Malwarebytes problem

Started by katlan, December 05, 2013, 04:01:48 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

katlan

Hi.  I'm Katlan.  I hope Corrine sees this so she knows I saw her post on the other site I was on.  Malwarebytes completely freezes and I have to turn the power off them back on on my computer.  After lots of suggestions I went to this website....http://malwaretips.com/blogs/malware-removal-guide-for-windows/ and did every step.  On #8 Part B, it ran to 98% then froze.  Again, I had to turn my laptop off.  At the point it froze, it said it had found 25 items they were in weatherbug and stopsign, if that helps at all.  I haven't had stop sign for a long time now and I got weatherbug by not unchecking it with an update.  I removed it also.
Here are the logs I saved from the different scans I did today....
Rogue Killer
RogueKiller V8.7.10 _x64_ [Nov 25 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : K [Admin rights]
Mode : Remove -- Date : 12/04/2013 09:10:09
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection :  ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) WDC WD5000BEVT-22A0RT0 ATA Device +++++
--- User ---
[MBR] 2432a6faad1ae4396dda5521468e6df3
[BSP] a3fb8650726bb93e382141701f95f9e1 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15000 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 30722048 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 30926848 | Size: 461838 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_12042013_091009.txt >>
RKreport[0]_S_12042013_090849.txt

Adware Cleaner:


# AdwCleaner v3.014 - Report created 04/12/2013 at 09:28:28
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : K - K-PC
# Running from : C:\Users\K\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2P5V5T3D\2-adwcleaner[1].exe
# Option : Clean
***** [ Services ] *****

***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Users\K\AppData\Local\Conduit
Folder Deleted : C:\Users\K\AppData\Local\filetypeassistant
Folder Deleted : C:\Users\K\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\K\AppData\LocalLow\PriceGong
File Deleted : C:\END
File Deleted : C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\udeyo9lr.default\searchplugins\safeguard-secure-search.xml
***** [ Shortcuts ] *****

***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\App24x7Help_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3310511
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\InstallIQ
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7601.17514

-\\ Mozilla Firefox v
[ File : C:\Users\K\AppData\Roaming\Mozilla\Firefox\Profiles\udeyo9lr.default\prefs.js ]

*************************
AdwCleaner[R0].txt - [3812 octets] - [04/12/2013 09:27:38]
AdwCleaner[S0].txt - [3748 octets] - [04/12/2013 09:28:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3808 octets] ##########

Junkware Removal Tool utility log:
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{B917673F-E918-4539-99E0-78C18A6470B8}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{B91A15FD-86DD-4CA8-B176-2E9F814F0B2B}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{BA398A34-A91E-4D4C-802D-488D8DFBC683}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{BBE6046E-F3E5-4F93-A83B-8A92C328D149}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{BD39FA20-6B92-4E37-B3F2-BB6ED26A9E3C}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{BD8AD206-68C8-43C7-965D-E2DC12D286D9}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C1476747-56AE-4389-B2CD-2D0EBB837B16}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C16C8E40-F056-42BF-A90D-B888D7E9EE9B}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C1AFC706-2C5C-45BC-8CF0-DFE79B7C8279}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C2AC613F-EBE5-4A5E-B047-F19C1C4747F7}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C2BE664F-27A0-4631-A0EF-C2DD7D434719}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C817218D-A921-4D91-AAEF-83DBC1EBBB85}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C89D09D0-0B8C-493C-A646-6A96AB50375A}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{C9542F79-EE50-47EE-90D6-81149BAA1213}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{CAED207C-AA5C-468C-BB34-436EF9CBCA5D}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{D07D5F5A-32E2-4DE3-8F71-AF5A51FBB1A7}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{D0FA47F9-0A84-466B-82F0-E16F02F386CE}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{D5794CB5-7116-44DF-BF95-C31D77DEF933}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{D6740DE9-5258-4079-9F3F-79CEEBF97E91}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{E1A6F565-0CBD-4C5F-A2BA-96A1DD4450A7}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{E8743FC6-D935-4D36-99A6-57670AEC4602}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{E8D5D7C5-AA5F-4017-8F56-CCE9EACB0C37}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{EA2E7A63-0436-46C9-9991-A3E199287370}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{EB47FF47-EA01-492D-B096-8C29EA123E68}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{EDC55129-F3D5-437F-A3CC-312169400A8D}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{F1F2C270-EFDF-4590-9313-4FD6197E2B13}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{F308030C-AF3E-448F-A30C-21190E595077}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{F6D14462-DF13-4F1C-BBD1-775C2B57C634}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{F8E54BFB-77B4-488E-9B77-83FDC0AC19E9}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{F9A1F18D-9922-4C08-9D20-DA1D93BB13AA}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{FBAC4655-FD43-46E8-97C0-FB8E6B9BA6D6}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{FDAD7D04-8735-452D-9C81-E5024526E970}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{FE6AFC9F-0659-45E5-97C4-B93CA9624DFA}
Successfully deleted: [Empty Folder] C:\Users\K\appdata\local\{FF274B22-AEDA-43D6-AE1B-38F6470F81D7}

