fltlib.dll error

sdforever

Banned
Local time
12:03 AM
Messages
6
I suddenly get this problem with fltlib.dll tonight,which I never had....
Every program I try to open,it says the process name followed by BAD IMAGE



and fltlib.dll is either not designed to run on Windows or it contains an error.I can open all the programs normally,but this tab is so boring.
Please anyone tell me what to do.pls.
thank you
 

My Computer

OS
Windows 7 Ultimate
Are you running Ad-aware? Also, what version of Windows7 Ultimate are you running? (RC or RTM)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Since this is a Microsoft file, from what I see on the Internet, running scf /scannow from a command prompt should bring it back.

As Jacee indicates, it appears that Ad-Aware does something to the file or may remove it. If you are using that, I'd recommend uninstalling it before running scf
 

My Computer

Computer Manufacturer/Model Number
Gateway, Toshiba Laptop, and Home Brew
OS
Windows 7 x64 HP, Windows 7 HP, Windows 7 Ult
CPU
Intel I3, Cerelon, Pentium 4 @ 3Ghz
Motherboard
Intel, Intel, Asus
Memory
8G, 3G, 3G
Graphics Card(s)
On-board Intel, On-board nVidia, nVIDIA card
Sound Card
on-board, on-board, SoundBlaster
Monitor(s) Displays
Hannspree HF237, Toshiba, SyncMaster 931B
Screen Resolution
default (all)
Hard Drives
1T internal, 320G internal, 160G internal, 1T networked
PSU
300w, unk, 650w
Case
black, black, grey
Cooling
air (all)
Keyboard
standard wired (all)
Mouse
standard wired (all)
Internet Speed
6M down, 768K up
Other Info
Home LAN through Linksys hub to 4 port and wireless switch/router. Networked HP 2600n. Wife's computer running Windows 7, and spare laptop running Ubuntu "Karmic Kola" (9.10).
This could also be a malware infection ... downloading bad codecs or using someone else's infected file(s) from an infected USB flash device.

We've seen a lot of [process name followed by BAD IMAGE] in the malware forums. I would suspect a TDSS infection.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi there

Hi there,first of all I would like to thank you for your responses.
I do not have Ad-Aware installed in my pc,but if it is an infection,then can you please tell me what to do?
I also forgot to mention that I tried sfc/ scannow but in the end it said that some of the drivers could not be fixed.
Waiting for your answers,Donald.
 

My Computer

OS
Windows 7 Ultimate
Download Malwarebytes' Anti-Malware to your desktop
|MG| Malwarebytes Anti-Malware 1.41 Download
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location (desktop). Copy and Paste that log into your next reply.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Malwarebytes' Anti-Malware 1.41
Database version: 2905
Windows 6.1.7600

10/4/2009 9:32:33 PM
mbam-log-2009-10-04 (21-32-29).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 226038
Time elapsed: 46 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117972.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117974.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117975.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117976.exe (Trojan.Dropper) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP223\A0123563.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP186\A0102670.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP191\A0106936.exe (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP201\A0109316.exe (Trojan.Agent) -> No action taken.
C:\Users\El Mariachi\Documents\KONAMI\Pro Evolution Soccer 6\save\folder2\folder2.exe (Worm.Sohanad) -> No action taken.
F:\System Volume Information\_restore{0747B80E-069B-4F60-9144-20CDDAAA6949}\RP192\A0064750.exe (Adware.EShoper) -> No action taken.
 

My Computer

OS
Windows 7 Ultimate
Click on MBam, then click update ....
Run it again, but this time make sure that everything is checked, and click Remove Selected.

Save the log again and post it in your next reply

BTW ...Worm.Sohanad is a worm that spreads itself by sending links to your contacts in messengers like Yahoo, AOL and Windows Live messengers. It changes the Internet Explorer (IE) home page and doesn't let you change the homepage address. It also disables Registry Editor, Task Manager and the Run option in Start-menu. Bugs in Internet explorer is the cause of such virus attacks.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Malwarebytes' Anti-Malware 1.41
Database version: 2905
Windows 6.1.7600

10/4/2009 9:32:47 PM
mbam-log-2009-10-04 (21-32-47).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 226038
Time elapsed: 46 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117972.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117974.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117975.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP217\A0117976.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP223\A0123563.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP186\A0102670.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP191\A0106936.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{0A0BC115-79E4-4FBC-9317-D843A6246D39}\RP201\A0109316.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\El Mariachi\Documents\KONAMI\Pro Evolution Soccer 6\save\folder2\folder2.exe (Worm.Sohanad) -> Quarantined and deleted successfully.
F:\System Volume Information\_restore{0747B80E-069B-4F60-9144-20CDDAAA6949}\RP192\A0064750.exe (Adware.EShoper) -> Quarantined and deleted successfully.

Sorry that was the log before the removing last night.I did remove them but the problems keep poping out anyway.Waiting for your response Jaycee.
 

My Computer

OS
Windows 7 Ultimate
Looks like your restore points are all infected... delete all of these, and rescan ( may have to turn "OFF" system restore !!! ) once the scan comes up 'clean', turn "ON" restore, and make a new restore point... then rescan, and make sure you are 'clean' again.... DeepFreeze would have prevented any infection, and you would NOT have had to go through the mill like this, but if you use DeepFreeze, you need to make sure all is 'clean and green...'
 

My Computer

Computer Manufacturer/Model Number
Samsung Q70 Notebook
OS
Windows 7 7600 OEM
CPU
Intel Duo T7500
Motherboard
Samsung
Memory
2Gb
Graphics Card(s)
Nvidia 512Mb ram
Sound Card
Realtek HD
Monitor(s) Displays
Built in
Screen Resolution
1900x800
Hard Drives
Fujitsu 200Gb SATA x 2
delete ur system restore.. clean ur system then go to this page fltlib.dll download - free dll files

download the file.. then locate this file in ur c drive or in windows 7 drive.. if the file version is same then copy that file and save it in desktop... then copy the file which u have downloaded and replace it with the infected file in windows 7 drive..

hopes that works
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
have u try any registry scan.. u must try it first
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
I tried to replace the file.....but the system won't let me do that.....saying that I do not have the rights to do it......because i am not a admin.......but i don't know why because my user has admin rights.....
 

My Computer

OS
Windows 7 Ultimate
try it in safe mode..
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
if u hav malwarebyte there is option in tools tab for deletin file namely file assasin.. try that
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
Do you have an active antivirus program running? I f you do, please run a 'complete' scan with it.
Also, what Firewall are you using?

This is old, but please read it as it's still very much relevant today:
How SOHANAD Became So Huge
Take the following steps to help prevent infection on your system:
•Enable a firewall on your computer.
•Get the latest computer updates for all your installed software.
•Use up-to-date antivirus software.
•Use caution when opening attachments and accepting file transfers.
•Use caution when clicking on links to web pages.
•Avoid downloading pirated software.
•Protect yourself against social engineering attacks.
•Use strong passwords.
disable Autorun in Windows: How to correct "disable Autorun registry key" enforcement in Windows

Are you still getting an error mesage about fltlib.dll?
If so, what does the message say?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hey folks thanks for everything there really......but the problem was solved after i replaced the old fltlib.dll with a new copy.......thank you guys for answering to me....thank you jacee and neoasr.....thank you reallly.......
 

My Computer

OS
Windows 7 Ultimate
dats gud
 

My Computer

OS
Windows 7 ultimate 32bit OEM 6.1 Build7600
CPU
Core 2 Duo CPU E7400 2.8GHz
Motherboard
Mercury PIG31T
Memory
2 GB RAM
Graphics Card(s)
NVIDIA GeForce 8400 GS
Sound Card
VIA HD
Monitor(s) Displays
Samsung SyncMaster 2033
Screen Resolution
1600*900
Hard Drives
500 GB
If F:\ is a USB flash drive, please download Flash_Disinfector http://www.techsupportforum.com/sectools/s...Disinfector.exe
or
http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe

Next, turn off the Autorun feature in Windows
http://www.howtogeek.com/howto/windo...nd-usb-drives/

*** Note: Be sure to insert your flashdrives before you begin!
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.

***Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

Change your passwords on the infected computer, using a known "Clean" computer. Do not chane them from the "infected" computer.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top