My grandma had a guy work on her laptop remotely and since then has had countless remote sessions. Odd files and folders saved in various places and users being added, deleted, enabled/disabled including the build in administrator etc. I completely (or at least I thought it was completely) wiped the os from the disk and installed Windows 10 Home from my own recovery flash drive. Once installation finished I looked around and still found bookmarks (although no account was signed in to the browser to sync bookmarks from) most being to sites supposedly HP help sites as well as yahoo search and whatnot. Also, there are still external IP addresses creating/enumerating/etc new and existing users (mind you, the only user that should be on it is the one I created for my grandma using a newly created Microsoft Account at the "clean" install I did). Somehow, the computer is linked to a workgroup and domain which also has external IP addresses involved. Even though her account should be the administrator user it's permissions have been revoked for most of the system/administrator settings and files and folders. I have run Rkill, and RogueKiller for 64bit is running now, so far, but I have yet to see if they've done any good.