Author Topic: Malwarebytes will not install?  (Read 11271 times)

0 Members and 1 Guest are viewing this topic.

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #15 on: August 23, 2015, 05:14:17 PM »
Hi Corrine this old computer was working good but every once in a while it will hang on the Welcome screen.
That is why I attempted to update Malwarebytes.
I will follow your instructions as always.

V_V I still have Regcleaner and use it to find MBAM hold outs.

What I attempted last night.
I followed the Hotfix instructions in the page below last night after midnight.

http://www.techsupportforum.com/forums/f50/malwarebytes-error-0xc000001d-1019058.html

That got Malwarebytes to partially download and look normal but it could not scan or update. Then it poped the 0xc000001d again.

Most of my problems may be with the slow dial up.



Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #16 on: August 23, 2015, 06:57:05 PM »
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:23-08-2015
Ran by Rosie Sparks (administrator) on RON (23-08-2015 14:38:04)
Running from C:\Documents and Settings\Rosie Sparks\Desktop
Loaded Profiles: Rosie Sparks (Available Profiles: Rosie Sparks & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
(Bitdefender) C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvsvc32.exe
(BroadJump, Inc.) C:\Program Files\BroadJump\Client Foundation\CFD.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(Microsoft Corporation) C:\WINDOWS\System32\RUNDLL32.EXE
(Microsoft® Corporation) C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
(Microsoft Corporation) C:\WINDOWS\System32\wscntfy.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office\WINWORD.EXE
(Creative Technology Ltd.) C:\WINDOWS\System32\devldr32.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /install
HKLM\...\Run: [BJCFD] => C:\Program Files\BroadJump\Client Foundation\CFD.exe [368706 2002-09-10] (BroadJump, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [385024 2008-01-31] (Apple Inc.)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [644696 2007-05-14] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1603152 2007-04-03] (CANON INC.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKU\S-1-5-21-682003330-813497703-1708537768-1005\...\Run: [MoneyAgent] => C:\Program Files\Microsoft Money\System\Money Express.exe [122940 1999-08-04] (Microsoft Corporation)
HKU\S-1-5-21-682003330-813497703-1708537768-1005\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => c:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [437160 2007-02-26] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2004-05-16]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk [2009-04-23]
ShortcutTarget: Microsoft Works Calendar Reminders.lnk -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe (Microsoft® Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk [2012-11-02]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [SlowFile Icon Overlay] -> {7D688A77-C613-11D0-999B-00C04FD655E1} => C:\WINDOWS\SYSTEM32\SHELL32.DLL [2012-06-08] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-682003330-813497703-1708537768-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.cnn.com/
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.cnn.com/
HKU\S-1-5-21-682003330-813497703-1708537768-1005\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-682003330-813497703-1708537768-1005\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-19 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-19 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-20 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-20 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} -  No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38118.8963888889
DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\itss51.dll [1999-07-02] (Microsoft Corporation)
Tcpip\..\Interfaces\{123780A6-ACF6-4684-B5D3-EABA0C31565C}: [NameServer] 64.136.173.147 64.136.164.146
Tcpip\..\Interfaces\{43D0A688-C1C3-40A6-AACA-53E9F31CA98B}: [DhcpNameServer] 192.168.1.254 192.168.1.254

