Malwarebytes does not open. I’ve done several clean reinstalls and it works for a day or so and then no longer updates or opens.
I ran aswMBR and gmer but don’t know what to do next. I did not click on aswMBR yet (Should I?) . Here are the results:
aswMBR version 1.0.1.2041 Copyright(c) 2014 AVAST Software
Run date: 2014-09-02 03:50:46
03:50:46.723 OS Version: Windows x64 6.1.7601 Service Pack 1
03:50:46.723 Number of processors: 4 586 0x2502
03:50:46.738 ComputerName: DAVID-THINK UserName: David
03:50:47.050 Initialize success
03:50:47.081 VM: driver load error: 2
03:59:14.315 AVAST engine defs: 14090102
04:00:29.443 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1
04:00:29.448 Disk 0 Vendor: TOSHIBA_ AGLA Size: 122104MB BusType: 3
04:00:29.470 Disk 0 MBR read successfully
04:00:29.491 Disk 0 MBR scan
04:00:29.500 Disk 0 unknown MBR code
04:00:29.507 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1200 MB offset 2048
04:00:29.515 Disk 0 Boot: NTFS code=1
04:00:29.527 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 110901 MB offset 2459648
04:00:29.564 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 10000 MB offset 229586944
04:00:29.598 Disk 0 scanning C:\Windows\system32\drivers
04:00:41.091 Service scanning
04:01:13.266 Modules scanning
04:01:13.269 Disk 0 trace - called modules:
04:01:13.272 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
04:01:13.273 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0xfffffa8006e2a060]
04:01:13.273 3 CLASSPNP.SYS[fffff88001ec743f] → nt!IofCallDriver → [0xfffffa8003b14950]
04:01:13.273 5 ACPI.sys[fffff88000f0e7a1] → nt!IofCallDriver → \Device\Ide\IAAStorageDevice-1[0xfffffa8004959050]
04:01:13.603 AVAST engine scan C:\Windows
04:01:14.813 AVAST engine scan C:\Windows\system32
04:05:51.418 AVAST engine scan C:\Windows\system32\drivers
04:06:01.549 AVAST engine scan C:\Users\David
04:10:30.400 AVAST engine scan C:\ProgramData
04:13:08.192 Scan finished successfully
04:15:41.577 Disk 0 MBR has been saved successfully to “C:\Users\David\Desktop\MBR.dat”
04:15:41.589 The log file has been saved successfully to “C:\Users\David\Desktop\aswMBR.txt”
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-09-05 07:04:02
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 → \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.AGLA 119.24GB
Running: 4d020k7s.exe; Driver: C:\Users\David\AppData\Local\Temp\pglcipob.sys
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [780:9108] 000007fefbe32070
Thread C:\Windows\System32\svchost.exe [780:7916] 000007fef8505fd0
Thread C:\Windows\System32\svchost.exe [1028:1336] 000007fefa58331c
Thread C:\Windows\System32\svchost.exe [1028:1528] 000007fef9d959a0
Thread C:\Windows\System32\svchost.exe [1028:4992] 000007feeb1820c0
Thread C:\Windows\System32\svchost.exe [1028:5008] 000007feeb1826a8
Thread C:\Windows\System32\svchost.exe [1028:7060] 000007feed4688f8
Thread C:\Windows\System32\svchost.exe [1028:5472] 000007feeab98a4c
Thread C:\Windows\System32\svchost.exe [1028:6432] 000007feea913efc
Thread C:\Windows\System32\svchost.exe [1028:8844] 000007feeb1829dc
Thread C:\Windows\system32\svchost.exe [1068:1124] 000007fefb3c034c
Thread C:\Windows\system32\svchost.exe [1068:1128] 000007fefb3bfb90
Thread C:\Windows\system32\svchost.exe [1068:4688] 000007fef37f0ea8
Thread C:\Windows\system32\svchost.exe [1068:4692] 000007fef37e9db0
Thread C:\Windows\system32\svchost.exe [1068:4804] 000007fef37f1c94
Thread C:\Windows\system32\svchost.exe [1068:3280] 000007feeb2038e4
Thread C:\Windows\system32\svchost.exe [1068:5164] 000007feeb20ccc4
Thread C:\Windows\system32\svchost.exe [1068:2204] 000007fef37eaa10
Thread C:\Windows\system32\svchost.exe [1068:7372] 000007fef228d3c8
Thread C:\Windows\system32\svchost.exe [1068:5268] 000007fef228d3c8
