This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Various Windows issues speed, Windows explorer, Firefox

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

 

I posted not too long ago about the same problems. Basically Windows takes forever to open and close down. Windows Explorer freezes and stops working. Firefox freezes as well. Windows Picture viewer the same. Sometimes, though, there aren't any problems at all. Last time, I ended up uninstalling Avast Antivirus, and that made it work. I get this message  frequently:

"The application was unable to start correctly (0xc0000022). Click OK to close the application." Some times the dialogue box is headed Spotify.exe. Every time I close down the computer, it says, that Spotify and Skype are preventing the closing down.

They seem to always be running in the background, though I've tried to close them down.

 

I don't know, whether it is an infection or a Windows problem, but I've run the aswMBR and the Farbar and here are the logs:

 

aswMBR:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-12-09 14:07:13
—————————–
14:07:13.645    OS Version: Windows x64 6.1.7601 Service Pack 1
14:07:13.646    Number of processors: 2 586 0x2A07
14:07:13.647    ComputerName: SHEANA-PC  UserName: Sheana
14:07:14.669    Initialize success
14:07:14.705    VM: initialized successfully
14:07:14.707    VM: Intel CPU virtualization not supported
14:25:36.535    AVAST engine defs: 17030301
14:25:41.689    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
14:25:41.695    Disk 0 Vendor: TOSHIBA_MQ01ABF050 AM0P1A Size: 476940MB BusType: 11
14:25:41.830    Disk 0 MBR read successfully
14:25:41.836    Disk 0 MBR scan
14:25:41.846    Disk 0 Windows 7 default MBR code
14:25:41.856    Disk 0 Partition 1 00     07    HPFS/NTFS NTFS       199900 MB offset 206848
14:25:41.890    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 409602048
14:25:41.898    Disk 0 Boot: NTFS     code=1
14:25:41.913    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS       276838 MB offset 409806848
14:25:42.024    Disk 0 scanning C:\Windows\system32\drivers
14:25:50.250    Service scanning
14:26:26.720    Modules scanning
14:26:26.740    Disk 0 trace - called modules:
14:26:26.774    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
14:26:26.782    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c78640]
14:26:26.789    3 CLASSPNP.SYS[fffff8800186043f] -> nt!IofCallDriver -> [0xfffffa800476e270]
14:26:26.797    5 ACPI.sys[fffff88000ef47a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004787060]
14:26:27.482    AVAST engine scan C:\Windows
14:26:29.104    AVAST engine scan C:\Windows\system32
14:28:57.469    AVAST engine scan C:\Windows\system32\drivers
14:29:06.925    AVAST engine scan C:\Users\Sheana
14:36:02.559    Disk 0 statistics 3260619/0/0 @ 3.60 MB/s
14:36:02.575    Scan stopped
14:37:45.012    Disk 0 MBR has been saved successfully to "C:\Users\Sheana\Desktop\MBR.dat"
14:37:45.023    The log file has been saved successfully to "C:\Users\Sheana\Desktop\aswMBR.txt"


Farbar:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09-12-2017
Ran by [removed] (administrator) on SHEANA-PC (09-12-2017 14:40:03)
Running from C:\Users\[removed]\Desktop\WhatTheTech\Farbar
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\SaferVPN\SaferVPN.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
() C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16776704 2016-12-15] (Realtek Semiconductor)
HKLM\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\…\Run: [AVGUI.exe] => "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [SaferVPN] => C:\Program Files (x86)\SaferVPN\SaferVPN.exe [10012592 2017-06-27] ()
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832264 2017-10-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify] => C:\Users\Sheana\AppData\Roaming\Spotify\Spotify.exe [21074320 2017-12-07] (Spotify Ltd)
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [Spotify Web Helper] => C:\Users\Sheana\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2017-12-07] (Spotify Ltd)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{05F01782-356A-4E6E-A8A7-5D782C0D6C0F}: [DhcpNameServer] [removed] [removed]

