error message at start up?
Page 1 of 2 12 LastLast
Results 1 to 15 of 22

Thread: error message at start up?

  1. #1
    Join Date
    Jun 2001
    Location
    Adelaide/Sth Australia
    Posts
    1,067

    error message at start up?

    Hi all,

    My folks have a new computer with Vista on it. The computer itself was pre-setup and for the main, has worked flawlessly. They use Zone Alarm Pro and since the last update (a couple of days ago) there has been at start up a command prompt window. Syntax: C:\Windows\System32\MSLATE~1.EXE and an accompanying dialogue box (same syntax as the command prompt window but also.

    ‘The NTVDM CPU has encountered an illegal instruction. CS.11d3 IP:0163 65 6e 74 66 Choose Close to terminate the application’

    Any ideas?

    Cheers,

    DrBass
    ASDL M/Dem | Router | 10/100 Eth/net Switch | Win 2K Server SP1 | Linux RH 7.2 | XP Pro SP1 x n | Toshiba 1410 Notebook – XP Pro | iPAC Pkt PC | >> NAV2K>> ZA Pro |

    --------------------
    All YOUR BASE ARE BELONG TO US!!

  2. #2
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Does it say something like "16 bit MS-DOS Subsystem" at the beginning of the error message?

  3. #3
    Join Date
    Jun 2001
    Location
    Adelaide/Sth Australia
    Posts
    1,067
    Hi Broni,

    No, the message is pretty much verbatim to the two examples given above ie i copied the command prompt title syntax and then the error message.

    cheers,

    DB
    ASDL M/Dem | Router | 10/100 Eth/net Switch | Win 2K Server SP1 | Linux RH 7.2 | XP Pro SP1 x n | Toshiba 1410 Notebook – XP Pro | iPAC Pkt PC | >> NAV2K>> ZA Pro |

    --------------------
    All YOUR BASE ARE BELONG TO US!!

  4. #4
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Download HijackThis:
    http://www.trendsecure.com/portal/en...kthis/download
    Click on Download HijackThis Installer
    Post HijackTHis log.

  5. #5
    Join Date
    Jun 2001
    Location
    Adelaide/Sth Australia
    Posts
    1,067
    OK, in the process of... get back within the day

    cheers,

    db
    ASDL M/Dem | Router | 10/100 Eth/net Switch | Win 2K Server SP1 | Linux RH 7.2 | XP Pro SP1 x n | Toshiba 1410 Notebook – XP Pro | iPAC Pkt PC | >> NAV2K>> ZA Pro |

    --------------------
    All YOUR BASE ARE BELONG TO US!!

  6. #6
    Join Date
    Jun 2001
    Location
    Adelaide/Sth Australia
    Posts
    1,067
    HiJack this log posted below, cheers:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:23:55 PM, on 1/06/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Acer\Empowering Technology\SysMonitor.exe
    C:\Windows\system32\taskeng.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
    C:\Program Files\SiS VGA Utilities\SiSTray.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
    C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.au.acer.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.au.acer.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
    O4 - HKLM\..\Run: [SiSTray] %ProgramFiles%\SiS VGA Utilities\SiSTray.exe
    O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
    O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\Windows\system32\mslatest_updt.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
    O13 - Gopher Prefix:
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
    O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

    --
    End of file - 5949 bytes
    ASDL M/Dem | Router | 10/100 Eth/net Switch | Win 2K Server SP1 | Linux RH 7.2 | XP Pro SP1 x n | Toshiba 1410 Notebook – XP Pro | iPAC Pkt PC | >> NAV2K>> ZA Pro |

    --------------------
    All YOUR BASE ARE BELONG TO US!!

  7. #7
    Join Date
    Jun 2008
    Posts
    1

    I'm having the same problem

    I'm having the same problem but running XP2. I am also getting the 16 bit error message. Can you please help?

  8. #8
    Join Date
    Jun 2008
    Posts
    4
    I'm having the same problem too, i'm running vista ultimate & im getting the 16 bit error message The NTVDM CPU has encountered an illegal instruction. My problem started after installing nero8 it asked for restart when install finished since that restart every logon i get the message......any help would be greatly appreciated. The problem may not be related to nero but that's when i recall the problem starting...

  9. #9
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    XP2 User, greekmafioso - you both need to start own topics, please.

  10. #10
    Join Date
    Jun 2008
    Posts
    4
    why must i start a new topic if im experiencing the exact same problem??

  11. #11
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    drbass
    There is some infection there, but I also need to clarify something.
    Is Zone Alarm your firewall, and NOD, your antivirus?

    Print these instructions out.

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    DISCONNECT PHYSICALLY FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebyt...are_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Post new HijackThis log.

  12. #12
    Join Date
    Jun 2008
    Posts
    1

    mslate~1.exe

    I am also haveing the same problem after installing nero 8.3.2.1 found on mininova. Currently I am scaning computer with AVG antivirus but it has not found anything yet.

  13. #13
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    zeus_excellent
    You need to start your own topic.

  14. #14
    Join Date
    Jun 2001
    Location
    Adelaide/Sth Australia
    Posts
    1,067
    Hi Broni,

    I completed both tasks as required. Firstly, the SUPERAntiSpyware found some things (log posted below this paragraph). Secondly, Malwarebyte found no issues at all. Finally, thanks for your ongoing support, it is appreciated.

    regards,

    DB

    SUPERAntiSpyware Log:
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 06/02/2008 at 11:39 AM

    Application Version : 4.1.1046

    Core Rules Database Version : 3472
    Trace Rules Database Version: 1463

    Scan type : Complete Scan
    Total Scan Time : 00:36:55

    Memory items scanned : 198
    Memory threats detected : 0
    Registry items scanned : 5631
    Registry threats detected : 0
    File items scanned : 75715
    File threats detected : 16

    Trojan.Unknown Origin
    C:\USERS\JOY\APPDATA\LOCAL\TEMP\~DFDA9F.TMP

    Adware.Tracking Cookie
    C:\Users\Joy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
    C:\Users\Joy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
    C:\Users\Joy\AppData\Roaming\Microsoft\Windows\Cookies\Low\joy@hitbox[1].txt
    C:\Users\Joy\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@adbrite[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@apmebf[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@clicktorrent[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@hitbox[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@mediaonenetwork[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@statcounter[1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
    C:\Users\pjk\AppData\Roaming\Microsoft\Windows\Cookies\Low\pjk@xiti[1].txt
    ASDL M/Dem | Router | 10/100 Eth/net Switch | Win 2K Server SP1 | Linux RH 7.2 | XP Pro SP1 x n | Toshiba 1410 Notebook – XP Pro | iPAC Pkt PC | >> NAV2K>> ZA Pro |

    --------------------
    All YOUR BASE ARE BELONG TO US!!

  15. #15
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Very good.
    I need new HJT log.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •