Lotofproblems- corrupt files D/L'd, folder access - farbar .txt inc

PunkNdrublik

New member
Local time
7:38 AM
Messages
3
Ive been suspicious of an attacker for over a year and recently I have issues downloading programs as they show corrupt especially windows fixit exe's. Frustration honed in when I had issues playing Magic Online ver 4.0 I would constantly have to relog from random disconnects, then I couldnt even log in as it would disconnect me as I logged in. uninstalled, deleted any temp files or folders for Wizards of the Coast and redownloaded and would get these types of messages after install
-
http://mtgoclientdepot.onlinegaming.wizards.com/MTGO.application resulted in exception. Following failure messages were detected:
+ File, client_M14.xml, has a different computed hash than specified in manifest.
-
everytime I retry after any new fix I think I find, its a different file but same error.
Recently I ran the TDDS scan and it did find an Ovula which I quarantined and removed but still same issues. Not sure on next steps and exhausted searching for what my exact problem is and how to fix (usually pretty good at this stuff) I can tell there are a lot of issues from the farbar scan .txt files but unsure how to read it. Posting them here and hope you guys can help. Cheers!
 

Attachments

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 home premium 64 bit
When trying to access c:/windows/serviceprofiles/networkservice/appdata/local/microsoft/mediaplayer/artcache/localMLS
it said i didnt have priveleges, clicked OK to have administrator priv (im only user) and it starts to go in folder then stopped responding, started to again and has been trying to load files in folder for 10 minutes now still waiting.when finally finished only 4 jpg's inside avg size 50k?
Then I found this also in appdata/local in the temp folder
MPcmdrun text doc 2348Kb (attached) and mpsigstub text doc 206kb
also in folder is an application mpam-b8692784.exe 0kb

Lastly I looked in event viewer and saw a plethra of warnings and crashes but im not understanding how to fix or what exactly each one is telling me, can I post a copy somehow here as well?
 

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 home premium 64 bit
When trying to access c:/windows/serviceprofiles/networkservice/appdata/local/microsoft/mediaplayer/artcache/localMLS
it said i didnt have priveleges, clicked OK to have administrator priv (im only user) and it starts to go in folder then stopped responding, started to again and has been trying to load files in folder for 10 minutes now still waiting.when finally finished only 4 jpg's inside avg size 50k?
Then I found this also in appdata/local in the temp folder
MPcmdrun text doc 2348Kb (attached) and mpsigstub text doc 206kb
also in folder is an application mpam-b8692784.exe 0kb

There are NTuser logs in the network service folder and a notepad with only this :
regf* * ìLëOêøË ° f i l e s \ N e t w o r k S e r v i c e \ N T U S E R . D A T ¼ˆholލ Íã켈holލ Íãì ½ˆholލ Íãìrmtm _8I§DIRTÿ ÿ ÿÿ ÿÿ w o r k \ m o u n t \ U s e r s \ A d m i n i s t r a t o r \ N T U S E R . D A T r o f i l e \ n t u s e r . d a t
EDIT - ive attached a few more files ive found that cause me to believe the system has been attacked via remote connections of some sort, i discovered these searching for fix to WMI stopped working and cannot reactivate service, error messages related to MSI corruptions (cant remember exactly what but trying to replicate)

Lastly I looked in event viewer and saw a plethra of warnings and crashes but im not understanding how to fix or what exactly each one is telling me, can I post a copy somehow here as well?
 

Attachments

Last edited:

My Computer My Computer

At a glance

Windows 7 home premium 64 bit
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 home premium 64 bit
1.) Download herdprotect: (choose the portable version)

Download herdProtect - Free Anti-Malware Platform

2.) Run the scan.

3.) When the scan finishes, save the results per the screenshot below. Then upload the log here.

DO NOT REMOVE ANYTHING YET. I will advise if anything needs removed when I receive the log.

Attached Images
313957d1397626709-degrading-windows-performance-save-results.png
 

My Computer My Computer

At a glance

Windows 10 ProAMD Ryzen 5 2400G Processor with Radeon RX Ve...G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-P...2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Built
OS
Windows 10 Pro
CPU
AMD Ryzen 5 2400G Processor with Radeon RX Vega 11 Graphics
Motherboard
ASRock X470 Master SLI/AC AM4 AMD Promontory X470 SATA 6Gb/s
Memory
G.SKILL Ripjaws V Series 16GB (2 x 8GB) 288-Pin DDR4 SDRAM D
Graphics Card(s)
2047MB NVIDIA GeForce GTX 1060 6GB (EVGA)
Sound Card
Motherboard Built in
Monitor(s) Displays
Acer R240HY bidx 23.8-Inch IPS HDMI DVI VGA (1920 x 1080) Wi
Screen Resolution
1920 x 1080
Hard Drives
1TB Sandisk SSD PLUS (Main drive)
500 GB Seagate 7200 RPM (Games)
500 GB Western Digital 7200 RPM (Virtual Machines)
PSU
CORSAIR TX Series TX650M 650W 80+ Gold Modular Power Supply
Case
CORSAIR CARBIDE SPEC-02 Mid-Tower Gaming Case, Red LED Fan
Cooling
220mm, two 120mm, and four 60mm fans
Keyboard
Wired Dell keyboard
Mouse
Wireless Logitech mouse
Internet Speed
250mb down, 30mb up
Antivirus
Panda Cloud Antivirus
Browser
Chrome-ish x64
Other Info
Your awesome for reading this.
Back
Top