Internet Explorer:
==================
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-19] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-19] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 5ndobl67.default
FF ProfilePath: C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\5ndobl67.default [2017-12-09]
FF Homepage: Mozilla\Firefox\Profiles\5ndobl67.default -> hxxps://www.google.es/?gws_rd=ssl
FF Extension: (Disable Media WMF NV12 format) - C:\Users\Sheana\AppData\Roaming\Mozilla\Firefox\Profiles\5ndobl67.default\features\{8d673d64-a133-4cbb-9cb3-108c29babeee}\[removed] [2017-12-01] [Lagacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-11-11] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-11-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.co.uk/?gws_rd=ssl
CHR StartupUrls: Default -> "hxxps://www.google.co.uk/?gws_rd=ssl"
CHR Profile: C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default [2017-11-03]
CHR Extension: (Google Slides) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-22]
CHR Extension: (Google Docs) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-21]
CHR Extension: (Google Drive) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-21]
CHR Extension: (YouTube) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-21]
CHR Extension: (Google Search) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-21]
CHR Extension: (Google Sheets) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-21]
CHR Extension: (Google Docs Offline) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-21]
CHR Extension: (Gmail) - C:\Users\Sheana\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-21]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 SaferVPN.Service; C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe [2547120 2017-06-27] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 AVG Antivirus; "C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe" [X]
S3 avgbIDSAgent; "C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe" [X]
S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 b06diag; C:\Windows\system32\drivers\bxdiaga.sys [88104 2012-03-08] (Broadcom Corporation)
S3 BFN7x64; C:\Windows\system32\drivers\Xeno7x64.sys [157288 2012-02-22] (Bigfoot Networks, Inc.)
S3 bxfcoe; C:\Windows\system32\drivers\bxfcoe.sys [178216 2012-02-22] (Broadcom Corporation)
S3 bxois; C:\Windows\system32\drivers\bxois.sys [539176 2012-02-22] (Broadcom Corporation)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R3 netr28x; C:\Windows\System32\DRIVERS\netr28x.sys [2473616 2014-12-10] (MediaTek Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-11-04] ()
S1 avgbdisk; \SystemRoot\system32\drivers\avgbdiska.sys [X]
S1 avgbidsdriver; \SystemRoot\system32\drivers\avgbidsdrivera.sys [X]
S0 avgbidsh; \SystemRoot\system32\drivers\avgbidsha.sys [X]
S0 avgblog; \SystemRoot\system32\drivers\avgbloga.sys [X]
S0 avgbuniv; \SystemRoot\system32\drivers\avgbuniva.sys [X]
S3 avgHwid; \SystemRoot\system32\drivers\avgHwid.sys [X]
S2 avgMonFlt; \SystemRoot\system32\drivers\avgMonFlt.sys [X]
S1 avgRdr; \SystemRoot\system32\drivers\avgRdr2.sys [X]
S0 avgRvrt; \SystemRoot\system32\drivers\avgRvrt.sys [X]
S1 avgSnx; \SystemRoot\system32\drivers\avgSnx.sys [X]
S1 avgSP; \SystemRoot\system32\drivers\avgSP.sys [X]
S2 avgStm; \SystemRoot\system32\drivers\avgStm.sys [X]
S0 avgVmm; \SystemRoot\system32\drivers\avgVmm.sys [X]
U3 aswMBR; \??\C:\Users\Sheana\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Sheana\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-08 11:36 - 2017-12-08 11:36 - 000262144 _____ C:\Windows\Minidump\120817-20108-01.dmp
2017-11-25 15:09 - 2017-12-09 14:40 - 000000000 ____D C:\FRST
2017-11-25 15:06 - 2017-11-25 15:10 - 000000000 ____D C:\Users\Sheana\Desktop\WhatTheTech
2017-11-24 14:40 - 2017-11-24 15:16 - 000000000 ____D C:\Users\Sheana\Desktop\me
2017-11-24 14:35 - 2017-11-24 14:35 - 000000985 _____ C:\Users\Sheana\Desktop\Billeddubletter iPhone.txt
2017-11-23 16:06 - 2017-11-23 16:06 - 000268064 _____ C:\Windows\Minidump\112317-14742-01.dmp
2017-11-23 15:01 - 2017-11-23 15:01 - 000268064 _____ C:\Windows\Minidump\112317-16458-01.dmp
2017-11-22 20:40 - 2017-12-09 13:55 - 000000000 ____D C:\Users\Sheana\AppData\Local\Spotify
