Hello all!
This is one that I can't wrap my head around. A client brought in a computer that is having the Other User issue. Backstory on it, she was having trouble on the computer, and instead of calling us, she clicked on a link. Then clicked on another, and so forth, until she had a guy connected to her computer. Now, she can't log into the computer.
It is running Windows 10. The computer boots up normally, and comes up to a screen to enter username and password with Other User displayed at the top. It also has at the bottom listed that if I wish to switch DOMAIN, to type in the domain first, or to log into the PC locally. So, I figured that the hacker just changed her to be setup to a domain. This is not the case.
I can boot the system to Safe Mode with Command Prompt and it loads in. From there I have verified that the computer is on WORKGROUP, and that the user "PCS Customer" is an Administrator with no password. I have even tried adding a password to the account, but when I boot normally, I cannot login.
After about 1 minute on the logon screen, the computer will reboot itself. I have also tried changing utilman.exe to cmd.exe and accessing net user on the logon screen, but it comes back with error code 1722, The RPC Server is unavailable. If I try to start the service, it says it is already started.
What can I do from here?
Thank you for the suggestions. I do know that reloading, or wipe and reload is an option, but I always avoid that IF possible. I did find a couple of things in the RunOnce and Run registry. I would upload them, but my Flash Drive died... one was related to RSTRUI.exe (System Restore). The other two used cmd.exe for some process with OneDrive.
I'm uploading a picture that shows the main logon screen. You will see the internet is disabled and the power button is not functioning correctly.
Oh, note. Typing in the password and hitting enter has no effect, as if it just ignores you.