Author Topic: Windows password hijack  (Read 4407 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Windows password hijack
« on: April 24, 2015, 11:31:00 AM »
Hi guys
Got a laptop which I think has been hijacked - when the user enters their Windows password, the system says it is incorrect and shows a link to reset the password. If you click the link it asks you to insert a USB flash disk, so looks very suspicious.
The FRST log is attached.
Cheers.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #1 on: April 24, 2015, 01:34:22 PM »
Hello,


Download attached fixlist.txt and save it to your USB flashdrive as fixlist.txt

>>  Boot into Recovery Environment


Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
  •     Press the Fix button once and wait.
  •     FRST will process fixlist.txt
  •     When finished, it will produce a log fixlog.txt on your USB flashdrive.
>>  Exit out of Recovery Environment and post me the log please.



Try to boot Windows normally...
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Windows password hijack
« Reply #2 on: April 24, 2015, 01:55:04 PM »
Hi
Many thanks for your help. I can get into Windows now. Fixlog.txt is attached as requested.

REDACTED

  • Guest
Re: Windows password hijack
« Reply #3 on: April 24, 2015, 02:00:32 PM »
The machine is behaving strangely - Windows Explorer keeps restarting/refreshing, I can't connect to the Internet and when I tried going into the network settings it gave a BSOD and rebooted.
{EDIT} The BSOD STOP error is 0x000000F4.
« Last Edit: April 24, 2015, 02:07:44 PM by crapazilla »

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #4 on: April 24, 2015, 02:11:46 PM »
Yes, I noticed this. I want you to delete FRST and to download fresh one from the link below:

http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/

Run the scan and attach both reports.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Windows password hijack
« Reply #5 on: April 24, 2015, 02:23:14 PM »
Ok will do that now. In the meantime, I managed to boot into safe mode with networking and download MBAM and Avast is installing. Sorry - maybe I should not have done this...

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #6 on: April 24, 2015, 02:25:17 PM »
Probably shouldn't.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Windows password hijack
« Reply #7 on: April 24, 2015, 02:36:45 PM »
Here's the latest log

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #8 on: April 24, 2015, 03:19:59 PM »
I need reports from Normal Windows, not from recovery.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Windows password hijack
« Reply #9 on: April 24, 2015, 06:48:39 PM »
I could only run FRST64 in safe mode with networking. When I try to run it under normal Windows it blue screens.
Here are the log files.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #10 on: April 24, 2015, 06:52:03 PM »
It seems that hard drive is dying. This probably explains why you have these issues.

Error: (04/24/2015 04:19:52 PM) (Source: atapi) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Ide\IdePort0.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Windows password hijack
« Reply #11 on: April 24, 2015, 06:55:45 PM »
Ok at least I know what's causing the problem.
Thanks so much for your help - I really appreciate it.

REDACTED

  • Guest
Re: Windows password hijack
« Reply #12 on: April 24, 2015, 09:11:53 PM »
Well I popped open the cover on the hard drive (it's in a Samsung laptop) and saw that someone had been tampering with it - there were no screws securing the cover and the hard drive was only partially connected to the SATA connector! Once I seated it properly the machine is behaving way better. MBAM found 94 threats which it has fixed. I have attached the latest FRST log if you wouldn't mind checking them to see if everything's ok now?

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Windows password hijack
« Reply #13 on: April 24, 2015, 10:59:49 PM »
You have Norton and Avast running simultaneously that is not good, you must uninstall one. Beside this, logs look fine.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE