Hi
I posted not too long ago about the same problems. Basically Windows takes forever to open and close down. Windows Explorer freezes and stops working. Firefox freezes as well. Windows Picture viewer the same. Sometimes, though, there aren't any problems at all. Last time, I ended up uninstalling Avast Antivirus, and that made it work. I get this message frequently:
"The application was unable to start correctly (0xc0000022). Click OK to close the application." Some times the dialogue box is headed Spotify.exe. Every time I close down the computer, it says, that Spotify and Skype are preventing the closing down.
They seem to always be running in the background, though I've tried to close them down.
I don't know, whether it is an infection or a Windows problem, but I've run the aswMBR and the Farbar and here are the logs:
aswMBR:
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-12-09 14:07:13
—————————–
14:07:13.645 OS Version: Windows x64 6.1.7601 Service Pack 1
14:07:13.646 Number of processors: 2 586 0x2A07
14:07:13.647 ComputerName: SHEANA-PC UserName: Sheana
14:07:14.669 Initialize success
14:07:14.705 VM: initialized successfully
14:07:14.707 VM: Intel CPU virtualization not supported
14:25:36.535 AVAST engine defs: 17030301
14:25:41.689 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:25:41.695 Disk 0 Vendor: TOSHIBA_MQ01ABF050 AM0P1A Size: 476940MB BusType: 11
14:25:41.830 Disk 0 MBR read successfully
14:25:41.836 Disk 0 MBR scan
14:25:41.846 Disk 0 Windows 7 default MBR code
14:25:41.856 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 199900 MB offset 206848
14:25:41.890 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 409602048
14:25:41.898 Disk 0 Boot: NTFS code=1
14:25:41.913 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 276838 MB offset 409806848
14:25:42.024 Disk 0 scanning C:\Windows\system32\drivers
14:25:50.250 Service scanning
14:26:26.720 Modules scanning
14:26:26.740 Disk 0 trace - called modules:
14:26:26.774 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
14:26:26.782 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c78640]
14:26:26.789 3 CLASSPNP.SYS[fffff8800186043f] -> nt!IofCallDriver -> [0xfffffa800476e270]
14:26:26.797 5 ACPI.sys[fffff88000ef47a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004787060]
14:26:27.482 AVAST engine scan C:\Windows
14:26:29.104 AVAST engine scan C:\Windows\system32
14:28:57.469 AVAST engine scan C:\Windows\system32\drivers
14:29:06.925 AVAST engine scan C:\Users\Sheana
14:36:02.559 Disk 0 statistics 3260619/0/0 @ 3.60 MB/s
14:36:02.575 Scan stopped
14:37:45.012 Disk 0 MBR has been saved successfully to "C:\Users\Sheana\Desktop\MBR.dat"
14:37:45.023 The log file has been saved successfully to "C:\Users\Sheana\Desktop\aswMBR.txt"
Farbar:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-12-2017
Ran by [removed] (administrator) on SHEANA-PC (09-12-2017 14:40:03)
Running from C:\Users\[removed]\Desktop\WhatTheTech\Farbar
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\SaferVPN\SaferVPN.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
() C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16776704 2016-12-15] (Realtek Semiconductor)
HKLM\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\…\Run: [AVGUI.exe] => "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [SaferVPN] => C:\Program Files (x86)\SaferVPN\SaferVPN.exe [10012592 2017-06-27] ()
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify] => C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe [21074320 2017-12-07] (Spotify Ltd)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify Web Helper] => C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2017-12-07] (Spotify Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{05F01782-356A-4E6E-A8A7-5D782C0D6C0F}: [DhcpNameServer] [removed] [removed]
Internet Explorer:
==================
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-19] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-19] (Oracle Corporation)
FireFox:
========
FF DefaultProfile: 5ndobl67.default
FF ProfilePath: C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\5ndobl67.default [2017-12-09]