2017-11-22 20:40 - 2017-11-22 20:40 - 000001772 _____ C:\Users\Sheana\Desktop\Spotify.lnk
2017-11-22 20:40 - 2017-11-22 20:40 - 000001758 _____ C:\Users\Sheana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-11-22 20:35 - 2017-12-09 14:15 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Spotify
2017-11-22 20:35 - 2017-11-22 20:35 - 000723152 _____ (Spotify Ltd) C:\Users\Sheana\Downloads\SpotifySetup(3).exe
2017-11-21 18:31 - 2017-11-21 18:31 - 000000000 ____D C:\ProgramData\BitDefender
2017-11-21 17:41 - 2017-11-21 17:41 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\adaware
2017-11-21 17:41 - 2017-11-21 17:41 - 000000000 ____D C:\Users\Sheana\AppData\Local\AdAwareDesktop
2017-11-21 17:37 - 2017-11-21 17:37 - 000002335 _____ C:\Users\Public\Desktop\Adaware Antivirus.lnk
2017-11-21 17:37 - 2017-11-21 17:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\adaware
2017-11-21 17:27 - 2017-11-21 17:27 - 000000000 ____D C:\Program Files\adaware
2017-11-21 17:20 - 2017-11-21 17:20 - 000000000 ____D C:\Users\Sheana\AppData\Local\AdAwareUpdater
2017-11-21 17:19 - 2017-11-21 17:19 - 000000000 ____D C:\Program Files\Common Files\adaware
2017-11-21 17:13 - 2017-11-21 17:13 - 002630064 _____ C:\Users\Sheana\Downloads\Adaware_Installer(16).exe
2017-11-21 17:13 - 2017-11-21 17:13 - 000000000 ____D C:\ProgramData\adaware
2017-11-21 14:44 - 2017-12-07 17:34 - 000000000 ____D C:\Users\Sheana\AppData\Local\CrashDumps
2017-11-20 09:31 - 2017-11-20 09:31 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-11-20 09:31 - 2017-11-20 09:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-12-09 14:05 - 2016-11-18 10:14 - 000000000 ____D C:\Users\Sheana\AppData\LocalLow\Mozilla
2017-12-09 14:05 - 2016-11-18 00:19 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-12-09 14:05 - 2016-01-22 12:16 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-09 14:01 - 2009-07-14 05:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-12-09 14:01 - 2009-07-14 05:45 - 000021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-12-09 13:56 - 2016-01-23 10:59 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Skype
2017-12-09 13:56 - 2009-07-14 06:13 - 000785366 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-09 13:56 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-12-09 13:52 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-08 11:36 - 2017-10-08 01:08 - 000000000 ____D C:\Windows\Minidump
2017-12-08 11:35 - 2017-10-08 01:07 - 361828116 _____ C:\Windows\MEMORY.DMP
2017-12-07 17:54 - 2016-01-21 19:27 - 000000000 ____D C:\Users\Sheana
2017-12-05 23:11 - 2016-01-21 19:34 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\vlc
2017-12-03 10:00 - 2009-07-14 06:08 - 000032590 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-12-01 11:09 - 2016-01-21 11:03 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-11-21 17:00 - 2016-01-21 11:18 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\AVG
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\ProgramData\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Program Files (x86)\AVG
2017-11-21 16:57 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\AvgSetupLog
2017-11-21 15:26 - 2017-11-01 13:35 - 001273768 _____ C:\Windows\ntbtlog.txt
2017-11-21 15:07 - 2017-09-27 22:14 - 000000000 _____ C:\Windows\SysWOW64\last.dump
2017-11-20 09:31 - 2016-02-21 20:41 - 000002697 _____ C:\Users\Public\Desktop\Skype.lnk
2017-11-20 09:31 - 2016-01-23 10:59 - 000000000 ____D C:\ProgramData\Skype
2017-11-20 09:30 - 2016-12-22 21:24 - 000000000 ____D C:\ProgramData\Package Cache
2017-11-16 16:57 - 2016-01-22 12:16 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\Mozilla
2017-11-15 20:37 - 2016-01-21 19:34 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2017-11-15 16:10 - 2016-01-21 11:04 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-11-11 20:39 - 2016-01-22 13:25 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-11-11 20:39 - 2016-01-22 13:25 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-11-11 20:39 - 2016-01-22 13:25 - 000000000 ____D C:\Windows\system32\Macromed
2017-11-11 20:38 - 2016-01-22 13:25 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-11-11 20:37 - 2016-01-21 11:01 - 000000000 ____D C:\Users\Sheana\AppData\Local\Adobe

==================== Files in the root of some directories =======

2017-11-04 17:59 - 2017-11-04 18:14 - 004096000 _____ () C:\Program Files (x86)\GUT3FBF.tmp

Some files in TEMP:
====================
2017-11-04 16:09 - 2016-04-09 07:59 - 001732864 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\dllnt_dump.dll
2016-12-13 16:51 - 2016-12-13 16:51 - 000763232 _____ (Google Inc.) C:\Users\Sheana\AppData\Local\Temp\GoogleUpdateSetup_latest.exe
2017-11-20 09:29 - 2017-11-20 09:29 - 014456872 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\vc_redist.x86.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-01 21:12

==================== End of FRST.txt ============================

 

 

Many thanks

Jens

Which antivirus are you using at the moment?

I think I see remnants of 2 different ones.

When Farbar Recovery Scan Tool was first run it should had also created Addition.txt
Can you please search for this and post it in your next reply.

Hi Juliet

-sorry to be back so quickly..

 

I'm using AdAware Free version. I recently uninstalled AVG, because it seemed to create problems.

 

Addition.txt:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-12-2017
Ran by [removed] (09-12-2017 14:40:52)
Running from C:\Users\[removed]\Desktop\WhatTheTech\Farbar
Windows 7 Home Premium Service Pack 1 (X64) (2016-01-21 18:27:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3135081951-948255948-2762818755-500 - Administrator - Disabled)
Guest (S-1-5-21-3135081951-948255948-2762818755-501 - Limited - Disabled)
Sheana (S-1-5-21-3135081951-948255948-2762818755-1000 - Administrator - Enabled) => C:\Users\Sheana

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: adaware antivirus (Disabled - Up to date) {2C8A0DAA-E78D-4944-DB01-263173C8FFD9}
AS: adaware antivirus (Disabled - Up to date) {97EBEC4E-C1B7-46CA-E1B1-1D43084FB564}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
AVG (HKLM\…\{E61E6143-4937-43FC-8C12-06B8A987484D}) (Version: 1.211.3 - AVG Technologies) Hidden
AVG 2016 (HKLM\…\{A1C2B71D-7DD1-4A1F-9B3C-9267CCFE9977}) (Version: 16.0.4568 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 17.7.3032 - AVG Technologies)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.2.18 - AVG Technologies)
doPDF 7.2 printer (HKLM\…\doPDF 7 printer_is1) (Version:  - Softland)
FMW 1 (HKLM\…\{36133E9F-B129-4206-9FB4-13F707787542}) (Version: 1.226.3 - AVG Technologies) Hidden
HZ DDP Player (HKLM-x32\…\HZ DDP Player) (Version:  - Sonoris Audio Engineering)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Java 8 Update 151 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 57.0.2 (x64 en-US) (HKLM\…\Mozilla Firefox 57.0.2 (x64 en-US)) (Version: 57.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 57.0.2.6549 - Mozilla)
MuseScore 2 (HKLM-x32\…\{4F0E15EA-F64C-11E5-9992-E717EA7DB0C8}) (Version: 2.0.3 - Werner Schweer and Others)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8018 - Realtek Semiconductor Corp.)
SaferVPN 4.0.1 (HKLM-x32\…\OpenVPN) (Version: 4.0.1 - )
Skype™ 7.32 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Spotify) (Version: 1.0.69.336.g7edcc575 - Spotify AB)
TeamViewer 10 (HKLM-x32\…\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player 2.1.3 (HKLM-x32\…\VLC media player) (Version: 2.1.3 - VideoLAN)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov)
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-19] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-11-04] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {12E50C69-3CB6-4B4F-830F-255CC057798A} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-12-15] (Realtek Semiconductor)
Task: {4181EF81-3C3E-4CA8-9FB7-C8D9256198B4} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {5A0AEBEF-E027-47E9-842C-7E14F11AA1A6} - \AVG EUpdate Task -> No File <==== ATTENTION
Task: {79C8FF37-5FAF-4CC4-8A1E-F91E61A11022} - System32\Tasks\0116avzUpdateInfo => C:\ProgramData\Avg_Update_0116avz\0116avz_AVG-Secure-Search-Update.exe
Task: {805CC98F-C591-41DF-AB27-6CCDACBEC9BB} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-09-05] (Oracle Corporation)
Task: {8DB25474-BD79-40FD-B5DD-057044430F8D} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {8DB25474-BD79-40FD-B5DD-057044430F8D} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-05-20] (Microsoft Corporation)
Task: {9B52586B-2EEF-4353-BDD7-CD85C7E43D66} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-11] (Adobe Systems Incorporated)
Task: {9D7A9C8E-9DF2-4D7B-9201-CD5EEDE43EE6} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime
Task: {9D7A9C8E-9DF2-4D7B-9201-CD5EEDE43EE6} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-05-20] (Microsoft Corporation)
Task: {A98D5621-4DC9-4E29-B03D-4B0DB90BDD15} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {A98D5621-4DC9-4E29-B03D-4B0DB90BDD15} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
Task: {A98D5621-4DC9-4E29-B03D-4B0DB90BDD15} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [2016-05-20] (Microsoft Corporation)
Task: {B51B90A5-7735-4E89-ABF9-0A89C714B810} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {B51B90A5-7735-4E89-ABF9-0A89C714B810} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-05-20] (Microsoft Corporation)
Task: {CBF0B5FE-50F8-4150-8BDD-0666A7D4431F} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-12-15] (Realtek Semiconductor)
Task: {E8D5BF17-3281-44E3-BB9A-B9CF855F3231} - \Antivirus Emergency Update -> No File <==== ATTENTION
Task: {E92476AA-2379-48E8-9F4C-E361CF0DEF63} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-12-15] (Realtek Semiconductor)
Task: {FBABC458-D980-4FD6-9E28-8887027D40A0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2016-01-21 10:58 - 2011-11-04 03:09 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-06-27 10:29 - 2017-06-27 10:29 - 010012592 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.exe
2017-06-27 10:29 - 2017-06-27 10:29 - 002547120 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe
2017-09-26 21:22 - 2017-09-26 21:22 - 001984000 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2017-11-22 20:40 - 2017-12-07 01:00 - 068214160 _____ () C:\Users\Sheana\AppData\Roaming\Spotify\libcef.dll
2017-11-22 20:40 - 2017-12-07 01:00 - 003112848 _____ () C:\Users\Sheana\AppData\Roaming\Spotify\libglesv2.dll
2017-11-22 20:40 - 2017-12-07 01:00 - 000089488 _____ () C:\Users\Sheana\AppData\Roaming\Spotify\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2017-11-02 21:34 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3135081951-948255948-2762818755-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Sheana\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{CAE3E590-1A56-4FB5-921F-740876D3993B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{2A4ED2D3-F733-47EF-91EF-00D35884DCF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{567D9D82-365D-4390-A528-4945C9D667A1}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7DF1F4CA-2470-4A18-A9C4-12F0D63F8594}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{E0CBB21C-F436-4CDE-8C3F-FF83548696B3}C:\users\sheana\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{BBEFA09D-53C3-4D27-8672-520CB59D7C3B}C:\users\sheana\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{8ACECEA7-BF18-4F44-96BA-F19E16549D79}] => (Block) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{9881CA47-E562-4E64-9872-DD50F23192CF}] => (Block) C:\users\sheana\appdata\roaming\spotify\spotify.exe
FirewallRules: [{887C498C-B225-4568-976E-3A512465E342}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{F43F98A3-2304-439C-A6AE-C1E331E9AC09}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{E7BF31DE-B450-4854-BB62-D31F4CB147AE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{2BEFB6DB-A1B9-4A41-8AB1-CBDD2171E1F8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{44423604-F800-47E8-BB4B-5BEDCFEDED2F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{EF9206AA-EF3D-4CBE-9B82-EC483BECB717}] => (Allow) C:\ProgramFiles(x86)\SaferVPN\SaferVPN.exe

==================== Restore Points =========================


==================== Faulty Device Manager Devices =============

Name: avgRdr
Description: avgRdr
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: avgRdr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: avgStm
Description: avgStm
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: avgStm
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/09/2017 01:58:07 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.

Program: Host Process for Windows Services
File: C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
    - It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C0000185
Disk type: 3

Error: (12/09/2017 01:58:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000006
Fault offset: 0x000000000000f947
Faulting process id: 0xf4
Faulting application start time: 0x01d370ed46cf0bd2
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: c:\windows\system32\sysmain.dll
Report Id: 997bef14-dce0-11e7-b5ca-10bf480796fa

Error: (12/09/2017 01:56:31 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.

Program: Host Process for Windows Services
File: C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
    - It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C0000185
Disk type: 3

Error: (12/09/2017 01:56:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000006
Fault offset: 0x000000000000f947
Faulting process id: 0xebc
Faulting application start time: 0x01d370ecf3b2b609
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: c:\windows\system32\sysmain.dll
Report Id: 6083d138-dce0-11e7-b5ca-10bf480796fa

Error: (12/09/2017 01:54:01 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.

Program: Host Process for Windows Services
File: C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
    - It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C0000185
Disk type: 3

Error: (12/09/2017 01:54:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000006
Fault offset: 0x000000000000f947
Faulting process id: 0x744
Faulting application start time: 0x01d370ec927fb729
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: c:\windows\system32\sysmain.dll
Report Id: 06f4d0f3-dce0-11e7-b5ca-10bf480796fa

Error: (12/09/2017 01:54:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (12/09/2017 09:55:49 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.

Program: Host Process for Windows Services
File: C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
    - It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C0000185
Disk type: 3

Error: (12/09/2017 09:55:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_SysMain, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: sysmain.dll, version: 6.1.7601.18933, time stamp: 0x55a6a1d1
Exception code: 0xc0000006
Fault offset: 0x000000000000f947
Faulting process id: 0x1318
Faulting application start time: 0x01d370cb6dc31dbc
Faulting application path: C:\Windows\system32\svchost.exe
Faulting module path: c:\windows\system32\sysmain.dll
Report Id: c012764f-dcbe-11e7-9b0c-10bf480796fa

Error: (12/09/2017 09:54:14 AM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.

Program: Host Process for Windows Services
File: C:\Windows\Prefetch\LOGONUI.EXE-F639BD7E.pf

The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
    - It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
    - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.

Additional Data
Error value: C0000185
Disk type: 3


System errors:
=============
Error: (12/09/2017 01:58:07 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Superfetch service terminated unexpectedly.  It has done this 3 time(s).

Error: (12/09/2017 01:56:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Superfetch service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (12/09/2017 01:55:57 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:55:57 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:54:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Superfetch service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

Error: (12/09/2017 01:53:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:53:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:53:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:53:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.

Error: (12/09/2017 01:53:23 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz
Percentage of memory in use: 52%
Total physical RAM: 4000.13 MB
Available physical RAM: 1911.11 MB
Total Virtual: 7998.43 MB
Available Virtual: 5635.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:270.35 GB) (Free:138.26 GB) NTFS
Drive d: (DATA) (Fixed) (Total:195.21 GB) (Free:99.36 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 493C1F0B)
Partition 1: (Not Active) - (Size=195.2 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=270.3 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

 

 

Thanx

Jens

Start Farbar Recovery Scan Tool with Administrator privileges

Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
Task: {4181EF81-3C3E-4CA8-9FB7-C8D9256198B4} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {5A0AEBEF-E027-47E9-842C-7E14F11AA1A6} - \AVG EUpdate Task -> No File <==== ATTENTION
Task: {79C8FF37-5FAF-4CC4-8A1E-F91E61A11022} - System32\Tasks\0116avzUpdateInfo => C:\ProgramData\Avg_Update_0116avz\0116avz_AVG-Secure-Search-Update.exe
Task: {E8D5BF17-3281-44E3-BB9A-B9CF855F3231} - \Antivirus Emergency Update -> No File <==== ATTENTION
FirewallRules: [{CAE3E590-1A56-4FB5-921F-740876D3993B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{2A4ED2D3-F733-47EF-91EF-00D35884DCF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
HKLM\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\…\Run: [AVGUI.exe] => "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
C:\Program Files (x86)\AVG
C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
S2 AVG Antivirus; "C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe" [X]
S3 avgbIDSAgent; "C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe" [X]
S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X]
C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe"
C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
S1 avgbdisk; \SystemRoot\system32\drivers\avgbdiska.sys [X]
S1 avgbidsdriver; \SystemRoot\system32\drivers\avgbidsdrivera.sys [X]
S0 avgbidsh; \SystemRoot\system32\drivers\avgbidsha.sys [X]
S0 avgblog; \SystemRoot\system32\drivers\avgbloga.sys [X]
S0 avgbuniv; \SystemRoot\system32\drivers\avgbuniva.sys [X]
S3 avgHwid; \SystemRoot\system32\drivers\avgHwid.sys [X]
S2 avgMonFlt; \SystemRoot\system32\drivers\avgMonFlt.sys [X]
S1 avgRdr; \SystemRoot\system32\drivers\avgRdr2.sys [X]
S0 avgRvrt; \SystemRoot\system32\drivers\avgRvrt.sys [X]
S1 avgSnx; \SystemRoot\system32\drivers\avgSnx.sys [X]
S1 avgSP; \SystemRoot\system32\drivers\avgSP.sys [X]
S2 avgStm; \SystemRoot\system32\drivers\avgStm.sys [X]
S0 avgVmm; \SystemRoot\system32\drivers\avgVmm.sys [X]
2017-11-21 17:00 - 2016-01-21 11:18 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\AVG
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\ProgramData\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Program Files (x86)\AVG
2017-11-21 16:57 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\AvgSetupLog
2017-11-04 16:09 - 2016-04-09 07:59 - 001732864 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\dllnt_dump.dll
2016-12-13 16:51 - 2016-12-13 16:51 - 000763232 _____ (Google Inc.) C:\Users\Sheana\AppData\Local\Temp\GoogleUpdateSetup_latest.exe
2017-11-20 09:29 - 2017-11-20 09:29 - 014456872 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\vc_redist.x86.exe
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~

Fixlog;

