{"id":10276,"date":"2021-12-05T07:53:34","date_gmt":"2021-12-05T07:53:34","guid":{"rendered":"https:\/\/lgildv5i97.onrocket.site\/answers\/?post_type=question&#038;p=10276"},"modified":"2021-12-05T07:54:29","modified_gmt":"2021-12-05T07:54:29","slug":"new-system-already-remotely-controlled","status":"publish","type":"question","link":"https:\/\/computing.net\/answers\/security\/new-system-already-remotely-controlled\/40833.html","title":{"rendered":"New System Already REMOTELY Controlled"},"content":{"rendered":"<p>New system setup- ALREADY under remote control PLEASE HELP<br \/>\nI just got New HP Touchscreen Desktop All in One. \/ seems connected\/running Windows NT ?<\/p>\n<p>sys info&#8230;<br \/>\nInstalled Physical Memory (RAM) = 8.00 GB<br \/>\nAvailable Physical Memory = 1.19 GB<br \/>\nTotal Virtual Memory = 9.68 GB<br \/>\nAvailable Virtual Memory = 2.32 GB<br \/>\nPage File Space 3.75 GB<br \/>\nHardware Abstraction Layer= Version &#8220;10.0.18362.752&#8221;<br \/>\nSMBIOS version was changed<br \/>\nHyper-V-VM Monitor Mode Extensions value = Yes<br \/>\nHyper-V-Second Level address Translation Extensions value = Yes<br \/>\nHyper-V- Virtualization Enabled in Firmware value = No<br \/>\nHyper-V- Data Execution Protection value = Yes<\/p>\n<p>**msg from manufacturer HP Assistant &#8211; says warning your firewall is not enabled. We recommend using one or at least turn on Windows Defender&#8230;so i go to turn on Windows Defender and it displays as if it is already on.<\/p>\n<p>Feel dumb &#8211; I&#8217;m CompTIA Certified (for yrs not @ Expert level = just basic) but still cannot figure out how this happens everytime. I believe (may not be true) but at set up something must auto start..or maybe really i did hacked\/controlled IMMEDIATELY upon going to the internet to do System Updates . How can that be avoided &#8211; need the many updates req&#8217;d even at initial set up.<\/p>\n<p>I was so excited but whenever i get a new pc or laptop i start up do updates and SOON thereafter are issues. So i waited 2 yrs &#8211; tried again. Followed ALL recommended set up steps..yet here again. SAME ISSUES<\/p>\n<p>I will notice small things here and there..so prompted me to search my PC files. Sure enough i discovered log files, when i try to view says I do not have access. (ie-1) PCR7 Config state &amp; Device Encryption Support both state Elevation Req&#8217;d to view 2) BIOS Version date, SMBIOS Version &amp; Embedded Controller date all appear w\/ different font than everything else 3) Secure Boot State, Kernel DMA Protection, Virtualization-based Security turned off CANNOT enable, &#8220;But there were MANY Notepad documents that I was able to access.<\/p>\n<p>So basically i think i became part of remote network. The overlay looks like Windows 10 but diff slightly.<\/p>\n<p>There are logs for everything. So i believe they had logs provide details for my system then created scripts\/programs whatever the term may be to change that.<\/p>\n<p>User ACLS limits me to certain things.<\/p>\n<p>Crazy BUT how to i set up correctly &#8211; there is no tower as All-in-One so wouldnt be able to get CMOS.. No recovery disks ,,,dont wanna pay $60 to get them.<\/p>\n<p>Can ANYONE help &amp; direct me? Even for a nominal fee &#8211; I WILL PAY I had rootkit on last laptop&#8230;went mad from 3 yrs trying to remove -while most thought in my head. I have the logs which show me everything..the more i search the more i discover has changed configurations. Microsoft Sevices, added many start up programs added &amp; also MUCH has been stopped\/disbled like the System Protect an the AuthLogon..I could go on and on.<\/p>\n<p>Now i will not go through that&#8230;if i have to use my Brand New Desktop being remote controlled by someone I will. Im not giving years of my life away anymore..it wasnt worth the peace of mind i have from the fear that i cant control my system and that means someone else cam &amp; has THAT QUICKLY after initial set up\/\/how do they find me so fast? could be default apps\/programs installed in default? I work as a Senior Sup &amp; Tech Support At-Home- Advisor for 2 years..but this is above my skill level &amp; paygrade. (is this type skill under a networking certification or Microsoft). Im lost<br \/>\n#Dumbfounded &amp; Disgusted<\/p>\n<p>[Not sure if the config details are correct, they are what is &#8216;displayed&#8217; to me. 64 Bit Op Sys but EVERYTHING changed &amp; runs under 32 bit duplicate file exe files, even Displayed Font looks slight diff (ie -in Control Panel&gt; System and Security &gt; System)<\/p>\n<p>My network Internet set on Public network profile. i have one pc but nonetheless unable to change options to make a home network even if i wanted to. THIS IS BS. I think of the millions who set up a new pc and never even notice these small type changes \/ even typos in Bios&#8230;how would they if you dont know where to look or recognize if you did.<\/p>\n<p>sys info&#8230;<br \/>\nInstalled Physical Memory (RAM) = 8.00 GB<br \/>\nAvailable Physical Memory = 1.19 GB<br \/>\nTotal Virtual Memory = 9.68 GB<br \/>\nAvailable Virtual Memory = 2.32 GB<br \/>\nPage File Space 3.75 GB<br \/>\nHardware Abstraction Layer= Version &#8220;10.0.18362.752&#8221;<br \/>\nSMBIOS version was changed<br \/>\nHyper-V-VM Monitor Mode Extensions value = Yes<br \/>\nHyper-V-Second Level address Translation Extensions value = Yes<br \/>\nHyper-V- Virtualization Enabled in Firmware value = No<br \/>\nHyper-V- Data Execution Protection value = Yes<\/p>\n<p>3 partitions<br \/>\nSCSI -Microsoft iSCSI Initator &#8211; PNP Device ID ROOT\\ISCSIPRT\\0000 (0000 in diff font)<br \/>\nMicrosoft Storage Spaces Controller ROOT\\SPACEPORT\\0000<br \/>\nModem &#8211; NO MODEM listed<br \/>\nNetwork Adapter &#8211; SOOO MANY CONFIGURATIONS ADDED, with Type as NOT AVAILABLE<br \/>\nNetwork Protocol SO MANY ADDED<br \/>\nBLUETOOTH DEVICE ADDED Personal Area Network<br \/>\nWAN Miniport &#8211; MANY MANY added<br \/>\nWinSock C:\\windows\\SysWOW64\\wsock32.dll<br \/>\nmany printers added &amp; including Microsoft XPS Document Writer v4 PORTPROMPT: Local Server<br \/>\nOneNote for Windows 10 Microsoft Software Printer Driver Microsoft.Office.OneNote_16001.12730.20190.0_x64__8wekyb3d8bbwe_microsoft.onenoteim_S-1-5-21-945171952-243697559-165242251-1001 Local Server<\/p>\n<p>HARDWARE Resources<br \/>\nConflicts\/Sharing<br \/>\nI\/O Port 0x00000000-0x0000000F Direct memory access controller<br \/>\nI\/O Port 0x00000000-0x0000000F PCI Express Root Complex<\/p>\n<p>I\/O Port 0x0000F000-0x0000FFFF PCI Express Root Port<br \/>\nI\/O Port 0x0000F000-0x0000FFFF Realtek PCIe GbE Family Controller<\/p>\n<p>Memory Address 0xFEE00000-0xFFFFFFFF PCI Express Root Complex<br \/>\nMemory Address 0xFEE00000-0xFFFFFFFF Motherboard resources<\/p>\n<p>Memory Address 0xFE800000-0xFE8FFFFF PCI Express Root Port<br \/>\nMemory Address 0xFE800000-0xFE8FFFFF Standard SATA AHCI Controller<\/p>\n<p>Memory Address 0xE0000000-0xEFFFFFFF AMD Radeon(TM) Vega 3 Graphics<br \/>\nMemory Address 0xE0000000-0xEFFFFFFF PCI Express Root Port<br \/>\nMemory Address 0xE0000000-0xEFFFFFFF PCI Express Root Complex<\/p>\n<p>Memory Address 0xFE500000-0xFE7FFFFF PCI Express Root Port<br \/>\nMemory Address 0xFE500000-0xFE7FFFFF AMD USB 3.10 eXtensible Host Controller &#8211; 1.10 (Microsoft)<\/p>\n<p>Memory Address 0xFEA00000-0xFEAFFFFF PCI Express Root Port<br \/>\nMemory Address 0xFEA00000-0xFEAFFFFF Realtek PCIe GbE Family Controller<\/p>\n<p>IRQ 0 High precision event timer<br \/>\nIRQ 0 System timer<\/p>\n<p>SOFTWARE ENVIRONMENT<br \/>\nSystem Drivers &#8211; A million listed<\/p>\n<p>Environment Variables<br \/>\nComSpec %SystemRoot%\\system32\\cmd.exe &lt;SYSTEM&gt;<br \/>\nDriverData C:\\Windows\\System32\\Drivers\\DriverData &lt;SYSTEM&gt;<br \/>\nNUMBER_OF_PROCESSORS 4 &lt;SYSTEM&gt;<br \/>\nOneDrive C:\\Users\\catlo\\OneDrive DESKTOP-GL90HTS\\catlo<br \/>\nOneDriveConsumer C:\\Users\\catlo\\OneDrive DESKTOP-GL90HTS\\catlo<br \/>\nOnlineServices Online Services &lt;SYSTEM&gt;<br \/>\nOS Windows_NT &lt;SYSTEM&gt;<br \/>\nPath C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath;%SystemRoot%\\system32;%SystemRoot%;%SystemRoot%\\System32\\Wbem;%SYSTEMROOT%\\System32\\WindowsPowerShell\\v1.0\\;%SYSTEMROOT%\\System32\\OpenSSH\\ &lt;SYSTEM&gt;<br \/>\nPath %USERPROFILE%\\AppData\\Local\\Microsoft\\WindowsApps; NT AUTHORITY\\SYSTEM<br \/>\nPath %USERPROFILE%\\AppData\\Local\\Microsoft\\WindowsApps; DESKTOP-GL90HTS\\catlo<br \/>\nPATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC &lt;SYSTEM&gt;<br \/>\nplatformcode 1M &lt;SYSTEM&gt;<br \/>\nPROCESSOR_ARCHITECTURE AMD64 &lt;SYSTEM&gt;<br \/>\nPROCESSOR_IDENTIFIER AMD64 Family 23 Model 24 Stepping 1, AuthenticAMD &lt;SYSTEM&gt;<br \/>\nPROCESSOR_LEVEL 23 &lt;SYSTEM&gt;<br \/>\nPROCESSOR_REVISION 1801 &lt;SYSTEM&gt;<br \/>\nPSModulePath %ProgramFiles%\\WindowsPowerShell\\Modules;%SystemRoot%\\system32\\WindowsPowerShell\\v1.0\\Modules &lt;SYSTEM&gt;<br \/>\nRegionCode NA &lt;SYSTEM&gt;<br \/>\nTEMP %SystemRoot%\\TEMP &lt;SYSTEM&gt;<br \/>\nTEMP %USERPROFILE%\\AppData\\Local\\Temp NT AUTHORITY\\SYSTEM<br \/>\nTEMP %USERPROFILE%\\AppData\\Local\\Temp DESKTOP-GL90HTS\\catlo<br \/>\nTMP %SystemRoot%\\TEMP &lt;SYSTEM&gt;<br \/>\nTMP %USERPROFILE%\\AppData\\Local\\Temp NT AUTHORITY\\SYSTEM<br \/>\nTMP %USERPROFILE%\\AppData\\Local\\Temp DESKTOP-GL90HTS\\catlo<br \/>\nUSERNAME SYSTEM &lt;SYSTEM&gt;<br \/>\nwindir %SystemRoot% &lt;SYSTEM&gt;<\/p>\n<p>Startup Programs<br \/>\nBtServer &#8220;c:\\program files (x86)\\realtek\\realtek bluetooth\\btserver.exe&#8221; Public HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<br \/>\nHPSEU_Host_Launcher c:\\system.sav\\util\\hpseuhostlauncher.exe DESKTOP-GL90HTS\\catlo HKU\\S-1-5-21-945171952-243697559-165242251-1001\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<br \/>\nOneDrive &#8220;c:\\users\\catlo\\appdata\\local\\microsoft\\onedrive\\onedrive.exe&#8221; \/background DESKTOP-GL90HTS\\catlo HKU\\S-1-5-21-945171952-243697559-165242251-1001\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<br \/>\nSecurityHealth %windir%\\system32\\securityhealthsystray.exe Public HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<br \/>\nWindowsDefender &#8220;%programfiles%\\windows defender\\msascuil.exe&#8221; Public HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run<\/p>\n<p>No Network Connections &#8211; showing at all<br \/>\na ZILLION Loaded Modules including<br \/>\nbridgecommunication 1.20.1790.0 444.27 KB (454,928 bytes) 3\/27\/2020 5:47 PM HP Inc. c:\\windows\\system32\\driverstore\\filerepository\\hpcustomcapcomp.inf_amd64_79c5c41204d03777\\x64\\bridgecommunication.exe<\/p>\n<p>startmenuexperiencehost Not Available 921.80 KB (943,928 bytes) 4\/1\/2020 10:12 AM Not Available c:\\windows\\systemapps\\microsoft.windows.startmenuexperiencehost_cw5n1h2txyewy\\startmenuexperiencehost.exe<br \/>\nSystem.Runtime.InteropServices.WindowsRuntime.ni 4.8.3752.0 9.00 KB (9,216 bytes) 2\/29\/2020 7:42 PM Not Available c:\\windows\\assembly\\nativeimages_v4.0.30319_64\\system.runtbff93e24#\\7fd43d0605b1366bc071e2bbdde312cf\\system.runtime.interopservices.windowsruntime.ni.dll<\/p>\n<p>virtualmonitormanager Not Available 92.50 KB (94,720 bytes) 3\/18\/2019 11:59 PM Not Available c:\\windows\\system32\\virtualmonitormanager.dll<br \/>\ntaskflowui Not Available 2.75 MB (2,880,000 bytes) 12\/25\/2019 9:31 AM Not Available c:\\windows\\shellcomponents\\taskflowui.dll<br \/>\nRtkAudUService64 1.0.205.1 909.78 KB (931,616 bytes) 4\/29\/2019 3:20 PM Realtek Semiconductor c:\\windows\\system32\\rtkauduservice64.exe<\/p>\n<p>winsqlite3 3.25.3.0 854.41 KB (874,912 bytes) 3\/18\/2019 11:44 PM SQLite Development Team c:\\windows\\system32\\winsqlite3.dll<\/p>\n<p>icu 63.1.0.0 2.21 MB (2,321,408 bytes) 6\/21\/2019 2:55 PM The ICU Project c:\\windows\\system32\\icu.dll<\/p>\n<p>PLUS many many Windows Error Reporting<\/p>\n<p>5\/7\/2020 5:25 PM Application Hang The program WindowsInternal.ComposableShell.Experiences.TextInput.InputApp. version 10.0.18362.752 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 3f44 Start Time: 01d6241d299a8098 Termination Time: 4294967295 Application Path: C:\\Windows\\SystemApps\\InputApp_cw5n1h2txyewy\\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe Report Id: 6c889094-50db-4849-8630-685445ef2bde Faulting package full name: InputApp_1000.18362.449.0_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App Hang type: Quiesce<\/p>\n<p>5\/7\/2020 3:45 AM Application Error Faulting application name: svchost.exe_TokenBroker, version: 10.0.18362.1, time stamp: 0x32d6c210 Faulting module name: combase.dll, version: 10.0.18362.815, time stamp: 0x0611db4a Exception code: 0xc0000602 Fault offset: 0x000000000001e445 Faulting process id: 0x2654 Faulting application start time: 0x01d6227177dff4c7 Faulting application path: C:\\windows\\system32\\svchost.exe Faulting module path: C:\\windows\\System32\\combase.dll Report Id: 17426cfa-64ea-431d-aff6-52e38693b485 Faulting package full name: Faulting package-relative application ID:<\/p>\n<p>5\/7\/2020 5:24 PM Application Error Faulting application name: StartMenuExperienceHost.exe, version: 0.0.0.0, time stamp: 0x5e708f15 Faulting module name: ucrtbase.dll, version: 10.0.18362.815, time stamp: 0x32a6df9a Exception code: 0xc0000409 Fault offset: 0x000000000006db9e Faulting process id: 0x2738 Faulting application start time: 0x01d62422db21742f Faulting application path: C:\\windows\\SystemApps\\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\\StartMenuExperienceHost.exe Faulting module path: C:\\windows\\System32\\ucrtbase.dll Report Id: a072e49c-db70-4b45-93d1-1934d10a80dc Faulting package full name: Microsoft.Windows.StartMenuExperienceHost_10.0.18362.449_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: App<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"iawp_total_views":5},"question-category":[56],"question_tags":[],"class_list":["post-10276","question","type-question","status-publish","hentry","question-category-security"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question\/10276","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/types\/question"}],"author":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/comments?post=10276"}],"wp:attachment":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/media?parent=10276"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question-category?post=10276"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question_tags?post=10276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}