamon] "c:\program files\lexmark x5400 series\lxdvamon.exe"
    mRun: [Lexmark X5400 Series Fax Server] "c:\program files\lexmark x5400 series\fm3032.exe" /s
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [<NO NAME>]
    mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
    mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
    mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
    StartupFolder: c:\users\joe\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: &AOL Toolbar Search - c:\programdata\aol\ietoolbar\resources\en-ie\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
    Notify: igfxcui - igfxdev.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\u6ab0kh2.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://vshare.toolbarhome.com/?hp=df
    FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=937811&p=
    FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
    FF - component: c:\program files\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nppl3260.dll
    FF - plugin: c:\program files\mpcstar\codecs\real\browser\plugins\nprpjplug.dll
    FF - plugin: c:\program files\veetle\player\npvlc.dll
    FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
    FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
    FF - plugin: c:\users\joe\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Extension: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\program files\nokia\nokia ovi suite\connectors\bookmarks connector\FirefoxExtension
    FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\u6ab0kh2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Extension: vShare Plugin: vshare@toolbar - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\u6ab0kh2.default\extensions\vshare@toolbar
    FF - Extension: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\u6ab0kh2.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
    FF - Extension: Flash Video Downloader - Youtube Downloader: artur.dubovoy@gmail.com - c:\users\joe\appdata\roaming\mozilla\firefox\profiles\u6ab0kh2.default\extensions\artur.dubovoy@gmail.com

    ============= SERVICES / DRIVERS ===============

    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 224240]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 30112]
    R1 dtcdrom;dtcdrom;c:\windows\system32\drivers\dtcdrom.sys [2010-8-19 201280]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_827e372d\AEstSrv.exe [2009-3-2 81920]
    R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-21 21504]
    R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2010-10-22 386560]
    R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [2008-1-21 21504]
    R2 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service --> c:\windows\system32\lxdvcoms.exe -service [?]
    R2 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2007-10-18 98984]
    R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-3-2 365952]
    R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-3-2 222512]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-9-22 112128]
    S2 DTNetService;DTNetService;c:\program files\daemon tools net\DTNetSrv.exe [2010-7-29 394560]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-29 136176]
    S3 BazisVirtualCDBus;WinCDEmu Virtual Bus Driver;c:\windows\system32\drivers\BazisVirtualCDBus.sys [2009-12-5 135320]
    S3 bthav;Bluetooth AV Profile;c:\windows\system32\drivers\bthav.sys [2008-7-10 34816]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2010-7-22 29736]

    =============== Created Last 30 ================

    2010-12-03 21:47:14 1696256 ----a-w- c:\windows\system32\gameux.dll
    2010-12-03 21:47:13 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-12-03 21:47:13 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-12-03 21:47:10 714240 ----a-w- c:\windows\system32\timedate.cpl
    2010-12-03 21:32:24 6273872 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{1a8dc228-2483-4b64-bdd3-59c86ef9fe9d}\mpengine.dll
    2010-11-25 21:42:54 483840
    w- c:\windows\system32\stapi32.dll
    2010-11-25 21:42:35 61440 ----a-w- c:\windows\system32\aestaren.dll
    2010-11-25 21:42:35 368640 ----a-w- c:\windows\system32\aestecap.dll
    2010-11-25 21:42:34 142848 ----a-w- c:\windows\system32\aestacap.dll
    2010-11-25 21:42:32 86016 ----a-w- c:\windows\system32\AESTCom.dll
    2010-11-25 21:42:32 536576 ----a-w- c:\windows\system32\idtmini1.exe
    2010-11-25 21:42:31 450652 ----a-w- c:\windows\sttray.exe
    2010-11-25 21:42:31 3567616 ----a-w- c:\windows\system32\stlang.dll
    2010-11-25 21:42:31 12021852 ----a-w- c:\windows\system32\idtcpl.cpl
    2010-11-25 19:16:57 21504 ----a-w- c:\users\joe\SysRestorePoint.exe
    2010-11-24 18:05:10 20 ----a-w- c:\windows\system32\AVGRSSTX.DLL
    2010-11-20 20:41:26
    d
    w- c:\users\joe\appdata\roaming\AVG10
    2010-11-20 20:36:21
    d--h--w- c:\progra~2\Common Files
    2010-11-20 20:34:14
    d
    w- c:\progra~2\AVG10
    2010-11-20 20:29:49
    d
    w- c:\progra~2\MFAData
    2010-11-16 19:06:00
    d
    w- c:\program files\YouTube Downloader Toolbar
    2010-11-16 19:06:00
    d
    w- c:\program files\common files\Spigot
    2010-11-16 19:06:00
    d
    w- c:\program files\Application Updater
    2010-11-14 17:21:42
    d
    w- c:\program files\iPod
    2010-11-14 17:21:40
    d
    w- c:\program files\iTunes
    2010-11-05 19:02:41 53816 ----a-w- c:\windows\system32\drivers\btwusb.sys
    2010-11-05 19:02:41 43683 ----a-w- c:\windows\system32\drivers\btwhid.sys

    ==================== Find3M ====================

    2010-10-19 10:41:44 222080
    w- c:\windows\system32\MpSigStub.exe
    2010-09-28 15:44:52 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
    2010-09-13 13:56:41 8147456 ----a-w- c:\windows\system32\wmploc.DLL
    2010-09-08 10:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-09-08 10:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-09-08 06:01:28 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-08 05:57:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-08 05:57:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
    2010-09-08 05:56:53 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-09-08 05:56:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-09-08 05:04:36 385024 ----a-w- c:\windows\system32\html.iec
    2010-09-08 04:26:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-09-08 04:25:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2010-09-06 16:20:29 125952 ----a-w- c:\windows\system32\srvsvc.dll
    2010-09-06 16:19:06 17920 ----a-w- c:\windows\system32\netevent.dll

    ============= FINISH: 22:18:29.64 ===============
    DDS Attach:
    DDS (Ver_10-11-27.01)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 08/06/2009 11:33:23
    System Uptime: 12/03/2010 21:50:13 (6385 hours ago)

    Motherboard: Quanta | | 306B
    Processor: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz | CPU | 1200/800mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 222 GiB total, 116.923 GiB free.
    D: is FIXED (NTFS) - 11 GiB total, 1.798 GiB free.
    E: is CDROM (CDFS)
    F: is CDROM ()
    G: is CDROM ()
    H: is CDROM ()
    I: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP196: 19/11/2010 14:55:50 - Removed AVG Free 9.0
    RP198: 20/11/2010 14:13:48 - Windows Update
    RP199: 20/11/2010 20:32:25 - Installed AVG 2011
    RP200: 20/11/2010 20:33:22 - Installed AVG 2011
    RP201: 21/11/2010 15:54:05 - Scheduled Checkpoint
    RP202: 23/11/2010 20:32:07 - Scheduled Checkpoint
    RP203: 25/11/2010 19:17:05 - Automatic Restore Point
    RP204: 25/11/2010 21:39:44 - Windows Update
    RP205: 29/11/2010 21:11:29 - Scheduled Checkpoint
    RP206: 30/11/2010 20:34:30 - Scheduled Checkpoint
    RP207: 01/12/2010 19:17:25 - Removed AVG 2011
    RP208: 01/12/2010 19:20:31 - Removed AVG 2011
    RP209: 02/12/2010 07:43:29 - Restore Operation
    RP210: 02/12/2010 13:09:00 - Windows Update
    RP211: 02/12/2010 18:04:42 - Restore Operation
    RP212: 02/12/2010 18:14:50 - Windows Update
    RP213: 03/12/2010 15:54:47 - Windows Update
    RP214: 03/12/2010 21:22:31 - Restore Operation
    RP215: 03/12/2010 21:31:49 - Windows Update
    RP216: 03/12/2010 21:47:17 - Windows Update
    RP217: 03/12/2010 22:15:11 - Automatic Restore Point

    ==== Installed Programs ======================

    ABBYY FineReader 6.0 Sprint
    Acrobat.com
    Activation Assistant for the 2007 Microsoft Office suites
    ActiveCheck component for HP Active Support Library
    Adobe AIR
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.2
    Adobe Shockwave Player
    Adobe Shockwave Player 11.5
    Akamai NetSession Interface
    AOL Toolbar 5.0
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Ask Toolbar
    Atheros Driver Installation Program
    µTorrent
    AVG 2011
    Bluetooth by hp
    Bonjour
    COMODO Internet Security
    Compatibility Pack for the 2007 Office system
    ConvertGenius 3.6
    CyberLink DVD Suite
    DAEMON Tools Net
    Deer Hunter - The 2005 Season
    DimSum 0.7.9
    ESU for Microsoft Vista
    GIMP 2.6.10
    Google Chrome
    Google Earth
    Google SketchUp 8
    Google Update Helper
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Common Access Service Library
    HP Customer Experience Enhancements
    HP DVD Play 3.7
    HP Help and Support
    HP Quick Launch Buttons 6.40 M1
    HP Total Care Advisor
    HP Total Care Setup
    HP Update
    HP User Guides 0138
    HP Wireless Assistant
    HPAsset component for HP Active Support Library
    HPNetworkAssistant
    Hunting Unlimited 2010
    Intel(R) Graphics Media Accelerator Driver
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 21
    Lexmark Toolbar
    Lexmark X5400 Series
    LightScribe System Software 1.14.17.1
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Works
    Mozilla Firefox (3.6.12)
    MpcStar 4.2
    MSVC80_x86_v2
    MSVC90_x86
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee Reveal
    My HP Games
    Nokia Connectivity Cable Driver
    Nokia Ovi Suite
    Nokia Ovi Suite Software Updater
    Norton Internet Security
    Norton Security Scan
    OGA Notifier 2.0.0048.0
    OpenOffice.org 3.2
    Ovi Desktop Sync Engine
    OviMPlatform
    PC Connectivity Solution
    PowerDirector
    PowerISO
    QuickTime
    Realtek 8169 8168 8101E 8102E Ethernet Driver
    Realtek USB 2.0 Card Reader
    Rosetta Stone V3
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2289158)
    Security Update for 2007 Microsoft Office System (KB2344875)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft Office Excel 2007 (KB2345035)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB982158)
    Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Synaptics Pointing Device Driver
    The Official Driver Theory Test (4th Edition, Revised May 2009)
    The Sims 2
    theHunter-Launcher (remove only)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Veetle TV 0.9.18
    WIDCOMM Bluetooth Software 6.2.0.5800
    Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Player Firefox Plugin
    WinRAR archiver
    Xilisoft AVI to DVD Converter 6
    YouTube Downloader Toolbar v4.1

