Victim of complex, clever APT going on 13 months, cannot secure any device or domain or email, or phone or anything, including new purchases, instantly compromised. Thinking of suicide now...

Hello. I am the unfortunate victim of a very clever APT that has led to me having to close down my charity law firm for the poor, and as no one would help me, I then spent all my equity and savings and even debt and borrowed so much it is impossible to recover, in my alone effort to learn about networks and use toolbox Kali and Tails and lots of microsoft and any secureity tools I could find, and always with compromised devices, instantly, and so it has been a horrible education where I fight and discover with broken tools, and I have discovered and learned a lot these 13 months, but also have gone from wealthy to closing 3 of my 4 businesses, including all charity projects, and the last of my businesses is dying, and I cannot produce economically in this compromised state, and am victim of much financial fraud and it is too much to even try to catch up and audit and notice, and I have been hospitalized multiple times this year and probably because I have been sleeping only every other day and in constant stress over this and the fact I cannot get even one device to be exclusively mine and secure and I have root control. None. Even if I go and buy one. And I did that many times, many ways, every tactic I could think of, and exhausted my cleverness, and my ideas, and have copies and lots of digital evidence, and even probably most of the malicious code---none was easy to obtain or find, but I have, and I have I am sure plenty of logs, code, and so on, that someone who knew these technologies and jargon professionally could definitely understand how this horrible awful, shockingly persistent and perfectly targetted at me hackerware hell works and maybe could create a countermeasure. I cannot. And I feel pain in my chest and heart, and I am only 31 and was before this a champion swimmer and a charity lawyer and now I am in ruins, and have nothiing, and I am just as imprisoned and cyber raped by day and night, and alienated socially as friends and relatives do not believe such malicious malware or cyber attack possible, but I have proven 95% of my claimed observed syptoms, which replicate always the same, and in same ways, and if anyone actually used this, or experienced it, they would know how terrible it is. And I lost everyone, and everything, and I have never worked harder, nor longer, nor had to be more clever, nor toiledmore, nor been more desperate any year of my life, and I gained lots of knowledge, lots of hackerware code and evidence and specific evidence, and mor, and logs and logs, and discovered emebedded strings and malicious code in unlikely files, like pictures, and scripts and desktop.ini is a negative value and it seems to be in every folder, and near any folder will not let me in unless I get clever about taking ownership, and /or using a live distro like tails can give me a more honest glimpse of the file system but even it and my linux laptop is deviant, and permissions changed, devices that were private now take policy, every time i install windows or buy a windows laptop I see in the GUI that the IIS is not enabled buut in fact 100% of the time it is, along with some folder wwwroot, and the whole experience of the OS feels so limited and I said once it was as though I live in a docker container, or else it is a snapshot that is virtualized and replicates, and later found evidence of both happening. Also, you don't need wireshark and ettercap to note the mutating urls as php and sql from god knows where always injects, but I tested and confirmed. And so I will list the primary areas that are always compromised and you then may understand how and why it has been impossible for me--and attorney who had no prior technical kowledge, but could write the blue and red field manuals from memeory now and can BASH with anybody, and knows every tool in Kali and a bit of some others, and a lot now about configurations and deployments and enterprises and the panther files especially the setup act log is very much clearly in plain language obvious it deploys in this same wretched specific very customized way, including modifying or creating some 30,000 entries in the registry, every single cert ca store is wrong and with asinine certificates and the only revocation list says from 1994 and in fact does not revoke anything, it adds more trusts, and some sloppiness the certificates if able to be seen, occasionally will have an active