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-12-2017
Ran by [removed] (13-12-2017 19:13:00) Run:2
Running from C:\Users\[removed]\Desktop\WhatTheTech\Farbar
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
Task: {4181EF81-3C3E-4CA8-9FB7-C8D9256198B4} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {5A0AEBEF-E027-47E9-842C-7E14F11AA1A6} - \AVG EUpdate Task -> No File <==== ATTENTION
Task: {79C8FF37-5FAF-4CC4-8A1E-F91E61A11022} - System32\Tasks\0116avzUpdateInfo => C:\ProgramData\Avg_Update_0116avz\0116avz_AVG-Secure-Search-Update.exe
Task: {E8D5BF17-3281-44E3-BB9A-B9CF855F3231} - \Antivirus Emergency Update -> No File <==== ATTENTION
FirewallRules: [{CAE3E590-1A56-4FB5-921F-740876D3993B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{2A4ED2D3-F733-47EF-91EF-00D35884DCF5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
HKLM\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\…\Run: [AVGUI.exe] => "C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" /gui
C:\Program Files (x86)\AVG
C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe
HKLM-x32\…\Run: [AvgUi] => "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
S2 AVG Antivirus; "C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe" [X]
S3 avgbIDSAgent; "C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe" [X]
S2 avgsvc; "C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" [X]
C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe"
C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
S1 avgbdisk; \SystemRoot\system32\drivers\avgbdiska.sys [X]
S1 avgbidsdriver; \SystemRoot\system32\drivers\avgbidsdrivera.sys [X]
S0 avgbidsh; \SystemRoot\system32\drivers\avgbidsha.sys [X]
S0 avgblog; \SystemRoot\system32\drivers\avgbloga.sys [X]
S0 avgbuniv; \SystemRoot\system32\drivers\avgbuniva.sys [X]
S3 avgHwid; \SystemRoot\system32\drivers\avgHwid.sys [X]
S2 avgMonFlt; \SystemRoot\system32\drivers\avgMonFlt.sys [X]
S1 avgRdr; \SystemRoot\system32\drivers\avgRdr2.sys [X]
S0 avgRvrt; \SystemRoot\system32\drivers\avgRvrt.sys [X]
S1 avgSnx; \SystemRoot\system32\drivers\avgSnx.sys [X]
S1 avgSP; \SystemRoot\system32\drivers\avgSP.sys [X]
S2 avgStm; \SystemRoot\system32\drivers\avgStm.sys [X]
S0 avgVmm; \SystemRoot\system32\drivers\avgVmm.sys [X]
2017-11-21 17:00 - 2016-01-21 11:18 - 000000000 ____D C:\Users\Sheana\AppData\Roaming\AVG
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\ProgramData\Avg
2017-11-21 17:00 - 2016-01-21 11:13 - 000000000 ____D C:\Program Files (x86)\AVG
2017-11-21 16:57 - 2016-01-21 11:13 - 000000000 ____D C:\Users\Sheana\AppData\Local\AvgSetupLog
2017-11-04 16:09 - 2016-04-09 07:59 - 001732864 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\dllnt_dump.dll
2016-12-13 16:51 - 2016-12-13 16:51 - 000763232 _____ (Google Inc.) C:\Users\Sheana\AppData\Local\Temp\GoogleUpdateSetup_latest.exe
2017-11-20 09:29 - 2017-11-20 09:29 - 014456872 _____ (Microsoft Corporation) C:\Users\Sheana\AppData\Local\Temp\vc_redist.x86.exe
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll -> No File
Emptytemp:

*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AVG => key not found
HKLM\Software\Classes\CLSID\{472083B1-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => key not found
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\AVG => key not found
HKLM\Software\Classes\CLSID\{472083B1-C522-11CF-8763-00608CC02F24} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4181EF81-3C3E-4CA8-9FB7-C8D9256198B4} => key not found
C:\Windows\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVGPCTuneUp_Task_BkGndMaintenance => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A0AEBEF-E027-47E9-842C-7E14F11AA1A6} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG EUpdate Task => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79C8FF37-5FAF-4CC4-8A1E-F91E61A11022} => key not found
C:\Windows\System32\Tasks\0116avzUpdateInfo => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0116avzUpdateInfo => key not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E8D5BF17-3281-44E3-BB9A-B9CF855F3231}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E8D5BF17-3281-44E3-BB9A-B9CF855F3231}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Antivirus Emergency Update" => removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CAE3E590-1A56-4FB5-921F-740876D3993B} => value not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2A4ED2D3-F733-47EF-91EF-00D35884DCF5} => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AvgUi => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AVGUI.exe => value not found.
"C:\Program Files (x86)\AVG" => not found.
"C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe" => not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AvgUi => value not found.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key not found
AVG Antivirus => service not found.
avgbIDSAgent => service not found.
avgsvc => service not found.
"C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe" => not found.
"C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe" => not found.
"C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe" => not found.
avgbdisk => service not found.
avgbidsdriver => service not found.
avgbidsh => service not found.
avgblog => service not found.
avgbuniv => service not found.
avgHwid => service not found.
avgMonFlt => service not found.
avgRdr => service not found.
avgRvrt => service not found.
avgSnx => service not found.
avgSP => service not found.
avgStm => service not found.
avgVmm => service not found.
"C:\Users\Sheana\AppData\Roaming\AVG" => not found.
"C:\Users\Sheana\AppData\Local\Avg" => not found.
"C:\ProgramData\Avg" => not found.
"C:\Program Files (x86)\AVG" => not found.
"C:\Users\Sheana\AppData\Local\AvgSetupLog" => not found.
"C:\Users\Sheana\AppData\Local\Temp\dllnt_dump.dll" => not found.
"C:\Users\Sheana\AppData\Local\Temp\GoogleUpdateSetup_latest.exe" => not found.
"C:\Users\Sheana\AppData\Local\Temp\vc_redist.x86.exe" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => key not found
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\AVG => key not found
HKLM\Software\Classes\CLSID\{472083B1-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avg => key not found
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\AVG => key not found
HKLM\Software\Classes\CLSID\{472083B1-C522-11CF-8763-00608CC02F24} => key not found