    ==== Event Viewer Messages From Past Week ========

    03/12/2010 21:52:00, Error: Service Control Manager [7023] - The DTNetService service terminated with the following error: The service has not been started.
    03/12/2010 21:52:00, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    03/12/2010 21:26:54, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.95.861.0 Loading engine version: 1.1.5703.0
    03/12/2010 15:46:38, Error: bowser [8003] - The master browser has received a server announcement from the computer LYNN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{426A35EE-2F25-485D-A5A0-6322C98414. The master browser is stopping or an election is being forced.
    02/12/2010 19:38:07, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00255641304F. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
    02/12/2010 19:36:02, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.0.15 for the Network Card with network address 00255641304F has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
    02/12/2010 19:35:07, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.12 for the Network Card with network address 00255641304F has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
    02/12/2010 18:09:43, Error: Microsoft-Windows-Windows Defender [2004] - Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x8050a001 Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support. Signatures loading: Backup Loading signature version: 1.95.191.0 Loading engine version: 1.1.5703.0
    02/12/2010 15:27:46, Error: Microsoft-Windows-PrintSpooler [19] - The print spooler failed to share printer Lexmark X5400 Series with shared resource name LexmarkX5400. Error 2114. The printer cannot be used by others on the network.

    ==== End Of File ===========================

    I'll post the malwarebytes log in my next post.


Comments

  • Registered Users, Registered Users 2 Posts: 1,340 ✭✭✭bhickey


    Hi I'm getting this error message

    Are you saying that the error messages simply says "Bad image"? Can you tell what program is giving this error message? When did the problem start and do you remember installing anything new at the time? I wouldn't be certain that there's a virus issue.

    You've both AVG 2011 (disabled?) and Comodo Internet Security installed as well as Windows Defender. Is there any change you could remove AVG and Comodo and install MSE to replace Windows Defender?


  • Posts: 3,518 ✭✭✭ [Deleted User]


    bhickey wrote: »
    Are you saying that the error messages simply says "Bad image"? Can you tell what program is giving this error message? When did the problem start and do you remember installing anything new at the time? I wouldn't be certain that there's a virus issue.

    You've both AVG 2011 (disabled?) and Comodo Internet Security installed as well as Windows Defender. Is there any change you could remove AVG and Comodo and install MSE to replace Windows Defender?

    It simply says ....exe bad image. Contact your software provider for assistance. Example if I open chrome it says
    chrome.exe Bad Image
    Once I click OK it runs. I have AVG disabled and comodo disabled while I was running the scan as per the guidelines. Sorry about the ignorance but what's MSE?


  • Registered Users, Registered Users 2 Posts: 1,340 ✭✭✭bhickey


    It simply says ....exe bad image.

    Okay but WHAT says ".... exe bad image"? Is it a popup window, if so does the windows have a title? Can you post a screenshot?
    I have AVG disabled and comodo disabled while I was running the scan as per the guidelines. Sorry about the ignorance but what's MSE?

    MSE is Microsoft Security Essentials

    In your process list there's :

    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe

    so Comodo is stull running something. Could you just completely uninstall it and AVG for the moment just to rule them out because it sounds like something is interrupting the process of loading programs?


  • Registered Users, Registered Users 2 Posts: 953 ✭✭✭hearny


    Follow Bhickeys advice.

    Sounds like you could have associated a program with the .exe file association.

    Screenshots are a good idea.

    You might also try this:

    http://www.ehow.com/how_5798568_restore-exe-file-associations.html


Advertisement