I am new to this forum so I will introduce myself quickly. My name is Waldek. I am 24yo and I live in UK. I have been playing same MMORPG - Tibia for about 12years.
Okay, so basically I have got a problem with my laptop and few other devices at home - but lets forget them now and concentrate on my laptop only.
The problem is that one day someone, somehow got my IP address. I was never being pinged or anything like that. So, one day after I pressed shutdown button my Win7 started doing some updates. After I turned it back ON it was continuing to install them (about 42.000 files/items). When my windows loaded I could see new icon on my desktop - Remote Desktop App (mstsc.exe located in system32). That is when I realized something is not okay. I unticked the ticked box under Remote settings, so it is not allowed anymore. This thing appeared on the other device connected through same WIFI router aswell. Basically I realized someone has done something to my PC and despite all protection I have had at this moment, it has been done because this setting was ON.
So I will try to come to conclusion or I will try to explain what is my problem now (I mean I will try, because I dont know what the problem is, or I am just not that "computer literate". Basically I can provide with all the information or screenshots upon request).
Okay, so things that draw my attention the most after this thing happened were:
- I could not reinstall Win10 on the other device (HP laptop), when I tried this setting from boot menu>fully reinstalling windows(deleting all the files aswell), because the reinstall always stopped at 43% and a message in blue window appeared saying "Trusted Modules Installer requested (something)". I could allow it or reject it. I was told to reject it, so I did. Then system was going off and back on, but this time in more Windows installing interface - not BIOS. So when I finished installation in Windows/Cortana my windows was carrying out a bunch of processes (most of them under process tiworker.exe) it also updates and then system automatically restarts, without even asking me if I agree.
- I have lots of Application Extensions for both my browsers Internet Explorer and Google Chrome. I cannot delete these files from my folders because I am not allowed to do so.
- I realised I have a bunch of devices or/and drivers in my Device Manager that I never had before, same as Inbound and Outbound rules in Windows Firewall. Most of them, if not all relate to each other (I mean Driver from device manager relates to Inbound/Outbound rule in Firewall). I am really not sure if that is the way it should be, therefore I can provide a screenshot if requested, or I can export both Inbound and Outboung rules into a notepad and copy>paste them here for you guys.
-My disc C changed its form into NTFS file system (in this laptop which is Win7, Compaq)
Seriously there is so many things I could list here that I dont even know where do I start and where do I finish, therefore I think it would be easier if someone ask me a question and I will try to provide with answer or a screenshot. However, thing that draw my attention the most is when I open Resource Monitor in my task manager. For example today I boot my laptop in safemode, it loaded a bunch of drivers, and then it said safe mode only loads essential drivers. When I had my wifi button off and icon was off aswell, i could see a one thing under Network Processes in Resource monitor, that had IP adress, port and it was rending and reciving B (around 100/sec).
So I leave it with you guys, and I only write it here because I did full (recomended) scan with malwarebytes througs Safe Mode with wifi (even router) off and it did not found anything. I guess my laptop is not mine anymore. If you thing I should run my scan one more time but with custom settings please let me know. Thank you!
PS. I have had malwarebytes ON when that thing happened, it was PREMIUM TRIAL version. Today my trial expires and I am not sure if I want to pay for it or not.
PS2. On one computer forum I was simply told, that I was DOOMED and I can burn my devices and router and buy new ones.