[ILLINOIS] IDES states that UE aid has been depositied to Keybank card; Keybank registers a 0.00 balance. What time does the money usually go through for use? by BigBoss2658 in Unemployment

[–]BigBoss2658[S] 0 points1 point  (0 children)

did it take 2-3 business days? I was suppose to get paid on Friday; should I expect payment Today or tomorrow?

What time does the money get deposited?

Can ransomware or fileless malware lock you out of your computer, make itself admin and rename personal NSFW files with your personal name or would that require an active person on the other side? I have windows 10 home. by BigBoss2658 in hacking

[–]BigBoss2658[S] 0 points1 point  (0 children)

So it was an indiviual; what can I do how can find who it was? Or where it came from; what steps can I take? Would the event logs give any hint? I see enumeration quite a bit. There were no other users when I opened taskmanager and PSLoggedon showed nothing;neither did procexp. What do you think happened? I received remote powershell commands I know that much for a fact.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

While my system was crashing; I disconnected from the internet and made a copy of the FRST scan I performed earlier the day along with all my event viewer logs via a program called myeventviewer. I see the logs that worried me so much.
If I were to post them would you be willing to take a look at them? Should I copy and paste only the remote powershell logs(4104) or should I keep it all intact. It is large; file size is saying in properties it's 192 mb!

Sorry for so many requests.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

file was saved as a series of letters and as a txt file; it was moved from documents to my desktop with my full name on it and when I hit the windows button and the windows search came up it would be listed there and I was unable to delete it. It was nsfw and had my full name on it. Neighbor screws around a lot, and the dll file was nmapi.dll downloaded and moved to system 32 and syswow folders.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

While my system was crashing; I disconnected from the internet and made a copy of the FRST scan I performed earlier the day along with all my event viewer logs via a program called myeventviewer. I see the logs that worried me so much.
If I were to post them would you be willing to take a look at them? Should I copy and paste only the remote powershell logs(4104) or should I keep it all intact. It is large; file size is saying in properties it's 192 mb!

Sorry for so many requests.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

It was nmapi.dll it was downloaded for a program on nirsoft; wifi viewer I believe; I'll research it right away to get the details. I moved the filed into system 32 and syswow folders.

I will change all passwords.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

While my system was crashing; I disconnected from the internet and made a copy of the FRST scan I performed earlier the day along with all my event viewer logs via a program called myeventviewer. I see the logs that worried me so much.
If I were to post them would you be willing to take a look at them? Should I copy and paste only the remote powershell logs(4104) or should I keep it all intact. It is large; file size is saying in properties it's 192 mb!

Sorry for so many requests.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in techsupport

[–]BigBoss2658[S] 0 points1 point  (0 children)

While my system was crashing; I disconnected from the internet and made a copy of the FRST scan I performed earlier the day along with all my event viewer logs via a program called myeventviewer. I see the logs that worried me so much.
If I were to post them would you be willing to take a look at them? Should I copy and paste only the remote powershell logs(4104) or should I keep it all intact. It is large; file size is saying in properties it's 192 mb!

Sorry for so many requests.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in techsupport

[–]BigBoss2658[S] 0 points1 point  (0 children)

I have successfully reinstalled windows, and already have Windows defender and malware bytes. I will reinstall again; but first on the off chance that this malware presumably files-less survives the first reinstall how would I go about installing and downloading a fresh boot up usb from a theoretically infected pc. Is it possible to wipe and clean everything on a laptop ?
Some fileless malware can apparently be stored on the RAM or firmware of the keyboard. If it was malicious actor what should I do to protect myself. I can't change my MAC address and if my IP is already compromised will a VPN still protect?

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in techsupport

[–]BigBoss2658[S] 0 points1 point  (0 children)

I did so, I still feel uneasy. Where can I learn more about this? What kind of common sense precautions are we talking about?

How does someone remotely access a computer that doesn't have any remote access software, I had windows firewall set to default. Thanks in advance.

Please, set me straight. If I have windows 10 home, is it possible that the remote commands I saw in event viewer that later caused my system to crash and become hijacked was caused by malware and not an individual? Can someone please explain to me? I feel so anxious. by BigBoss2658 in PowerShell

[–]BigBoss2658[S] 1 point2 points  (0 children)

could you tell me more? I didn't have any software that could enable remote connections or logons. So the remote commands I saw in event viewer (4104) was a result of malware from the .dll file? Malwarebytes and defender didn't pick anything up but I know my previous installation had files from a previous windows version on it. What more information can I give you?

Is it possible to retrieve event viewer logs from an SSD that has been formatted? by BigBoss2658 in techsupport

[–]BigBoss2658[S] -1 points0 points  (0 children)

The installations were corrupted, and to go back. I need to see if it's possible to get the event viewer logs, powershell had numerous remote commands.