Hi there! I'm hoping you can help. This is what I've got going on. 1. I've got two desktop.ini files that suddenly showed up on a reboot yesterday. I deleted them, cleaned them out of my recycle bin. This morning, I found them in my pictures file folder. When I tried to delete them, it at first said I couldn't because they were in use. I was able to delete the 2nd one. Following that...I was able to preview the contents of the first file, then delete it. Below is the code I found in the preview of the document. [.shellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,21779 InfoTip=@%SystemRoot%\system32\shell32.dll, -12688 IconResource=%SystemRoot%\system32\imageres.dll,-113 IconFile%SystemRoot%\system32\shell32.dll IconIndex=-236 2. On my c drive I have some oddities going on that I had not previously noticed. They may have always been like this and I just didn't notice. But I think it's a new development. a. I have a $Recycle.Bin folder that is locked to even administration. b. My documents and settings folder is locked even to administration c. hiberfil.sys 11.7GB (hibernation has been disabled on my machine) d. pagefile.sys 15.7GB When I try to delete hiberfil.sys and pagefile.sys it says they are currently in use. 3. Scanned with Avast, Malwarebytes and used the TFC cleaner. All virus scans came back to me clean. 4. When I tried to enter SafeMode so I could run my virus/malware scans there, it did not give me the proper safe mode options. Instead it gave me a blue box with the following info... Please select Boot Device: CDROM: PS-HL-DT-ST BDDVDRW UH12L SATA: 3M-ST2000DL003-9VT166 At that time I hit Esc and signed into Windows via regular/normal mode. The only possible point of infection that I can recall over the past 24hrs has been getting spammed on Facebook. Someone hit a bunch of my posts with an advertisement for weight loss. I un-friended the person of course. Logged off Facebook. Did my virus and malware scans, and cleaned any temp files before going back into Facebook. I did not notice any user end glitches after the incident. This all may be nothing, but I'd fill safer if someone more knowledgeable than me would take a look. I appreciate the assistance very much! Thank you!