link on the "statement" of publisher and will have a verisign root that has a statment from an entirely separate company or a known alleged CA publisher will have a misspelling of name, or whatevr, but what is key is that a lot of services that nobody would want in this combination, except a malicious remote controlling unknown hostile truly mean person, and each service has its own store set, and all are insane and irrevocable crazy certificates, a 3rd level, minor certificate upon close inspection will have actually more power than god, and can do anything anywhere, cotntrol encryption, encrypt dom0, control tpm, anything. And so the devices are taking olicy and orders and so on, and even in sysprep which I cannot even make it do, but I can get it into audit mode (but by then sysprep has run eenough times the damage is there, present, and irreparable) and I cannot be secure online either as I am, I discovered, not just subject to constant injection and bad roots of trust on all devices, and provisioning and more and worse, but I am also under attack by any web applications and/or APIs and I admit I am not even expert enough to say th difeerence, but I can tell you from testing, and observation, and lots of pain and hell and torment and struggle, that many many APIs are NOT kind to me, including the OAuth2 which does identify me, and of course, it is used, and abused, and so are many many other APIs and I am not a programmer nor a developer, it is a lucky thing I can use BASH and pre-made modules in Kali or else I would not have found most of what I have found. But here I am, now more than a year later, lost most anybody in my life that I valued, and lost essentially 4 startups, including 2 charities, I made and were succeessful and I was proud, but now 3 are dead and 1 on life support and likely to be bankrupt and close also, and myself I went from having a good life style and comfortable income from my many enterprising efforts to the depths of poverty with so much debt and in fcat creditors and alleged debts in numbers you cannot imagine which I havenever used, nor heard of, and between all APIs and online threats, and the law email I had was stolen and google never gave it back, and it to this day is now a "service account" and I am always told by google who does not care a bit that sensitive information is in there, including about children, as I was helping families dealing with divorce, and myself recently abandoned then and divorced, anyways so that information which needed protection, and I had protected it, but then, one day, all my financial accounts, my publishing accounts, my domains, my emails, everything, taken. And I got some back. But not that one. And I even begged and threated lawsuit (that I have no time or means or ability to even file as I am now so destitute) beggeding and demanding they either give it back or else destroy it, because children are vulnerable and google does not respond and does not care, and any person if I ever can get anyone to talk to me, just says to use the go/recover or whatever it is, but I have copies of injection and code from "temp files" that, are anything but, coookies,  and APIs and whatnot httponly get json token and I do not know the client secret not have any ability to take or asert control, and so some companies gave me my accounts back over months of process, but some have not. And I hate that after I have essentially done everything possible I could think of and spent and sacrificed so much, and aged probably 30 years, and in fact... if it went away today... I don't even know if I have the health or energy, and certainly no longer the financial ability, to even recover. And... I had been so hopeful and tries so very hard. Just want to be free. Even on one damned device. From that maybe I could fight back and take back. But no, always deprived of me. or any affor that seems to be working ends up undone by replication or by being this separate, parralel memory state or something, like fake, and I am at the end of my rope. And I can feel it in my body that I am not in good health, and I have nothing, and everyone I valued in my life is gone, and my clients I was helping pro bono all of them suffered when I was forced to withdraw the cases, and I think one or two may even have died. And ... I ... I think, if a year ago, I knew I would still be here a year later, except having given and spent and tried everything and been broken and unsuccessful and lost so much.... I ... would rather have died. By any means. Drawn and quartered, anything would be better than this year...

I am not here seeking pity. I am wondering every day why not put a .45 hollowpoint in my brain stem, (which I am sure would be the best way, if that was how I was going to go) or otherwise just hook up some callibration hydrogen and a rebreather mask, or a damn shopping bag and just , inhale pure nitrogen and pass out and peace finally. Peace. My god. ... But I won't. I hope. ANd I think I was at that feeling as long ago as February and... I tried getting help from the state authorities and one had trouble talking to me as at that time I was having a MitM issue with both the browser and the device which I thought was my router and had my router's name, but turned out to be a hiden hotspot stuffed in the case of one of my desktops and was branded T-Mobile...

I have changed geography, devices, ISP, VPNs, and more, and tried everything. I promise you I was never free for even one second. Always contained. Always imprisoned. And unable to just even work in peace and try and rebuild a new business or save one of mine, but no... too much to ask. And now I am alone. Literally. And have nothing.
Jackie ManIT ManagerCommented:
Do you have a backup of your data?
yo_beeDirector of Information TechnologyCommented:
Love the one liner suggestion after that lengthy very detailed outline novel of a question.  

What I would recommend is systematically work form the ground up.

A few questions:
1: Do you have a central file storage (NAS or SAN)?
2: Are all your machines Windows OS.
3: How are you see that your system is compromised. Something as clever as you outlined seems like it would want to remain hidden.  
4: What is the code purpose?
5: Is this a domain (Active Directory) infrastructure?
6: Have you tried WIRESHARK?

If you have a NAS I would start with all systems off accept your NAS then boot a single clean fresh machine and see if you see this machine stays stable or is it compromised immediately  as you have already experienced. If the system stay clean you can start to assume that the threat is not located on the NAS.  From there I would start up one server at a time and monitor the effects.

From my point of view you will need to rebuild everything from the ground up.
btanExec ConsultantCommented:
Rebuild and move on. Since you mentioned APT and the elaborate attack suffered, you would have also alerted the authority. Backup and recovery is essential especially in the case of ransomware attack if you are hit by it. I would eventually suggest you go into a managed security provider with your hosted data managed by external provider,  it will quickly get you up running and not be worried on the control implementation. There is still a nominal fees if you can still handle it.

But it would seems the "when" happened and it is rather difficult for you and team to become the incident responsers effectively. Let others manage for you then. It is alright to be hit but it is how you can recover quickly. Think through again. And not give up. We learn from lesson and I believe your experience will be a valuable one to the community and your future. If it does not work out to rebuild and recover, get a job with a security centric cloud provider and venture into it to learn the ropes and eventually be a user of it...and come back to contribute to the masses again.
Acronis True Image 2019 just released!

Create a reliable backup. Make sure you always have dependable copies of your data so you can restore your entire system or individual files.

Richard SandersAuthor Commented:
I will now answer your questions directly, and I have log files and weird ass files available upon request if you want, I have capture4d much of the malicious code and even broke some of the databases myself with math (only ones relying on font changes and they can be broken with basic 14th century frequency analytics--I am kind of a huge probability/stats/econometrics guy. And I purposefully had had my law firm harddrive using NOT the ellipses standard of encryptioon but the factors of huuuuge primes, and my cypheralgor8ithm could not be derived without seeming to be random and the cypher itself was like 40 random characters only I knew--and I recently found a keylogger so now I am thinking... oh.... so much for a mathematics front door that is a gate of 10,000 meters of tungsten....
Richard SandersAuthor Commented:
REBUILD AND MOVE ON IS NOT POSSIBLE, I WILL EXPLAIN WHAT I KNOW FARTHER DOWN BUT THIS IS A HUGE PROBLEM TO ME AS I HAVE REBUILT THREE TIMES< FROM SCRATCH< AND NEVER ESCAPED. (A total of 14 laptops and 6 desktops) and more routers and such than you can imagine, and 10 phones at least. and tried using T-Mobile, Verizon, Google-Fi, and currently on Sprint and not safer, but cheaper
Richard SandersAuthor Commented:
STATE AUTHORITY AND I EXCHANGED EMAILS (with great difficulty thanks to MitM but I did not know that was cause then) and be was useless, would not meet me, would not visit, would not allow me to visit, would not allow my sending him anything by US Mail (much more secure than poisoned DNS with many redirects...) and he expected me to demonstarte all of this, prior to my technical knowledge with 3 screenshots, aka how many bitmapsfit in an attachment. So.... they suck. Now thinking maybe FBI but fear will not be taken seriously
Richard SandersAuthor Commented:
I want to also thank you all for joining the topic and hearing me and voicing ideas... I have felt so horribly lonely these 13 months and have lost friends, and become extremely isolated and alienated and that has made my life a living hell. So thank you all, even if we do not solve it, I am hugely grateful your even looking at it and voicing thoughts. I really do appreciate it. And thank you.


Q: What I would recommend is systematically work form the ground up.
A: I would love to, and have tried, and am actually quite expert at all of Kali, some subraph, tails--easy, and have tried to get a good install of black arch but it fails. Anyway even my Kali, does not have correct finger prints but after 100s of tries at least it will run some of the tools... but I have only broken tools, and there is this certificate propogation that poisons any device, even a clean from microsoft usb installer, and I have interruped at early as possible (audit mode as built in admin just prior OOBE but sysprep has run a bunch, and can confirm the registry changes 30k of them happen in sysprep, as recorded by setupact log, and the cert root certificates are just some combo of damned hilarious (3rd level untrusted [but the system is trusting it and you cannot revoke it] that can do literally "anything" including change power state so the machine will not poswt, or encrypt dom0 with like a fork of vericrypt, control TPM, etc.

