Caller connected to Win XP computer and modified it so password is changed, makint it unbootable

Posted on 2013-12-03
Last Modified: 2013-12-24
A caller connected to the Compaq Presario over the internet.  While talking with the owner on the telephone, the owner was told she had to pay $179 to extend the OS license for 2 years.
The owner refused to pay.  The caller said she would have to reboot the machine to disconnect him.  When she rebooted, the machine password would no longer work.

I used a password reset program in Spotmau suite.  It said the password for all users had been set to "blank."  When I tried to reboot, I got a dialogue box asking for the password.  I tabbed to the "ok" button and clicked in.  The blank password did not work.   I tried another password reset program from Hiren's CD.  It reported success at making the administrator password "blank."   The result was the same.  Each time I reboot, the machine asks for a password and I have none other than the "blank".  

My question is who knows how to correct the problem.  And, also who knows if the problem can be solved by using the Compaq on board "PC Recovery" programs to Reinstall the Windows XP.  It is XP Sp2.  I loaded Sp3, but found out the the AMD Sempron CPU chip cannot run XP Sp3.  Had to do a PC Recovery, load the sp2 back, and all the software.  Would like to avoid that much difficulty if something less taxing will work.

Question by:JLBlake
  • 5
  • 2
LVL 14

Expert Comment

ID: 39694321
I have always used NT offline password recovery:

Not sure if this is the one you used from Hiren's cd.  If so, did you choose the option to unlock and clear the built-in administrator account?  I'm assuming you are logging into a local account, the local administrator and it says (This Computer) at the login screen.

Author Comment

ID: 39694475
I was careful to choose default options in the password reset.  I am somewhat of the opinion that the password was changed and in fact its location was also changed so that traditional reset programs  do their work in one place and the modified password is located somewhere else.  I feel sure that the two different applications I used to reset the password did in fact carry out their intended functions, however the intended function did not correct the need expressed by a small dialogue box asking for the password input.

Expert Comment

ID: 39694782
change the password, then safe mode right away. The machine will have a RAT most likely calling home to the scammer, disconnect it from the internet and scan with malwarebytes, avast, trendmicro etc
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.


Author Comment

ID: 39699255
Maybe I have not made the problem clear enough.  Safe or regular mode is not available because the machine request entry of the password before you get to any operational situation so that any application can be run.  Malwarebytes, Spybot, and others are unavailable because whatever was done to the machine, requires the successful entry of a password before the system displays anything on the start desktop.  In safe and regular mode, the stopping point is before one gets to any options that relate to normal operations options.
LVL 14

Expert Comment

ID: 39699293
Is this a BIOS password then?  The prompt for password comes up before you see the regular windows login.  If that seems to be the case you can open the machine up and take out the CMOS battery and wait 5 minutes and that should clear the password.

Search "BIOS password reset your computer model" on google for more info on the specific procedure for that computer.

Author Comment

ID: 39706673
It is not a bios password issue.  The request for a password comes up after the first appearance of the Windows logo that shows during the early boot period.  It is almost as if it runs half the boot process for Windows after which it stops to ask for a password.  Despite the blanking of the password in the windows accounts, it still stops before getting to any login point at which it may ask for a password.

I am near the point running the pc recovery product that is loaded on the small partition on the disk that has the boot partition.   I am hopeful that the pc recovery will work, even though it means

Accepted Solution

JLBlake earned 0 total points
ID: 39723043
I was able to correct the problem by running the built-in pc restore.  It took a long time, meaning I had to reload all the software which had been written over  by the reloading of the os.  Reloading the os, wiped out the demand for a password or sign in.

Author Closing Comment

ID: 39737666
Nothing else reported to me seemed to offer a serious attempt to solve the problem.  I finished to reset and the machine is working well.  I do not want a bunch of emails from EE saying I have ignored the question.

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Log files are useful in diagnosing and repairing problems.  This is a list of common log files and their standard locations that I've compiled.   While this is not exhaustive, it is a pretty good list that I've found to be useful.  I may update it f…
This article describes how to set permissions to allow a limited-permissions user to start and stop a particular System Service.   It is always best to give users only the permissions that they need to perform their job, so tweaking particular permi…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question