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 12/04/2013 at  9:45:34.70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Not sure what else is needed.  I have 2 1/2 year old Acer Aspire 7551-7422 laptop.  Quad core, AMD Phenom.

If you need anything else let me know.  I'll need layman instructions for sure!

Thank you very much.

Kathy (Katlan)



zep516

Hi Katlan,

Welcome to the forum. :) I'll get you started on what to do next,

Corrine will just need a couple more log reports from you, she will also be helping you.


Please download DDS.scr by sUBs and save it to your desktop.  If you have a old copy (prior to Ver_2012-11-20.01) please delete it and download a fresh copy.

   Link

    1 Disable any script blocker and then double-click dds.scr to run.
    2 Shortly after two logs will appear, DDS.txt & Attach.txt
    3 The logs will automatically be saved to your desktop.

   Next

Please download Security Check by screen317 from Here

    Save it to your Desktop.
    Double-click SecurityCheck.exe and follow the on-screen instructions inside of the black box.
    A Notepad document should open automatically called checkup.txt.
    Please post the contents of that document with the other requested logs.
You're only as safe as your last update.

katlan

Here you go....
DDS log:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 8.0.7601.17514
Run by K at 0:13:37 on 2013-12-05
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3838.2477 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_9_900_117_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://acer.msn.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -
TB: WOT: {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344} : DHCPNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\253502342797374716C602C416B6560275966496 : DHCPNameServer = 8.8.8.8 209.84.253.12 205.201.148.13
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\2556460225F6F6660294E6E6 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\342797374716C6C416B656 : DHCPNameServer = 8.8.8.8 209.84.253.12 205.201.148.13
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\35D6162747F52556075616475627 : DHCPNameServer = 192.168.5.200
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\75169707F62747F5143636563737 : DHCPNameServer = 192.168.5.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\E4544574541425 : DHCPNameServer = 10.0.0.1
TCP: Interfaces\{0A02532D-5205-4E69-94CD-F4FF38A4D344}\F416B677F6F646331343 : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
x64-TB: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
x64-Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
x64-Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2013-9-27 248240]
R1 A2DDA;A2 Direct Disk Access Support Driver;C:\EEK\Run\a2ddax64.sys [2013-12-4 26176]
R1 ElRawDisk;ElRawDisk;C:\Windows\System32\drivers\rsdrvx64.sys [2013-9-29 26024]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\System32\drivers\mwlPSDFilter.sys [2009-6-2 22576]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\System32\drivers\mwlPSDNserv.sys [2009-6-2 20016]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\System32\drivers\mwlPSDVDisk.sys [2009-6-2 60464]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-19 202752]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2011-4-19 321104]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-4-19 868896]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-12-3 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-12-3 701512]
R2 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2013-1-20 134944]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-6-28 255744]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2010-4-16 144640]
R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-11-19 243232]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2010-6-8 406056]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-12-3 25928]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2011-4-19 38456]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe --> c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [?]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2010-6-10 40448]
S3 cleanhlp;cleanhlp;C:\EEK\Run\cleanhlp64.sys [2013-12-4 57024]
S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-5-26 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2010-4-16 50432]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-26 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-7-26 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2013-12-04 20:30:08 10285968 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{799EE074-5A70-4F2E-B6F0-243AF60C41D5}\mpengine.dll
