Hi klrock :)

Follow the instructions below please.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Download the right version of FRST for your system:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Make sure the Addition.txt box is checked
  • Click on the Scan button
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-11-2017
Ran by Kerry (administrator) on K-PC (16-11-2017 14:43:57)
Running from C:\Users\Kerry\Desktop
Loaded Profiles: Kerry (Available Profiles: Kerry)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ABBYY (BIT Software)) C:\Program Files (x86)\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\\NSBU.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\TimeMgmtDaemon.exe
(GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\WhsMcClient.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\WSConnectorUpdate.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Symantec Corporation) C:\Program Files\Norton Security with Backup\Engine\\NSBU.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\ProviderRegistryService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\LANConfigSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
() C:\Program Files (x86)\GIGABYTE\smart6\dbios\SDBMSG.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(GlavSoft LLC.) C:\Program Files\TightVNC\tvnserver.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\Launchpad.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Microsoft Corporation) C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(BitTorrent Inc.) C:\Users\Kerry\AppData\Roaming\uTorrent\uTorrent.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(BitTorrent Inc.) C:\Users\Kerry\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe
(BitTorrent Inc.) C:\Users\Kerry\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\smart6\timelock\AlarmClock.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Windows Server\Bin\Microsoft.HomeServer.Archive.TransferService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Kerry\Desktop\FRST64 (1).exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [tvncontrol] => C:\Program Files\TightVNC\tvnserver.exe [1725408 2017-03-14] (GlavSoft LLC.)
HKLM\...\Run: [Launchpad] => C:\Program Files\Windows Server\Bin\Launchpad.exe [1099360 2012-11-02] (Microsoft Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2010-09-09] (CANON INC.)
HKLM\...\RunOnce: [RPMKickstart] => C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.)
HKLM-x32\...\RunOnce: [SDBOK] => C:\Program Files (x86)\GIGABYTE\smart6\dbios\run.exe [207400 2009-07-06] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4836032 2017-08-14] (Disc Soft Ltd)
HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\Run: [SkyDrive] => C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257224 2017-10-21] (Microsoft Corporation)
HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\Run: [uTorrent] => C:\Users\Kerry\AppData\Roaming\uTorrent\uTorrent.exe [1985984 2017-10-27] (BitTorrent Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2017-10-17] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{24DCB72F-3C6A-4035-A688-03D4F217905E}: [DhcpNameServer]

Internet Explorer:
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2957907037-1284653929-173307917-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11913&l=dis&prt=NSBU&chn=1007450&geo=US&ver=
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
BHO: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine\\coIEPlg.dll [2017-10-03] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HelperObject Class -> {00C6482D-C502-44C8-8409-FCE54AD9C208} -> C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItBHO.dll [2005-12-22] (TechSmith Corporation)
BHO-x32: Norton Identity Safety -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton Security with Backup\Engine32\\coIEPlg.dll [2017-10-03] (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine\\coIEPlg.dll [2017-10-03] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine32\\coIEPlg.dll [2017-10-03] (Symantec Corporation)
Toolbar: HKLM-x32 - SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll [2005-12-22] (TechSmith Corporation)
Toolbar: HKU\S-1-5-21-2957907037-1284653929-173307917-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-2957907037-1284653929-173307917-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security with Backup\Engine\\coIEPlg.dll [2017-10-03] (Symantec Corporation)

FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon => not found
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.11.0.41\coFFAddon => not found
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)

CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3333887&octid=EB_ORIGINAL_CTID&ISID=M04E60662-87BC-4222-A125-574BEC80859C&SearchSource=55&CUI=&UM=8&UP=SPD07634BD-C4D4-493C-913C-D652C598EA05&D=121215&SSPV=
CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxp://freebies.about.com/od/free-plans/tp/free-kitchen-island-plans.htm","hxxp://www.oldpaintdesign.com/2012/06/29/gaby-kitchen-island/","hxxp://www.diynetwork.com/how-to/rooms-and-spaces/kitchen/how-to-build-a-kitchen-cart","hxxp://my.xfinity.com/?cid=cust","hxxps://web.mail.comcast.net/zimbra/mail?app=mail#1","hxxps://malwaretips.com/blogs/trovi-removal/","chrome://newtab/","chrome://newtab/","hxxps://search.yahoo.com/?type=994519&fr=yo-yhp-ch","hxxps://search.yahoo.com/?type=316617&fr=yo-yhp-ch","hxxp://searchinterneat-a.akamaihd.net/hm?eq=U0EeCFZVBB8SRggUeA5eVVhJERhAdA5cTA0TRQcOIVxeURRFFwYXIQ9ZV1xJEVAFIk0FA1oDB0VXfV5bFElXTwhuIUpLMlwQ"
CHR DefaultSearchURL: Default -> hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o=APN11908
CHR DefaultSearchKeyword: Default -> NortonSafe
CHR DefaultSuggestURL: Default -> hxxps://ss-sym.search.ask.com/ss?q={searchTerms}&li=ff
CHR Profile: C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default [2017-11-16]
CHR Extension: (Slides) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-15]
CHR Extension: (Docs) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-15]
CHR Extension: (Google Drive) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-15]
CHR Extension: (YouTube) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-15]
CHR Extension: (Form Filler) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnjjngeaknajbdcgpfkgnonkmififhfo [2017-10-15]
CHR Extension: (Flip this) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\donljlliiecjcagcenoeohjmabfegkph [2017-10-15]
CHR Extension: (Google Calendar) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-10-15]
CHR Extension: (Google Play Music) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-10-15]
CHR Extension: (Flash Playlist) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fanagokoaogopceablgmpndejhedkjjb [2017-11-16]
CHR Extension: (Sheets) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-15]
CHR Extension: (Norton Home Page for Chrome) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfoabcdjalmeenbjjngidappmppchblc [2017-10-15]
CHR Extension: (Google Docs Offline) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-15]
CHR Extension: (AdBlock) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-11-14]
CHR Extension: (Pinterest Save Button) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-11-16]
CHR Extension: (Norton Safe) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbmobhkkblcgdifigjglcjneplefbkmh [2017-10-15]
CHR Extension: (Fetchee: Price Tracking Wishlist) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkejdkgihbncgfffggdokommlakigcgg [2017-10-15]
CHR Extension: (Search Incognito) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlcgjkbdmlnfmelambncafejbemlfodl [2017-10-15]
CHR Extension: (Google Play Music) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2017-10-15]
CHR Extension: (Norton Identity Safe) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2017-10-15]
CHR Extension: (MP3 Player) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbiheleggoempookkoblhdgmlojbicob [2017-10-15]
CHR Extension: (StumbleBar by StumbleUpon) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2017-10-15]
CHR Extension: (Cently (Coupons at Checkout)) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kegphgaihkjoophpabchkmpaknehfamb [2017-11-11]
CHR Extension: (Loom - Video Recorder: Screen, Webcam and Mic) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\liecbddmkiiihnedobmlmillhodjkdmb [2017-11-14]
CHR Extension: (Wikibuy) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nenlahapcbofgnanklpelkaejcehkggg [2017-11-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-15]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2017-10-15]
CHR Extension: (Evernote Web Clipper) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2017-11-03]
CHR Extension: (Gmail) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-15]
CHR Extension: (Chrome Media Router) - C:\Users\Kerry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-16]
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\\Exts\Chrome.crx <not found>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files\Norton Security with Backup\Engine\\Exts\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Professional.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [660768 2007-12-06] (ABBYY (BIT Software))
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2291904 2017-08-14] (Disc Soft Ltd)
R2 HealthAlertsSvc; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
S2 initMonitor; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
R2 NotificationsProviderSvc; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)
R2 NSBU; C:\Program Files\Norton Security with Backup\Engine\\NSBU.exe [326144 2017-10-04] (Symantec Corporation)
R2 providers_system; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)
R2 ServiceProviderRegistry; C:\Program Files\Windows Server\Bin\ProviderRegistryService.exe [41568 2012-11-02] (Microsoft Corporation)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.) [File not signed]
R2 SqmProviderSvc; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)
R2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [1725408 2017-03-14] (GlavSoft LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WSS_ComputerBackupProviderSvc; C:\Program Files\Windows Server\Bin\SharedServiceHost.exe [30592 2011-03-02] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files\Norton Security with Backup\NortonData\\Definitions\BASHDefs\20171108.001\BHDrvx64.sys [1872024 2017-10-11] (Symantec Corporation)
R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\160B000.029\ccSetx64.sys [187520 2017-10-03] (Symantec Corporation)
R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-10-15] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-10-15] (Disc Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [508056 2017-10-18] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [158360 2017-10-18] (Symantec Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-10-04] ()
S3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2017-10-16] ()
R1 IDSVia64; C:\Program Files\Norton Security with Backup\NortonData\\Definitions\IPSDefs\20171115.001\IDSvia64.sys [1056920 2017-10-13] (Symantec Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [192952 2017-11-03] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2017-11-16] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [45504 2017-11-16] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-10-31] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2017-11-16] (Malwarebytes)
R3 SRTSP; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSP64.SYS [812704 2017-10-03] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\160B000.029\SRTSPX64.SYS [49304 2017-10-03] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\160B000.029\SYMEFASI64.SYS [1868416 2017-10-03] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [102568 2017-10-15] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\160B000.029\Ironx64.SYS [301288 2017-10-03] (Symantec Corporation)
R1 SymNetS; C:\Windows\system32\drivers\NSBUx64\160B000.029\SYMNETS.SYS [566912 2017-10-03] (Symantec Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-16 14:43 - 2017-11-16 14:44 - 000022862 _____ C:\Users\Kerry\Desktop\FRST.txt
2017-11-16 14:43 - 2017-11-16 14:43 - 000000000 ____D C:\Users\Kerry\Desktop\FRST-OlderVersion
2017-11-16 14:43 - 2017-11-16 14:43 - 000000000 ____D C:\FRST
2017-11-16 14:31 - 2017-11-16 14:31 - 000000000 ____D C:\Windows\System32\Tasks\Remediation
2017-11-16 11:13 - 2017-11-16 14:43 - 002392576 _____ (Farbar) C:\Users\Kerry\Desktop\FRST64 (1).exe
2017-11-16 11:11 - 2017-11-16 11:11 - 002392576 _____ (Farbar) C:\Users\Kerry\Downloads\FRST64 (1).exe
2017-11-15 09:23 - 2017-11-15 09:23 - 019053215 _____ C:\Users\Kerry\Downloads\MFL39760238-Eng%2BSpan.pdf
2017-11-15 03:11 - 2017-10-15 11:31 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts.original
2017-11-14 21:19 - 2017-11-14 21:19 - 000000000 ____D C:\Users\Kerry\Documents\eagle
2017-11-14 21:17 - 2017-11-14 21:17 - 000942749 _____ C:\Users\Kerry\Downloads\LM317+Benchtop+PSU (1).sch
2017-11-14 21:16 - 2017-11-15 03:22 - 000000000 ____D C:\Users\Kerry\AppData\Roaming\Eagle
2017-11-14 21:16 - 2017-11-14 21:16 - 000000000 ____D C:\Users\Kerry\AppData\Roaming\CadSoft
2017-11-14 21:14 - 2017-11-14 21:14 - 000000828 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EAGLE.lnk
2017-11-14 21:13 - 2017-11-14 21:14 - 000000000 ____D C:\Program Files\EAGLE 8.4.1
2017-11-14 21:11 - 2017-11-14 21:11 - 107898120 _____ (Autodesk, Inc. ) C:\Users\Kerry\Downloads\Autodesk_EAGLE_8.4.1_English_Win_64Bit.exe
2017-11-14 21:10 - 2017-11-14 21:10 - 000942749 _____ C:\Users\Kerry\Downloads\LM317+Benchtop+PSU.sch
2017-10-18 04:20 - 2016-10-11 09:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2017-10-18 04:20 - 2016-10-11 09:31 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2017-10-18 04:20 - 2016-10-11 09:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2017-10-18 04:20 - 2016-10-11 09:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================



Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-11-2017
Ran by Kerry (16-11-2017 14:44:18)
Running from C:\Users\Kerry\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2017-10-15 13:43:01)
==================== Accounts: =============================

Administrator (S-1-5-21-2957907037-1284653929-173307917-500 - Administrator - Disabled)
Guest (S-1-5-21-2957907037-1284653929-173307917-501 - Limited - Disabled)
Kerry (S-1-5-21-2957907037-1284653929-173307917-1000 - Administrator - Enabled) => C:\Users\Kerry

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Enabled - Up to date) {30744133-1E94-7B35-F4A3-82A5AEF1CBAA}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton Security (Enabled - Up to date) {8B15A0D7-38AE-74BB-CE13-B9D7D5768117}
FW: Norton Security (Enabled) {084FC016-54FB-7A6D-DFFC-2B9050228CD1}

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

@BIOS (HKLM-x32\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.11 - GIGABYTE)
µTorrent (HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\uTorrent) (Version: - BitTorrent Inc.)
7-Zip 17.01 beta (x64) (HKLM\...\7-Zip) (Version: 17.01 beta - Igor Pavlov)
ABBYY FineReader 9.0 Professional Edition (HKLM-x32\...\{F9000000-0001-0000-0000-074957833700}) (Version: 9.00.724.5507 - ABBYY)
Arduino (HKLM-x32\...\Arduino) (Version: 1.8.5 - Arduino LLC)
AutoGreen B10.1021.1 (HKLM-x32\...\{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) Hidden
AutoGreen B10.1021.1 (HKLM-x32\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE)
Big Solitaires 3D 1.4 (HKLM-x32\...\Big Solitaires 3D 1.4_is1) (Version:  - Felix Jose Cladellas)
BitTorrent (HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\BitTorrent) (Version: - BitTorrent Inc.)
Bullzip PDF Printer (HKLM\...\Bullzip PDF Printer_is1) (Version: - Bullzip)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MP Navigator EX 5.1 (HKLM-x32\...\MP Navigator EX 5.1) (Version:  - )
Canon MX410 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX410_series) (Version:  - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.35 - Piriform)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: - Disc Soft Ltd)
DriverUpdate (HKLM\...\{DAAA600A-9F08-4BC8-ABE2-6763F93957C6}) (Version: 4.3.1 - Slimware Utilities Holdings, Inc.) Hidden
EAGLE 8.4.1 (HKLM\...\{AUTODESK-EAGLE-8-4-1}_is1) (Version: 8.4.1 - Autodesk, Inc.)
Easy Tune 6 B11.0512.1 (HKLM-x32\...\{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE) Hidden
Easy Tune 6 B11.0512.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE)
Etcher 1.1.2 (only current user) (HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\573339af-d9e1-5dd3-804c-e0162fac1f41) (Version: 1.1.2 - Resin Inc.)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.98 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.98 - Etron Technology)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: - Google Inc.) Hidden
Hoyle Casino 2006 (remove only) (HKLM-x32\...\HCS10DL) (Version:  - )
Hoyle Puzzle Games 2004 (HKLM-x32\...\{12362BED-DF87-40CD-97AB-A6DA564E8B8F}) (Version: 1.00.0000 - Sierra) Hidden
Hoyle Puzzle Games 2004 (HKLM-x32\...\InstallShield_{12362BED-DF87-40CD-97AB-A6DA564E8B8F}) (Version: 1.00.0000 - Sierra)
Image Resizer for Windows (64 bit) (HKLM\...\{617CA6E9-D5FB-4017-8130-82E68C56C34D}) (Version: 3.0.4802.35565 - Brice Lambson) Hidden
Image Resizer for Windows (HKLM-x32\...\{69d72156-6582-4556-8637-06f40aa7f85b}) (Version: 3.0.4802.35565 - Brice Lambson)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Malwarebytes version (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: - Malwarebytes)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2957907037-1284653929-173307917-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MyHarmony (HKLM-x32\...\{2AD8F8A1-ECE5-4890-BCC2-B4396370A0D4}) (Version: 1.0.302 - Logitech)
Norton Security (HKLM-x32\...\NSBU) (Version: - Symantec Corporation)
Opera Stable 48.0.2685.52 (HKLM-x32\...\Opera 48.0.2685.52) (Version: 48.0.2685.52 - Opera Software)
Pretty Good Solitaire 2k (HKLM-x32\...\Pretty Good Solitaire 2k) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Smart 6 B11.0512.1 (HKLM-x32\...\{3B35725F-C623-4A1E-B5CC-99C0868679E3}) (Version: 1.00.0000 - GIGABYTE)
SnagIt 8 (HKLM-x32\...\{A900E37C-AAE3-44FB-8EE7-7E61F7087CE7}) (Version: 8.0.0 - TechSmith Corporation)
TightVNC (HKLM\...\{DEE0B752-52D8-4615-9BEE-1EDA46628960}) (Version: - GlavSoft LLC.)
Windows Home Server 2011 Connector (HKLM\...\{C1E4D639-4A33-4314-809E-89BD0EF48522}) (Version: 6.1.8800.16400 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2957907037-1284653929-173307917-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2957907037-1284653929-173307917-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2957907037-1284653929-173307917-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2957907037-1284653929-173307917-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2957907037-1284653929-173307917-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers1: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ContextMenuHandlers1-x32: [FineReader9ContextMenu] -> {59A3380E-5305-4cea-BD99-4F2FF510C91F} => C:\Program Files (x86)\ABBYY FineReader 9.0\FRIntegration.dll [2007-12-07] (ABBYY Software Ltd)
ContextMenuHandlers1-x32: [Image Resizer] -> {51B4D7E5-7568-4234-B4BB-47FB3C016A69} => C:\Program Files\Image Resizer for Windows\ShellExtensions.dll [2013-02-23] (Brice Lambson)
ContextMenuHandlers1-x32-x32: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItShellExt.dll [2005-12-22] (TechSmith Corporation)
ContextMenuHandlers1-x32-x32: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\\NavShExt.dll [2017-10-03] (Symantec Corporation)
ContextMenuHandlers2: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\\NavShExt.dll [2017-10-03] (Symantec Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers4-x32: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItShellExt.dll [2005-12-22] (TechSmith Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers6: [BUContextMenu] -> {F7CAA2A1-67A2-44BB-B20F-202FD8EB1DAB} => C:\Program Files\Norton Security with Backup\Engine\\buShell.dll [2017-10-03] (Symantec Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers6: [Symantec.Norton.Antivirus.IEContextMenu] -> {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} => C:\Program Files\Norton Security with Backup\Engine\\NavShExt.dll [2017-10-03] (Symantec Corporation)

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {158A8CB4-DF03-47BF-AE67-67D2E60B5880} - System32\Tasks\{D6C61AE3-E101-45A8-85FC-5B698BD7ADE8} => C:\Windows\system32\pcalua.exe -a "C:\Users\Kerry\Downloads\Bookworm Virus Free Full Version Game No Brainer Installation.exe" -d C:\Users\Kerry\Downloads
Task: {1839229F-6C58-496C-91D5-B1B86D18D053} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-15] (Google Inc.)
Task: {1CAE832B-66F6-4D7D-AED4-2CB245C9F917} - System32\Tasks\Opera scheduled Autoupdate 1508242614 => C:\Program Files\Opera\launcher.exe [2017-10-24] (Opera Software)
Task: {1D299765-8E17-438A-93C9-299E0A233451} - System32\Tasks\Norton Security with Backup\Norton Security with Backup Error Processor => C:\Program Files\Norton Security with Backup\Engine\\SymErr.exe [2017-10-03] (Symantec Corporation)
Task: {252E13FC-A4EB-4DEA-A3F4-95B7C99DDB13} - System32\Tasks\Microsoft\Windows\Windows Server\Backup => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {3BE208CD-0754-487A-B4F3-57B6EE9B13D5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-09-20] (Piriform Ltd)
Task: {3EC00715-8329-4733-A279-45C9C4FD86B4} - System32\Tasks\Microsoft\Windows\Windows Server\UploadCEIPData => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {5679B023-1FD4-4A33-9353-EDEF83617EE2} - System32\Tasks\{69325FE3-CE27-498F-B696-0CD22EDB1E17} => E:\24 Pop Cap Games\24 Pop Cap Games\Cracks\bookworm.deluxe.1.0.keygen-tsrh.exe
Task: {5FA34632-7CE9-475B-B661-18803A729717} - System32\Tasks\{0D64264D-D901-4EB0-B610-18C60BE2590C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files\PopCap Games\Bejeweled Deluxe\PopUninstall.exe" -c "C:\Program Files\PopCap Games\Bejeweled Deluxe\Install.log"
Task: {70D2010C-6D2A-4489-B939-2D7305D6F5FA} - System32\Tasks\Microsoft\Windows\Windows Server\Health Definition Updates => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {76722B7E-E6E4-47CE-904B-3B5B6D610909} - System32\Tasks\Microsoft\Windows\Windows Server\SaveCEIPData => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {85D60BFD-5E19-4420-83D0-3B517B9F47A0} - System32\Tasks\Microsoft\Windows\Windows Server\Alert Evaluations => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {90A55F5B-5883-4216-BAE8-2E8C4CCEFCFA} - System32\Tasks\Microsoft\Windows\Windows Server\InstallAddIns => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {9AFD38E9-89A3-4572-92CC-B4A16B39916C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-15] (Google Inc.)
Task: {9FDDE42C-7339-4345-BF10-6AB51995C9C4} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton Security with Backup\Engine\\WSCStub.exe [2017-10-03] (Symantec Corporation)
Task: {B76CBEC2-7072-448E-A7B6-B1092165FF5F} - System32\Tasks\Microsoft\Windows\Windows Server\RenewClientCertificate => C:\Program Files\Windows Server\Bin\RunTask.exe [2012-11-02] (Microsoft Corporation)
Task: {D93D461A-4288-4E84-B691-63BFD38BC672} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2017-10-03] (Symantec Corporation)
Task: {EC19FB41-5385-45F7-9E07-F58141846D09} - System32\Tasks\{BEF1E75A-721D-4AE9-9278-FFFDBA736CF9} => E:\24 Pop Cap Games\24 Pop Cap Games\Cracks\bookworm.deluxe.1.0.keygen-tsrh.exe
Task: {ECCD2FFE-B7F4-437F-9C59-99BFB67B3BEA} - System32\Tasks\{FAD7673B-18F1-4862-91F8-C457268CE82A} => E:\24 Pop Cap Games\24 Pop Cap Games\Cracks\bookworm.deluxe.1.0.keygen-tsrh.exe
Task: {F039F236-6A00-4383-A036-E95A7AD789DF} - System32\Tasks\Norton Security with Backup\Norton Security with Backup Error Analyzer => C:\Program Files\Norton Security with Backup\Engine\\SymErr.exe [2017-10-03] (Symantec Corporation)

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Kerry\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm

ShortcutWithArgument: C:\Users\Kerry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Play Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi
ShortcutWithArgument: C:\Users\Kerry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\MP3 Player.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=kbiheleggoempookkoblhdgmlojbicob

2017-10-15 08:01 - 2017-10-15 08:01 - 000008704 _____ () C:\Windows\assembly\GAC_64\GBHO\\GBHO.dll
2017-10-15 12:19 - 2017-10-04 12:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-10-15 12:19 - 2017-10-04 12:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-10-15 08:01 - 2009-12-01 13:13 - 000035880 _____ () C:\Program Files (x86)\GIGABYTE\smart6\dbios\SDBMSG.exe
2017-10-15 07:54 - 2015-06-01 20:00 - 000102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-11-14 14:07 - 2017-11-10 03:57 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libglesv2.dll
2017-11-14 14:07 - 2017-11-10 03:57 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libegl.dll
2017-10-15 08:01 - 2009-06-10 15:28 - 000106496 _____ () C:\Program Files (x86)\GIGABYTE\smart6\dbios\DBIOS.dll

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\...\.scr: EAGLESCR => "C:\Program Files\EAGLE 8.4.1\eagle.exe" -C "" "%1" <==== ATTENTION

(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2017-10-15 11:31 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2957907037-1284653929-173307917-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kerry\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

MSCONFIG\startupreg: DriverUpdate => "C:\Program Files\DriverUpdate\DriverUpdate.exe" -boot

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{482AF744-00B3-4E7B-89F5-4BCBB7265448}] => (Allow) C:\Program Files\TightVNC\tvnserver.exe
FirewallRules: [{922F7201-36D8-4899-A06A-298DF4BF0BCD}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4D6E0DC4-9B0B-41F7-B64F-53B8B1C6D171}] => (Allow) C:\Users\Kerry\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{588E1DBD-69AD-4431-9A38-417C69828D3F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{453FD19D-0E9A-46A2-AD73-CCDD3AFA90FB}] => (Allow) LPort=2869
FirewallRules: [{4155E841-8B2F-46B5-AAD4-CD14B5025357}] => (Allow) LPort=1900
FirewallRules: [{1A3ED6D3-67ED-40EB-9926-3D297A2C07C2}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{4EBEE59D-5E8B-4D4F-A699-34B3E85BEC91}] => (Allow) C:\Program Files\Opera\48.0.2685.50\opera.exe
FirewallRules: [{B8F289C7-DF61-45B7-8171-399065685768}] => (Allow) C:\Program Files\Opera\48.0.2685.52\opera.exe
FirewallRules: [{4B87FEA7-C2E3-4D76-AC80-9648AA40BB28}] => (Allow) C:\Users\Kerry\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{7A10D65E-D2EB-4247-8A3D-466923EB6DEF}] => (Allow) C:\Users\Kerry\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{AFD80B00-D100-45CD-804A-A0FACCACA3B2}] => (Allow) C:\Users\Kerry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{56087F2C-9A9E-4C27-8BCC-E3A0D56DD0A5}] => (Allow) C:\Users\Kerry\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{CBF94F7D-1A17-4176-BCD6-DD202C931A3C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

14-11-2017 21:14:38 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
15-11-2017 03:00:14 Windows Update
16-11-2017 03:00:10 Windows Update

==================== Faulty Device Manager Devices =============

Application errors:
Error: (11/16/2017 12:41:16 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {95c062dc-2784-484b-9906-ac188d033531}

Error: (11/08/2017 12:38:05 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/08/2017 12:11:10 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

AddWin32ServiceFiles: Unable to back up image of service SlimWare Services since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (11/07/2017 12:35:05 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/06/2017 12:41:27 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/05/2017 12:41:28 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/04/2017 01:28:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SharedServiceHost.exe, version: 6.1.1839.0, time stamp: 0x4d38a956
Faulting module name: KERNELBASE.dll, version: 6.1.7601.23915, time stamp: 0x59b94f2a
Exception code: 0xe0434352
Fault offset: 0x000000000001a06d
Faulting process id: 0xc40
Faulting application start time: 0x01d352944cfdd06e
Faulting application path: C:\Program Files\Windows Server\Bin\SharedServiceHost.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: d03addf2-c131-11e7-87e9-001583edfd9b

Error: (11/04/2017 01:28:54 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: SharedServiceHost.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Runtime.InteropServices.COMException
   at TaskSchedulerV2.ITaskFolder.DeleteTask(System.String, Int32)
   at Microsoft.WindowsServerSolutions.Common.ProviderFramework.SchedulerVersion2.DeleteTask(System.String)
   at Microsoft.WindowsServerSolutions.Common.ProviderFramework.Scheduler.RegisterTask(Microsoft.WindowsServerSolutions.Common.ProviderFramework.TaskDefinition, Boolean)
   at Microsoft.WindowsServerSolutions.DataProtection.PCBackup.Provider.ScheduledTaskManager.UpdateScheduledTask(Boolean)
   at Microsoft.WindowsServerSolutions.DataProtection.PCBackup.Provider.ScheduledTaskManager.CheckCompliance(Boolean)
   at Microsoft.WindowsServerSolutions.DataProtection.PCBackup.Provider.ScheduledTaskManager.<OnBackupCompletion>b__1(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   at System.Threading.ThreadPoolWorkQueue.Dispatch()

Error: (11/04/2017 01:17:04 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/02/2017 11:09:04 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
This is often caused by incorrect security settings in either the writer or requestor process.

   Gathering Writer Data

   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {e06c02fb-b3f5-4790-8279-2d5bfb4a029b}

Error: (11/15/2017 05:52:09 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 05:52:03 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 05:51:57 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 05:51:51 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 05:51:45 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 05:51:39 PM) (Source: cdrom) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\CdRom0.

Error: (11/15/2017 03:22:37 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {C332C124-340D-4430-AA0D-C75602876FCC} did not register with DCOM within the required timeout.

Error: (11/15/2017 03:22:37 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {FE9617F6-E606-42AA-BECC-0E9CDA246D63} did not register with DCOM within the required timeout.

Error: (11/15/2017 03:22:37 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {C2BFE331-6739-4270-86C9-493D9A04CD38} did not register with DCOM within the required timeout.

Error: (11/15/2017 03:22:37 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C} did not register with DCOM within the required timeout.

Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Percentage of memory in use: 19%
Total physical RAM: 16301.12 MB
Available physical RAM: 13164.42 MB
Total Virtual: 32600.42 MB
Available Virtual: 29423.52 MB

Drive c: () (Fixed) (Total:223.47 GB) (Free:117.55 GB) NTFS
Drive d: (New Volume) (Fixed) (Total:698.64 GB) (Free:518.84 GB) NTFS

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 6766F099)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 775E42CE)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)