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Rosie Sparks\Application Data\Mozilla\Firefox\Profiles\705fd0xx.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 gzserv; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [57520 2013-10-23] (Bitdefender)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 avc3; C:\WINDOWS\System32\DRIVERS\avc3.sys [633344 2013-04-17] (BitDefender)
R3 avchv; C:\WINDOWS\System32\DRIVERS\avchv.sys [242504 2012-11-02] (BitDefender)
R3 avckf; C:\WINDOWS\System32\DRIVERS\avckf.sys [486536 2013-04-17] (BitDefender)
R1 bdftdif; C:\Program Files\Bitdefender\Antivirus Free Edition\bdftdif.sys [148600 2013-04-17] (Bitdefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys [135472 2013-07-16] (BitDefender LLC)
R3 ctljystk; C:\WINDOWS\System32\DRIVERS\ctljystk.sys [3712 2001-08-17] (Creative Technology Ltd.)
S3 EL90XBC; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [66591 2001-08-17] (3Com Corporation)
R3 emu10k; C:\WINDOWS\System32\drivers\emu10k1m.sys [283904 2001-08-17] (Creative Technology Ltd.)
R3 emu10k1; C:\WINDOWS\System32\drivers\ctlfacem.sys [6912 2001-08-17] (Creative Technology Ltd.)
R3 gameenum; C:\WINDOWS\System32\DRIVERS\gameenum.sys [10624 2008-04-13] (Microsoft Corporation)
R1 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [164952 2013-04-22] (BitDefender LLC)
S3 HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [907456 2001-08-17] (Conexant)
R1 P3; C:\WINDOWS\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation)
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
R3 sfman; C:\WINDOWS\System32\drivers\sfmanm.sys [36480 2001-08-17] (Creative Technology Ltd.)
R0 trufos; C:\WINDOWS\System32\DRIVERS\trufos.sys [355744 2013-05-28] (BitDefender S.R.L.)
R3 Winachcf; C:\WINDOWS\System32\DRIVERS\winachcf.sys [737975 2001-08-15] (Conexant)
S3 catchme; \??\C:\DOCUME~1\ROSIES~1\LOCALS~1\Temp\catchme.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #17 on: August 23, 2015, 07:00:47 PM »
Additional scan result of Farbar Recovery Scan Tool (x86) Version:23-08-2015
Ran by Rosie Sparks (2015-08-23 14:40:26)
Running from C:\Documents and Settings\Rosie Sparks\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-682003330-813497703-1708537768-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
Guest (S-1-5-21-682003330-813497703-1708537768-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-682003330-813497703-1708537768-1000 - Limited - Disabled)
Rosie Sparks (S-1-5-21-682003330-813497703-1708537768-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Rosie Sparks
SUPPORT_388945a0 (S-1-5-21-682003330-813497703-1708537768-1002 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Bitdefender Antivirus Free Edition (Enabled - Up to date) {9488E0FA-F058-4673-850E-E755F112BABC}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

56K PCI Voice Modem SF-1156IV R9A (HKLM\...\VEN_14F1&DEV_1036&SUBSYS_026013E0) (Version:  - )
AccessRamp Installer (HKLM\...\AccessRamp Installer) (Version:  - )
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM\...\Adobe Shockwave Player) (Version: 10.3.0.24 - Adobe Systems, Inc.)
Bitdefender Antivirus Free Edition (HKLM\...\BitDefender Gonzales) (Version: 1.0.21.1099 - Bitdefender)
Camera Window (Version: 4.6.2 - Canon) Hidden
Canon Camera WIA Driver (Version: 6.2.5 - Canon) Hidden
Canon Camera WIA Driver 6.2.5 (HKLM\...\InstallShield_{4B66765B-8596-4698-A208-E23D11D84AA7}) (Version: 6.2.5 - Canon)
Canon Camera Window for ZoomBrowser EX (HKLM\...\InstallShield_{B34BE30D-A759-4EC2-B58F-19FE2DEBF651}) (Version: 4.6.2 - Canon)
Canon i560 (HKLM\...\CANONBJ_Deinstall_CNMCP58.DLL) (Version:  - )
Canon iP4500 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4500_series) (Version:  - )
Canon My Printer (HKLM\...\CanonMyPrinter) (Version:  - )
Canon PhotoRecord (HKLM\...\{D958FAC4-BAE0-4B1D-A42E-DE9BFDE7DDEE}) (Version: 02.02.00013 - Cisra)
Canon PIXMA iP4000 (HKLM\...\CANONBJ_Deinstall_CNMCP64.DLL) (Version:  - )
Canon Utilities Easy-PhotoPrint (HKLM\...\Easy-PhotoPrint) (Version:  - )
Canon Utilities Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version:  - )
Canon Utilities Solution Menu (HKLM\...\CanonSolutionMenu) (Version:  - )
Canon Utilities ZoomBrowser EX (HKLM\...\{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}) (Version: 04.06.01035 - CISRA)
Easy-WebPrint (HKLM\...\Easy-WebPrint) (Version:  - )
EPSON Perf 3490 3590 Guide (HKLM\...\Silent Package Run-Time Sample) (Version:  - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version:  - )
EPSON TWAIN 5 (HKLM\...\{9A3EABC0-CA06-11D4-BF77-00104B130C19}) (Version:  - )
FileASSASSIN (HKLM\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft Data Access Components KB870669 (HKLM\...\KB870669) (Version:  - Microsoft Corporation)
Microsoft Encarta Encyclopedia 2000 (HKLM\...\Encarta Encyclopedia 2000 A) (Version:  - )
Microsoft Expedia Streets & Trips 2000 (HKLM\...\Microsoft Streets & Trips 2000) (Version: 7.0.26.1700 - Microsoft Corp.)
Microsoft Money 2000 Standard Edition (HKLM\...\MSMONEYV80) (Version:  - )
Microsoft Picture It! Express 2000 (HKLM\...\{A586D09E-1D2C-11D3-9A6B-00105A98B681}) (Version: 4.0.0.0 - Microsoft)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Word 2000 (HKLM\...\{00170409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Works 2000 Setup Launcher (HKLM\...\Works2kSetup) (Version:  - )
Mozilla Firefox 39.0.3 (x86 en-US) (HKLM\...\Mozilla Firefox 39.0.3 (x86 en-US)) (Version: 39.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSN Toolbar (HKLM\...\{08234a0d-cf39-4dca-99f0-0c5cb496da81}) (Version: 4.0.0379.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero Express (HKLM\...\{A4D7B764-4140-11D4-88EB-0050DA3579C0}) (Version: 5.5.9 - ahead software gmbh)
NVIDIA Display Driver (HKLM\...\NVIDIA Display Driver) (Version:  - )
Pen Tablet (HKLM\...\InstallShield_{FE2FF182-7DB1-43FB-BFDE-7C44C26867AE}) (Version: 4.76.0005 - Wacom Technology Corporation)
Pen Tablet (Version: 4.76.0005 - Wacom Technology Corporation) Hidden
QuickTime (HKLM\...\{BFD96B89-B769-4CD6-B11E-E79FFD46F067}) (Version: 7.4.1.14 - Apple Inc.)
RealPlayer G2 (HKLM\...\RealPlayer 6.0) (Version:  - )
Rescue Disk (HKLM\...\Norton Rescue) (Version:  - )
WebFldrs XP (Version: 9.50.6513 - Microsoft Corporation) Hidden
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.7.0018.5 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 10 (HKLM\...\Windows Media Player) (Version:  - )
Windows PowerShell(TM) 1.0 (HKLM\...\KB926139-v2) (Version: 2 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

25-05-2015 20:56:10 System Checkpoint
26-05-2015 22:01:25 System Checkpoint
27-05-2015 22:36:43 System Checkpoint
29-05-2015 12:13:21 System Checkpoint
30-05-2015 13:38:37 System Checkpoint
31-05-2015 13:46:36 System Checkpoint
01-06-2015 14:43:26 System Checkpoint
02-06-2015 14:43:58 System Checkpoint
03-06-2015 19:48:03 System Checkpoint
04-06-2015 20:02:43 System Checkpoint
05-06-2015 20:55:56 System Checkpoint
07-06-2015 12:14:37 System Checkpoint
08-06-2015 15:17:20 System Checkpoint
09-06-2015 15:32:45 System Checkpoint
10-06-2015 19:01:14 System Checkpoint
11-06-2015 21:19:39 System Checkpoint
12-06-2015 22:17:09 System Checkpoint
13-06-2015 23:03:58 System Checkpoint
14-06-2015 23:04:42 System Checkpoint
15-06-2015 23:33:30 System Checkpoint
17-06-2015 12:29:51 System Checkpoint
18-06-2015 12:44:01 System Checkpoint
19-06-2015 12:44:35 System Checkpoint
20-06-2015 13:26:51 System Checkpoint
21-06-2015 17:18:50 System Checkpoint
22-06-2015 18:32:39 System Checkpoint
23-06-2015 19:38:23 System Checkpoint
24-06-2015 20:04:36 System Checkpoint
25-06-2015 22:16:05 System Checkpoint
26-06-2015 22:25:49 System Checkpoint
27-06-2015 23:06:28 System Checkpoint
29-06-2015 15:32:56 System Checkpoint
30-06-2015 17:38:25 System Checkpoint
01-07-2015 17:58:20 System Checkpoint
02-07-2015 18:46:47 System Checkpoint
03-07-2015 19:07:23 System Checkpoint
04-07-2015 19:27:51 System Checkpoint
05-07-2015 19:57:29 System Checkpoint
06-07-2015 19:59:10 System Checkpoint
07-07-2015 20:20:47 System Checkpoint
08-07-2015 21:05:49 System Checkpoint
09-07-2015 21:09:02 System Checkpoint
10-07-2015 21:59:30 System Checkpoint
11-07-2015 22:20:13 System Checkpoint
12-07-2015 22:23:40 System Checkpoint
13-07-2015 23:41:26 System Checkpoint
15-07-2015 00:01:31 System Checkpoint
16-07-2015 00:32:56 System Checkpoint
17-07-2015 10:49:22 System Checkpoint
18-07-2015 10:51:55 System Checkpoint
19-07-2015 12:51:59 System Checkpoint
20-07-2015 15:55:07 System Checkpoint
21-07-2015 16:24:48 System Checkpoint
22-07-2015 18:35:03 System Checkpoint
23-07-2015 19:13:40 System Checkpoint
24-07-2015 19:50:57 System Checkpoint
25-07-2015 21:41:21 System Checkpoint
27-07-2015 11:39:52 System Checkpoint
28-07-2015 21:14:19 System Checkpoint
29-07-2015 21:22:01 System Checkpoint
30-07-2015 22:17:01 System Checkpoint
31-07-2015 22:20:39 System Checkpoint
01-08-2015 22:44:29 System Checkpoint
03-08-2015 14:16:05 System Checkpoint
04-08-2015 15:16:01 System Checkpoint
05-08-2015 17:36:54 System Checkpoint
06-08-2015 18:45:20 System Checkpoint
07-08-2015 20:37:12 System Checkpoint
08-08-2015 21:12:46 System Checkpoint
09-08-2015 22:16:31 System Checkpoint
11-08-2015 12:53:00 System Checkpoint
12-08-2015 15:27:32 System Checkpoint
13-08-2015 19:28:30 System Checkpoint
14-08-2015 20:33:57 System Checkpoint
15-08-2015 21:56:41 System Checkpoint
16-08-2015 22:39:14 System Checkpoint
17-08-2015 22:57:45 System Checkpoint
19-08-2015 20:34:38 System Checkpoint
20-08-2015 22:16:55 System Checkpoint
22-08-2015 00:55:13 System Checkpoint
23-08-2015 01:02:43 System Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2004-05-11 22:15 - 2003-03-31 12:00 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{CDB5A8D9-C81E-4BEC-96E6-AEDF911F09D8}.job => C:\WINDOWS\system32\msfeedssync.exe

