Hi,
I've been having trouble since December 2008 when my laptop began to crash - windows vista home premium. I found out my husband had been copying everything with Windows Easy Migration ever 3-4 months, as well as setting up remote dialing, and even breaking into my hotmail account and stealing my contacts, emails and then "planting" his email in a contact in instant messenger to receive my stuff.
I have not been able to wipe clean and re-install. My software came on the laptop, and my back up discs are somewhere in the states. Since we are going through a nasty divorce and I have a lot of evidence on here I have been concerned about losing it. I've tried to back it up to disk and flash drives without much success.
He has been everywhere on my computer, changing everything and mapping the computers remotely etc., I continue to find stuff to this iday. I have a lot of screen shots of what he's done, but not the knowledge to get him out!! He has made special login settings above my own, there are progams I can not do anything with, or get him out of etc.,
I'm terrified to "clean it" but I have had this particular error now 3 times (last time lost paper I wrote it on) and I am concerned pretty soon will crash for good.
C:\windows\system32\config\systemprofile\desktop refers to a location that is unavailable. it could be on a hard drive on this computer, or on a network. Check to make sure that the disk is properly inserted, or that you are connected to the internet or your network, and then try again. If still cannot be located, the information might have been moved to a different location.
I was hoping to read more before starting - but am worried now. Any help would be appreciated ! Anything you see with "lick-pc", "licklager" or "peacefrog" will be part of his email addresses.
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay, but I will do my best to keep it as short as possible.
I am not a lawyer, but…. what is/has been happening sounds like it's stepping over a fair few legal boundaries. Your profile doesn't say what country you're from, but most countries have laws against the theft of computer data and tampering with computer equipment. You should really be taking this to the local Police Department's computer crime section - if we erase data and security holes, there won't be evidence left for you in case you need it. We may be trained in malware removal, and part of that steps along security lines, but we are not qualified forensic investigators, and as such, whatever we find/erase here would probably not go very far at all in court (if needed). Therefore, before proceeding, I ask that you make sure this is what you want to do, and that you don't intend to take legal action against him with this information - if you do, please go through the police instead. Adding/removing data from your computer before you go to the proper authorities isn't the right thing to do until it has been examined by them. Keep the computer offline, change your passwords, and create new email accounts for the moment.
If there are no such laws in existence where you are from, then please post back and we will be happy to try and assist you, but you should get a legal opinion first.
I am dual citizen from USA living in Quebec, Canada. Unfortunitely, neither the police nor my legal aid lawyer, nor microsoft for that matter were interested in making him stop.
He's admitted he did it - once he claims - however, what I care most about is straightening my system and retaining the pictures and documents that I have - that is the evidence I am concerned about. I am sueing for divorce - I just want him out of my system and my computer under control.
I had the recently posted wowfx problem as well ……..I also keep getting lost on here I apologize
here is some of the screen shots of how he was using messenger, I am trying to post some test from msn messenger but it's too big. Do you want me to show you the rest of the screen shots? or wait?
the orders kind of mixed up, but you'll see what I mean about him being every where. He also got into my Windows Media Center and I think turned my camera on –Oh, the messenger text is pretty long, so let me know if there's another way to send that please.
We have to deal with things methodically - we'll get to your individual issues, but we have to take a look at the overall picture first. The screenshots contain personal information - mainly his, but no matter what he's done to you, it's still respectable to keep that information private. We will deal with the sharing folders issue though - but for now, don't post anymore unrequested information, and don't log onto your MSN account. If we need them again, we'll ask for them, but for now please remove them from your previous post.
1) DDS [external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt
Save both reports to your desktop.
2) GMER
Please download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Right click GMER.exe and click Run as Administrator. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that have been checked. Uncheck the following …
Sections
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and put it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
3) Users Launch Notepad, and copy/paste everything in the codebox below into the new document. Go up to "File Save As" and click the drop-down box to change the "Save As Type" to "All Files" and save it to your desktop as runme.bat.
@echo off
if exist results.txt del results.txt
echo "===User Accounts===" >> results.txt
net user >> results.txt 2>>&1
del %0
Locate runme.bat on your Desktop and right-click on it, and select Run as Administrator.
Post the contents of results.txt from your desktop.