2013-12-04 20:19:36 965000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{99C0FADF-CA8F-C261-1DE3-4D61F662F85A}\GapaEngine.dll
2013-12-04 20:18:12 984160 -c----w- C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_MsMpEng.exe_fa11301ec6142e7fa62c17aa3a3ae38b293f567_cab_0e26be5f\setup.exe
2013-12-04 16:55:28 -------- d-----w- C:\EEK
2013-12-04 16:52:24 -------- d-----w- C:\Users\K\New folder
2013-12-04 16:52:05 -------- d-----w- C:\Users\K\Emisisoft Emergency Kit
2013-12-04 14:51:00 -------- d-----w- C:\Users\K\AppData\Local\FileTypeAssistant
2013-12-04 14:37:10 -------- d-----w- C:\Windows\ERUNT
2013-12-04 14:27:36 -------- d-----w- C:\AdwCleaner
2013-12-04 13:49:45 -------- d-----w- C:\ProgramData\HitmanPro
2013-12-03 21:29:36 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-12-03 21:29:36 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-03 20:09:15 -------- d-----w- C:\Users\K\AppData\Roaming\Malwarebytes
2013-12-03 20:07:37 -------- d-----w- C:\ProgramData\Malwarebytes
2013-12-03 19:48:40 10285968 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-12-03 19:32:06 -------- d-----w- C:\TDSSKiller_Quarantine
2013-11-15 03:27:09 -------- d-----w- C:\0d3c97b53951bb5b4756101e1a4a
2013-11-06 16:06:34 965000 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BFA0BFCC-FD4D-4260-81BE-7A49702A9A57}\gapaengine.dll
.
==================== Find3M  ====================
.
2013-11-19 10:21:41 267936 ------w- C:\Windows\System32\MpSigStub.exe
2013-10-12 02:31:48 1188864 ----a-w- C:\Windows\System32\wininet.dll
2013-10-12 02:30:42 830464 ----a-w- C:\Windows\System32\nshwfp.dll
2013-10-12 02:29:21 859648 ----a-w- C:\Windows\System32\IKEEXT.DLL
2013-10-12 02:29:08 324096 ----a-w- C:\Windows\System32\FWPUCLNT.DLL
2013-10-12 02:04:18 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-10-12 02:03:08 656896 ----a-w- C:\Windows\SysWow64\nshwfp.dll
2013-10-12 02:01:25 216576 ----a-w- C:\Windows\SysWow64\FWPUCLNT.DLL
2013-10-12 01:32:57 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2013-10-12 01:15:03 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-10-10 23:32:19 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-10 23:32:19 692616 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-10-05 20:25:35 1474048 ----a-w- C:\Windows\System32\crypt32.dll
2013-10-05 19:57:25 1168384 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-10-04 02:28:31 190464 ----a-w- C:\Windows\System32\SmartcardCredentialProvider.dll
2013-10-04 02:25:17 197120 ----a-w- C:\Windows\System32\credui.dll
2013-10-04 02:24:49 1930752 ----a-w- C:\Windows\System32\authui.dll
2013-10-04 01:58:50 152576 ----a-w- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
2013-10-04 01:56:25 168960 ----a-w- C:\Windows\SysWow64\credui.dll
2013-10-04 01:56:00 1796096 ----a-w- C:\Windows\SysWow64\authui.dll
2013-10-03 02:23:48 404480 ----a-w- C:\Windows\System32\gdi32.dll
2013-10-03 02:00:44 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2013-09-28 01:09:10 497152 ----a-w- C:\Windows\System32\drivers\afd.sys
2013-09-27 14:53:06 248240 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2013-09-27 14:53:06 134944 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2013-09-25 02:26:40 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2013-09-25 02:26:40 154560 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2013-09-25 02:23:33 28672 ----a-w- C:\Windows\System32\sspisrv.dll
2013-09-25 02:23:33 135680 ----a-w- C:\Windows\System32\sspicli.dll
2013-09-25 02:23:01 28160 ----a-w- C:\Windows\System32\secur32.dll
2013-09-25 02:22:59 340992 ----a-w- C:\Windows\System32\schannel.dll
2013-09-25 02:21:50 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2013-09-25 02:21:07 1447936 ----a-w- C:\Windows\System32\lsasrv.dll
2013-09-25 01:58:17 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2013-09-25 01:57:26 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2013-09-25 01:57:24 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
2013-09-25 01:56:42 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2013-09-25 01:03:24 30720 ----a-w- C:\Windows\System32\lsass.exe
2013-09-08 02:30:37 1903552 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-09-08 02:27:14 327168 ----a-w- C:\Windows\System32\mswsock.dll
2013-09-08 02:03:58 231424 ----a-w- C:\Windows\SysWow64\mswsock.dll
.
============= FINISH:  0:14:23.16 ===============