So I have thooroughly exhausted the idea of new hardware and software and have discovered that locally I am attacked and reduced in permission and online the same, but via middleware and API abuse and some 53 webapps that I cannot even identify yet

A few questions:
1: Do you have a central file storage (NAS or SAN)?
A: No. I( had the install media on dvds and on usb drives, but they have become corrupted, including the DVDs which I had believed to be finalized DVD-Rs but they have new files on them which is weird, and I cannot explain. But my business and my home were just my own private devices. Not they are provisioned and taking policy and have confirmed that but will resist any notion they are "domain joined" but all run the local server, and all users are treated as remote users, unchangeably, including built in admin object. I get the sense of a "shasred PC" and "shared permissions" with some mal actor who has greaterpermissions than I do but I cannot find.

Some hypothesis now confirmed and captured their files:
1. ADAM folder and install qand silent uninstall of policy (yes, captured folder in audit mode and captured events in event scheduler)
2. Possibility of use of "puppetware" especially ansible and gradle? (Yes, have found both, hidden, quite well, but have confirmed both occur.) and have copies.
3. Disguised SQL embedded and injection and PHP threats? (Confirmed) in windows AND wireshark.
4. I have used various live distros of linux for investigative purpioses e.g. Tails was great for seeing the files that were under the files I could not access in Windows, whether I attempted to modify security permissions or not, and copy things. Kali has been pretty awesome but really only a few of its tools have felt relevant or at least to me. Maybe if I were better. I honestly have been messing with trying to change the bootloader from some "PXE" environment of "//?/bunch of crazy90-4893j949n843934890n to something sensible, or change the environment variables so I feel less contained or paravirtualized, and I have some indication one or both is happening.

**Strangest finding but unconfirmed: Sophos Trial of its pro software, while I had access, believed the Windows 10 Pro to be actually Windows RT. Not been able to experiment further.

Note: have found many .elf files and .lock files; but the file "desktop.ini" is littered everywhere. Oh and if I attack the registry and mess with its security in order to do so, it heals instantly, and I think it puts me in a side-by-side memory state, as if I did not matter.
2. All Windows OS?
A: Yes and no, mainly yes but I had the coreboot libre purism 13 and it showed compromise very rapidly despite the kill switches being in kill position, and I have no clue how (no USB evil maid even had a chance to run or be in it) and I can only describe its "compromise" as 67% certain, and seems to require the remote access (common element, this cannot be revoked on any) and its apparent vulnerability was IRC chat of all things. I cannot explain further.
3: How are you see that your system is compromised. Something as clever as you outlined seems like it would want to remain hidden.
A: of yeh, a majority of all files, and folders, are added the permission "Everyone: Deny" and so removing that will often allow access, but the severe ones I have been able to see using OS linux or changing the owner in permissions to say built in admin and then enabling him and logging in as him-->there is a ton of group policy customization that has occcured but the computer insists it does not follow group policy or directory, but it definitely 100% does. Just will not let me near it; and in Power Shell which was used to rapidly execute much of this, I find everything to be aliased and lots of things have the name (bigendian-littleendian-littleendian-bigendiean) but as number sequences, so... I hope maybe that means something?

I also was able to get a thorough look at the system, any of them from from initial cold boot ctrl+shift+f3
Q: code purpose?
A: Unknown. Middleware, & API control, and hostile drivers and more.
5: A: it behaves as one but the "adam folder" rapidly silently uninstalls in OOBE while cortana is doing her garbage.
6: Love wireshark. Ettercap my other lover.  

