Hello, I'm carlo and I have been experiencing this problem for about a week now. The windows defender is not functioning and the win explorer keeps on closing. here is my hijackthis file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:04:04 AM, on 9/14/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal

Running processes:
E:\Garena Plus\ggdllhost.exe
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x86__8wekyb3d8bbwe\LiveComm.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\ROCCAT\Pyra Mouse\PyraMonitor.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\SAP\SapSetup\setup\Updater\NwSapSetupUserNotificationTool.exe
C:\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SearchNewTab - {247C1C83-2732-3BC7-EEB2-E396B7A03BD5} - C:\ProgramData\SearchNewTab\51d306498ecc9.dll
O2 - BHO: IE BHO Utility - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files\Surf Canyon\surfcanyon.dll
O2 - BHO: ccontiNuetooSave - {6BED00BF-7BC3-F17B-A6BB-4165CDCB73AE} - C:\ProgramData\ccontiNuetooSave\518be789b9b18.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM..\Run: [ROCCAT Pyra Mouse] "C:\Program Files\ROCCAT\Pyra Mouse\PyraMonitor.EXE"
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM..\Run: [SAP_WUS_UNT] "C:\Program Files\SAP\SAPsetup\setup\Updater\NwSapSetupUserNotificationTool.exe"
O4 - HKLM..\Run: [NBAgent] "C:\Program Files\Nero\Nero 11\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKCU..\Run: [Google Update] "C:\Users\CARLOANGELO\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU..\Run: [GarenaPlus] "E:\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - HKCU..\Run: [Google Update] "C:\Users\CARLOANGELO\AppData\Local\Google\Desktop\Install{86d2a8d6-db8b-14d9-5de1-5751848d2b22}\???\???\???{86d2a8d6-db8b-14d9-5de1-5751848d2b22}\GoogleUpdate.exe" >
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip..{4C4B3412-0AC2-4F76-8F28-AD831DBD7C9C}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{5C84F35A-CDEC-4166-9670-DB9CFF86C726}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{60CD6EBD-7829-4817-A2A4-8F59E62E9A31}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{7EACEE6B-6B8D-4AC0-8280-C0B9BCC88FEB}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{AEC38CD7-46CF-44C2-89BE-34FC1554F56A}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{AF66B876-174B-468F-8611-7B801BD59B44}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{BF6490B6-56F8-4422-9F34-23FF07A264F5}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip..{F3079A77-AAE9-4543-B3D2-C35A92C75B7D}: NameServer =
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Globe Tattoo Broadband. OUC (Globe Tattoo Broadband. RunOuc) - Unknown owner - C:\Program Files\Globe Tattoo Broadband\UpdateDog\ouc.exe
O23 - Service: HWDeviceService.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: @C:\Program Files\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files\Nero\Update\NASvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: SAPSetup Automatic Workstation Update Service (NWSAPAutoWorkstationUpdateSvc) - SAP AG - C:\Program Files\SAP\SAPsetup\setup\Updater\NwSapAutoWorkstationUpdateService.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

End of file - 7987 bytes

Please. Any help will be appreciated. :)

Hi Carlo,

I am suspecting that your computers system files may have been corrupted for some reason which is preventing windows explurorer to run normally. Do you have any antivirus installed on computer? Some virus can corrupt system files. Try to do a system restore. If this doesn't help them the best solution would be to install a fresh copy of windows. Best of luck. If you like, this article may be helpful to learn more about this problem: http://www.techyv.com/questions/windows-explorer-error-message-when-so-many-windows-are-open

Running a system restore on an infected machine will only increase the corruption of potentially situation saving files.

DONT DO A SYSTEM RESTORE. I hope this gets to you quick enough. One of the worst things to do to an infected machine is execute a system restore.

Boot yourself into Safe Mode and start checking your event logs, look for unusual activity. Whilst in safe mode you should also use your AV to run a scan. If you have avast then you should boot into safe mode and execute a full boot scan.

It's not always a virus - have you been playing with any OS critical files or drivers?

A serious question though... why are you relying on Windows Defender? That's one of Microsofts biggest fails alongside Vista and the Microsoft Surface.

Hey thanks for the replies. I'm not relying on windows defender. I'm just saying that when it returns an error when opened, the windows explorer started to close. And i didn't system restore. And I didn't play with any OS critical files or drivers. I boot into safe mode now and check my event logs.


Nice one - I was horrified to see the system restore suggestion. Did you manage to get some records from your log? If you did post them here and we'll see what we can do.



WD and MSE has stopped everything that tried to get into my computer on win7 and since i started using win8


Hello again! This is the system log saved as text. Really thanks for the help! The windows explorer still keeps on closing for about 10-20seconds if not in use. Please help. :(


for the time it take i would try downloading malwarebytes or superantispyware and do a full scan scan

answer ,sensible browser , for the most part ,exceptions ,trying program that people seeking help , say they have problems with

Does it come up with windows stopped responding or something and it would be a virus I think im just getting fed up with my pc getting viruses

