Okay, scan is clean. I have questions and answers-or suggestions.
MsMpEng.exe. is a process that originally was in Windows Defender Antispyware. It was known to cause problems then. And now that Windows One Care is out, users are finding that problem is still turning up.
First, if you have not done it already, download
Avast if that's the AV you want to use> save it to your desktop. Don't run it yet:
Please reopen the HijackThis log to 'do system scan only.'
Check each of the following if present. Note: Don't click on Fix Checked until you have checked them all
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
Close all Windows except HijackThis and click on 'Fix Checked.'
Boot into Safe Mode> Set the system to Work Offline
Start> Run> type in
msconfig> enter> Selective Startup> Startup tab> UNCHECK the Windows OneCare entries:
OcHealthMon.exe
winssnotify.exe
msfwsvc.exe
Also uncheck WinCinemaMgr.exe
Apply> OK
Control Panel> Add/Remove Programs> UNINSTALL the Windows One Care entries.
Start> Run> type in
services.msc> double click on a2service> change Startup type to Manual.
Double click the Avast setup on the desktop to run/install.
Reboot into Normal Mode. Note: ignore the nag message and close it after checking 'don't show this message again.'
Stay in Selective Startup.
See if this resolves the problem. If it does not:
Do the Error Check
Run the System FileChecker.
I have 2 more steps if the above doesn't handle it. From what I read, this continues to be an ongoing 'bug' because it's dependent on the system configurations and users have different configurations- at least that's the excuse Ms is currently using.
BTW, several people found the Win32.sys problem was being caused by the Logitech Quick Cam. Changing the Service for LVPrcSrv.exe resolved it!.
Edit: Remind me to remind you to empty the Recycle Bin!