New
#1
Computer only works in safe mode
My computer now only works in safe mode. If I boot it up regularly it freezes up after a couple minutes and the when I try and shut it down it is stuck on the shutdown screen until I manually shut it down with the power button. I have run all updates and deleted unnecessary drivers and programs. I have McAfee installed on my computer. I have tried a system restore but it didnt work. Anything involving a reboot does not work. It has been like this for a month now with no luck in fixing it.
In the event log these are the errors from when it started:
-The maximum file size for session "McAfee.{E4367DA7-2B80-47f3-86D2-7626A18FC6F4}" has been reached. As a result, events might be lost (not logged) to file "C:\ProgramData\McAfee\MCLOGS\ETW\mclogs.etl". The maximum files size is currently set to 16777216 bytes.
-Session "McAfee.{E4367DA7-2B80-47f3-86D2-7626A18FC6F4}" stopped due to the following error: 0xC0000188
-Name resolution for the name lt.andomedia.com timed out after none of the configured DNS servers responded.
-Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
15 user registry handles leaked from \Registry\User\S-1-5-21-3138664587-982425383-2400673865-1000:
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\My
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\CA
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Policies\Microsoft\SystemCertificates
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Policies\Microsoft\SystemCertificates
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Policies\Microsoft\SystemCertificates
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Policies\Microsoft\SystemCertificates
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\Root
Process 6084 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-3138664587-982425383-2400673865-1000\Software\Microsoft\SystemCertificates\trust
-Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
-Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {f1108854-cd9b-43e0-a0c5-7a59ffb1e567}
-The Windows Update service did not shut down properly after receiving a preshutdown control.
NO IDEA WHAT THESE MEAN. And there are still a lot more....
any help would be extremelyyyyyyyyyy appreciated I have tried everything I know to do.