"Windows mail could not be started. error 80041161

Yeah, there seem to be a lot of toolbars - usually packed with an installer of other pgms. This is a fairly common "problem", but not necessarily harmful.

The only one you might want to keep is Winamp - but a toolbar can always be replaced, so I suggest letting AdwCleaner clean up everything in the next step (clean)

AdwCleaner is a two step process. Scan then Clean

AdwCleaner Step 2: Scan and Clean
  • Right-click AdwCleaner.exe on your Desktop and select Run As Administrator.

  • Click on the Scan button.
    >> AdwCleaner begins scanning your system. It might take some time to complete.
  • After the scan has finished... click on the Clean button.
    • Answer OK to the "close all programs" prompt, then follow the onscreen prompts.
    • Answer OK to the "restart the computer" prompt to complete the removal process.
      >> The AdwCleaner[S#].txt log is opened in your default Text editor when the machine has restarted.
      :info: [R#] gets incremented every time you run AdwCleaner - the highest number is the most recent.
  • Paste the entire AdwCleaner log in your next post.
    :info: AdwCleaner logs are located in the C:\AdwCleaner folder if you need to reference them again.

 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thanks Slartybart

This is the log which emerged from doing the Clean in AdwCleaner.

I recognise some entries - in the few minutes since the Clean run I only notice FireFox may have been set back to an earlier state - no big deal.

You mentioned WinAmp - I noted that after the Scan run and did a Control Panel Uninstall on it as I have never used it sufficiently to keep it.

The Log:

# AdwCleaner v3.018 - Report created 09/02/2014 at 20:31:35
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : pfo - FURIOUSFRED
# Running from : C:\Users\pfo\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Partner
[x] Not Deleted : C:\Program Files (x86)\jZip
Folder Deleted : C:\Program Files (x86)\Nosibay
Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
[x] Not Deleted : C:\Users\pfo\AppData\Local\jZip
Folder Deleted : C:\Users\pfo\AppData\Local\OpenCandy
Folder Deleted : C:\Users\pfo\AppData\Local\Temp\jZip
Folder Deleted : C:\Users\pfo\AppData\LocalLow\jziptoolbar
Folder Deleted : C:\Users\pfo\AppData\Roaming\Nosibay
File Deleted : C:\Users\pfo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jZip.lnk
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\jZip
Key Deleted : HKCU\Software\Nosibay
Key Deleted : HKCU\Software\smartbar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\jZip
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\PrimoPDF\OpenCandy
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428


-\\ Mozilla Firefox v22.0 (en-US)

[ File : C:\Users\pfo\AppData\Roaming\Mozilla\Firefox\Profiles\v679wako.default-1391462979186\prefs.js ]


*************************

AdwCleaner[R0].txt - [12051 octets] - [05/02/2014 21:25:52]
AdwCleaner[R1].txt - [9021 octets] - [09/02/2014 19:07:19]
AdwCleaner[S0].txt - [7418 octets] - [09/02/2014 20:31:35]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7478 octets] ##########
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
ok thanks,

These were not cleaned for some reason:
[x] Not Deleted : C:\Program Files (x86)\jZip
[x] Not Deleted : C:\Users\pfo\AppData\Local\jZip

Please restart you machine and then follow this guide fro jZip virus removal:
Remove Search.Jzip.com (Virus Removal Guide)

Run the scans in the order specified and paste all logs here for review. You can run all of the scans and then post all of the logs on one post.

There will be more scanners to run until your machine is clean. I'll look at the logs when they are posted.

Thanks,

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thank you.


OK here we go:
STEP 1: Remove Search.Jzip.com browser hijacker with AdwCleaner

logs for scan and clean attached


STEP 2: Remove Search.Jzip.com from Internet Explore, Firefox and Google Chrome with Junkware Removal Tool



jrt.txt log attached

STEP 3: Remove Search.Jzip.com malicious files from your computer with Malwarebytes Anti-Malware Free


STEP 4: Double check for the Search.Jzip.com infection with HitmanPro

Hope this is useful.
 

Attachments

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
Ok, good. it will take me a while to read through the logs.

There were other malware threats that I saw before this run of scanners, but I think the scans you ran should have addressed some of them. There might be one or two still hanging on, so I'll post what I see and suggest teh next course of action.

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
JRT cleaned up a bunch of 'stuff' interestingly there were a lot of WLM empty folders (a bug fixed in WEM 2012). I wonder if they got in the way of the original issue posted.

Since WLM did not do proper garbage collection, I want you to run Old Timer- Temp File Cleaner

Restart your machine in case there are any system operations pending

Click here to download Old Timer-TFC.
>> save the application to your Desktop.
:info: Old Timer-TFC is a standalone application, there is no install.

:warn:Save your work and close all open windows.
TFC will close ALL open programs including your browser!

Right click, run as administrator TFC

Click the Start button to begin cleaning up temporary files and folders.

:warn: Do not work on other things while TFC is running - most applications use some sort of temporary files. Just let TFC run by itself on the machine until it completes.

:busted: If TFC prompts you to reboot, do so immediately.
:busted: If TFC does NOT prompt you, then reboot your machine immediately after TFC has completed.

After restarting the machine - yet another set of scans (you don't have to download the same scanners again)

Mobogenie is classified as a Potential Unwanted Program (PUP).
See: Remove Mobogenie virus (Removal Guide) - it's pretty much the same set of scans, but you uninstall Mobogenie 1st, then let the scanners clean up.

When that's all done, there's one more I'd like to use, just to cover the bases.

You're doing great, soon you can try to install WLM again!... but not yet

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thanks Slartybart - unfortunately the TFC scan has been running over 12 hours. If it is still working that's fine. There is no indication of anything happening. There seems no hint of any log file when looking in from the other laptop.

The first two 'user' temp folders flew in as there were no files requiring deletion. My user account has been worked on for over 12 hours. Last time TFC was run it was all done in, I believe, less than 3 hours.

I will run it again just now to see what happens, but will stop it after a few hours done or not.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
And. to answer my own question: shut down, boot Safe Mode, shut down, boot normal, run TFC. All as expected.

Log attached.
 

Attachments

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
And. to answer my own question: shut down, boot Safe Mode, shut down, boot normal, run TFC. All as expected.

Log attached.

I like it when members answer their own questions :)

I guess what ever is on your system was fighting OTL. There really wasn't much (3.5MB GB) cleaned up once you got into safe mode.

I would run the machine in safe mode until things improve. No sense having malware retrench your system.

Ok, I have to backtrack a bit. I've been working on some other threads and I need to figure out what you need to do next so I don't suggest something you've already done (unless it needs to be repeated)

Give me a bit of time to regroup.

thanks

Bill
.
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Slartybart;2688372 There really wasn't much (3.5 MB) cleaned up once you got into safe mode.[/QUOTE said:
Wasn't it 3.5GB?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Home Premium 64 bit
CPU
Intel
Memory
6GB
Graphics Card(s)
Intel
Hard Drives
240 GB SSD (Kingston)
Antivirus
Avast
Browser
IE 11
Slartybart;2688372 There really wasn't much (3.5 MB) cleaned up once you got into safe mode.[/QUOTE said:
Wasn't it 3.5GB?

It does look like 3.5GB:"Total Files Cleaned = 3,565.00 mb". The question I have - a bit off topic - is whether it is useful to re-run the TFC scan to clear out even more, if more files can be found? Or does that introduce the possibility of inflicting damage?
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
Yeah, you guys got me :o.... GB (I corrected my original post)
No need to run TFC more than once, one run of TFC is sufficient. It's not a cumlative clean - it's a one pass clean.


I back tracked to the files I asked you about and finally did the research...

I think you have already cleaned these up with the scans you've performed, but I'd like you to check a few things.

In an elevated Command prompt enter the following commands and post the results (found in the output file)
C:\RegQueryDirC.txt

echo "Query Clickmein" > C:\RegQueryDirC.txt
reg query "HKLM\Software\ClickMeIn 1" /s >> C:\RegQueryDirC.txt
echo "********************" >> C:\RegQueryDirC.txt
echo "Query Run" >> C:\RegQueryDirC.txt
reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /s >> C:\RegQueryDirC.txt
cd \
echo "********************" >> C:\RegQueryDirC.txt
echo "Dir C: clickMeIn" >> C:\RegQueryDirC.txt
dir /s /a clickmein*.* >> C:\RegQueryDirC.txt
pause


After you've looked at the output, you can press any key to continue, then type
exit




Please download the Farbar Recovery Scan Tool
Select the 64-bit version.


Save it to your Desktop.
  • Double-click the downloaded file to run it.
  • When the tool opens click Yes to disclaimer.
  • Press the Scan button.
  • FRST64 makes a log (FRST.txt) in the same directory (Desktop) from which the tool is run.
Please provide the FRST.txt in your reply. <<---

Thanks
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
speaking of backtracking, did you run through the Mobogenie guide? I didn't see any logs.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thanks Slartybart

Considering these points:
"echo "Query Clickmein" > C:\RegQueryDirC.txt"
This created the C:\RegQueryDIRC.TXT as above

"reg query "HKLM\Software\ClickMeIn 1" /s >> C:\RegQueryDirC.txt"
The reg.exe was not found
I tried and failed to copy reg.exe from \Windows\WOW64 to C:\ due to permissions - I have done a TakeOwnership and rebooted, then looked at Security of this file and added my username as admin and full control, then rebooted – it still would not copy due to permissions

I could not proceed further

echo "********************" >> C:\RegQueryDirC.txt
echo "Query Run" >> C:\RegQueryDirC.txt
reg query "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /s >> C:\RegQueryDirC.txt
cd \
echo "********************" >> C:\RegQueryDirC.txt
echo "Dir C: clickMeIn" >> C:\RegQueryDirC.txt
dir /s /a clickmein*.* >> C:\RegQueryDirC.txt
pause





Previous scans - mobogenie: Are these the ones in #64?

OK here we go:
STEP 1: Remove Search.Jzip.com browser hijacker with AdwCleaner

logs for scan and clean attached


STEP 2: Remove Search.Jzip.com from Internet Explore, Firefox and Google Chrome with Junkware Removal Tool



jrt.txt log attached

STEP 3: Remove Search.Jzip.com malicious files from your computer with Malwarebytes Anti-Malware Free


MBAM log shows no threats

STEP 4: Double check for the Search.Jzip.com infection with HitmanPro

Hope this is useful.
Attached Files
clip_image001.gif

AdwCleaner[S1].txt (1.1 KB, 3 views)
clip_image001.gif

AdwCleaner[R2].txt (1.0 KB, 3 views)
clip_image001.gif

JRT.txt (118.0 KB, 3 views)
clip_image001.gif

mbam-log-2014-02-10 (20-04-08).txt (1.9 KB, 3 views)
clip_image001.gif

HitmanPro_20140210_1822.log (343.2 KB, 4 views)

Also - I could not find these to attach in #64, I think, and one from today:
 

Attachments

Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
That's very odd - reg should have been found.

Please do not do things like copy or take ownership of any system files - it will only corrupt Windows and complicate this recovery session.
If I ask you to do something and it doesn't work, ask me about it. I might have had a typo or given you an incorrect parameter, I'll come back to reg query in another post... I think the clickmein malware was taken care of by the scans - that was just a means to check if it was.

You could have continues with the other commands though - the reg query run might have failed, but the next set should have worked (I condensed it and removed the redirect output to >> C:\RegQueryDirC.txt)
Essentially all these commands do are change to the root directory of C:
list everything with clickmein in the filename (including clickmein 1 or clickmein 7) with any filetype
cd \
dir /s /a clickmein*.*

Please launch an http://www.sevenforums.com/tutorials/783-elevated-command-prompt.html and enter the commands above. You mght get "File not found" and that's good - you don't want it to be found.

Regarding Mobogenie, no I did not mean the logs from post 64.

I asked for a few things in post# 66 and you might missed the Mobogenie guide. I apologize for missing mobogenie in the first place, since the process is simple and the scans are the same - you could have followed the browser instructions and then run the scans once. As I missed the malware , I suggested a second doing the browser fixes in the mobogenie guide and then run of the scans..... agian. I know it's confusing, and I'll try to be more explicit.

Hold off on running anything else except the dir command.

I'll see what the FRST log tells me.

Why wouldn't reg work is another question. I'm beginning to think that a clean install might be your only hope as we stumble across one issue (WLM won't install), then another (Group Policy error in SFC), then more (malware) and next (reg doesn't work). There might be too many issues to fix piecemeal.

Where did you get the idea to do use takeownership of a system file anyway? Most casual Windows users don't use commands of that level.

.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thanks Slartybart - understood.

The DOS commands were attempted in the truncated form you suggest. Loads of lines of file names flashed past each with a 'The directory name ......... is too long.'

I tried various /a /s etc combinations so there are several extra lines, but that may be a result you wish if there is no clickmein to be found.

Here is one example of the many lines displayed:
"The directory name C:\Users\pfo\Local settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\zSuppliers\Finance\Bank Name\Bank Branch Name is too long."

The common elements in all lines are: 'The directory name ......... is too long.'

_____________________________________________

mobogenie removal:

STEP 1 : Uninstall Mobogenie program from your computer

This was done by Control Panel and the listed Mobogenie was removed from the uninstall list.

STEP 2: Remove Mobogenie adware from your computer with AdwCleaner

Post #74 has the S1 and R2 log files attached

STEP 3: Remove Mobogenie browser hijackers with Junkware Removal Tool

The JRT.txt is in #74

STEP 4: Remove Mobogenie virus with Malwarebytes Anti-Malware Free


I run MBAM PRO, daily updated, this scan was in #74, and subsequent scans return 'no threats found'.

STEP 5: Double-check for the Mobogenie infection with HitmanPro


HitmanPro log(s) are in #74.


ALSO:
"Where did you get the idea to do use takeownership of a system file anyway? Most casual Windows users don't use commands of that level."

Good question. Frequently when installing a program, well not that frequently as I don't overly do installs, there is an error that a folder cannot be used and the unnamed folder does not have permissions. So I do a Take Ownership - my userID has admin permissions - and the install proceeds.

Two examples are C:\Program Data\Adobe\Lightroom and Photoshop Elements\new version.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
Ok thanks Phil,

At this point your best solution is a re-install.

You should have a Win7 OEM install disc from Acer and another one that contains the drivers.
Find them.

Change the view to include hidden and systme files then
Manually back up your User Profile (copy C:\Users\pfo to an external drive) - there will be a few .dat (NTuser, UsrClass) files that might not be copied (in use condiition).
If you have data in folders outside of your User profile, then you'll need to copy those folders too.

The information you supplied here:
Here is one example of the many lines displayed:
"The directory name C:\Users\pfo\Local settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live Mail\Storage Folders\Imported Folder\zSuppliers\Finance\Bank Name\Bank Branch Name is too long."

is interesting - the junction: Local settings should point to AppData\Local.

Try this as a test for information... in an elevated command prompt, type the following commands:
cd \Users\pfo
dir /a:l

When you've had a chance to read the results, you can type exit to close the Command Prompt window

You should see results similar to those in the codebox below.
Code:
C:\Windows\system32> dir /a:l
 Volume in drive C has no label.
 Volume Serial Number is 7603-9E3E
 Directory of C:\Users\BaseUser
12/12/2013  12:06    <JUNCTION>     Application Data [C:\Users\BaseUser\AppData\Roaming]
12/12/2013  12:06    <JUNCTION>     Cookies [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Cookies]
12/12/2013  12:06    <JUNCTION>     Local Settings [C:\Users\BaseUser\AppData\Local]
12/12/2013  12:06    <JUNCTION>     My Documents [C:\Users\BaseUser\Documents]
12/12/2013  12:06    <JUNCTION>     NetHood [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/12/2013  12:06    <JUNCTION>     PrintHood [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/12/2013  12:06    <JUNCTION>     Recent [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Recent]
12/12/2013  12:06    <JUNCTION>     SendTo [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\SendTo]
12/12/2013  12:06    <JUNCTION>     Start Menu [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Start Menu]
12/12/2013  12:06    <JUNCTION>     Templates [C:\Users\BaseUser\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
              10 Dir(s)  85,663,137,792 bytes free

I don't give up easily, but in this case I think it's in your best interest to re-install. Every turn we take is riddled with anouther issue.

To make certain no malware is on your system I'll ask you to run a clean command after you say your data is backed up and is safe.

Sooo, find those discs and you'll be back in business in a day or so
(1 hour to re-install, 30 minutes to copy only your data - not your entire profile to the fresh install, 2-3 hours Windows updating, a couple of hours to re-install your favorite applications)

It takes me about 4 hours, but I've doen it so many times and I don't have a lot of applications

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Thanks - I'll look out the disks and follow your advice.

Of course there were no disks, but a 'Create Recovery Disks' procedure was there and I did that, so I have Acer recovery disks.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Acer 5745DG
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i3 CPU M 370 @ 2.40GHz
Motherboard
Acer ZR7D
Memory
4.00 GB
Graphics Card(s)
NVIDIA GeForce GT 425M
Sound Card
(1) High Definition Audio Device (2) NVIDIA High Definitio
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 119 Hz
Hard Drives
WDC WD3200BEVT-22A23T0
3 partitions
S/N W -DXW167AM03248
Size 298.09 GB
Internet Speed
6690
Antivirus
Avast Pro
Browser
Firefox 28
Other Info
Sound:
Card 1 - Microsoft High Definition Audio Device
Card 2 - High Definition Audio Device
Card 3 - High Definition Audio Device
Card 4 - NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Card 5 - NVIDIA High Definition Audio
Card 6 - NVIDIA High Definition Audio
VideoController1 - NVIDIA GeForce GT 425M
Video Processor - GeForce GT 425M
Video Driver Version - 9.18.13.2723
Video Driv
Ok good enough. I worked on another thread and their machine came with Win7 OEM disks + a driver disk.

I'd still like to see how the junctions are defined
Try this as a test for information... in an elevated command prompt, type the following commands:
cd \Users\pfo
dir /a:l > C:\JunctList.txt



I've located the Acer pages that will help guide you, but want to wait until you tell me that your data is backed up.

So let me know when you're ready. I'm heading out for dinner soon, will check the thread wehn I get back. Just wanted to let you know.

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Hi Phil,

I'd like you to make a System Repair Disk (a CD-R is fine - it's not that big)
See: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html

This is different from the Acer Recovery discs you already made. You'll boot the system with the System Repair disc and from there you can run the command to clean the drive.
Once the drive is clean, then you can boot the machine with the Acer Recovery Disc and restore the machine to factory conditions.

Let me know when your data is backed up and you have created the System repair disc. Once you clean the drive, there's no turning back, so I want to be certain you have your data.

Bill
.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Pavilion dv6-6c10us
OS
x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
CPU
AMD A6-3420M APU with Radeon(tm) HD Graphics
Motherboard
Hewlett-Packard 1805
Memory
6.00 GB
Graphics Card(s)
AMD Radeon(TM) HD 6520G
Sound Card
(1) AMD High Definition Audio Device (2) IDT High Definiti
Monitor(s) Displays
HP W2072a 20" LCD (1600 x 900) @ 60 Hz
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
ST640LM0 00 HM641JI SATA Disk Device
Keyboard
Logitech k520 wireless KB
Mouse
Logitech m320 wireless mouse (bundled with KB)
Internet Speed
15/5 | 54 MB Wireless 'n'
Antivirus
Realtime: Defender or Avast | On-demand: Malwarebytes, ESET
Browser
IE 11 on Win8, IE 10 on win 7
Other Info
Media: [Gimp, Audacity, VLC] || Comm: [WEmail 2012, Skype] || Productivity: [OpenOffice,| Textpad] || Utils: [Sysinternals, cCleaner, Speccy, Defraggler]
Back
Top