Thread C:\Windows\system32\svchost.exe [1068:2872] 000007fef228d3c8
Thread C:\Windows\system32\svchost.exe [1068:1564] 000007fef228d3c8
Thread C:\Windows\system32\svchost.exe [1232:1364] 000007fefaa98274
Thread C:\Windows\system32\svchost.exe [1232:2928] 000007fefaa98274
Thread C:\Windows\system32\svchost.exe [1380:3424] 000007feed4abd88
Thread C:\Windows\system32\svchost.exe [1380:3232] 000007feec6900cc
Thread C:\Windows\system32\svchost.exe [1380:5208] 000007feed405124
Thread C:\Windows\system32\svchost.exe [1380:5416] 000007fef7645170
Thread C:\Windows\System32\spoolsv.exe [1760:2664] 000007fef5e110c8
Thread C:\Windows\System32\spoolsv.exe [1760:2652] 000007fef4ef6144
Thread C:\Windows\System32\spoolsv.exe [1760:2648] 000007fef8505fd0
Thread C:\Windows\System32\spoolsv.exe [1760:2632] 000007fef42d3438
Thread C:\Windows\System32\spoolsv.exe [1760:2628] 000007fef85063ec
Thread C:\Windows\System32\spoolsv.exe [1760:1584] 000007fef42d3438
Thread C:\Windows\System32\spoolsv.exe [1760:2688] 000007fef85063ec
Thread C:\Windows\System32\spoolsv.exe [1760:2680] 000007fef75a5e5c
Thread C:\Windows\System32\spoolsv.exe [1760:2756] 000007fef7915074
Thread C:\Windows\System32\spoolsv.exe [1760:2856] 000007fef5ec8760
Thread C:\Windows\System32\spoolsv.exe [1760:4924] 0000000074871e74
Thread C:\Windows\System32\spoolsv.exe [1760:4644] 000007fef7982288
Thread C:\Windows\system32\svchost.exe [1788:1812] 000007fefc951a70
Thread C:\Windows\system32\svchost.exe [1788:1820] 000007fefc951a70
Thread C:\Windows\system32\svchost.exe [1788:1836] 000007fefc951a70
Thread C:\Windows\system32\svchost.exe [1788:1844] 000007fef8e62c70
Thread C:\Windows\system32\svchost.exe [1788:1860] 000007fef8e6fb40
Thread C:\Windows\system32\svchost.exe [1788:1876] 000007fef8e81d20
Thread C:\Windows\system32\svchost.exe [1788:1880] 000007fef8e6f6f0
Thread C:\Windows\system32\svchost.exe [1788:1976] 000007fef8aa35c0
Thread C:\Windows\system32\svchost.exe [1788:4884] 000007fef8aa5600
Thread C:\Windows\system32\svchost.exe [1788:3300] 000007feeae92888
Thread C:\Windows\system32\svchost.exe [1788:3208] 000007fefbd82940
Thread C:\Windows\system32\svchost.exe [2008:2076] 000007fef8505fd0
Thread C:\Windows\system32\svchost.exe [2008:2092] 000007fef85063ec
Thread C:\Windows\system32\svchost.exe [2008:5128] 000007fee8eb8470
Thread C:\Windows\system32\svchost.exe [2008:3200] 000007fee8ec2418
Thread C:\Windows\system32\svchost.exe [2008:5976] 000007feed405124
Thread C:\Windows\system32\svchost.exe [2008:6980] 000007fee8ec976c
Thread C:\Windows\system32\svchost.exe [3172:2184] 000007fef8505fd0
Thread C:\Windows\system32\svchost.exe [3172:2188] 000007fef42d3438
Thread C:\Windows\system32\svchost.exe [3172:2192] 000007fef85063ec
Thread C:\Windows\system32\svchost.exe [4896:5000] 000007fef9602f9c
Thread C:\Windows\System32\StikyNot.exe [5532:5564] 000007fefb202bf8
Thread C:\Windows\system32\rundll32.exe [5712:5824] 0000000002ea55c0
Thread C:\Windows\system32\rundll32.exe [5712:5740] 0000000002ea55c0
Thread C:\Windows\system32\rundll32.exe [5712:4852] 0000000002ea55c0
Thread c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [1324:1612] 000007fefdefa808
Thread C:\Windows\explorer.exe [3416:6716] 000007fef9602f9c
Thread C:\Windows\explorer.exe [3416:3904] 000007fedc552118
Thread C:\Windows\explorer.exe [3416:6384] 000007feea2ba3f8
Thread C:\Windows\explorer.exe [3416:5404] 000007fef9602f9c
Thread C:\Windows\explorer.exe [3416:6840] 000007fef9602f9c
Thread C:\Windows\explorer.exe [3416:6636] 000007fefa7b1010
Thread C:\Windows\explorer.exe [3416:6456] 000007fedc3ef5bc
Thread C:\Windows\System32\svchost.exe [5828:5668] 000007feed409874
---- EOF - GMER 2.1 ----
I’d appreciate any help you can provide.
Thank you
David Y