Attach log:


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/24/2011 12:06:53 AM
System Uptime: 12/4/2013 7:38:28 PM (5 hours ago)
.
Motherboard: Acer            |  | Aspire 7551                   
Processor: AMD Phenom(tm) II N970 Quad-Core Processor | Socket S1G4 | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 451 GiB total, 410.914 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e97d-e325-11ce-bfc1-08002be10318}
Description: Plug and Play Software Device Enumerator
Device ID: ROOT\SYSTEM\0000
Manufacturer: (Standard system devices)
Name: Plug and Play Software Device Enumerator
PNP Device ID: ROOT\SYSTEM\0000
Service: swenum
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
18 Wheels of Steel - American Long Haul
64 Bit HP CIO Components Installer
Acer Backup Manager
Acer Crystal Eye webcam
Acer ePower Management
Acer eRecovery Management
Acer Game Console
Acer Games
Acer Registration
Acer ScreenSaver
Acer Updater
Acrobat.com
Adobe AIR Free Download Packages
Adobe Flash Player 11 ActiveX
Adobe Reader 9.5.5 MUI
Adobe Reader Free Download Packages
Agatha Christie - Death on the Nile
Alcor Micro USB Card Reader
ALPS Touch Pad Driver
AMD USB Filter Driver
ATI Catalyst Install Manager
Backup Manager Basic
Bejeweled 2 Deluxe
Bing Rewards Client Installer
Blackhawk Striker 2
Broadcom Gigabit NetLink Controller
Build-a-lot 2
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Chuzzle Deluxe
CyberLink PowerDVD 9
D3DX10
Diner Dash 2 Restaurant Rescue
DJ_AIO_05_F4400_Software_Min
Dora's Carnival Adventure
eBay Worldwide
eSobi v2
FATE
File Type Assistant
Free File Viewer 2012
HP Deskjet F4400 Printer Driver 14.0 Rel. 5
Identity Card
Jewel Quest - Heritage
Jewel Quest Solitaire 2
John Deere Drive Green
Junk Mail filter update
Launch Manager
Malwarebytes Anti-Malware version 1.75.0.1300
Mesh Runtime
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Default Manager
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MyWinLocker
MyWinLocker Suite
NOOK for PC
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
PDF-Viewer
Penguins!
Plants vs. Zombies
PokerStars.net
Polar Bowler
Polar Golfer
Realtek High Definition Audio Driver
Recuva
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Shredder
Skype™ 5.10
SpywareBlaster 5.0
Times Reader
Toolbox
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3)
Virtual Villagers 4 - The Tree of Life
Welcome Center
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WOT for Internet Explorer
Zuma's Revenge
.
==== Event Viewer Messages From Past Week ========
.
12/4/2013 3:18:18 PM, Error: Service Control Manager [7031]  - The Microsoft Antimalware Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 15000 milliseconds: Restart the service.
12/4/2013 3:18:09 PM, Error: volsnap [14]  - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
12/4/2013 3:18:09 PM, Error: Microsoft Antimalware [5008]  - Microsoft Antimalware engine has been terminated due to an unexpected error.   Failure Type: Crash   Exception code: 0xc0000006   Resource: file:C:\Program Files (x86)\InstallShield Installation Information\{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}\setup.exe
12/4/2013 2:19:04 PM, Error: Service Control Manager [7000]  - The McAfee SiteAdvisor Service service failed to start due to the following error:  The system cannot find the file specified.
12/4/2013 11:58:23 PM, Error: atapi [11]  - The driver detected a controller error on \Device\Ide\IdePort0.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The WLAN AutoConfig service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Windows Audio Endpoint Builder service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Superfetch service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Program Compatibility Assistant Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Network Connections service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 100 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Human Interface Device Access service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The HomeGroup Listener service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Distributed Link Tracking Client service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/4/2013 1:23:22 PM, Error: Service Control Manager [7031]  - The Desktop Window Manager Session Manager service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
12/4/2013 1:23:04 PM, Error: Service Control Manager [7031]  - The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
12/4/2013 1:22:02 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
.
==== End Of File ===========================

