This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected or hardware trouble?

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey Crew, Geez…I'm in a big pickle now. At first I thought it was a hardware thing…..now I am not so sure. Here is what I have been dealing with: A few days ago, computer would not start up. At all. I unplugged things, and plugged them all back in securely. Nothing. Lights were on everything, BUT the tower. The keyboard, soundsystem and screen all had lights. But not on tower FRONT…there was a light on in the back. I tried unplugging and replugging things into the APC Big Battery thing on the floor….and that worked, and got things started. When it started it up though, my security had been knocked out, and had to reinstall and turn the firewall back on. The next day, instead of shutting down completely, I decided to just "put it in sleep mode" at night…so from there it started up fine. On the third day….it would not begin out of "sleep mode" either…I went through unplugging and plugging again, and finally got it up and running. Again had to set up security again…and this time…all lights came on, except for light on keyboard, but it worked. On the fourth day…took more fussing and unplugging and plugging and I turned off the back up battery and "reset" it, and plugged things back in, and this got it to start…. So at this point, I was thinking it was the backup APC thing on the floor (it's a big heavy black box) I thought it was the trouble. BUT, this time, when things got up and running, security was fine, but I was informed that I had to update my Itunes, which I had just done the other day…it was the same "updates" ….but I started to update them again anyway, thinking hey didn't "take". THEN, I was notified that "some of my Itunes" files are missing. And sure enough, about 60% of my music is gone…. So, is this a nasty malware thing because I make fun of anonymous on my Facebook? Or is it a hardware thing - the big battery on the floor?, Or a friend said it could be the little battery in the "Mother Board" in the tower? REMINDER: I don't know the lingo, I am in Techy Kindergarten.,….so please spell things out very carefully for me. I would be grateful for any assistance. :unsure:
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


If I had to make a guess, I'm thinking it's a hardware issue, but it never hurts to run a few scans just to ensure there is no malware on the machine. I'll be glad to help you with that.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt




Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and choose Run as Administrator on GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello Patndoris. I'm so grateful for your assistance. I am a full on unreformed unrepentant Luddite…so we will have to bear with each other. I'm thinking hardware too now, because each day it has taken more and more time to start up - involving unplugging and plugging back in several times…like trying to get car engine to turn over. Ha! But I don't drive either…so you can imagine the swear words. I do however have a stubborn streak the size of the Grand Canyon, which is a gift at times like this. K…so I have lots' of trouble with the lingo….Zip files in particular are beyond brain surgery for me…. When I was here before for malware removal….I did the third DDS option thing from the instruction page, "Link 1" and I could pull that off. So I repeated that procedure again. I was given two logs…here is the first one: (it says not to post the second, unless asked) DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 20:45:44.31 on 29/11/2011 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.895.186 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Acer\Empowering Technology\SysMonitor.exe C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe C:\Acer\Empowering Technology\ePerformance\MemCheck.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Windows\RtHDVCpl.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Real\realplayer\Update\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\Rundll32.exe C:\Windows\ehome\ehmsas.exe C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\WUDFHost.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\rundll32.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe c:\program files\common files\installshield\updateservice\isuspm.exe C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe C:\Windows\system32\taskeng.exe C:\Users\Owner\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\Owner\Downloads\dds (3).scr C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.ca/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://en.ca.acer.yahoo.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://ca.rd.yahoo.com/customize/ycomp/defaults/su/*http://ca.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uURLSearchHooks: H - No File mURLSearchHooks: H - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Acer Empowering Technology Monitor] c:\acer\empowering technology\SysMonitor.exe mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe mRun: [Acer Product Registration] "c:\program files\acer registration\ACE1.exe" /startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [WHITNEY_S2P] c:\program files\samsung\samsung scx-4x21 series\psu\Scan2pc.exe mRun: [PCMMediaSharing] c:\program files\acer arcade live\acer homemedia connect\kernel\dms\PCMMediaSharing.exe mRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe mRun: [Acer Assist Launcher] c:\program files\acer assist\launcher.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\acerpr~1.lnk - c:\program files\acer registration\ACE1.exe StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Yahtzee/Images/stg_drm.ocx DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: c:\progra~1\google\google~4\GoogleDesktopNetwork3.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=3MvANHFNQxb.yvOnb3UHZg&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor= FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: c:\users\owner\appdata\roaming\mozilla\firefox\profiles\r1yjv0iq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\picasa2\npPicasa2.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\owner\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\owner\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\mozilla\firefox extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\real\realplayer\browserrecordplugin\firefox\Ext FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R1 MpKsla1ece34b;MpKsla1ece34b;c:\programdata\microsoft\microsoft antimalware\definition updates\{cfdab4c1-f10b-4e88-9792-f8804bebba32}\MpKsla1ece34b.sys [2011-11-29 28752] R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\acer arcade live\acer homemedia connect\kernel\dms\CLMSServer.exe [2007-9-13 269448] R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.SYS [2007-12-26 5120] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024] R3 SiS6350;SiS6350;c:\windows\system32\drivers\SISGRKMD.sys [2007-9-13 454520] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\drivers\SiSGB6.sys [2007-9-13 46592] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-4-1 183560] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-7-18 39272] . =============== Created Last 30 ================ . 2011-11-29 16:59:04 28752 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{cfdab4c1-f10b-4e88-9792-f8804bebba32}\MpKsla1ece34b.sys 2011-11-29 16:54:48 56200 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{cfdab4c1-f10b-4e88-9792-f8804bebba32}\offreg.dll 2011-11-29 16:54:08 6668624 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{cfdab4c1-f10b-4e88-9792-f8804bebba32}\mpengine.dll 2011-11-28 21:18:36 ——– d—–w- c:\program files\iPod(61) 2011-11-28 21:18:19 ——– d—–w- c:\program files\iTunes(62) 2011-11-23 03:36:36 ——– d—–w- c:\program files\QuickTime(74) 2011-11-23 03:28:49 ——– d—–w- c:\program files\iPod(64) 2011-11-23 03:27:21 ——– d—–w- c:\program files\iTunes(65) 2011-11-09 15:32:55 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-11-09 15:32:33 913280 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 15:32:31 31232 —-a-w- c:\windows\system32\drivers\tcpipreg.sys 2011-11-09 15:32:03 707584 —-a-w- c:\program files\common files\system\wab32.dll . ==================== Find3M ==================== . 2011-10-03 08:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-06 13:30:12 2043392 —-a-w- c:\windows\system32\win32k.sys 2011-09-01 02:35:59 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-09-01 02:28:15 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-09-01 02:22:54 2382848 —-a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 20:48:10.18 ===============
Sorry….I'm adding the second log….because I have no idea if I will even be able to start up again…I'm afraid of losing the log…I don't know how to zip things or attach them, so I had copy and pasted it into gmail..


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 14/12/2007 12:26:17 PM
System Uptime: 29/11/2011 12:38:57 PM (8 hours ago)
.
Motherboard: Acer | | F672CR
Processor: Intel® Pentium® D CPU 3.00GHz | Socket 775 | 3000/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 72 GiB total, 17.774 GiB free.
D: is FIXED (NTFS) - 72 GiB total, 70.737 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1417: 28/11/2011 4:30:17 AM - Scheduled Checkpoint
RP1418: 29/11/2011 12:51:31 PM - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acer Arcade Live Main Page
Acer Assist
Acer DV Magician
Acer DVDivine
Acer eDataSecurity Management
Acer Empowering Technology
Acer ePerformance Management
Acer HomeMedia
Acer HomeMedia Connect
Acer Registration
Acer ScreenSaver
Acer SlideShow DVD
Acer Tour
Acer VideoMagician
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.3.1
APC PowerChute Personal Edition
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AVG 2011
Bing Bar
Bonjour
CCleaner (remove only)
D3DX10
DivX Setup
Google Chrome
Google Desktop
Google Earth
Google Gmail Notifier
Google Photos Screensaver
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
GoToMeeting 4.8.0.723
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
iPhone Configuration Utility
iTunes
Java Auto Updater
Java™ 6 Update 29
Junk Mail filter update
LightScribe 1.4.142.1
Malwarebytes' Anti-Malware
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
MobileMe Control Panel
Mozilla Firefox (3.0.8)
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Picasa 2
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Revo Uninstaller 1.90
Safari
SAMSUNG Dr. Printer
Samsung SCX-4x21 Series
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
SiS VGA Utilities
Skype™ 3.6
SmarThru 4
SmarThru PC Fax
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
VC80CRTRedist - 8.0.50727.4053
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
.
==== Event Viewer Messages From Past Week ========
.
29/11/2011 2:39:55 AM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.115.2686.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.7801.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
29/11/2011 2:29:22 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.3.190:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.159.110:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.143.213:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.143.213:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.134.160:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.67.130.140:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.93.59:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.89.123:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.88.19:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.88.128:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.8.97:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.4.39:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.28.74:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.28.127:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.24.93:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.21.157:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.20.181:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.20.106:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.2.207:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.2.156:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.18.123:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.16.213:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.16.197:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 70.66.12.109:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 24.138.60.150:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.98.3:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.100.11:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 192.168.100.11:6331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 169.254.192.218:63331. The error status code is contained within the returned data.
29/11/2011 12:39:20 PM, Error: Microsoft-Windows-HttpEvent [15021] - An error occured while using SSL configuration for socket address 169.254.192.218:6331. The error status code is contained within the returned data.
28/11/2011 3:49:29 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Apple Mobile Device service, but this action failed with the following error: An instance of the service is already running.
28/11/2011 3:48:29 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
28/11/2011 3:47:53 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
28/11/2011 11:15:21 AM, Error: EventLog [6008] - The previous system shutdown at 11:08:22 AM on 28/11/2011 was unexpected.
28/11/2011 10:17:53 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {4991D34B-80A1-4291-83B6-3328366B9097} to the user Owner-PC\Owner SID (S-1-5-21-4230733952-2736013862-825621023-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
.
==== End Of File ===========================
First, please know it's always fine to copy and paste your logs. That is never a problem for us.

I don't see any evidence of malware in your logs. However, I did notice in your installed programs that AVG2011 is still showing up (even though it isn't running). Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine. I really doubt this is the cause of your issues, but it could (in theory) contribute to boot up problems. So I think we should remove it and see what happens.

I see that you have RevoUninstaller on your computer. Let's use that to completely make sure AVG is removed.

  • Double click the new Revo Uninstaller Icon on the desktop to start the program.
  • You will now see a list of installed programs that Revo Uninstaller can remove.
  • Locate the program you are uninstalling: AVG2011
  • Right Click the Icon then choose Uninstall.
  • Click yes to the warning and choose the Uninstall Mode
  • Choose the Advanced option and then click Next.
  • This will launch the programs built in uninstaller. Be patient it can take several seconds.
  • Once the uninstaller is done click Next.
  • Revo Uninstaller will now scan for leftover information. Be patient it can take several seconds.
  • Once this scan is done click Next.
  • You will then be presented of the leftover entries found by Revo Uninstaller
  • Look at ALL of the entries to ensure they relate to the uninstall.
  • Next click Select All > Delete to remove the entries.
  • Click Next.
  • If there are any program file folders left over you will be presented with a list to be removed.
  • Again look at ALL of the entries to ensure they are related to the uninstall.
  • Click Select All > Delete to remove the entries.
  • Click Finish to go back to the uninstall list.
  • Close the program

After you have completed the steps, if the machine does not do so as a part of the un-install, please reboot the computer and see if there is any change in the boot up.


Let me know how this goes and then we'll regroup and see where we are. You do have a few updates for security purposes to do, but I'd rather not do those just yet until we see if we get any improvement.
Well, I followed instructions, but was unable to locate AVG 2011 at all. And how the heck is that still there anyway? The first time I came here, we isolated that as the source of many problems, and Tom K and I bombed the heck out of the thing. It was cleared….and I can assure you, after all that, I have not knowingly reinstalled AVG….in fact, I've been telling friends to avoid it altogether. So if you are seeing it, how did it get there again…and why can't I find it through the revoinstaller thing? Also, I noticed that my revo uninstaller icon, has a red X over it, like it is being blocked or something….. is that meaningful?
Well, where I was seeing it is in the list of installed programs in the DDS attach.txt file. It is possible it has been removed but whatever registry entries showed the program in the install list were still there. If you don't see it in RevoUninstaller, and if it doesn't appear in Start > Control Panel > Programs/Features, then I wouldn't worry about it.

I'll give you the updates to do now:

Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website.


Update Adobe Flash
There have been updates to Adobe Flash to address security vulnerabilities. You should download the latest version from the Adobe Flash downloads.



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 update 1 and Save it to your Desktop.
  • Scroll down to where it says Java SE 7
  • Click the Download JRE button to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u1-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are three options in the window to clear the cache - check then ALL
      Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. If you have any objection to doing this please omit this step
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



Then I'd like you to try rebooting the system in safe mode just to see if there is any improvement in boot time. Here are the instructions for how to do that:


Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.

Let me know what happened when you tried this please.
Ok…before I begin these downloads…. At the Adobe site, it offers "McAfee Security Scan Plus" with the download….should I uncheck that before I download? Also :blush: umm….er…I don't know how to "save something to my desktop"….and when I have inadvertently saved things, I have no idea where they are in the machine or how to go and get them. I'm not kidding. :blush:
No you wouldn't want McAfee Security Scan Plus.

If you aren't comfortable with how to do the installs from those sites (or saving files to your desktop), I can give you some links you might find easier to use. At Filehippo (where all of these files are located), you will see a green box on the right side with a downward pointing arrow and the words "Download Latest Version" or "Download This Version". Just click on that link and it should start the download for you (but it may take a few seconds).
http://www.filehippo.com/download_adobe_reader/
http://www.filehippo.com/download_flashplayer_ie/10987/
http://www.filehippo.com/download_jre_32/

Then you can try the safe mode booting and see what happens.
Alrighty. Seems I have downloaded the Adobe, the Adobe Flash, and the Java thingys. Just note, when I commenced each - I was warned that "this file may harm your computer"….but I remember from Tom K, that I could just continue anyway…so I did. Also, the first one I did..Adobe - was "interrupted", and I had to redo it. I've noticed that happening the last few times I had to update something, the download was "interrupted", even though I was not doing anything else on the the machine. So, now, this rebooting in safe mode thing - before I begin. I have real fear that the machine may not restart ….at least not without much work….and it is getting late where I am. So before I do it, I will want to log out of here - in case I have to log in from another machine tomorrow….and I will be busy tomorrow, so may not get back to you till tomorrow evening. Before I try the rebooting now though - What is BIOS? And when you say "log into your usual account"….which account are you speaking of? What usual account?
I'm glad you got the downloads done and installed. There are a number of reasons a download can be interrupted. If this is hardware related (which I'm still leaning toward) that could be affecting things. As long as you can eventually get files downloaded, I wouldn't worry too much about that just yet.

As for BIOS…..I'll save you a long explanation and let's just go with, it's the brains that make the whole thing start up when you push the power button. (If you want the long complicated answer you can go to Wikipedia/BIOS to read more about it.)

Basically, to get to safe mode, when you reboot your computer, as soon as you hear the machine start (usually you can hear the fan or the hard drive start up) - begin tapping the F8 key repeatedly. If you do it too many times it will just beep at you, but you can't hurt anything. The key to getting to the screen you want is to start tapping right away. If you wait too long, you'll end up booting normally.

Log in to your usual account is really geared towards people who have multiple users on the machine. I'm guessing it's just you - so just log in as you normally would.

Also, don't be alarmed that in safe mode your icons will likely look larger and your screen may look like things are bigger. Things also take longer to run sometimes in safe mode. That is normal and will go away when you reboot normally the next time. Safe mode is basically a way to load just those files that are needed to make the machine run and not much more. If you tell me it boots into safe mode straight away and perfectly and without any issues whatsoever, then we may want to consider a few more scans to see if malware is hiding somewhere we haven't found. More likely, you'll have the same kinds of power and boot issues you've been experiencing - which will narrow it down to hardware, and then I can get you to the forum that can better deal with that for you.

I'll look forward to hearing from you sometime tomorrow. I work during the day so it would likely be tomorrow evening before I could look at what you post anyway.
OK… So upon startup this morning - it still took a few tries, about 3 times…but not nearly as many as the last few days had…and when I was able to get safe mode going, windows opened normally….I then hit restart and away I went. Somehow in all this though, I first lost half my Itunes file…(literally hundreds of CD's :smack: ). Today, when I went to see if it was restored….I was prompted to "repair" it….so I clicked that, and it claimed to "download Itunes". Well now, when I try to open Itunes I get told that it can't be "read" because I downloaded a new version…So I tried to go to Itunes from google search and got a message that "this may be an attack"… Have I lost ALL of my music and podcasts forever now? Man, it took me days to put them all on the machine….. :( Other than that my browser seems to running quicker and changes between tabs is faster…I'm on Google Chrome.
Well, I'm not seeing any evidence that this is malware. So, I'd like to refer you to our Windows Forum for additional help in determining if this is a hardware or power supply issue. When posting there, please feel free to include a link to this post in case they need to see any information contained in the logs.

As for the iTunes, I'm not sure I can really answer the question. I did do a quick Google search and it does appear that there have been issues in the past where music libraries become corrupted. There are many threads about it on the apple forums. However, you would need to look at posts related to the version from which you just updated to see the appropriate solution. I'm not sure what address you used when clicking from your Google search but the Apple iTunes support communities are here. Hopefully, you'll find an answer to your iTunes issues there.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI