Dear Everyone
Thanks for your interest. I have managed to save the picture of the pop-up in my earlier post. As far as accessing any programs e.g. Outlook or Windows Mail, the pop-up occurs b4 I attempt to do anything during the final stages of boot-up. I do not use Windows
Mail or Live mail just Outlook. I installed MS Live a long time ago. Yes East coat of AU is Australia.
I'll do a search to see what has been changed. Also have been through the event log; there were a couple of 'warnings' re WLIDSCV.EXE e.g.
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
22 user registry handles leaked from \Registry\User\S-1-5-21-494384865-741982679-1953478462-1001:
Process 3704 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-494384865-741982679-1953478462-1001
Process 3704 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-494384865-741982679-1953478462-1001
Process 3704 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-494384865-741982679-1953478462-1001
and so on
"Given a couple of sysinfo logs and product reg key values, it should be possible to identify the rogue software very quickly."
Let me know how you want these log entries presented / filtered
regards
Andy.