==================== Loaded Modules (Whitelisted) ==============

2014-05-19 02:46 - 2013-03-19 12:07 - 00508136 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\sqlite3.dll
2014-05-19 02:46 - 2013-09-03 14:29 - 00095088 _____ () C:\Program Files\Bitdefender\Antivirus Free Edition\BDMetrics.dll
2009-02-04 02:25 - 2008-09-16 20:18 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll
2005-10-28 09:14 - 2001-09-23 15:41 - 00524377 _____ () C:\Program Files\BroadJump\Client Foundation\stlport_4_0_0_DDR.dll
2005-10-28 09:14 - 2001-09-26 03:23 - 00196695 _____ () C:\Program Files\BroadJump\Client Foundation\BJIntlCore_1_1_DDR.dll

==================== Alternate Data Streams (Whitelisted) =========

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-682003330-813497703-1708537768-1005\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Rosie Sparks\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
DNS Servers: 64.136.173.147 - 64.136.164.146
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

DomainProfile\AuthorizedApplications: [C:\Program Files\instant messenger\aim.exe] => Enabled:AOL Instant Messenger
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\AOL\1125199124\ee\AOLServiceHost.exe] => Enabled:AOL Services
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\AOL\Loader\aolload.exe] => Enabled:AOL Loader
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\sessmgr.exe] => Disabled:@xpsp2res.dll,-22019
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Rosie Sparks\Local Settings\TEMP\7zS2.tmp\SymNRT.exe] => Enabled:Norton Removal Tool
StandardProfile\AuthorizedApplications: [C:\WINDOWS\System32\mmc.exe] => Enabled:Microsoft Management Console
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
DomainProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22007
DomainProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22008
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22002

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/23/2015 02:05:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application frst.exe, version 23.8.2015.0, faulting module frst.exe, version 23.8.2015.0, fault address 0x0002105e.
Processing media-specific event for [frst.exe!ws!]

Error: (08/22/2015 06:13:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application createrestorepoint.exe, version 1.0.0.0, faulting module createrestorepoint.exe, version 1.0.0.0, fault address 0x00001094.
Processing media-specific event for [createrestorepoint.exe!ws!]

Error: (08/22/2015 02:51:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application createrestorepoint.exe, version 1.0.0.0, faulting module createrestorepoint.exe, version 1.0.0.0, fault address 0x00001094.
Processing media-specific event for [createrestorepoint.exe!ws!]

Error: (08/22/2015 02:29:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application createrestorepoint.exe, version 1.0.0.0, faulting module createrestorepoint.exe, version 1.0.0.0, fault address 0x00001094.
Processing media-specific event for [createrestorepoint.exe!ws!]

Error: (08/22/2015 02:25:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application createrestorepoint.exe, version 1.0.0.0, faulting module createrestorepoint.exe, version 1.0.0.0, fault address 0x00001094.
Processing media-specific event for [createrestorepoint.exe!ws!]

Error: (08/09/2015 03:02:12 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (08/09/2015 03:02:12 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (08/09/2015 03:02:11 PM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The connection with the server was terminated abnormally

Error: (07/30/2015 12:40:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 39.0.0.5659, faulting module mozalloc.dll, version 39.0.0.5659, fault address 0x00001aa1.
Processing media-specific event for [plugin-container.exe!ws!]

Error: (07/29/2015 10:17:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application flashplayer18_ga_install.exe, version 1.5.0.41, faulting module flashplayer18_ga_install.exe, version 1.5.0.41, fault address 0x0000598b.
Processing media-specific event for [flashplayer18_ga_install.exe!ws!]


System errors:
=============
Error: (08/23/2015 09:04:55 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The MBAMService service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/22/2015 02:05:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.

Error: (08/22/2015 02:05:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/22/2015 02:05:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows User Mode Driver Framework service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/22/2015 02:05:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (08/22/2015 02:05:17 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 57696 milliseconds: Restart the service.


Microsoft Office:
=========================
Error: (08/23/2015 02:05:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: frst.exe23.8.2015.0frst.exe23.8.2015.00002105e

Error: (08/22/2015 06:13:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: createrestorepoint.exe1.0.0.0createrestorepoint.exe1.0.0.000001094

Error: (08/22/2015 02:51:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: createrestorepoint.exe1.0.0.0createrestorepoint.exe1.0.0.000001094

Error: (08/22/2015 02:29:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: createrestorepoint.exe1.0.0.0createrestorepoint.exe1.0.0.000001094

Error: (08/22/2015 02:25:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: createrestorepoint.exe1.0.0.0createrestorepoint.exe1.0.0.000001094

Error: (08/09/2015 03:02:12 PM) (Source: crypt32) (EventID: 8) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

Error: (08/09/2015 03:02:12 PM) (Source: crypt32) (EventID: 8) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThis network connection does not exist.

Error: (08/09/2015 03:02:11 PM) (Source: crypt32) (EventID: 8) (User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThe connection with the server was terminated abnormally

Error: (07/30/2015 12:40:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe39.0.0.5659mozalloc.dll39.0.0.565900001aa1

Error: (07/29/2015 10:17:26 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: flashplayer18_ga_install.exe1.5.0.41flashplayer18_ga_install.exe1.5.0.410000598b


==================== Memory info ===========================

Percentage of memory in use: 88%
Total physical RAM: 511.3 MB
Available physical RAM: 58.48 MB
Total Virtual: 2480.45 MB
Available Virtual: 1801.57 MB

==================== Drives ================================

Drive c: (GATEWAY) (Fixed) (Total:37.26 GB) (Free:17.25 GB) FAT32 ==>[drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 37.3 GB) (Disk ID: 3C0D3C0C)
Partition 1: (Active) - (Size=37.3 GB) - (Type=0C)

==================== End of log =

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 19371
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Malwarebytes will not install?
« Reply #18 on: August 23, 2015, 09:30:34 PM »
Your diagnosis may be right, Ron, the problem may bes related to a slow dial-up connection.  There is another possibility as well.  BitDefender does not appear to like MBAM.  Although it was when upgrading from Windows 8.1 to Windows 10, a common friend from FL ran into a problem after updating BitDefender -- it essentially nuked MBAM.  Although, I wouldn't expect the free version to have a problem with MBAM. 

As I see it, you have two options to try:

1.  Disable BidDefender and then try installing MBAM.  If you already have the downloaded installer, run that.  Otherwise, you may be better off using the Malwalrebytes "Hotfix Installer" from this page.
2.  If the program isn't downloading completely due to your slow connection, you could download it to a USB from the library or a family member or friend with a faster connection.  Although they may be behind a bit, the updates can be manually downloaded from http://data.mbamupdates.com/tools/mbam-rules.exe to a USB and after installing MBAM, manually update.  (If you go this route, you may still want to disable BitDefender before your start the installation.)

