Forum Home
Press F1
 
Thread ID: 139782 2015-06-28 01:37:00 Virus treatment Cicero (40) Press F1
Post ID Timestamp Content User
1403745 2015-06-28 01:37:00 Chum asked what to do re his computer insisting he was putting in the wrong password, which he knew was ok.
I thought it might be a virus, which has proved to be the case, Dragon crowd in CH CH are fixing.

My question is, how do you start to fix if you can't get into the computer.

Thanks lads and PC
Cicero (40)
1403746 2015-06-28 01:52:00 You do not need login access, just the ability to read the file system. Using a live media with tools on it can remove the infection and could allow normal login, or you could remove/change the password.

Alternatively, putting the hard drive as a slave to another system and access it that way.

Cheers,

KK
Kame (312)
1403747 2015-06-28 02:50:00 Easy as to get into the computer, even if you don't know the password, As Kame posted, boot from a CD with the right software and either change to something else or completely remove the password. If you don't have the right Software, you can do it from a Windows DVD by using the command prompt and various ways from there.

Get that sort of thing all the time on customers computers here, and before bringing back I ask " when you first start the computer is there a password" Often reply is "no" Get it back here and guess what --- Password protected. Some get quite a shock when you tell them I simply removed it / bypassed it in less than a minute and carried on. :nerd:

Cant remember who it was now, but someone here posted along the lines of no computer is safe to gaining entry ( even servers) if you have physical access to it - and the knowledge. ;)
wainuitech (129)
1403748 2015-06-28 03:52:00 Not clear about CD, Would original DVD do the trick,or do you make one in anticipation.? Cicero (40)
1403749 2015-06-28 05:16:00 Not clear about CD, Would original DVD do the trick,or do you make one in anticipation.? You can do it from a Windows DVD, but not directly.

What I mean by that is theres no Magic hidden option to bypass a password.

What you have to do is open a command prompt Via the DVD, then theres several commands that can be typed in that will activate the hidden Administrator account. Some require changing / overwriting a couple of files ( exe's) then theres another step after that, OR you can alter the reg once you load the hive Via DVD. Once the admin account is active, you log in Via that, and since Admin has full access you can simply go into the user accounts and remove the password.

Trouble with the above is if the admin account has been pass worded as well you need to bypass /change/ Know that as well.

You could also try simply resetting the password Via Command prompt: Have a read of just some of teh options: here (www.technibble.com)

As it says: You can do a lot of damage to a system if you dont know what you are doing.

Much easier via dedicated software on a CD --- Boot from the CD, couple of clicks and done ;)
wainuitech (129)
1403750 2015-06-28 05:24:00 With Eset that shouldn't arise.
Mate was using old windows anti virus.

Will look into making CD.

Ta for info.
Cicero (40)
1403751 2015-06-28 06:26:00 While no antivirus is perfect, Nod should stop actions like that as long as its set up fully.

What it wont stop is if some scammer Via a phone call logs in remotely and alters settings.

Had that the other day with a person, they put a password on the computer Via remote, and then the following day called back saying if the person wanted the password it would cost them $250 to release the computer. By this time I had already removed it :) Apparently the ladies husband "spoke" to the scammers -- She was gobsmacked at the language when he told them what they could do :D
wainuitech (129)
1403752 2015-06-28 07:00:00 Charming, we are on our guard.:>) Cicero (40)
1403753 2015-06-28 23:05:00 With Eset that shouldn't arise.


Dont assume that at all, stuff can & does get past it .
But even then its more an issue caused by user stupidity , no AV is perfect. :)
1101 (13337)
1403754 2015-06-29 00:19:00 Dont assume that at all, stuff can & does get past it .
But even then its more an issue caused by user stupidity , no AV is perfect. :)

Righto.
Cicero (40)
1