Checkup log:
Results of screen317's Security Check version 0.99.77 
Windows 7 Service Pack 1 x64 (UAC is enabled) 
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled! 
Microsoft Security Essentials   
Antivirus up to date! 
`````````Anti-malware/Other Utilities Check:`````````[/u]
SpywareBlaster 5.0   
Malwarebytes Anti-Malware version 1.75.0.1300 
Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````[/u] 
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
Malwarebytes Anti-Malware mbamservice.exe 
Malwarebytes Anti-Malware mbamgui.exe 
Malwarebytes' Anti-Malware mbamscheduler.exe   
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````[/u]

Thank you.

Corrine

Hi, Katlan.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

1.  In your last post at GardenWeb you said,
Quote from: KatlanI created a system restore point to go back to aug. 31. I did that long before trying all the steps at the above listed site.
Since there are no restore points shown in your log, do you mean that you restored your computer to that date prior to running the tools?

2.  Please follow the instructions to run Malwarebytes Chameleon at Use Chameleon to run Malwarebytes Anti-Malware on infected systems : Malwarebytes Support.  Let me know if it works and post the log file.



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

katlan

No, I didn't do a system restore.  But I thought I had one created for Aug. 31. 
I'm in the process of running the malwarebytes chameleon.  There are 12 steps.
Do you want me to do all of them?  I'm asking now that I'm on #7, haha.

So if I do all 12, do you want all 12 logs posted in the same post?

GR@PH;<'S

katlan,
Please post the logs that you get  :goodie:

GR@PH;<'S
press Enter then have a Brandy then if the problem is still there have another Brandy
Q: does it work
A: It does seem to for a few hours at least.

katlan

Chameleon #1

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 12:27:53 PM
mbam-log-2013-12-05 (12-27-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203916
Time elapsed: 4 minute(s), 59 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)


Chameleon #2
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 12:59:04 PM
mbam-log-2013-12-05 (12-59-04).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203907
Time elapsed: 2 minute(s), 42 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #3
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 1:24:03 PM
mbam-log-2013-12-05 (13-24-03).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203960
Time elapsed: 2 minute(s), 42 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #4
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 1:30:33 PM
mbam-log-2013-12-05 (13-30-33).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203963
Time elapsed: 2 minute(s), 33 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #5
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 1:35:59 PM
mbam-log-2013-12-05 (13-35-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203965
Time elapsed: 2 minute(s), 33 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #6
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 1:42:32 PM
mbam-log-2013-12-05 (13-42-32).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203963
Time elapsed: 2 minute(s), 32 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

katlan

Chameleon #7
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 3:39:09 PM
mbam-log-2013-12-05 (15-39-09).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 203997
Time elapsed: 3 minute(s), 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #8
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 3:49:01 PM
mbam-log-2013-12-05 (15-49-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204013
Time elapsed: 5 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Your screen elements are hidden from view. Press Esc or move pointer to the center of the screen to return to Mail.
Press Esc or move pointer here to return to Mail.by on 
by
Deep BlueTime for a break.
AllPhotoColor

Chameleon #9
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 4:00:55 PM
mbam-log-2013-12-05 (16-00-55).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204012
Time elapsed: 3 minute(s), 9 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #10
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 4:11:10 PM
mbam-log-2013-12-05 (16-11-10).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204014
Time elapsed: 3 minute(s), 42 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #11
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 4:19:47 PM
mbam-log-2013-12-05 (16-19-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204013
Time elapsed: 3 minute(s), 19 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

Chameleon #12
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/5/2013 4:28:13 PM
mbam-log-2013-12-05 (16-28-13).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204021
Time elapsed: 3 minute(s), 43 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)


I don't know what the heck that is at the end of #8.  I erased it all and copied and pasted again and it's still saying about moving the pointer to the center of the screen.....

So there you go, all 12 are done.

Corrine

Hi, Katlan.

Sorry for the delay in responding  We reached a surprising 62°F today so have been "out & about". 

1.  The message at the end of #8 is related to Yahoo mail.  If you are having problems with Yahoo mail, the suggestion at I can login to Yahoo but cannot access my e-mail? apparently works:
Quote
Yahoo Mail is undergoing some service difficulties. The site is up and running but the service is not provided as it is. A temporary workaround will be to access the Yahoo emails from the link "http://m.yahoo.com/mail" website. This is the link used for Yahoo Mobile application. But this works for normal PC web browsers too!

2.  The purpose of Malwarebytes Chameleon is to get the program to run when it is blocked.  So, it only would have been necessary to run enough "tests" until the program ran.  However, since it ran 12 quick scans and didn't find anything, that is a good sign. 

3.  I have some questions for you:

-- Were you doing a quick scan or full scan when MBAM locked up?  With Malwarebytes a quick scan is all that is ever needed.
-- Do you use Windows Live Mail?
-- What setting do you have for Windows Update?  The list of updates in your log doesn't show as much as I would expect.  I also note that you are still using IE8.  You should at least have updated to IE10, although IE11 is was recently added to Windows Update.   You can download IE10 from here:  Download Internet Explorer 10 from Official Microsoft Download Center.

4.  Adobe Reader is seriously out of date.  Java, Adobe Reader and Flash are responsible for the bulk of the malware vulnerabilities since 2000.  As illustrated in the chart at AV-TEST - Adobe & Java Make Windows Insecure, "The PDF format is most frequently used as a malware transporter for vulnerabilities."  Personally, I replaced Adobe Reader with Sumatra PDF some years ago.  See Replacing Adobe Reader with Sumatra PDF.

If you wish to continue using Adobe Reader, please uninstall both Adobe Reader 9.5.5 MUI and the unnecessary Adobe Reader Free Download Packages.  The current version of Adobe Reader is XI (11.0.05) for Windows is available here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows.

Note: UNcheck any pre-checked additional options presented with the update. They are not part of the software update and are completely optional.

5.  Let's get a third party opinion.  Please go here to run an on-line scan from ESET.

  • Note: It is easiest if you use Internet explorer for this scan.  (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic.



Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

katlan

Corrine, you have to take advantage of nice weather in December!

o.k. for the questions.....I always did the full scan.  And when the box pops up asking if I want to scan C or D I always checked both boxes.  So I only need to do the quick scan?  Should I try malwarebytes quick scan now before doing anything else?

I do not use Windows Live Mail.  I use verizon yahoo mail.  It doesn't download onto my computer.

I actually quit doing the updates thinking I should get the malwarebytes running correctly first.  Guess that was another mistake. 

Should I download IE10 before doing anything else?  Does it automatically replace IE8 or do I have to uninstall 8?

Adobe is another reason I quit the updates.  Every single time I get an adobe update message and I click on it to install the updates, it would freeze and not finish the update.  Then back to turning the power off then back on again.