=========== EmptyTemp: ==========

BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1051928 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 0 B
Firefox => 16406979 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 16554 B
NetworkService => 20466 B
Sheana => 467820730 B

 

 

I'll run the diskcheck  later. The way the thing works right now, everything takes forever :(  Can the disk checks run in safe mode just as well?

 

Jens

RecycleBin => 239880335 B
EmptyTemp: => 703.6 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:29:19 ====

Also, when it seems to be bogging down, open task manager
then click on the button at the bottom and chose
'show all processes from all users'

See if you can find something using the most CPU.

I ran disk check. When it had finished, it strangely was about to start all over again - I cancelled that, and the computer was able to start normally.

It turned out, Windows Update hadn't been doing anything (!), so I ran the 6 updates available.

The processes - apart from Firefox - which uses the CPU the most are Spotify, Skype and SaferVPN (this was just a trial version, but it won't uninstall)

So must I disable Skype and Spotify? They shouldn't be running at all, maybe the problems got something to do with them also?

 

Computer seems better after Disk Check..

So must I disable Skype and Spotify

It wont hurt to disable them, re-enable when needed.
 
We can take out SaferVPN

Open your control panel
System Preferences -> Network.
Then select the SaferVPN from the left pane and delete it by clicking on the minus sign

~~~~~~~~~~~~~~~~~~~~~~
Please run the below fix only once.

Start Farbar Recovery Scan Tool with Administrator privileges

Right click/highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
2017-06-27 10:29 - 2017-06-27 10:29 - 010012592 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.exe
2017-06-27 10:29 - 2017-06-27 10:29 - 002547120 _____ () C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe
HKU\S-1-5-21-3135081951-948255948-2762818755-1000\…\Run: [SaferVPN] => C:\Program Files (x86)\SaferVPN\SaferVPN.exe [10012592 2017-06-27] ()
R2 SaferVPN.Service; C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe [2547120 2017-06-27] ()
C:\Program Files (x86)\SaferVPN\SaferVPN.Service.exe
C:\Program Files (x86)\SaferVPN
FirewallRules: [{EF9206AA-EF3D-4CBE-9B82-EC483BECB717}] => (Allow) C:\ProgramFiles(x86)\SaferVPN\SaferVPN.exe
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~

[external image: G0tu5D9.png]Emsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;
  • created by Aura

~~
please post these 2 logs when finished.

Here goes:

 

Farbar:

 

Firefox => 358601574 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Sheana => 91244 B

RecycleBin => 4558 B
EmptyTemp: => 373.7 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-12-2017 12:47:28)

C:\Program Files (x86)\SaferVPN => moved successfully

==== End of Fixlog 12:47:29 ====

 

EEK:

 

Emsisoft Emergency Kit 2017.11.0.8219 stable [en-us]
OS: Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)

Forensics log

Date    Component    Action    Details    
12/15/2017 1:45:31 PM    User SHEANA-PC\SHEANA    Infection quarantined    PUP "Application.AdReg (A)" in "{95B7759C-8C7F-4BF1-B163-73684A933233}".    
12/15/2017 1:45:30 PM    User SHEANA-PC\SHEANA    Infection quarantined    Malware "Application.Downloader (A)" in "SpotifySetup-39223635.exe".    
12/15/2017 1:36:41 PM    Scanner    Scan finished    Found 2 objects , user to decide on further actions.    
12/15/2017 1:34:04 PM    Scanner    Detection    PUP "Application.AdReg (A)" in "{95B7759C-8C7F-4BF1-B163-73684A933233}" and PUP "Application.Downloader (A)" in "SpotifySetup-39223635.exe"    
12/15/2017 1:31:56 PM    User SHEANA-PC\Sheana    Scan started    Malware Scan    
12/15/2017 1:31:55 PM    User SHEANA-PC\Sheana    Setting modified    "Detect PUPs" has been changed to "Enabled".    
12/15/2017 1:31:33 PM    User    Update    Downloaded and installed 42 files (2182 kb) (48 sec.).    
12/15/2017 1:30:45 PM    Core    Notification    "Recommended Reading:Ransomware-as-a-Service: Commoditizing ransomware".    
12/15/2017 1:30:40 PM    User    Update    Failed with error "Server returned error" (0 sec.).    
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI