Start a Conversation

Unsolved

This post is more than 5 years old

1411

July 5th, 2010 15:00

HiJacked! Help!

I have a Optiplex gx240 XP Pro SP1 (I no just got this computer from a friend very outdated). I cut it on today and POP_UPs from hell began to attack me. I have pop-up viagra and pron sites. It wont lext me run AVG and the MS Sercutiy says everything is fine. The fake AV Security is telling me to scan and buy. Almost every program wont open and ballon notfiacation says it is infected. Cannot open add/remove programs, or support and help. Can open Windows Explore but can open anything rom there it will luanch byt then disappear.  There are a lot of old out dated and bad programs. I want to know where I start first. I can back up files to an exernal but I'm afraid to using it and it get infected. HELP!

My friend NEVER updated drivers but Windows updates she said was being done everyday. How can I load and use software if I cant open anything?

 Should I do a diagnostic for bios? I dont even see the local setting for other user in Win Eplr. the [properties for the ad displayed in location "kkkk//c:docs and settings....."

3 Apprentice

 • 

20.5K Posts

July 5th, 2010 16:00

Hi NessA816,

Welcome to Dell Community. :emotion-1:

Considering the amount of infection and issues on that computer, I feel that your best route to take would be to do a factory restore or reformat/reinstall of the operating system. Yes, SP1 is extremely outdated, so you will need to update Windows, once you get things cleaned up. Unless you take that computer back to factory settings, finding all the malware would be like finding a needle in a haystack, and even then we might not get it all.

See instructions and options here: http://support.dell.com/support/topics/global.aspx/support/dsn/en/document?c=us&cs=19&docid=58E26A65A4388E4FE040AE0AB7E107E3&l=en&s=dhs

Best of luck with this project.

 

10 Posts

June 24th, 2021 16:00

Dell lap bios hijack can not be reverse does not matter what you do, how do you get it in the first place, you do not need to do anything, Dell got supported attack inside the bios itsef, the malware come in from the software chip with dell pc call "computrance" from absolute software, this is antitheft software inside bios, the momennt the software is activated, the pc is finish, just throw it away.

this software got 3 settings, activate, disable, diactivate, once malware activated, it control the pc from there, the 3setting is greyed up and the button can not be click, the malware  connect the pc to online admistrators and less than 30minutes your pc is under controll remotly, whatever is dell assistant it is, it will be stop from running and permanently will not run on that pc, the setting is backdated in thhe registry.

the secure boot will be disable, software controll is enable, now the microsoft window will be running in the container, and this is set as default window you will be using and a partition is set in the harddrive for the window to boot from there, you the owner of the pc will be just ordinary users, you have joined group which is controlled by the system, users are prevented from making system wide changes, only administrators got complete privillage to make changes, this is even dell will not help you, nothing work, you can not even open control pannel, the window you install is there, the bitdifender, Malwarebite and all antivirus you install is working, you can scan the pc and nothing is found and yet the pc had already been hijacked, if you managed to change any permission settings, the window will crush, and any attempt to reset the window will failed and the blue screen of death will appear, from then, the default migration setting will be set on you the owner of the pc, any new pc you bought, the settings from malware memory will trigger the default migration settings untill you run away from window pc.

The problems with dell will never help you even if you have a waranty, if at all they take the pc for repair, they will wipe the pc clean and never investigate the problems, the momennt the pc is return, this time less than 15m, the entire problems is back before you finishes setting the same pc brought back from their workshope, the problems continue, will never end, I threw away my working inspiron and move away from window pc.

10 Posts

June 24th, 2021 17:00

This story may be old but the exactly is happening in window 10 and it is more more advance and complicated, Window in the container run as default window and its setting, the group is controll by system, window NT-AUTHORITY complicated, nothing works if you try to chhange anythhing because the window is being run in the container, no home user can knows what is happening, scanning find nothing, the default user I seted was me but now it not, I tried to change it back to me but it is not posible, I can open the scurity seting to change the user but it is saying I do not have permission to edit and change and nothing can be change, if I change it, it can not be save, the button is greyed up, it was window message pop up telling me the window am working on is in the container, I whould have even not known it, I chhange secure boots from bios, disable software controll, it was back at next reboot, 

I whent to this window folder only open by internet explore 11 in window 10, C:\Windows\Logs\PBR\Panther\MigLog.xml,  this gives me more detail about the groups and its migration settings and I gave up, there is nothing I can do, am just a home user with basic nowledge, dell is very far away, not even close to know what is happening with their pc out there, dell will not wast time for non paying customer if you want to report anything, their auto assistant is there to help you but that assistant is alway prevented from rumming and it can not work on the window in the container.

 

No Events found!

Top