The only file showing related to Malwarebytes is FileASSASSIN, which is a completely separate program from Malwarebytes Anti-Malware.  However, there are some leftover files that we can clean up though, including an old Microsoft Security Essentials scheduled scan as well as the reminders about Windows XP end of service, which I know you are well aware of. 

Please do the following to run FRST: 

Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system
  • Open Notepad (Start =>All Programs => Accessories => Notepad).
  • Copy/Paste the entire contents of the code box below into Notepad.
Code: [Select]
start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-682003330-813497703-1708537768-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKU\.DEFAULT -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-19 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-19 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-20 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-20 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} -  No File
Toolbar: HKU\S-1-5-21-682003330-813497703-1708537768-1005 -> No Name - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} -  No FileS3
catchme; \??\C:\DOCUME~1\ROSIES~1\LOCALS~1\Temp\catchme.sys [X]
Task: C:\WINDOWS\Tasks\Microsoft Antimalware Scheduled Scan.job => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
c:\Program Files\Microsoft Security Client
C:\WINDOWS\system32\xp_eos.exe
EmptyTemp:
end
  • Click Format and ensure Wordwrap is unchecked.
  • Important:  Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt
  • Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
    • Press the Fix button once and wait.
    • FRST will process fixlist.txt
    • When finished, it will produce a log fixlog.txt in the same folder/directory as FRST64.exe
    • Please post the log in your next reply.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #19 on: August 23, 2015, 10:05:45 PM »
Thanks Corrine

I am so dumb I don’t know how to do this.

Important:  Save the code to the same folder/directory that FRST.exe is located in, naming it as fixlist.txt

I am down to there but don't know what to do next.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 19371
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Malwarebytes will not install?
« Reply #20 on: August 24, 2015, 12:35:27 AM »
Oops, sorry, Ron, I didn't refresh the site so just saw your post.  No hurry though since we're not dealing with malware anyway. 

Ok, now that your have fixlist.txt saved, FRST was programmed so well that with the both of them in the same location, all you need to do is go back to FRST.exe and launch it.  When FRST opens, click "Fix" and it will find the text file and do as instructed!  The fixlog.txt will be saved to the same place as the other FRST files.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #21 on: August 24, 2015, 01:58:37 AM »
OK saved fixlist.txt to desktop and clicked FIX in FRST.
FRST acted like it was sorting things out and then got the popup.

“FRST.exe has encountered a problem and needs to close.”

Wow I am really sick of that message.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 19371
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Malwarebytes will not install?
« Reply #22 on: August 24, 2015, 01:41:56 PM »
Are both fixlist.txt and FIRST on the desktop?  If yes and it still isn't working we can go in a different direction.  We aren't dealing with removing anything malicious, just doing a bit of cleanup and none of what is involved in the cleanup would have any effect on installing MBAM. 


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #23 on: August 24, 2015, 03:16:34 PM »
Yes FRST.exe, FRST.txt, FRST.addition.txt, and fixlist.txt are on the desktop.


When I click on RFST.exe  it closes every thing else that is open is that normal.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 19371
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Malwarebytes will not install?
« Reply #24 on: August 24, 2015, 04:15:41 PM »
Yes, FRST is instructed to "close processes".  This is done because open processes such as BitDefender may interfere with removal.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Pete!

  • Hero Member
  • *****
  • Posts: 5171
    • View Profile
Re: Malwarebytes will not install?
« Reply #25 on: August 25, 2015, 12:48:09 PM »
Sorry for interrupting but......
........Most of my problems may be with the slow dial up.
That's a definite possibility.
When I was still using dial-up, I had trouble staying connected to the Malwarebytes server well enough to download anything.
When trying to update the database, I would either lose contact with the server, before it was done, or a new database would get put up and the download would start over (MBAM has very frequent database updates).

Now that I have broadband, that's not a problem.

Offline ron350

  • Full Member
  • ***
  • Posts: 33
    • View Profile
Re: Malwarebytes will not install?
« Reply #26 on: August 25, 2015, 03:32:16 PM »
 Good to know it is not malware now I have to save all of My Documents and MY Pictures before the computer dies.