F5F Stay Refreshed Hardware Desktop You're experiencing significant security issues. Let's find ways to address this for a regular home user.

You're experiencing significant security issues. Let's find ways to address this for a regular home user.

You're experiencing significant security issues. Let's find ways to address this for a regular home user.

S
seeker07
Senior Member
349
02-26-2023, 01:37 PM
#1
Greetings! (tl;dr most prevalent has been put in bold) Windows 11 x64 Dell BIOS (apparently current as of this post) Alienware M17(R [I think]) i7-9750H Samsung NVMe 1 TB (PM981) 16 GB RAM, not sure what company (Dell) Onboard Intel UHD Graphics 630 Nvidia GeForce RTX 2070 with Max-Q Design "Gateway" Comcast - Xfinity provided. A month ago, I ran netstat -a in PowerShell and saw I was connected to some device named “goatse” through like 8 connections . I frequently cannot visit .gov websites or something with a SSO cross-site won’t load. My internet is often slow. I KNOW THIS IS A LONG POST BUT PLEASE BEAR WITH ME. THANKS!! I have been looking for a company that can fix my Alienware M17 (laptop). It has Dell’s full warranty and technical service help, but they cannot solve my problems. It started 2 years ago when my Alienware laptop was hacked along with my Dell Inspiron 3880 desktop. Neither computer has acted nor performed as it should since then despite having their motherboards replaced and the hard drive replaced on the desktop and the hard drive scrubbed like you do on the laptop. The desktop’s on-board ethernet port was not recognized by the BIOS (something you can do with "Dell Commander" I didn't know about this until after I bought a new motherboard. Sometimes it would not turn on at all, then I’d give it a try a day or two later and it would turn on. Files in “Program Files” would appear like an empty folder named “Trello” would reappear after I first deleted it because it mysteriously appeared one day. One time I had my modem and router unplugged and my mouse was moving on its own. Any device that uses Wi-Fi in my home will have its hidden BSSID revealed. All sorts of problems have come and gone. Things break, like, for example, I tried to update my BIOS firmware. From the in-Windows application, it would BSOD. And when I tried to flash the BIOS from the UEFI menu, it would not recognize any USB flash drives. It wasn’t until after I reset Windows 11 that UEFI started recognizing them again and I was able to update my firmware. Many times, https websites come back as unsecure. Sometimes if I refresh the webpage, it will load right, but often I must click on “continue to the website anyway” and then when the webpage loads after I connect through this bad certificate (or whatever is wrong) the website will load correctly with the proper “lock” (or in Edge it will say “Added security”). On my Galaxy Z Fold 3 the Galaxy App Store had a bunch of apps that were clearly not from the official repository . My ISP website account is protected by an OTP text message and one time I received a OTP without requesting one and a new user appeared in my account. Currently I often must disable (then, for preference re-enable) “audio enhancements” to get my sound to work. In Windows Security, Memory Integrity won’t turn off. I’ve turned it off and rebooted probably 10 times with Dell technicians, and it remains on every time. My ethernet port on my laptop used to work sporadically, now my router has it set to “Paused” when you can only pause Wi-Fi connections, I can’t even pause ethernet connections. There was a module FRST64.exe exposed a "module" installed in my Dell SupportAssist folder that was named Nerdbank Streams , something I found on GitHub as a unicast program. When I run peerblock, it blocks multicasting connection attempts 100 times every minute and a random country or two in between. For a while I couldn’t visit my router’s gateway. I have reinstalled Windows 11 at least 50 times and every time it gets corrupted. For example all my tasks that come out of the box in the task scheduler are deleted. I don’t know what to do. Nobody’s advice works. People tell me I seem paranoid. I am paranoid because of the big things that prove something/someone is happening to me. BitDefender is useless. And I have a $3,000 computer that runs like a $500 computer and has depreciated and an $800 desktop that I just don’t turn on anymore unless I need it to create a Windows boot drive or something. It seems the only thing that might help me is built for enterprise sized and priced large business solutions. But I don’t have the money or know-how to even try those options. Is there anything you can do to help me? Sorry for the super long letter, Austin Minidump.zip
S
seeker07
02-26-2023, 01:37 PM #1

Greetings! (tl;dr most prevalent has been put in bold) Windows 11 x64 Dell BIOS (apparently current as of this post) Alienware M17(R [I think]) i7-9750H Samsung NVMe 1 TB (PM981) 16 GB RAM, not sure what company (Dell) Onboard Intel UHD Graphics 630 Nvidia GeForce RTX 2070 with Max-Q Design "Gateway" Comcast - Xfinity provided. A month ago, I ran netstat -a in PowerShell and saw I was connected to some device named “goatse” through like 8 connections . I frequently cannot visit .gov websites or something with a SSO cross-site won’t load. My internet is often slow. I KNOW THIS IS A LONG POST BUT PLEASE BEAR WITH ME. THANKS!! I have been looking for a company that can fix my Alienware M17 (laptop). It has Dell’s full warranty and technical service help, but they cannot solve my problems. It started 2 years ago when my Alienware laptop was hacked along with my Dell Inspiron 3880 desktop. Neither computer has acted nor performed as it should since then despite having their motherboards replaced and the hard drive replaced on the desktop and the hard drive scrubbed like you do on the laptop. The desktop’s on-board ethernet port was not recognized by the BIOS (something you can do with "Dell Commander" I didn't know about this until after I bought a new motherboard. Sometimes it would not turn on at all, then I’d give it a try a day or two later and it would turn on. Files in “Program Files” would appear like an empty folder named “Trello” would reappear after I first deleted it because it mysteriously appeared one day. One time I had my modem and router unplugged and my mouse was moving on its own. Any device that uses Wi-Fi in my home will have its hidden BSSID revealed. All sorts of problems have come and gone. Things break, like, for example, I tried to update my BIOS firmware. From the in-Windows application, it would BSOD. And when I tried to flash the BIOS from the UEFI menu, it would not recognize any USB flash drives. It wasn’t until after I reset Windows 11 that UEFI started recognizing them again and I was able to update my firmware. Many times, https websites come back as unsecure. Sometimes if I refresh the webpage, it will load right, but often I must click on “continue to the website anyway” and then when the webpage loads after I connect through this bad certificate (or whatever is wrong) the website will load correctly with the proper “lock” (or in Edge it will say “Added security”). On my Galaxy Z Fold 3 the Galaxy App Store had a bunch of apps that were clearly not from the official repository . My ISP website account is protected by an OTP text message and one time I received a OTP without requesting one and a new user appeared in my account. Currently I often must disable (then, for preference re-enable) “audio enhancements” to get my sound to work. In Windows Security, Memory Integrity won’t turn off. I’ve turned it off and rebooted probably 10 times with Dell technicians, and it remains on every time. My ethernet port on my laptop used to work sporadically, now my router has it set to “Paused” when you can only pause Wi-Fi connections, I can’t even pause ethernet connections. There was a module FRST64.exe exposed a "module" installed in my Dell SupportAssist folder that was named Nerdbank Streams , something I found on GitHub as a unicast program. When I run peerblock, it blocks multicasting connection attempts 100 times every minute and a random country or two in between. For a while I couldn’t visit my router’s gateway. I have reinstalled Windows 11 at least 50 times and every time it gets corrupted. For example all my tasks that come out of the box in the task scheduler are deleted. I don’t know what to do. Nobody’s advice works. People tell me I seem paranoid. I am paranoid because of the big things that prove something/someone is happening to me. BitDefender is useless. And I have a $3,000 computer that runs like a $500 computer and has depreciated and an $800 desktop that I just don’t turn on anymore unless I need it to create a Windows boot drive or something. It seems the only thing that might help me is built for enterprise sized and priced large business solutions. But I don’t have the money or know-how to even try those options. Is there anything you can do to help me? Sorry for the super long letter, Austin Minidump.zip

S
Sukibooki
Member
204
02-26-2023, 01:37 PM
#2
It's challenging to understand at first, but it seems there are several possible reasons behind the issue. You didn't describe the specifics of the hacking incident you experienced. Could you clarify what exactly happened? What steps did you take afterward to resolve the situation? Right now, you might be dealing with malware, viruses, or issues with software and hardware. It's notable that Dell doesn't assist in such cases, which may be a consequence of purchasing their products. I would advise avoiding them for several reasons. The best approach you should have taken was to completely wipe your drive and reinstall Windows. Ideally, do this on a brand-new test drive using Rufus from another computer. Just create a fresh copy without any additional software or bloatware. If the same problems persist after this process, remember to disconnect all other devices and accounts before investigating further.
S
Sukibooki
02-26-2023, 01:37 PM #2

It's challenging to understand at first, but it seems there are several possible reasons behind the issue. You didn't describe the specifics of the hacking incident you experienced. Could you clarify what exactly happened? What steps did you take afterward to resolve the situation? Right now, you might be dealing with malware, viruses, or issues with software and hardware. It's notable that Dell doesn't assist in such cases, which may be a consequence of purchasing their products. I would advise avoiding them for several reasons. The best approach you should have taken was to completely wipe your drive and reinstall Windows. Ideally, do this on a brand-new test drive using Rufus from another computer. Just create a fresh copy without any additional software or bloatware. If the same problems persist after this process, remember to disconnect all other devices and accounts before investigating further.

L
Luxyonity
Member
157
02-26-2023, 01:37 PM
#3
I believe there is a backdoor and the hacker is installing malware that my BitDefender can't find to run basically any commands he wants. When I was first hacked I do not remember exactly what happened, but I remember for sure that my laptop and desktop both had to have Windows reinstalled.
L
Luxyonity
02-26-2023, 01:37 PM #3

I believe there is a backdoor and the hacker is installing malware that my BitDefender can't find to run basically any commands he wants. When I was first hacked I do not remember exactly what happened, but I remember for sure that my laptop and desktop both had to have Windows reinstalled.

M
MediaZoX
Junior Member
27
02-26-2023, 01:37 PM
#4
The MyLastPass extension has stopped functioning properly.
M
MediaZoX
02-26-2023, 01:37 PM #4

The MyLastPass extension has stopped functioning properly.

E
Eren888111
Member
85
02-26-2023, 01:37 PM
#5
I wouldn't get hung up on what BitDefender or any antivirus software can or cannot find. Except for maybe very few scenarios they're largerly useless if the user doesn't already have the know how to avoid harmful interactions. I would say Malewarebytes is good tho and almost all you need could be provided for by Windows defender. Do a scan with Malewarebtyes So that being said, I would still do what I've mentioned to see the result. The theory is to isolate all of your personal files, data, syncs and everything from the hardware. The idea is to have a PC that has similar software to when it was first put together. This means no access to any secondry drives or files coming from you and no data syncing from Chrome or any other accounts. Best practice is to keep the PC outside of your home network as well. To put it simply, fully isolate the a new OS on a fully erased drive or even better a cheap brand new drive. This could be overkill, but without being there with you this is the only time efficient thing I could think of. After that, we still can't rule out anything malicious embedded in your hardware, like a rootkit in a bios for example. But if your software issues, (like that reappearing folder for example) returned after doing this. Then we have at least narrowed down the number of things that could be wrong. It's very rare that this would be the case but theoratically it is possible. Remember that even your router or a USB device that isn't nessecerily a thumb drive could still carry any sort of malicious software, so just use this logic when you start the process. Preferably be prepared to keep the system disconnected from internet during the eniter test.
E
Eren888111
02-26-2023, 01:37 PM #5

I wouldn't get hung up on what BitDefender or any antivirus software can or cannot find. Except for maybe very few scenarios they're largerly useless if the user doesn't already have the know how to avoid harmful interactions. I would say Malewarebytes is good tho and almost all you need could be provided for by Windows defender. Do a scan with Malewarebtyes So that being said, I would still do what I've mentioned to see the result. The theory is to isolate all of your personal files, data, syncs and everything from the hardware. The idea is to have a PC that has similar software to when it was first put together. This means no access to any secondry drives or files coming from you and no data syncing from Chrome or any other accounts. Best practice is to keep the PC outside of your home network as well. To put it simply, fully isolate the a new OS on a fully erased drive or even better a cheap brand new drive. This could be overkill, but without being there with you this is the only time efficient thing I could think of. After that, we still can't rule out anything malicious embedded in your hardware, like a rootkit in a bios for example. But if your software issues, (like that reappearing folder for example) returned after doing this. Then we have at least narrowed down the number of things that could be wrong. It's very rare that this would be the case but theoratically it is possible. Remember that even your router or a USB device that isn't nessecerily a thumb drive could still carry any sort of malicious software, so just use this logic when you start the process. Preferably be prepared to keep the system disconnected from internet during the eniter test.

S
Shibouh
Senior Member
369
02-26-2023, 01:37 PM
#6
You’ve likely cleaned up your drives and reinstalled Windows, which greatly reduces the chance of consumer malware being present. It looks like you’re mixing unrelated factors—possibly memory or hard drive problems might be causing the corruption you’re seeing. BSSIDs only appear when devices create a Wi-Fi network, not when clients connect. Certificate errors often stem from incorrect time synchronization (NTP) settings; ensure your clock is accurate and auto-sync enabled. Network traffic from foreign IPs is normal, as is multicast data coming from your system. The issue with tasks disappearing could be due to scheduled tasks failing or third-party firewall misconfiguration.
S
Shibouh
02-26-2023, 01:37 PM #6

You’ve likely cleaned up your drives and reinstalled Windows, which greatly reduces the chance of consumer malware being present. It looks like you’re mixing unrelated factors—possibly memory or hard drive problems might be causing the corruption you’re seeing. BSSIDs only appear when devices create a Wi-Fi network, not when clients connect. Certificate errors often stem from incorrect time synchronization (NTP) settings; ensure your clock is accurate and auto-sync enabled. Network traffic from foreign IPs is normal, as is multicast data coming from your system. The issue with tasks disappearing could be due to scheduled tasks failing or third-party firewall misconfiguration.

R
ratelslang3
Member
167
02-26-2023, 01:37 PM
#7
I have thoroughly tested the memory and the hard drive and they are okay. Windoows 11 is set to auto-sync the time according to my timezone. I've used PeerBlock for a decade and never multicast anything before, but then again it might be a new list they put up. What and who(m) would I be multicasting to? A Dell Technician is coming over today to replace my motherboard and install a new SSD with everything preloaded. The only thing I can think of now is OneDrive. I'll give that a good cleaning. I can't keep the computers off the internet, I have online university to attend. I suppose we'll see if replacing those parts help. I'll post back if anything else weird happens. Thank you for your replies.
R
ratelslang3
02-26-2023, 01:37 PM #7

I have thoroughly tested the memory and the hard drive and they are okay. Windoows 11 is set to auto-sync the time according to my timezone. I've used PeerBlock for a decade and never multicast anything before, but then again it might be a new list they put up. What and who(m) would I be multicasting to? A Dell Technician is coming over today to replace my motherboard and install a new SSD with everything preloaded. The only thing I can think of now is OneDrive. I'll give that a good cleaning. I can't keep the computers off the internet, I have online university to attend. I suppose we'll see if replacing those parts help. I'll post back if anything else weird happens. Thank you for your replies.