Solved

Windows 8 hacked.

Posted on 2014-01-25
13
296 Views
Last Modified: 2014-01-25
PC laptop with Windows 8 hacked by a foreign "faux help service" left the machine locked.  Will only start to safe mode, has no system restore settings available, will not go online.

Any solutions to fix problems or best just do a factory restore?
0
Comment
Question by:DwEckert
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
  • +2
13 Comments
 
LVL 95

Expert Comment

by:John Hurst
ID: 39809400
If you can get to Metro and then PC Settings, you can "Refresh your PC" . This will keep your documents but will remove Applications that did not come with Windows 8. This should work, but you will have to reinstall some things.

.... Thinkpads_User
0
 
LVL 35

Assisted Solution

by:Dan Craciun
Dan Craciun earned 167 total points
ID: 39809401
You can probably fix it, but can't trust it anymore.

Factory reset, then restore data from backups.

HTH,
Dan
0
 
LVL 23

Expert Comment

by:Mysidia
ID: 39809405
When you say "locked";  you mean the computer won't boot -- they have reconfigured the machine to deny access, or they are presenting some custom software that refuses entry?

My suggestion would be to copy any important documents or other materials off the machine and do the factory restore.

It may be possible to defeat the lockout, if you can run tools to analyze the startup settings.
However,  it will always be doubtful whether the machine is clean  and can be trusted anymore, or  whether a configuration with covert persisting  custom malware  has been setup.
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 
LVL 95

Assisted Solution

by:John Hurst
John Hurst earned 333 total points
ID: 39809414
@DwEckert - To clarify the above, Windows 8 Refresh is new with Windows 8 and does a form of reinstall that keeps data. I have done one, and the results were very reliable.

.... Thinkpads_User
0
 
LVL 24

Expert Comment

by:aadih
ID: 39809429
Please save your data and files from the safe mode, Just in case. Then, as Thinkpads_User advises: perform a Windows 8 refresh install.
0
 

Author Comment

by:DwEckert
ID: 39809431
thinkpads_user.

Can get to the Metro screen.  The click on Desktop goes to safe mode.  Tried Metro to PC Settings to "Refresh Your PC without effecting your files".  The first message said there was a problem refreshing your PC, no changes were made, check for solutions to the problem which takes it back to safe mode with no more answers.

Mysidia,  The computer will turn on & off, but only comes to safe mode.  No custom software that I can find to block entry.

There is no internet connection, either wifi or Ethernet.
0
 
LVL 35

Expert Comment

by:Dan Craciun
ID: 39809436
It doesn't really matter if "Refresh" is working or not.

The machine was compromised and cannot be trusted anymore.
Do a hard reset (factory restore), preferably with a format first.
0
 
LVL 95

Expert Comment

by:John Hurst
ID: 39809439
Any solutions to fix problems or best just do a factory restore?

Since you can get to Metro but Windows 8 Refresh will not work, then at this point, you need to back up and do a factory restore. Refresh is pretty much the last hope in a Windows 8 system.

Assuming you do this:

1. Do the factory restore.
2. Update all Drivers.
3. Update all Windows 8 updates.
4. Now go to Metro Windows Store and Update to Windows 8.1. Do this before installing applications.
5. Now Install Applications.
6. Now do all final updates and you should be done.

.... Thinkpads_User
0
 

Author Comment

by:DwEckert
ID: 39809445
I fixed it.

In metro went to msconfig.  The settings had been changed to "selective startup".  Changed back to normal and rebooted.

Came on in to Metro, went to the full desktop.  Got on line with wifi.

Now I will do a full cleaning and update to 8.1.

Darn foreign help desk, scammers going after little grandmothers.  They should be shot.
0
 
LVL 95

Accepted Solution

by:
John Hurst earned 333 total points
ID: 39809458
When you finish cleaning up, do the following:

1. Ensure UAC is ON and working.
2. Install brand name, paid Antivirus.
3. Get EMET V 4.1 free from Microsoft and install it. EMET obfuscates addressing and keeps hackers at bay. I use it on every system now.

... Thinkpads_User
0
 
LVL 24

Expert Comment

by:aadih
ID: 39809466
I fixed it. ~DwEckert.

Great. You did it. :-)
0
 

Author Closing Comment

by:DwEckert
ID: 39809557
Good help, as always.  Good suggestions got me thinking about other possibilities which lead to the solution.

Thanks.
0
 
LVL 95

Expert Comment

by:John Hurst
ID: 39809563
@DwEckert - Thank you very much and I was happy to help.

.... Thinkpads_User
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Security measures require Windows be logged in using Standard User login (not Administrator).  Yet, sometimes an application has to be run “As Administrator” from a Standard User login.  This paper describes how to create a shortcut icon to launch a…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
The goal of this Micro Tutorial is to help navigate beginning users with the app store on Windows 8. It will explain exciting features how to maximize your PC through these apps. This will be demonstrated using Windows 8 operating system.

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question