I havfe private ownership of what were intended not policy or runtime or managed devices, ergo I have no network ppl or other network infrastructure. I tried to build a custom network of my own design but was poisoned by permissions/bad-certs. Was to be Untangled->FreeBsd(nginx reverse proxy on top; any iptable if possible carefully configured)-->fortinet expired box running pfsense, configured->various APs each 1 zone, 1-3

BUT sadly I have not been able to build it due to permissions violations.... ALSO have been seeing "cloudos" and "cloud deploy" recently in reference to this replicating state.
Richard SandersAuthor Commented:
want me to select a couple of logs or other oddities for upload and maybe that will be helpful? Or at least interesting?
Richard SandersAuthor Commented:
most AM/AV solutions are useless bc the evil agent (unknown) will get beneath the kernal, misconfigure it, which is allowed, make it horrible, then they either lack permissions, take instruction not to scan certain i/o and mapped ram, etc, and or otherwise see the kernal hand a wrong instruction to a software piece, via a legitimate method..... I need awesome hueristics and so far the best have been 1. Win/Sysinternals tools, but not any good at repair, 2. Sophos,but maybe false positive with the whole WinRT detection, and Webroot business (the priciest one) it correctly flags many things but cannot do anything for lack of permission, even when run as admin
Richard SandersAuthor Commented:
Random one from a difficult to find, hidden, and permission blocked xml that I was able to eventually read but not delete or modify of course....

I figure it is important but that is beyond me and I have so sos o much of stuff that... taking requests.....

<?xml version="1.0" encoding="utf-8"?>
    Categories from the enum:

      <category name="Reboot" />
      <error code="0" messageID="Reboot successfully scheduled." />
      <category name="Content" />
      <category name="Certificates" />
      <category name="DeviceManagement" />

    <category name="Scripts" />

    <category name="DeviceManagement" />

        <category name="DeviceName" />
        <error code="0" messageID="Device name set successfully." />
    <category name="Security" />

    <category name="Certificates" />

    <category name="InitialCustomization" />

    <category name="Applications" />

    <category name="UxLockdown" />

    <category name="Applications" />

    <category name="Policies" />
    <error code="0" messageID="Policies applied successfully." />
    <error code="86000011" messageID="Policy is not allowed." />

    <category name="UpgradeWindowsEdition" />
    <error code="0" messageID="Windows successfully upgraded." />

      <category name="Certificates"/>

    <category name="Connectivity" />
    <category name="Connectivity" />
    <category name="Connectivity" />

      <category name="InitialCustomization" />
    <category name="InitialCustomization" />

    <category name="InitialCustomization" /> <!-- applies to all MCSF -->
      <error code="0" messageID="OOBE successfully configured." />
      <category name="Policies"/>
      <category name="PowerSettings"/>

      <category name="Connectivity"/>

    <category name="Policies"/>

    <category name="Content" />

      <category name="InitialCustomization"/>
      <category name="InitialCustomization"/>

        <category name="InitialCustomization"/>

    <category name="UxLockdown" />

    <category name="UxLockdown" />

    <category name="InitialCustomization" />

    <category name="UxLockdown" />
    <category name="UxLockdown" />
    <category name="InitialCustomization" />

    <category name="DeviceManagement" />

      <category name="DeviceManagement" />

      <category name="Content" />

    <category name="Connectivity"/>

    <category name="Connectivity"/>

    <category name="InitialCustomization"/>

    <category name="InitialCustomization"/>

    <category name="Connectivity"/>

    <category name="Connectivity" />

    <category name="CleanPC" />

Richard SandersAuthor Commented:
and any effort to boot live into Parted Magic, gets hijacked.... and also the boot and nuke not so effective since ssd.... and windows diskpart and utilities not formatting it
Richard SandersAuthor Commented:
this one is from something called phone.inf and I admit not to understand it but I can guess at what it might be....

ALSO guest is forced by policy, and cannot change, certutil will not run, and guest hypervisor v control is not able to be removed among other changes

Richard SandersAuthor Commented:
THIS also seems maybe important?

12/19/2017 12:47:08 PM Info ICD Started
12/19/2017 12:47:21 PM Warning Image customization functionality is disabled because imaging tools are not installed.
12/19/2017 12:47:21 PM Warning Exception on reading AutoLaunchConfigScenarioId. The key 'AutoLaunchConfigScenarioId' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowTitle. The key 'ICDWindowTitle' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowHeight. The key 'ICDWindowHeight' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowWidth. The key 'ICDWindowWidth' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowMinHeight. The key 'ICDWindowMinHeight' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowMinWidth. The key 'ICDWindowMinWidth' does not exist in the appSettings configuration section.
12/19/2017 12:47:21 PM Warning Exception on reading ICDWindowState. The key 'ICDWindowState' does not exist in the appSettings configuration section.
12/19/2017 12:48:31 PM Info Loaded Knobs schema hive at C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:48:31 PM Error WpxGetFileEdition (onecore\base\ntsetup\wpx\core\store.cpp:103) - 0x80070002:
12/19/2017 12:48:31 PM Error     No SKU information file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.sku.xml available for store file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:48:31 PM Info Loaded settings from Windows Unknown Unknown
12/19/2017 12:48:31 PM Info Loaded Knobs schema hive at C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.dat
12/19/2017 12:48:31 PM Error WpxGetFileEdition (onecore\base\ntsetup\wpx\core\store.cpp:103) - 0x80070002:
12/19/2017 12:48:31 PM Error     No SKU information file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.sku.xml available for store file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.dat
12/19/2017 12:48:31 PM Info Loaded settings from Windows Unknown Unknown
12/19/2017 12:54:33 PM Info Project 'C:\projects\Project_1.icdproj.xml' loaded successfully
12/19/2017 12:54:33 PM Info Loaded Knobs schema hive at C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:54:33 PM Error WpxGetFileEdition (onecore\base\ntsetup\wpx\core\store.cpp:103) - 0x80070002:
12/19/2017 12:54:33 PM Error     No SKU information file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.sku.xml available for store file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:54:33 PM Info Loaded settings from Windows Unknown Unknown
12/19/2017 12:54:33 PM Info Loaded Knobs schema hive at C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.dat
12/19/2017 12:54:33 PM Error WpxGetFileEdition (onecore\base\ntsetup\wpx\core\store.cpp:103) - 0x80070002:
12/19/2017 12:54:33 PM Error     No SKU information file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.sku.xml available for store file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Desktop-Provisioning.dat
12/19/2017 12:54:33 PM Info Loaded settings from Windows Unknown Unknown
12/19/2017 12:55:53 PM Info Loaded Knobs schema hive at C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:55:53 PM Error WpxGetFileEdition (onecore\base\ntsetup\wpx\core\store.cpp:103) - 0x80070002:
12/19/2017 12:55:53 PM Error     No SKU information file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.sku.xml available for store file C:\Program Files\WindowsApps\Microsoft.WindowsConfigurationDesigner_1000.15063.1.0_x86__8wekyb3d8bbwe\Microsoft-Common-Provisioning.dat
12/19/2017 12:55:53 PM Info Loaded settings from Windows Unknown Unknown

Richard SandersAuthor Commented:
I could go for miles but common themes seem to be that it always deploys into the weak and stupid netbios namespace and that cannot change, it will use turredo and ipv6 no matter what, and it will not allow you to see all the users and orgs and security items, and the users are treated as computers, and the certs as they are, horrid, basically allow for no real actial power could oppose them.....

Here is a zip of the panther (I have seen it a bit different a few times but I am guessing this is informative to somebody, hopefully)
David Johnson, CD, MVPOwnerCommented:
this one is from something called phone.inf and I admit not to understand it but I can guess at what it might be....
.inf files are information files for the setting up of drivers and it exists on all windows platforms since windows 3.0
btanExec ConsultantCommented:
Adding on to what David shared, these set of numbers are Microsoft Activation Centers worldwide telephone numbers. They are toll and toll-free telephone numbers for Volume Licensing Activation. Not something unusual and normally comes with installation of the OS.
Richard SandersAuthor Commented:
I appreciate the responses and have begun trying the ideas. I want to share a new find today as it makes no sense, adding on top of the whole torturous yet bizarre experience, am I reading this wrong or is this referring to Windows RT (which I believe was Windows 8 embedded?) Does this help shine any light? Thank you everyone for the help, I am truly desperate and I have so many many many files and logs and code and data, but no expertise and was feeling of no hope. I appreciate you all wanting to help me. It is giving me some hope again. Thank you. I will reply again once I have tested all the above suggestions. Thank you and Merry Christmas.
Richard SandersAuthor Commented:
Also am still puzzling over a well-hidden but discovered folder called "Systemd" and inside it is a modified .wim file named windowsdefender or something. And it is in a folder called container(s)? I can grab a screen shot if you like. But is that not a linux or unix thing?
Richard SandersAuthor Commented:
I have noticed a pattern where gaining access to the persisting hidden storage that is "temporary" is extraordinarily difficult but I managed to grab some just now and want to know if any of you programmers can make heads or tails of it, as these seem to recur (I tested and found it on the other laptop also) thanks again for any advice and help. I appreciate it more than you could possibly know. Thank you.
Richard SandersAuthor Commented:
I am persuaded as to the harmlessness of the phone.inf and in fact only uploaded it as I noticed it was and am much more concerned about the setupactlog if anyone knows their deployments and could maybe give that a look at, I'd appreciate it as it seems alarming to me in quite a few places.
Richard SandersAuthor Commented:
Last one for now, sorry, I just found a bunch of the files I had earlier referenced and would love to know what someone with the education to understand them can maybe shine some light for me if I am being concerned for good reason or not. Thanks. There were also two .sqm but would not upload, possible they are the source of the injections/redirects? Okay well it is not allowing an upload, too many file types not allowed; but these range from what look like object c ++ to .sqm and many that are just of type "file" and no extension. And others too, some databases, some xml, some htm and html, and a bunch of STH and of particular interest to me are these files again just "file" but named "script..." something or other, existing in folders named "remote".
David Johnson, CD, MVPOwnerCommented:
Do you have windows messenger installed?  .sqm files are commonly associated with Windows Messaging
btanExec ConsultantCommented:
I am not sure how much can be helped. Just sharing what I can best appreciate below.

For the logs, there is nothing unusual as they are usage log and likely same for WindowsRT
With Windows 8 (.NET 4.5), a new NGen mode: "Auto NGen" has been introduced. Basically, the .NET runtime generates usage logs for managed applications. When the system is idle, an automatic maintenance task runs in the background and generates native images. This way developers no longer have to deal with NGen explicitly. Note that this feature is only enabled for .NET 4.5+ applications that target Window Store or use the GAC...... Every time the application run it creates a new type of logs called “Assembly Usage Logs” in the AppData windows directory..NET runtime lifecycle with NGen managed applications

Also Windows kernel can support Linux running through use of Windows Subsystem for Linux (WSL). It is a collection of components that enables native Linux ELF64 binaries to run on Windows. It contains both user mode and kernel mode components. Assuming if this WSL exist, then you should also find kernel mode drivers (lxss.sys and lxcore.sys) in your machine. They are responsible for handling Linux system call requests in coordination with the Windows NT kernel. As for the folder of the Systemd found in the .wim, it may be some installation leftover - not certain what created those though.

For the INetCookie/container.dat, that replaces index.dat  with IE10 and Windows7. There is also past naming of it as "WebCacheV24.dat". It is large size as it stores all cache/history information. May want to try  BrowsingHistoryView
The browsing history table includes the following information: Visited URL, Title, Visit Time, Visit Count, Web browser and User Profile. BrowsingHistoryView allows you to watch the browsing history of all user profiles in a running system, as well as to get the browsing history from external hard drive.

Nothing much on the phone.inf but you can see the activation center matches and I would have thought you are referring to %WINDIR%\Inf\Setupapi*.log which used to log Plug and Play device installations. The flagged "setupactlog", I supposed it is "setupact.log". This contains debugging messages from the Kernel-Mode Driver Framework coinstaller, which is a Microsoft Win32 DLL that assists in device installation. yet another big file that is used for troubleshooting Windows installation When a failure occurs in Windows Setup, review the entires in the Setuperr.log file, then the Setupact.log file, and then other log files as appropriate