I'm fine with getting rid of Adobe.  So I should uninstall everything that has the word Adobe in it then download and install Sumatra PDF?

Do you want me to download IE10 before running ESET?

Hope I gave all the info you asked for......

Corrine

Hi, Katlan.  When we run into a computer problem, it is hard to know what to do first and what is important. 

1.  It concerns me that you seem to frequently need to do a "hard shutdown" (using the power button).  When something seems to be taking a long time or "stops responding", are you able to access Task Manager?  From Task Manager, you can click on "Applications" and select End Task on the application that shows "Not Responding".  The keyboard shortcut to access Task Manager is Ctrl + Shift + Esc (while simultaneously holding the Control + Shift keys, tap the Escape key).  Although written for Windows XP, Microsoft KB Article 323527 is still applicable, How to use and troubleshoot issues with Windows Task Manager.  A brief video is also available at Exit a program that isn't responding.

2.  Since you have a fair number of things to do, before you do anything else, please create a fresh System Restore point.  My advice is to create a new System Restore point every time before making changes to your computer.  This way, if you run into problems, you can return your computer to the point where it was stable.

3.  Go ahead and do a Quick Scan with Malwarebytes which is all you should ever need.  Anti-malware programs will often slow down or appear to freeze when scanning archives.

4.  You don't want to uninstall everything with with the word Adobe in it.  See the following:

Acrobat.com -- uninstall
Adobe AIR Free Download Packages -- update Adobe AIR here:  AIR Download Center
Adobe Flash Player 11 ActiveX -- do NOT uninstall
Adobe Reader 9.5.5 MUI -- uninstall
Adobe Reader Free Download Packages -- uninstall

5.  Restart your computer and then install Sumatra PDF.

6.  Let's make sure ESET doesn't find anything before moving on to the other updates.  Scan with ESET next and post the resultant log. 


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

katlan

Corrine, I do know how to use task manager.  When I can I use it.  But when the computer completely freezes I can't get task manager to come up.

I set a restore point for today 12/6/13.

I ran a malwarebytes quick scan.  It ran!  Here's the log:
Malwarebytes Anti-Malware (Trial) 1.75.0.1300
http://www.malwarebytes.org/
Database version: v2013.12.05.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
K :: K-PC [administrator]
Protection: Enabled
12/6/2013 2:06:40 PM
mbam-log-2013-12-06 (14-06-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 204035
Time elapsed: 3 minute(s), 1 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)

I uninstalled  Acrobat.com and  Adobe Reader 9.5.5 MUI

When I click on uninstall for Adobe Reader Free Download Packages a box pops up it says Uninstall Manager
at the top.  It's blank in the middle.  At the bottom left corner there a box to check and in small print it says
Remove this manager from Add/Remove programs
I the bottom right corner is a box to click that says Close.

Do I just close the box?  Do I check the box in the bottom left corner that says Remove this manager?

I didn't restart my computer and install Sumatra yet since I can't get the Adobe Reader Free Download Package to uninstall. 




Corrine

Hi, Katlan.

After doing further research, I see what you mean about Adobe Reader Free Download Packages.  Go ahead and close the box.  Then uninstall "File Type Assistant" first.  Then try again to uninstall the Adobe Reader Free Download Packages.  It appears they are both extras that came with other software that was installed. 

If you cannot remove them, move on to the next step and let me know in your next reply.  We'll take care of them another way.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

katlan


katlan

I uninstalled File Type Assistant successfully.  Tried to uninstall Adobe Reader Free Download Package again, same thing happened.  Empty box.  I closed the box.  Shut down the computer.  Rebooted, 50 some thousand updates were applied and I now have IE10!

Sumatra PDF has been installed successfully also.  Should I update Adobe AIR next or run the scan from ESET and post that log?