Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf
Am I going crazy or are my spider senses tingling?

Here's what I've been noticing lately on a fresh, ShredOS-wiped SSD.

- I have been having to "switch user" (from the same admin account) to the exact same account to even be able to see the BitLocker encryption status of my huge 8 TB backup drive. I also get multiple instances of that little nvtray thing whenever I do this, I can close one, but not the new ones.
- The UAC wallpaper takes seconds to load sometimes, it has never been like this.
- I'm unable to set different wallpapers on different monitors.
- Screen reader got downloaded and was autorunning in the background without me even seeing it. I'm unable to click "Set timezone automatically". Weird additional features like ssh got automatically downloaded.
- Inability to mount .iso files natively, 7-zip opens them just fine.
- Windows Defender Firewall will let programs access the internet without me even clicking the popup to allow them.
- Mullvad VPN's site reports DNS leaks even though I turned off secure DNS in Edge just as they say you should on their page here: https://mullvad.net/en/help/dns-leaks/



I ran MSERT and it found some stuff, this is the log:

code:

Results Summary:
----------------
Found Trojan:Win32/Malgent, partially removed.
Found HackTool:Win32/Patcher and Removed!
Found HackTool:Win32/Keygen!MSR and Removed!
Found HackTool:Win32/Keygen and Removed!
Found HackTool:Win32/Crack, partially removed.
Successfully Submitted MAPS Report
Successfully Submitted Heartbeat Report
Microsoft Safety Scanner Finished On Mon Aug 21 07:10:48 2023
MS defender offline reports nothing.

SFC /scannow showed nothing, with dism online it says everything is fine and dandy - sadly I cannot mount a windows ISO and use the WIM as a repair source.

UAC is weird as well, it's as if I'm not an administrator - setting startups usually doesn't work.

I'm going to try making a new local account and setting that as administrator instead and if that doesn't work it's new account time.

Any other advice?

Thanks!

AEMINAL fucked around with this message at 07:27 on Aug 22, 2023

Adbot
ADBOT LOVES YOU

AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf
Why I think I'm paranoid:

I have not noticed any unusual GPU or CPU activity or attempts at logins/password changes (my ancient gmail that I use for everything is 2-fa as f-ck so no one but me will ever be able to change anything)

BG3 runs perfectly.

Intel ME and my mobo firmware are up to date.

My wallet.dat backup file has not been stolen, I keep it as a sanity check to see if the pittance of mBTC is ever transferred away.

Most things work, except the whole kernel stack enforcement thing because of EAC - and my computer is reporting enhanced hardware security in Windows Security.

AEMINAL fucked around with this message at 07:30 on Aug 22, 2023

AEMINAL
May 22, 2015

barf barf i am a dog, barf on your carpet, barf
Most issues seem to have disappeared after making my admin account local, lmao

gently caress Windows 11 :mad:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply