This is a read-only archive. No new posts or registrations. Privacy Page
Software

Errors after Windows 10 factory reformat and reset

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everyone. I have a friend who bought a Dell Windows 8 desktop a year ago. I helped him set it up and do the free Windows 10 upgrade. Everything worked fine until December when he suddenly started getting script error messages constantly as well as a bunch of annoying pop ups. A week ago he bough a new HP inkjet printer. I don't have the model number handy but it was a $99 job. When he went to try and install it the script error messages started popping up and he was unable to get it installed and working. During this process a helpdesk popup showed up in the lower right hand corner of the screen with a message from 'Richard', supposedly from HP, stating 'I see your having trouble, do you need help?' Needless to say I wish he had called me at this point but he did not. My friend conversed with this person who promised that he could fix the issue for only $19.99. So, my friend gave him remote control of his PC. 'Richard' proceeded to download several software packages to his pc, multiple windows popped up and closed, and 'Richard' declared the issue fixed and asked for his credit card number to cover the now $199.99 cost of 'fixing' the error. Fortunately at this point my friend became suspicious and refused to give his credit card information and asked to be billed. There is more but you get the point. He called me at this point and I told him to shut off everything. Fortunately he does nothing more than e-mail and puzzles. I went over the next day and performed a factory reset of his PC including wiping the hard drive which took a total of almost 7 hours. I did the upgrade to windows 10 and installed all of the updates. He is using Windows Defender as his virus/malware protection and Windows firewall. I installed the printer and everything worked fine. Yesterday he started getting the script error pop ups again. He is worried that his PC is infected again.

 

My question is, is this a Windows 10 known issue, is it an issue with with IE 11, or is this a potential malware/virus issue? Could 'Richard' have corrupted the factory backup partition while he had control of the PC? or Could 'Richard' have infected the BIOS in some way? I've never seen that happen but you never know so I am asking. Not sure what to do here. I would think that any infection would have been removed during the factory reset.

 

Any help or suggestions would be greatly appreciated.

 

Thanks,

 

The Catman

Hi The Catman and welcome to our forums

:welcome:

 

Sorry to hear of your friend's trouble with his computer.

 

I'll try and deal with the questions you ask, in the best way possible, but there are several "unknowns" that tend to cloud the issues.

 

Hopefully a suitable way forward will also be set out for your consideration,

 

However let's get started:

 

1 is this a Windows 10 known issue

 

No it's not a known issue with Win 10

 

2 is this a potential malware/virus issue?

 

It's possible, however if you "wiped the drive" before reinstalling Windows this generally is sufficient to deal effectively with most infections current at that point of time. It could easily have become infected "post wipe" so to speak. However see referral to our Virus and Spyware forum.

 

3 Could 'Richard' have corrupted the factory backup partition while he had control of the PC?

 

Yes, anyone who is given remote access to a computer in this way can do practically anything from a distance, that an owner can do whilst sitting in front of the computer. This is why many experts counsel against allowing any remote access from an unknown person or organisation. Anyone allowing remote access by even a trusted reliable and honest person of integrity and repute should be aware of the steps needed to terminate a Remote Access session in the quickest way  and to prevent further access sessions. This can be tricky sometimes so a general recommendation might be just not to allow any Remote Access without the most stringent precautions being taken. However as always it's your friend's call on how he wishes to use his computer.

 

4 Could 'Richard' have infected the BIOS in some way?

 

This is most unlikely and at this stage can be ignored.

 

5 I would think that any infection would have been removed during the factory reset.

 

See answer to 2 above (one of the "unknowns" referred to earlier is your statement that you wiped the "hard drive" and it took 7 hours and then performed a factory reset… there is a potential inconsistency here in that if you did not use removable media to perform the factory reset but relied upon the Factory Restore Partition on the hard drive then the hard drive could not have been wiped….  If you used external media to perform the reset then there is no inconsistency…Sorry I am not trying to be pedantic here, only to help identify a way forward for your friend..

 

Another unknown is that many Win 8 machines shipped in the last year, with UEFI rather than BIOS and with "Secure Boot" enabled this makes it difficult to boot from removable media without taking additional steps. 

 

I think that a good way forward, might be for you to consider the following:

 

1 Reset Internet Explorer 11 back to default settings,  this will remove any settings that may be incorrect and causing the issues.

 

2 Download and install Mozilla Firefox and try testing the computer using that browser rather than Internet Explorer. (if the pops ups stop then it's diagnostically significant and will help point us in the right direction in seeking a permanent fix.

 

3 If the above two steps do not provide an improvement that is satisfactory then visit our Virus and Spyware Removal forum, post the appropriate log files into a new topic that you start in that forum (please don't post them in this forum here as we don't analyse them or deal with malware issues in this forum here) Please be sure to post your logs in one post and do not add a further post until you have received a reply from a Virus and Spyware removal expert (they look for posts that have not been replied to, so adding a post to your topic just confuses the issue)

 

4 The instruction you need are here:

https://forums.whatthetech.com/index.php?showtopic=106388

It would be helpful to them if you could include a link to this topic here in your initial post to them, so that the Virus and Spyware removal expert knows what has previously transpired.

 

5 Once your friend's computer has been given an "all clear" by the Malware removal expert it will reassure your friend that the final logs (and be prepared for a number of them to be requested) are not showing any malicious code. If there are still issues with the computer then post back here in this topic and one of the experts here will do their best to help.

Regards

paws

Thank you for getting back to me so quickly. Having read your reply I will correct myself in having said that I 'Wiped' the drive. I used no third party software in the process. I also used no removable media in the process. I simply used the options available through windows 10 to 'reformat' the drive to remove all information prior to reinstalling Windows 8 from the backup partition. It is this reformatting that took several hours to be completed. I understand that reformatting is definitely not the same thing as actually wiping and overwriting a drive. I thought this on board method would be sufficient to remove any possible infections. After Windows 8 was reinstalled I installed Windows 10 plus all updates and installed the printer with no issues.

 

My friend is away until Wednesday so I have no access to his PC until then. I will try steps 1 and 2 as you suggested. If there are still issues then I will move on to steps 3, 4, and 5.

 

I guess the question I have now is, was my assumption incorrect in that the reformatting was, as I performed it, sufficient to remove all infections? Can some infections survive the reformatting process? This will be helpful the next time I have a friend or family call me with an issue and could save me a lot of time.

 

Thanks so much for the help. It is very much appreciated.

 

The Cat Man

Hi The Cat Man,

Thanks for the additional information, it's most helpful.

:thumbup:

 Malware removal advice is not provided in this topic here, you will need to seek assistance from a Virus and Spyware removal expert over in the forum referred to previously, however some general remarks can be made that hopefully will help you.

 

Generally speaking, using the recovery Partition to restore the computer to its "factory condition" is sufficient to effectively neutralise most infections that are common today.

However the following points are worth noting:

 

1 It is possible (just possible, though highly unlikely) that the Recovery Partition could have become infected, however this is so rare that for the time being it can probably be discounted.

 

2 There is a facility on some computers when using the restore procedure to retain some existing  files….. … these might be client data files, documents and the like or other files and folders sometimes retained in a new directory/folder created by the recovery process and often named "Windows Old" If this happened with your friend's computer it's not possible to categorically rule out infection in these files.

 

3 Old backups or just copied files or application installations discs (especially from sources of unknown provenance) may be contained within USB memory sticks, CD's or DVD's or other removable media and it's possible that these could carry infections and could easily "jump across" so to speak when used on the recently restored computer. ( hence my earlier reference to "post wipe infections")

 

4 Some folks are also so keen to get using their computer again after a "restoration procedure" that they forget that there must be no access allowed to the Internet, or other machines or sources of data, until their anti virus and firewall are up and running and that the initial access to the Internet must be restricted solely to updating the anti virus and updating Windows… definitely no trying out email (not even just to see if it works!.. or installing extra applications) and definitely no visiting any Internet site other that Windows Update and anti virus update site (if different!) Windows updates should continue after a reboot and continue to be run until no further updates are available.

 

Its possible for a computer to become reinfected again even within a few seconds if these precautions are not taken.

 

Once Windows is updated then windows 10 is usually set (on home versions) to update automatically…

 

To sum up:

Using the procedure you outlined is generally sufficient to neutralise most of the infections found commonly today… but do bear in mind the additional points made above.

 

When you open a topic in our Virus and Spyware removal forum then the expert there will be able to ascertain (from the logfiles you will be asked to submit) more detailed information on the state of your friend's computer and will be able to provide step by step instructions individualised to the specific computer concerned, on a way forward to deal with any potential infection. They will also provide guidance at the end of the process on how your friend can best avoid problems in the future.

Regards

paws

Steps 1 and 2 were tried but errors are still occurring. I will be posting on the Virus/Malware removal section of this web site. Thank you for your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI