Start a Conversation

Unsolved

This post is more than 5 years old

F

13970

November 25th, 2007 10:00

NTVDM CPU message on startup

Hi, I hope someone can shed some light on my problem.  My operating system is Windows Vista Home Premium and in the last week the following message started appearing when I log on.
C:\Windows\system32\runonce.exe
followed by :
16 bit MS-DOS Subsystem
The NTVDM CPU has encountered an illegal instruction.
CS:11F6 IP:63 00 63 00 65
Choose Close to terminate program.
 
When I choose "close" the sytem starts up as normal, although much slower, and then everything appears to be running ok. 
I can't remember adding anything new to the system lately, however, I did receive an email with a hoax message regarding "

http://www.symantec.com/security_response/writeup.jsp?docid=2002-011511-

0444-99&tabid=1

Has my system been infected by a virus or is this a trojan or similar?  I have checked several forums, but none have given a solution directly to my problem.
I am grateful to anyone who can help me. 
Thanks
 

3.3K Posts

November 25th, 2007 11:00

                 It sounds like you might have a trojan. Norton will probably want to charge you to get rid of it. Try the symantic system scan and see if it finds anything.
         AVG  would probably find it and rid you of it, but it definitley sounds like a trojan.
 
 Check it out here:
 

4 Posts

November 25th, 2007 12:00

Thanks for that advice.  I have McAfee Security Centre on my system, which hasn't found anything.  I loaded AVG which listed an Adware hotbar, and the rest were cookies.  As I don't really know what I'm looking for, I can't tell which, if any of these is causing the problem. 
What should I be looking for?
Thanks again,

November 25th, 2007 21:00

Hi Fitkid, Take a look at http://support.microsoft.com/kb/314106, especially the part about checking your RunOnce key to see what is going on. If you don't want to manually poke about in the registry, you can use autoruns from http://www.microsoft.com/technet/sysinternals/SystemInformation/Autoruns.mspx. The KB article applies to XP, but should be applicable to Vista as well.

4 Posts

November 26th, 2007 11:00

Thank you so much for your reply.  I have looked at the "Autoruns", but am extremely dense and can't see anything suspicious.  What should I be looking for.  Nothing really stands out. 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run   
+ !AVG Anti-Spyware AVG Anti-Spyware (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe
+ Adobe Photo Downloader Adobe Photoshop Album Starter Edition 3.2 component (Verified) Adobe Systems Incorporated c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe
+ Adobe Reader Speed Launcher Adobe Acrobat SpeedLauncher (Verified) Adobe Systems, Incorporated c:\program files\adobe\reader 8.0\reader\reader_sl.exe
+ ATICCC   c:\program files\ati technologies\ati.ace\clistart.exe
+ ISUSPM Startup Macrovision FLEXnet Connect Software Manager (Not verified) Macrovision Corporation c:\program files\common files\installshield\updateservice\isuspm.exe
+ MediaBarFileManager OD2MediaBar_VistaFileManager (Verified) On Demand Distribution ltd c:\program files\on demand distribution\od2 music manager\od2mediabar_vistafilemanager.exe
+ My Web Search Bar Search Scope Monitor MyWebSearch SearchScope Monitor (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\m3srchmn.exe
+ MyWebSearch Email Plugin My Web Search Plugin Loader (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\mwsoemon.exe
+ QuickTime Task  (Not verified) Apple Computer, Inc. c:\program files\quicktime\qttask.exe
+ RoxWatchTray RoxMMTrayApp Module (Not verified) Sonic Solutions c:\program files\common files\roxio shared\9.0\sharedcom\roxwatchtray9.exe
+ SigmatelSysTrayApp Sigmatel Audio system tray application (Not verified) SigmaTel, Inc. c:\windows\sttray.exe
+ SiteAdvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\6172\siteadv.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce   
+ InstallShieldSetup InstallShield (R) Setup Launcher (Verified) InstallShield Software Corporation c:\program files\installshield installation information\{1e2f8ae3-3437-44e6-bb75-e95751d6b83f}\setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup   
+ Bluetooth.lnk Bluetooth Tray Application (Not verified) Broadcom Corporation. c:\program files\widcomm\bluetooth software\bttray.exe
+ Picture Package Menu.lnk SonyTray.exe (Not verified) Sony Corporation c:\program files\sony corporation\picture package\picture package menu\sonytray.exe
+ Picture Package VCD Maker.lnk Residence (Not verified) Sony Corporation. c:\program files\sony corporation\picture package\picture package applications\residence.exe
+ SetPoint.lnk Logitech SetPoint Event Manager (UNICODE) (Not verified) Logitech Inc. c:\program files\setpoint\setpoint.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run   
+ DellSupport Dell Support (Not verified) Gteko Ltd. c:\program files\dellsupport\dsagnt.exe
+ EPSON Stylus C86 Series EPSON Status Monitor 3 (Not verified) SEIKO EPSON CORPORATION c:\windows\system32\spool\drivers\w32x86\3\e_s4i0r2.exe
+ My Web Search Community Tools My Web Search Community Tools (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\m3impipe.exe
+ swg GoogleToolbarNotifier (Verified) Google Inc c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe
HKLM\SOFTWARE\Classes\Protocols\Filter   
+ application/x-internet-signup insmimefilter Module  c:\program files\tiscali\tiscali internet\dlls\tiscalifilter.dll
HKLM\SOFTWARE\Classes\Protocols\Handler   
+ ms-itss Microsoft® InfoTech Storage System Library (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\information retrieval\msitss.dll
+ siteadvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\6172\siteadv.dll
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components   
+ 0   File not found: About:Home
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks   
+ AVG Anti-Spyware 7.5 AVG Anti-Spyware shellexecutehook (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved   
+ Display Monitor CPL Extension   c:\windows\system32\deskmon.dll
+ Display Panning CPL Extension   File not found: deskpan.dll
+ My Bluetooth Places BTNeighborhood DLL (Not verified) Broadcom Corporation. c:\windows\system32\btneighborhood.dll
+ Roxio DragToDisc Shell Extension DirectCD Shell Extention DLL (Verified) Sonic Solutions c:\program files\roxio\drag-to-disc\shellex.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers   
+ PDF Shell Extension PDF Shell Extension (Not verified) Adobe Systems, Inc. c:\program files\common files\adobe\acrobat\activex\pdfshell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects   
+ Adobe PDF Reader Link Helper Adobe PDF Helper for Internet Explorer (Verified) Adobe Systems, Incorporated c:\program files\common files\adobe\acrobat\activex\acroiehelper.dll
+ CBrowserHelperObject Object BAE.dll (Not verified) Dell Inc. c:\program files\bae\bae.dll
+ CPub Object McAfee Privacy Service Popup Killer 9.0 (Verified) McAfee, Inc. c:\program files\mcafee\mps\mcpopup.dll
+ EpsonToolBandKicker Class EPSON Web-To-Page (Not verified) SEIKO EPSON CORPORATION c:\program files\epson\epson web-to-page\epson web-to-page.dll
+ Google Toolbar Helper Google IE Client Toolbar (Verified) Google Inc c:\program files\google\googletoolbar2.dll
+ mwsBar BHO My Web Search Bar (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\mwsbar.dll
+ MyWebSearch Search Assistant BHO MyWebSearch Search Assistant (Not verified) MyWebSearch.com c:\program files\mywebsearch\srchastt\3.bin\mwssrcas.dll
+ scriptproxy VSCore Script Scanner (Verified) McAfee, Inc. c:\program files\mcafee\virusscan\scriptcl.dll
+ SSVHelper Class Java(TM) Platform SE binary (Verified) Sun Microsystems, Inc. c:\program files\java\jre1.6.0_01\bin\ssv.dll
+ TVEngine Helper   File not found: c:\program files\hbtools\hbtv\hbtvhelper.dll
+ Yahoo! Toolbar Helper Yahoo! Toolbar (Verified) Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn\yt.dll
+ {089FD14D-132B-48FC-8861-0048AE113215} SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\6172\siteadv.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks   
+ mwssrcas.dll MyWebSearch Search Assistant (Not verified) MyWebSearch.com c:\program files\mywebsearch\srchastt\3.bin\mwssrcas.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar   
+ epson web-to-page.dll EPSON Web-To-Page (Not verified) SEIKO EPSON CORPORATION c:\program files\epson\epson web-to-page\epson web-to-page.dll
+ googletoolbar2.dll Google IE Client Toolbar (Verified) Google Inc c:\program files\google\googletoolbar2.dll
+ McAfee SiteAdvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\6172\siteadv.dll
+ mwsbar.dll My Web Search Bar (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\mwsbar.dll
+ yt.dll Yahoo! Toolbar (Verified) Yahoo! Inc. c:\program files\yahoo!\companion\installs\cpn\yt.dll
HKLM\Software\Microsoft\Internet Explorer\Extensions   
+ @btrez.dll,-12650   c:\program files\widcomm\bluetooth software\btsendto_ie.htm
+ Uninstall BitDefender Online Scanner v8   c:\windows\bdoscandel.exe
Task Scheduler   
+ Check Updates for Windows Live Toolbar.job MSN Search Toolbar Scheduled Update Utility (Not verified) Microsoft Corporation c:\program files\windows live toolbar\msntbup.exe
+ McDefragTask.job QuickClean Console Application (Verified) McAfee, Inc. c:\program files\mcafee\mqc\qcconsol.exe
+ McQcTask.job QuickClean Console Application (Verified) McAfee, Inc. c:\program files\mcafee\mqc\qcconsol.exe
HKLM\System\CurrentControlSet\Services   
+ 0166801196070795mcinstcleanup   File not found: C:\Windows\TEMP\016680~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini
+ AOL ACS AOL Connectivity Service (Verified) AOL LLC c:\program files\common files\aol\acs\aolacsd.exe
+ AVG Anti-Spyware Guard AVG Anti-Spyware guard (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\guard.exe
+ btwdins Handles installation and removal of Bluetooth devices. (Not verified) Broadcom Corporation. c:\program files\widcomm\bluetooth software\bin\btwdins.exe
+ LBTServ Logitech Bluetooth Service (Not verified) Logitech Inc. c:\program files\common files\logitech\bluetooth\lbtserv.exe
+ McAfee HackerWatch Service McAfee HackerWatch Service (Verified) McAfee, Inc. c:\program files\common files\mcafee\hackerwatch\hwapi.exe
+ mcmscsvc Manages McAfee users. (Verified) McAfee, Inc. c:\program files\mcafee\msc\mcmscsvc.exe
+ McNASvc Allows McAfee applications to communicate securely on the local network. (Verified) McAfee, Inc. c:\program files\common files\mcafee\mna\mcnasvc.exe
+ McODS Scans specified locations on this computer for viruses and other threats. The service runs for scheduled scans and manual scans. (Verified) McAfee, Inc. c:\program files\mcafee\virusscan\mcods.exe
+ mcpromgr Manages protection problems on this computer for McAfee programs. (Verified) McAfee, Inc. c:\program files\mcafee\msc\mcpromgr.exe
+ McProxy McAfee Proxy Service (Verified) McAfee, Inc. c:\program files\common files\mcafee\mcproxy\mcproxy.exe
+ McRedirector McAfee Redirector Service (Verified) McAfee, Inc. c:\program files\common files\mcafee\redirsvc\redirsvc.exe
+ McShield Scans files for viruses and other threats when they are accessed by this computer. (Verified) McAfee, Inc. c:\program files\mcafee\virusscan\mcshield.exe
+ McSysmon Monitors potentially unauthorized changes to this computer. (Verified) McAfee, Inc. c:\program files\mcafee\virusscan\mcsysmon.exe
+ MDM Supports local and remote debugging for Visual Studio and script debuggers. If this service is stopped, the debuggers will not function properly. (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\vs7debug\mdm.exe
+ MpfService MpfService (Verified) McAfee, Inc. c:\program files\mcafee\mpf\mpfsrv.exe
+ MPS9 Provides identity protection and parental controls. (Verified) McAfee, Inc. c:\program files\mcafee\mps\mps.exe
+ MSK80Service This service filters e-mail messages on your computer (Verified) McAfee, Inc. c:\program files\mcafee\msk\msksrver.exe
+ MyWebSearchService My Web Search Bar (Not verified) MyWebSearch.com c:\program files\mywebsearch\bar\3.bin\mwssvc.exe
+ RoxWatch9 RoxSniffer9 Module (Not verified) Sonic Solutions c:\program files\common files\roxio shared\9.0\sharedcom\roxwatch9.exe
+ SiteAdvisor Service Provides low-level support for McAfee SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\6172\saservice.exe
+ STacSV Manages SigmaTel Audio Universal Jack configurations. (Not verified) SigmaTel, Inc. c:\program files\sigmatel\c-major audio\wdm\stacsv.exe
HKLM\System\CurrentControlSet\Services   
+ Asapi ASAPI (Not verified) VOB Computersysteme GmbH c:\windows\system32\drivers\asapi.sys
+ ASCTRM TR Manager (Not verified) Windows (R) 2000 DDK provider c:\windows\system32\drivers\asctrm.sys
+ AVG Anti-Spyware Driver  (Verified) GRISOFT LTD c:\program files\grisoft\avg anti-spyware 7.5\guard.sys
+ AvgAsCln AVG7 Clean Driver (Verified) GRISOFT LTD c:\windows\system32\drivers\avgascln.sys
+ BTWUSB Driver for Bluetooth USB Devices (Not verified) Broadcom Corporation. c:\windows\system32\drivers\btwusb.sys
+ cdrbsdrv CD-ROM Filter Driver for Windows2000/xp (Not verified) B.H.A Corporation c:\windows\system32\drivers\cdrbsdrv.sys
+ cdrbsvsd   File not found: C:\Windows\System32\Drivers\cdrbsvsd.sys
+ DLABMFSM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlabmfsm.sys
+ DLABOIOM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlaboiom.sys
+ DLACDBHM Shared Driver Component (Verified) Sonic Solutions c:\windows\system32\drivers\dlacdbhm.sys
+ DLADResM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dladresm.sys
+ DLAIFS_M Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlaifs_m.sys
+ DLAOPIOM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlaopiom.sys
+ DLAPoolM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlapoolm.sys
+ DLARTL_M Shared Driver Component (Verified) Sonic Solutions c:\windows\system32\drivers\dlartl_m.sys
+ DLAUDF_M Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlaudf_m.sys
+ DLAUDFAM Drive Letter Access Component (Verified) Sonic Solutions c:\windows\system32\dla\dlaudfam.sys
+ DRVMCDB Device Driver (Verified) Sonic Solutions c:\windows\system32\drivers\drvmcdb.sys
+ DRVNDDM Device Driver Manager (Verified) Sonic Solutions c:\windows\system32\drivers\drvnddm.sys
+ DSproct Process Trigger Driver (Not verified) Gteko Ltd. c:\program files\dellsupport\gtaction\triggers\dsproct.sys
+ dsunidrv GUniDriver (Not verified) Gteko Ltd. c:\program files\dellsupport\drivers\dsunidrv.sys
+ IpInIp IP in IP Tunnel Driver  File not found: system32\DRIVERS\ipinip.sys
+ mfebopk Buffer Overflow Protection Driver (Verified) McAfee, Inc. c:\windows\system32\drivers\mfebopk.sys
+ mfehidk Host Intrusion Detection Link Driver (Verified) McAfee, Inc. c:\windows\system32\drivers\mfehidk.sys
+ mferkdk VSCore Code Analysis Driver (Verified) McAfee, Inc. c:\windows\system32\drivers\mferkdk.sys
+ mfesmfk System Monitor Filter Driver (Verified) McAfee, Inc. c:\windows\system32\drivers\mfesmfk.sys
+ MHNDRV Multimedia Home Network component driver (Not verified) Microsoft Corporation c:\windows\system32\drivers\mhndrv.sys
+ MPFP McAfee Personal Firewall Plus Driver (Verified) McAfee, Inc. c:\windows\system32\drivers\mpfp.sys
+ NwlnkFlt IPX Traffic Filter Driver  File not found: system32\DRIVERS\nwlnkflt.sys
+ NwlnkFwd IPX Traffic Forwarder Driver  File not found: system32\DRIVERS\nwlnkfwd.sys
+ PxHelp20 Px Engine Device Driver for Windows 2000/XP (Not verified) Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls   
+ C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL Google Desktop (Not verified) Google c:\program files\google\google desktop search\googledesktopnetwork3.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify   
+ LBTWlgn Logitech Bluetooth Service (Not verified) Logitech Inc. c:\program files\common files\logitech\bluetooth\lbtwlgn.dll
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors   
+ Bluetooth Printer Port bthcrp DLL (Not verified) Broadcom Corporation. c:\windows\system32\bthcrp.dll
Thanks for your patience!
 

November 27th, 2007 08:00

Hi Fitkid,
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce   
+ InstallShieldSetup InstallShield (R) Setup Launcher (Verified) InstallShield Software Corporation c:\program files\installshield installation information\{1e2f8ae3-3437-44e6-bb75-e95751d6b83f}\setup.exe
Whack it and see what happens.  (To get rid of it, in autoruns just right click it and pick delete).

4 Posts

November 27th, 2007 14:00

Hi Stupidcomputernickname!!  Thanks for taking the time to look at all that spaghetti!  I have followed your instructions, and am afraid that the problem is still there, exactly the same!  I was convinced it would do the trick.  I'm beginning to think I'm stuck with this thing.  My system won't allow me to restore to a previous point, I've already tried.  Any other suggestions are most gratefully received. 
Thank you for your patience and help!
 

November 29th, 2007 01:00

Hi Fitkid, If you deleted the key, and it came back the next time you booted, something is adding it, which suggests that you are infected by a virus/malware/trojan. Are your virus sigs & stuff up to date? Unfortunately, if you really are infected, the best thing for you to do is wipe the machine and reinstall everything. Sorry I couldn't be of more help :-(
No Events found!

Top