You have a worm:
C:\WINDOWS\system32\msasvc.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe
Let's try to kill it. . . .
FIRST:
Click Start > Run > type services.msc and Click OK
Locate Microsoft authenticate service (MsaSvc) and RightClick on it to bring up the Service Properties Window.
First: Stop the service by clicking the Stop Button.
Next: Disable it by changing the Startup Type to Disabled and click Apply.
NEXT:
Run HijackThis and open the Misc Tools section and select Delete an NT service and follow the instructions to enter and remove that entry.
Reboot
-- Please go to this link and follow the instructions to scan with WinPFind by OldTimer.
Please submit the WinPFind Log along with a fresh HJT ScanLog and we'll go from there.
Best Luck
PP





Reply With Quote