Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spyware Detected.


  • Please log in to reply
13 replies to this topic

#1 CosmicSaturn

CosmicSaturn

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 04 June 2008 - 01:49 PM

Well guys I have the background of Spyware detected on my computer.
AVG scan could not even find it.
So i installed Spybot which found it. Then it destroyed it....until i restarted my computer.
SO i tried your smithfraud thing on my own and it did not work.
Could i get some additional help please? I don't know what to go to next.




BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:21 PM

Posted 04 June 2008 - 05:17 PM

Run the following fix:

How to remove the Smitfraud / Generic Zlob / Quicknavigate / Virtual Maid

After that run a full system scan with Malwarebytes' Anti-Malware.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 04 June 2008 - 07:18 PM

Malwarebytes' Anti-Malware 1.14
Database version: 826

8:16:46 PM 6/4/2008
mbam-log-6-4-2008 (20-16-46).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 118261
Time elapsed: 40 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Dell Users\Local Settings\Temp\.tt26.tmp (Rogue.Installer) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-2358853742-1472975049-492975197-1005\Dc7.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP256\A0326712.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP256\A0326735.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP256\A0326767.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Process.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dell Users\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dell Users\Local Settings\Temp\.ttE.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
Um, AM i safe?

#4 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:21 PM

Posted 04 June 2008 - 07:26 PM

How's your computer behaving now?

As a double check you could run a full system scan with SuperAntiSpyware in Safe Mode.

How to start Windows in Safe Mode
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#5 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 04 June 2008 - 07:58 PM

Sorry for the really late respawn, I'm doing perfect =D.
If i have a problem once I logg on tommorow, ill try that step.
Thank You Very Much for finnaly respawning to my message ^_^.
Thought it was a unactive site for a bit =P

#6 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:03:21 PM

Posted 04 June 2008 - 08:13 PM

If you’re clean, you should create a new Restore Point to prevent possible re-infection from an old one.

Go Start > Programs > Accessories > System Tools and click System Restore. Choose the radio button marked Create a Restore Point on the first screen then click Next. Give the Restore Point a name and then click Create. Then use Disk Cleanup to remove all but the most recently created Restore Point. Go Start > Run and type: "Cleanmgr" (without the quotes). Click Ok > More Options tab > Clean Up in the System Restore section to remove all previous restore points except the newly created one.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#7 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 June 2008 - 08:26 AM

I would....but Im not clean.
Actually, I think it has gotten worst.
I'm doing all the scans over again cuase when they are done I can search the internet with a toolbar again and also change the background.
But why....is it coming back?
I feeel like its stuck.

Oh yea, a New Pop-up that I don't know what button to press.

Malware Alret!

Attenion! Adware.W32.SpyShredder spyware detected. Adware.W32.SPySJredder provies REMOTE ACCESS to your PC and can STEAL your CREDIT CARD, passwords and other private data. Also it prompts fraud advertising popup windows. This process is a security HIGH-risk and recommended to be killed.
Type: Trojan Horse




I would....but Im not clean.
Actually, I think it has gotten worst.
I'm doing all the scans over again cuase when they are done I can search the internet with a toolbar again and also change the background.
But why....is it coming back?
I feeel like its stuck.

Oh yea, a New Pop-up that I don't know what button to press.

Malware Alret!

Attenion! Adware.W32.SpyShredder spyware detected. Adware.W32.SPySJredder provies REMOTE ACCESS to your PC and can STEAL your CREDIT CARD, passwords and other private data. Also it prompts fraud advertising popup windows. This process is a security HIGH-risk and recommended to be killed.
Type: Trojan Horse

#8 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 June 2008 - 08:33 AM

Now i could say.
The Spyware is probably beating me.
When i open the mirror list download page, once i click download IT cloeses it out.
:thumbsup:
Now I need support.

#9 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:01:21 AM

Posted 05 June 2008 - 08:48 AM

http://www.bleepingcomputer.com/forums/ind...mp;#entry839950

rerun MBAM even if you can't update it manually

use another computer to download the updater from if you have to

If you don't stay on top of this disinfection and try to kill it, it will win
Chewy

No. Try not. Do... or do not. There is no try.

#10 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 June 2008 - 10:19 AM

~Sigh.....
I try to install SpuerAntispyware and now whenever I click finish, the computer brings me back to the intallition page where it says modify, repair or unistiall.
If I click cancel it says installiton is not finish.......
So i try again and its the same thing.
I think this thing destroyed me.
unless the spyware doctor can do something when its done scanning.

#11 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 June 2008 - 10:34 AM

THe Scan finished and i got my desktop back.
It says i have to restart my computer for the SUPERAntiSpyware actually but once i do that ill get the problems again so is their any alternatative?
Oh yea, and I deleted the bug screen server and ctfmon thing from my process tree.
Theres is something called Jusched there, is that bad also?

#12 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:01:21 AM

Posted 05 June 2008 - 10:55 AM

See if you can download SDFix, the directions are complicated, see if someone can print you a copy

http://www.bleepingcomputer.com/forums/t/131299/how-to-use-sdfix/

SDFix should install in safe mode


http://www.malwareremoval.com/tutorials/safemodeboot.php

I am assuming this is windows xp, if vista then sdfix won't work
Chewy

No. Try not. Do... or do not. There is no try.

#13 CosmicSaturn

CosmicSaturn
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:01:21 AM

Posted 05 June 2008 - 12:16 PM

SDFix: Version 1.188
Run by richard on Thu 06/05/2008 at 12:31

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
sysrest.sys

Path :
\??\C:\WINDOWS\system32\sysrest.sys

sysrest.sys - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-05 13:06:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000040
"TracesSuccessful"=dword:00000036

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk 9.0"
"C:\\Program Files\\Common Files\\AOL\\1169771362\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1169771362\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\Patcher.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\NewPatcher.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\NewPatcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\MapleStory.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maples\\MapleStory.exe:*:Enabled:MapleStory"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\MapleStory.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\MapleStory.exe:*:Enabled:MapleStory"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\Patcher.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\NewPatcher.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Maplestory\\NewPatcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Xfire\\xfire.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Xfire\\xfire.exe:*:Enabled:Xfire"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AOL 9.1\\waol.exe"="C:\\Program Files\\AOL 9.1\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe:*:Enabled:AOL TopSpeed"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL System Information"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\GChase\\Grand Chase\\main.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\GChase\\Grand Chase\\main.exe:*:Enabled:GrandChase"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Rohan\\rohanclient.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\Rohan\\rohanclient.exe:*:Enabled:Rohan Online Game"
"C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\DS\\eMule\\emule.exe"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\The Shins\\Chutes Too Narrow\\DS\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Documents and Settings\\richard\\Local Settings\\Temp\\.tt12.tmp"="C:\\Documents and Settings\\richard\\Local Settings\\Temp\\.tt12.tmp:*:Enabled:enable"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Thu 6 Mar 2008 46,432 A..H. --- "C:\Program Files\AOL 9.1\AOLphx.exe"
Thu 6 Mar 2008 54,624 A..H. --- "C:\Program Files\AOL 9.1\AOLphxex.exe"
Thu 6 Mar 2008 33,120 A..H. --- "C:\Program Files\AOL 9.1\rbm.exe"
Fri 9 May 2008 88 ..SHR --- "C:\WINDOWS\system32\42931AAF92.sys"
Fri 9 May 2008 3,350 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BITF.tmp"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BITD.tmp"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT11.tmp"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b69c46c5109d0f8b0dee9fab84906813\BIT10.tmp"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT12.tmp"
Thu 24 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa6c916bb150f8a929e7a4ffdfbc120f\BITE.tmp"
Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BITD.tmp"
Fri 9 May 2008 96,072 ...H. --- "C:\Program Files\Common Files\AOL\TopSpeed\3.0\WBUnins.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Documents and Settings\All Users\Documents\My Music\The Shins\Chutes Too Narrow\New Folder\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Documents and Settings\All Users\Documents\My Music\The Shins\Chutes Too Narrow\New Folder\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Documents and Settings\All Users\Documents\My Music\The Shins\Chutes Too Narrow\New Folder\Spybot - Search & Destroy\TeaTimer.exe"
Sun 30 Dec 2007 8 A..H. --- "C:\Documents and Settings\Dell Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun 30 Dec 2007 8 A..H. --- "C:\Documents and Settings\Dell Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun 30 Dec 2007 8 A..H. --- "C:\Documents and Settings\Dell Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sun 30 Dec 2007 8 A..H. --- "C:\Documents and Settings\Dell Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Wed 29 Aug 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Wed 29 Aug 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Wed 29 Aug 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Wed 29 Aug 2007 8 A..H. --- "C:\Documents and Settings\Guest\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 5 Jun 2008 8 A..H. --- "C:\Documents and Settings\Mitch\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 5 Jun 2008 8 A..H. --- "C:\Documents and Settings\Mitch\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 5 Jun 2008 8 A..H. --- "C:\Documents and Settings\Mitch\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 5 Jun 2008 8 A..H. --- "C:\Documents and Settings\Mitch\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\richard\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\richard\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\richard\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\richard\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
THat is what i got from the SDFix thing.
I almost thought it worked....till 30secs into logging on the screen came back...

These winds poped up

-Malware Alert
-Windows Script Host(Cannot find file C:\Documents and Settings\richard\Local Settings\Temp\.tt10.tmp.vbs)

Good Luck Snow

#14 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:01:21 AM

Posted 05 June 2008 - 12:50 PM

Has teatimer been running during all this?
Chewy

No. Try not. Do... or do not. There is no try.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users