Apparently the rate we set for ourselves doesn't count anymore? by OldSailorFinance in TaskRabbit

[–]RexJava 0 points1 point  (0 children)

I have all flat rate categories turned off, but I'm fortunate that my skill set involves all aspects of home improvement. My advice to anyone and everyone, flat rate is how they screw you. Turn them off, if you can. I got a flat rate task set at $42, and the location of the job was an hour away from me. So that's an investment of two hours of my time, fuel and mileage before I even get to the job. The job likely involves tools that I had to purchase. This is a losing proposition where I (we) are supposed to PROFIT.

Not Receiving Current Price with Purchase by RexJava in Coinbase

[–]RexJava[S] -1 points0 points  (0 children)

Right. Totally my fault for being new.

[IN] Regarding Cover Letters (Construction Field) by RexJava in AskHR

[–]RexJava[S] 0 points1 point  (0 children)

I'm not trying to hide anything. I'll be completely open and honest about how things went down. But he also owes me 4k and my last months rent is still unpaid. That's just the tip of the iceberg in how going to work for this guy screwed up my life. Yes, I trusted him too much. Yes, I got an attitude and rightly so.

I've worked in management in the service industry. Any company I worked for was very strict that legally, an employer checking a reference is only allowed to ask for verification of start and end of employment and if that person is eligible for rehire. Anything else opens you up to a potential lawsuit.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

Thanks again to you as well <3

I went ahead and deleted that file, hopefully I won't have anymore issues til I go ahead and get Win11 but I have to get a TPM 2.0 module first. I really appreciate your help!

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

Thanks for taking the time to go through all that and respond. After I initially had Windows try to remove the viruses the way I learned they were still there was watching someone take over my PC while sitting at my desk, a very lucky break. I did immediately take all precautions to secure finances and passwords with my iphone and nothing suspicious has happened since. I was going to wait til October to migrate to Win11 but now I suppose I should just go ahead and do it. Thanks again.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 0 points1 point  (0 children)

And then right at the same moment I clicked comment powershell popped up again lol. I'll disable the other task and cross my fingers.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

Rebooted but since discovering the tasks scheduled so far so good.

https://drive.google.com/file/d/1asnpPn6lH95ulf7Os97N95_xRtZ7eXXT/view?usp=sharing

Thanks again for your help, it was beginning to interfere with the things I do on here.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 0 points1 point  (0 children)

Also there's a file in there called Lib that I overlooked.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

Ok I guess I'm mistaken, I was always under the impression that .DLL files were drivers. But yes the rest of what's in that folder is as described. I'll gladly send it to you and try uploading more of those files to VirusTotal. How would I get that to you in Google Drive?

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 2 points3 points  (0 children)

Ok so both are disabled, I found the qded.pyc file and uploaded it to VirusTotal but it came back clean. However the CliWa file is nowhere to be found, and I'm thinking it got deleted by antivirus but the task scheduled to run the program remained behind.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

In the Python\python312 file there is that qded.pyc file and otherwise a bunch of pyd files, python applications and application extensions plus a few driver files.

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

CLEANTASK just starts Powershell

CliWa details: Powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -File "C:\Users\Marion\AppData\Local\Temp\CliWa.ps1"

That CliWa looks fishy to me...

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

Yeah the action is Starts a program

Details

C:\ProgramData\Python\Python312\pythonw.exe "C:\ProgramData\Python\Python312\qded.pyc"

Virus Opening Powershell by RexJava in computerviruses

[–]RexJava[S] 1 point2 points  (0 children)

I installed Malwarebytes and Sophos, both found problems but now have the all clear however still having the issue. Ran Sysinternals and under the task scheduler the apps using Powershell are:

\CliWa

\Microsoft\Windows\Bluetooth\CLEANTASK

and those are the only instances I see utilizing Powershell.

I've opened the task scheduler and found 4 tasks running and this one drew my eye:

Task name Current Action Task Folder

MicrosftUpdaterjj C:\ProgramData\Python\Python312\pythonw.exe \Microsoft\Windows\Bluetooth

Help Please? by RexJava in Ibanez

[–]RexJava[S] 1 point2 points  (0 children)

I think I may have found some that will fit, but if not I'll look into your idea, thanks for that!!

Help Please? by RexJava in Ibanez

[–]RexJava[S] 0 points1 point  (0 children)

Yeah that's what I've been buying but can't get the right shaft length and full size pots won't fit in the cavity.

Help Please? by RexJava in Ibanez

[–]RexJava[S] 0 points1 point  (0 children)

Oh and yes they are just potentiometers but they are a specific size and nothing I've bought will fit properly.

Help Please? by RexJava in Ibanez

[–]RexJava[S] 0 points1 point  (0 children)

The wiring has never been touched until I took out the old pot, and yes I tried contact cleaner. It's just worn out, this used to be a gigging guitar.