Author Topic: [Inactive] Windows Vista: {program}.exe - Bad Image errors  (Read 1963 times)

0 Members and 1 Guest are viewing this topic.

Offline matrixebiz

  • Bronze Member
  • Posts: 3
[Inactive] Windows Vista: {program}.exe - Bad Image errors
« on: April 24, 2012, 09:27:01 pm »
Please help with errors after login. Long pop-up error message
exe - Bad Image     ................ \msvcp80.dll is either not designed to run .............

DDS
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Margaret at 23:19:45 on 2012-04-24
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.2.1033.18.3002.1804 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Pogo Games\PGMTrusted.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11g_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\lpksetup.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Gamers Unite! Snag Bar BHO: {26a7ca19-7d58-411d-b2da-f1b0324cbffc} - c:\program files\gamers unite! snag bar\Toolbar.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Gamers Unite! Snag Bar: {25515a79-c1c7-4b97-97f8-31a711694487} - c:\program files\gamers unite! snag bar\Toolbar.dll
uRun: [Sidebar] "c:\program files\windows sidebar\Sidebar.exe" /autorun
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [Facebook Update] "c:\users\margaret\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
Trusted Zone: facebook.com\apps
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{80E284BB-5892-487C-A038-3BE65D485C49} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{ABA804B7-C7A4-4750-BA68-39F1BBCAC362} : DhcpNameServer = 10.188.15.20
Notify: igfxcui - igfxdev.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 PGMTrusted;PGMTrusted;c:\program files\pogo games\PGMTrusted.exe [2012-1-4 519888]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-23 365952]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 112128]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-3-24 136176]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-23 193840]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-3-24 136176]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-25 02:18:00   6734704   ----a-w-   c:\programdata\microsoft\microsoft antimalware\definition updates\{697f84bf-0121-4f5d-9064-2c4f98bf4cf2}\mpengine.dll
2012-04-25 02:06:10   --------   d-sh--w-   C:\$RECYCLE.BIN
2012-04-25 01:51:14   98816   ----a-w-   c:\windows\sed.exe
2012-04-25 01:51:14   518144   ----a-w-   c:\windows\SWREG.exe
2012-04-25 01:51:14   256000   ----a-w-   c:\windows\PEV.exe
2012-04-25 01:51:14   208896   ----a-w-   c:\windows\MBR.exe
2012-04-25 01:46:14   --------   d-----w-   c:\program files\CCleaner
2012-04-25 01:40:52   --------   d-----w-   c:\users\margaret\appdata\roaming\Malwarebytes
2012-04-25 01:40:39   --------   d-----w-   c:\programdata\Malwarebytes
2012-04-25 01:40:37   22344   ----a-w-   c:\windows\system32\drivers\mbam.sys
2012-04-25 01:40:37   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2012-04-24 21:05:07   --------   d-----w-   c:\users\margaret\appdata\local\Facebook
2012-04-23 04:06:09   --------   d-----w-   c:\programdata\PlayfulAge
2012-04-23 04:00:50   --------   d-----w-   c:\program files\iWin.com
2012-04-22 06:02:40   --------   d-----w-   c:\programdata\e-FunSoftGames
2012-04-22 05:58:54   --------   d-----w-   C:\Games
2012-04-22 05:57:34   --------   d-----w-   c:\programdata\PogoDGC
2012-04-22 05:57:03   --------   d-----w-   c:\program files\Pogo Games
2012-04-15 02:30:02   --------   d-----w-   c:\program files\Gamers Unite! Snag Bar
2012-04-11 14:52:32   5120   ----a-w-   c:\windows\system32\wmi.dll
2012-04-11 14:52:32   172032   ----a-w-   c:\windows\system32\wintrust.dll
2012-04-11 14:52:32   157696   ----a-w-   c:\windows\system32\imagehlp.dll
2012-04-11 14:52:32   12800   ----a-w-   c:\windows\system32\drivers\fs_rec.sys
2012-04-11 14:52:16   3602816   ----a-w-   c:\windows\system32\ntkrnlpa.exe
2012-04-11 14:52:16   3550080   ----a-w-   c:\windows\system32\ntoskrnl.exe
2012-04-10 21:38:33   2409784   ----a-w-   c:\program files\windows mail\OESpamFilter.dat
2012-03-27 06:04:49   6734704   ----a-w-   c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
.
==================== Find3M  ====================
.
2012-04-25 01:41:27   798208   ----a-w-   c:\windows\system32\dbghelp.dll
2012-03-24 17:52:42   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-22 20:30:56   98816   ----a-w-   c:\windows\system32\mfps.dll
2012-03-22 20:29:01   4096   ----a-w-   c:\windows\system32\drivers\fr-fr\dxgkrnl.sys.mui
2012-03-22 20:29:01   4096   ----a-w-   c:\windows\system32\drivers\en-us\dxgkrnl.sys.mui
2012-03-22 20:29:01   369664   ----a-w-   c:\windows\system32\WMPhoto.dll
2012-03-22 20:29:01   252928   ----a-w-   c:\windows\system32\dxdiag.exe
2012-03-22 20:29:01   195584   ----a-w-   c:\windows\system32\dxdiagn.dll
2012-03-22 20:29:00   974848   ----a-w-   c:\windows\system32\WindowsCodecs.dll
2012-03-22 20:29:00   519680   ----a-w-   c:\windows\system32\d3d11.dll
2012-03-22 20:29:00   321024   ----a-w-   c:\windows\system32\PhotoMetadataHandler.dll
2012-03-22 20:29:00   189440   ----a-w-   c:\windows\system32\WindowsCodecsExt.dll
2012-03-22 18:55:37   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2012-03-22 17:27:47   505392   ----a-w-   c:\windows\system32\msvcp71.dll
2012-03-22 17:27:47   353840   ----a-w-   c:\windows\system32\msvcr71.dll
2012-03-22 17:27:46   1066544   ----a-w-   c:\windows\system32\MFC71.dll
2012-03-22 17:27:46   1053232   ----a-w-   c:\windows\system32\MFC71u.dll
2012-02-28 01:18:55   1799168   ----a-w-   c:\windows\system32\jscript9.dll
2012-02-28 01:11:21   1427456   ----a-w-   c:\windows\system32\inetcpl.cpl
2012-02-28 01:11:07   1127424   ----a-w-   c:\windows\system32\wininet.dll
2012-02-28 01:03:16   2382848   ----a-w-   c:\windows\system32\mshtml.tlb
2012-02-15 15:01:50   4547944   ----a-w-   c:\windows\system32\usbaaplrc.dll
2012-02-15 15:01:50   43520   ----a-w-   c:\windows\system32\drivers\usbaapl.sys
2012-02-14 15:45:30   219648   ----a-w-   c:\windows\system32\d3d10_1core.dll
2012-02-14 15:45:30   160768   ----a-w-   c:\windows\system32\d3d10_1.dll
2012-02-13 14:12:08   1172480   ----a-w-   c:\windows\system32\d3d10warp.dll
2012-02-13 13:47:57   683008   ----a-w-   c:\windows\system32\d2d1.dll
2012-02-13 13:44:40   1068544   ----a-w-   c:\windows\system32\DWrite.dll
2012-02-02 15:16:25   2044416   ----a-w-   c:\windows\system32\win32k.sys
2012-01-31 12:44:05   237072   ------w-   c:\windows\system32\MpSigStub.exe
.
============= FINISH: 23:20:34.57 ===============


ATTACH
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 22/03/2012 4:12:03 PM
System Uptime: 24/04/2012 11:02:58 PM (0 hours ago)
.
Motherboard: Hewlett-Packard |  | 3612
Processor: Pentium(R) Dual-Core CPU       T4200  @ 2.00GHz | CPU | 1200/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 287 GiB total, 241.318 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.719 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Acrobat.com
ActiveCheck component for HP Active Support Library
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader 9
Adobe Shockwave Player
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Driver Installation Program
Bonjour
CCleaner
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CyberLink DVD Suite
CyberLink YouCam
ESU for Microsoft Vista
Facebook Video Calling 1.2.0.159
Gamers Unite! Snag Bar
Google Toolbar for Internet Explorer
Google Update Helper
HDAUDIO Soft Data Fax Modem with SmartCP
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.7
HP Help and Support
HP Quick Launch Buttons 6.40 H2
HP Total Care Advisor
HP Total Care Setup
HP Update
HP User Guides 0118
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
Intel(R) Graphics Media Accelerator Driver
iTunes
Java Auto Updater
Java(TM) 6 Update 31
Java(TM) 6 Update 7
LabelPrint
LightScribe System Software  1.14.17.1
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Works
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee Reveal
NetWaiting
Norton Internet Security
Pizza Chef 2 (remove only)
Pogo Games (remove only)
Power2Go
PowerDirector
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek USB 2.0 Card Reader
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
.
==== Event Viewer Messages From Past Week ========
.
24/04/2012 9:39:40 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
24/04/2012 9:39:40 PM, Error: Service Control Manager [7000]  - The Windows Search service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
24/04/2012 9:16:48 PM, Error: Service Control Manager [7023]  - The Security Center service terminated with the following error:  Security Center is not a valid Win32 application.
24/04/2012 9:14:51 PM, Error: Service Control Manager [7000]  - The Norton Internet Security service failed to start due to the following error:  The system cannot find the path specified.
24/04/2012 9:14:50 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
24/04/2012 9:14:50 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
24/04/2012 9:14:46 PM, Error: Microsoft-Windows-Dhcp-Client [1002]  - The IP address lease 192.168.0.10 for the Network Card with network address 00265E731A7C has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
24/04/2012 9:07:01 AM, Error: Microsoft-Windows-Kernel-General [5]  - {Registry Hive Recovered} Registry hive (file): '\??\C:\Users\Margaret\AppData\Local\Microsoft\Windows\UsrClass.dat' was corrupted and it has been recovered. Some data might have been lost.
24/04/2012 3:06:36 PM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B68-F52A-11D8-B9A5-505054503030}
24/04/2012 11:19:28 PM, Error: Microsoft-Windows-LanguagePackSetup [1003]  - CBS error 0x800f0825 reported while operating on UI Language Pack for fr-FR
24/04/2012 11:03:35 PM, Error: Microsoft Antimalware [3002]  - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed.     Feature: Behavior Monitoring     Error Code: 0x80004005     Error description: Unspecified error      Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
24/04/2012 11:03:32 PM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  SRTSP SRTSPX
24/04/2012 11:03:32 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the LightScribeService Direct Disc Labeling Service service to connect.
24/04/2012 11:03:32 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device service to connect.
24/04/2012 11:03:32 PM, Error: Service Control Manager [7000]  - The Parallel port driver service failed to start due to the following error:  The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
24/04/2012 11:03:32 PM, Error: Service Control Manager [7000]  - The Apple Mobile Device service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
24/04/2012 10:00:44 PM, Error: Service Control Manager [7030]  - The PEVSystemStart service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
23/04/2012 6:45:18 PM, Error: Microsoft-Windows-DistributedCOM [10016]  - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {A47979D2-C419-11D9-A5B4-001185AD2B89}  to the user Margaret-PC\Margaret SID (S-1-5-21-4212146639-792667624-4018200256-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
18/04/2012 8:08:53 PM, Error: Service Control Manager [7031]  - The Apple Mobile Device service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
.
==== End Of File ===========================
« Last Edit: April 24, 2012, 09:37:45 pm by Hoov »



Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 24717
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #1 on: April 24, 2012, 09:40:33 pm »
Hello, welcome to SpywareHammer.

I go by Hoov, and I will be helping you with your problem. I must ask you to do a few things for me.

First, tell me everything that you have done, if anything, to try and fix this problem.Also tell me any other problems you are having, no matter how small or long you have been dealing with them.

Second, please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause those helping you to pull out thier hair.

Third, follow my instructions - If you can't for some reason, or if you don't understand something, please tell me. If you deviate from my instructions, tell me, it may make a difference on where we go.

Fourth, Have faith. I will do all I can to get your computer working, and if I can't - someone else here will know something else to try.

Fifth, if we start this fix, I need you to stick with me until the end. Just because your computer is running better does not mean it is fixed.

Before we start trying to fix your computer, you need to make sure your data is backed up. Also let me know of any software you have running that encrypts your harddrive.

One last thing, I need you to tell me if this computer belongs to a school or to a company or orginization of some kind. If it does, please let me know. Also tell me if there is an IT department responsible for this computer.

Now onto trying to fix your computer.

Is this the only error message that you get, or does it change? What happened to your computer just before this started? Did the computer crash, install a program, uninstall a program, windows update?

Did you have any problems before this started?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline matrixebiz

  • Bronze Member
  • Posts: 3
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #2 on: April 25, 2012, 04:44:27 am »
Hello, thank you for responding. This is a friends computer and all she really does is use the internet so thinking it must be some Spyware infection.
When trying to run itunes, Adobe and some other programs I get this error mesage and the program does not start. First noticed it when during login. I've tried malwarebytes, combofix, ccleaner and tddskiller also tried sfc /scannow but said some files couldn't be fixed.
What do you want me to do next?

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 24717
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #3 on: April 25, 2012, 07:24:16 am »
I am not convinced it is malware, it might be a simple case of using an older program on a new Operating System. Try going to this page and downloading the file and installing it. Once you have done that, reboot your computer and test it out and see if the problem is still around.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline matrixebiz

  • Bronze Member
  • Posts: 3
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #4 on: April 25, 2012, 04:31:33 pm »
Tried that and still the same errors :(

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 24717
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #5 on: April 25, 2012, 05:04:34 pm »
I need you to go to the administration tools in Vista / Windows 7. They are in the Control Panel. Open the Admin tools, then open the event viewer. Over on the left hand side expand the window category and then click on  System. Then up at the top click on Action and then click on Save Events As, type in system as the file name,  make sure file type EVTX is selected, and then navigate so it will save the file to your desktop, then click save. Over on the left hand side and click on Application. Then up at the top click on Action and then click on Save Events As, type in application as the file name,  make sure file type EVTX is selected, and then navigate so it will save the file to your desktop, then click save. Zip them both up into a single zip file, post them back here in your next reply as attachments.


Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on click on the change parameters option.




  • Once you are in there, check all four boxes and then click on the OK button.



  • Now click the Start Scan button.



  • This is what you will see during the scan,


  • and this is what you will see when the scan is done if any threats are found. Don't change any of the recommended actions. Click the continue button.



  • Once the fix is done you might see this,




  • or it may ask you to reboot the computer to complete the process. Click on Reboot Now.

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 24717
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Windows Vista: {program}.exe - Bad Image errors
« Reply #6 on: May 28, 2012, 06:43:11 pm »
matrixebiz, do you still need help?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!