FF Homepage: Mozilla\Firefox\Profiles\5ndobl67.default -> hxxps://www.google.es/?gws_rd=ssl
FF Extension: (Disable Media WMF NV12 format) - C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\5ndobl67.default\features\{8d673d64-a133-4cbb-9cb3-108c29babeee}\[removed] [2017-12-01] [Lagacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.co.uk/?gws_rd=ssl
CHR StartupUrls: Default -> "hxxps://www.google.co.uk/?gws_rd=ssl"
CHR Profile: C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default [2017-11-03]
CHR Extension: (Google Slides) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-22]
CHR Extension: (Google Docs) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-21]
CHR Extension: (Google Drive) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-21]
CHR Extension: (YouTube) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-21]
CHR Extension: (Google Search) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-21]
CHR Extension: (Google Sheets) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-21]
CHR Extension: (Google Docs Offline) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-21]
CHR Extension: (Gmail) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-21]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 SaferVPN.Service; C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe [2547120 2017-06-27] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AVG Antivirus; "C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe" [X]
S3 avgbIDSAgent; "C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe" [X]
S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-11-04] ()
S1 avgbdisk; \SystemRoot\system32\drivers\avgbdiska.sys [X]
S1 avgbidsdriver; \SystemRoot\system32\drivers\avgbidsdrivera.sys [X]
S0 avgbidsh; \SystemRoot\system32\drivers\avgbidsha.sys [X]
S0 avgblog; \SystemRoot\system32\drivers\avgbloga.sys [X]
S0 avgbuniv; \SystemRoot\system32\drivers\avgbuniva.sys [X]
S3 avgHwid; \SystemRoot\system32\drivers\avgHwid.sys [X]
S2 avgMonFlt; \SystemRoot\system32\drivers\avgMonFlt.sys [X]
S1 avgRdr; \SystemRoot\system32\drivers\avgRdr2.sys [X]
S0 avgRvrt; \SystemRoot\system32\drivers\avgRvrt.sys [X]
S1 avgSnx; \SystemRoot\system32\drivers\avgSnx.sys [X]
S1 avgSP; \SystemRoot\system32\drivers\avgSP.sys [X]
S2 avgStm; \SystemRoot\system32\drivers\avgStm.sys [X]
S0 avgVmm; \SystemRoot\system32\drivers\avgVmm.sys [X]
U3 aswMBR; \??\C:\Users\Sheana\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Sheana\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-08 11:36 - 2017-12-08 11:36 - 000262144 _____ C:\Windows\Minidump\120817-20108-01.dmp
2017-11-25 15:09 - 2017-12-09 14:40 - 000000000 ____D C:\FRST
2017-11-25 15:06 - 2017-11-25 15:10 - 000000000 ____D C:\Users\Sheana\Desktop\WhatTheTech
2017-11-24 14:40 - 2017-11-24 15:16 - 000000000 ____D C:\Users\Sheana\Desktop\me
2017-11-24 14:35 - 2017-11-24 14:35 - 000000985 _____ C:\Users\Sheana\Desktop\Billeddubletter iPhone.txt
2017-11-23 16:06 - 2017-11-23 16:06 - 000268064 _____ C:\Windows\Minidump\112317-14742-01.dmp
2017-11-23 15:01 - 2017-11-23 15:01 - 000268064 _____ C:\Windows\Minidump\112317-16458-01.dmp
2017-11-22 20:40 - 2017-12-09 13:55 - 000000000 ____D C:\Users\Sheana\AppData\Local\Spotify
2017-11-22 20:40 - 2017-11-22 20:40 - 000001772 _____ C:\Users\Sheana\Desktop\Spotify.lnk
2017-11-22 20:40 - 2017-11-22 20:40 - 000001758 _____ C:\Users\Sheana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-11-22 20:35 - 2017-12-09 14:15 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Spotify
2017-11-22 20:35 - 2017-11-22 20:35 - 000723152 _____ (Spotify Ltd) C:\Users\Sheana\Downloads\SpotifySetup(3).exe
2017-11-21 18:31 - 2017-11-21 18:31 - 000000000 ____D C:\ProgramData\BitDefender
2017-11-21 17:41 - 2017-11-21 17:41 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\adaware
2017-11-21 17:41 - 2017-11-21 17:41 - 000000000 ____D C:\Users\Sheana\AppData\Local\AdAwareDesktop
2017-11-21 17:37 - 2017-11-21 17:37 - 000002335 _____ C:\Users\Public\Desktop\Adaware Antivirus.lnk
2017-11-21 17:37 - 2017-11-21 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\adaware
2017-11-21 17:27 - 2017-11-21 17:27 - 000000000 ____D C:\Program Files\adaware
2017-11-21 17:20 - 2017-11-21 17:20 - 000000000 ____D C:\Users\Sheana\AppData\Local\AdAwareUpdater
2017-11-21 17:19 - 2017-11-21 17:19 - 000000000 ____D C:\Program Files\Common Files\adaware
2017-11-21 17:13 - 2017-11-21 17:13 - 002630064 _____ C:\Users\Sheana\Downloads\Adaware_Installer(16).exe
2017-11-21 17:13 - 2017-11-21 17:13 - 000000000 ____D C:\ProgramData\adaware
2017-11-21 14:44 - 2017-12-07 17:34 - 000000000 ____D C:\Users\Sheana\AppData\Local\CrashDumps
2017-11-20 09:31 - 2017-11-20 09:31 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-11-20 09:31 - 2017-11-20 09:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-09 14:05 - 2016-11-18 10:14 - 000000000 ____D C:\Users\Sheana\AppData\LocalLow\Mozilla
2017-12-09 14:05 - 2016-11-18 00:19 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-12-09 14:05 - 2016-01-22 12:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-09 14:01 - 2009-07-14 05:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-12-09 14:01 - 2009-07-14 05:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-12-09 13:56 - 2016-01-23 10:59 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Skype
2017-12-09 13:56 - 2009-07-14 06:13 - 000785366 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-09 13:56 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-12-09 13:52 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-08 11:36 - 2017-10-08 01:08 - 000000000 ____D C:\Windows\Minidump
2017-12-08 11:35 - 2017-10-08 01:07 - 361828116 _____ C:\Windows\MEMORY.DMP
2017-12-07 17:54 - 2016-01-21 19:27 - 000000000 ____D C:\Users\Sheana
2017-12-05 23:11 - 2016-01-21 19:34 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\vlc
2017-12-03 10:00 - 2009-07-14 06:08 - 000032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-12-01 11:09 - 2016-01-21 11:03 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-21 17:00 - 2016-01-21 11:18 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\AVG
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\ProgramData\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Program Files (x86)\AVG
2017-11-21 16:57 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\AvgSetupLog
2017-11-21 15:26 - 2017-11-01 13:35 - 001273768 _____ C:\Windows\ntbtlog.txt
2017-11-21 15:07 - 2017-09-27 22:14 - 000000000 _____ C:\Windows\SysWOW64\last.dump
2017-11-20 09:31 - 2016-02-21 20:41 - 000002697 _____ C:\Users\Public\Desktop\Skype.lnk
2017-11-20 09:31 - 2016-01-23 10:59 - 000000000 ____D C:\ProgramData\Skype
2017-11-20 09:30 - 2016-12-22 21:24 - 000000000 ____D C:\ProgramData\Package Cache
2017-11-16 16:57 - 2016-01-22 12:16 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Mozilla
2017-11-15 20:37 - 2016-01-21 19:34 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2017-11-15 16:10 - 2016-01-21 11:04 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-11-11 20:39 - 2016-01-22 13:25 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-11-11 20:39 - 2016-01-22 13:25 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-11-11 20:39 - 2016-01-22 13:25 - 000000000 ____D C:\Windows\system32\Macromed
2017-11-11 20:38 - 2016-01-22 13:25 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-11-11 20:37 - 2016-01-21 11:01 - 000000000 ____D C:\Users\Sheana\AppData\Local\Adobe
==================== Files in the root of some directories =======
2017-11-04 17:59 - 2017-11-04 18:14 - 004096000 _____ () C:\Program Files (x86)\GUT3FBF.tmp
Some files in TEMP:
====================
2017-11-04 16:09 - 2016-04-09 07:59 - 001732864 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\dllnt_dump.dll
2016-12-13 16:51 - 2016-12-13 16:51 - 000763232 _____ (Google Inc.) C:\Users\Sheana\AppData\Local\Temp\GoogleUpdateSetup_latest.exe
2017-11-20 09:29 - 2017-11-20 09:29 - 014456872 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\vc_redist.x86.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-12-01 21:12
==================== End of FRST.txt ============================
Many thanks
Jens