Windows 10: Suspicious activity on my laptop

Discus and support Suspicious activity on my laptop in AntiVirus, Firewalls and System Security to solve the problem; From last 2 weeks I have observed suspicious activity going on in my Laptop. Here are the symptoms/sequence of events happening and few things I tried... Discussion in 'AntiVirus, Firewalls and System Security' started by Saurabh_3601, Feb 12, 2021.

  1. Suspicious activity on my laptop


    From last 2 weeks I have observed suspicious activity going on in my Laptop. Here are the symptoms/sequence of events happening and few things I tried but nothing seems to Work.


    Note: I have Dell Inspiron 15 series Laptop and I have Win10 Home on my laptop.


    Sequence of events:

    1. Suddenly 2 weeks back while working, my laptop got hanged. When I restarted to recover from hang, it started asking for BIOS System password which I had never set before. Somehow after trying many attempts, fortunately my Laptop User account user name it took as BIOS system password. Upon entering BIOS system password, it prompted for HDD password which also, I never set. Somehow I entered the same my laptop user account name as password and it took that. Now with every boot it asks for BIOS system password and HDD password.
    2. Since I was able to proceed by entering password, I did not bother much initially. However, after few days, i started noticing some suspicious activity on my Laptop:
      • I see that some unknown email accounts get added as administrator account under Start->Settings->Accounts->Your Info.
      • Also, the same unknown email account is added under Start->Settings->Accounts->Email and app accounts
      • I noticed that the same unknown account was added to one drive.
      • I removed these accounts from all places mentioned above. However, after few hours of using the laptop, again i see that same unknown account gets added as administrator account.



    Actions I have taken:

    So, i suspected that this is some malware got into my system. So i tried below things to recover:

    1. Ran Windows defender quick scan - Nothing found
    2. Ran Kaspersky total security scan - No thread found
    3. McAfee scan - No thread found
    4. Reset Laptop to factory defaults. After resetting, again started showing same symptoms as described above
    5. Downloaded Recovery image from Dell site for my Laptop serial number and tried re-installing the image from USB. After re-installing the images, again started showing same symptoms as described above.
    6. Tried downloading Win10 Home from Microsoft website and then installed on my laptop. While installing i formatted and deleted all partitions. After installing Win10, again started showing same symptoms as described above.
    7. One other thing I observed which makes me think that malware is not getting erased even after i re-install complete OS. I observed that after re-installing Windows 10, I did not at all configure my wi-fi neither i connected to LAN at all. I disabled the Wifi from taskbar. I just left the laptop as it is. After some time i noticed that wi-fi automatically got enabled and trying to connect but it could not connect since i have not configured password at all. I again disabled wi-fi and left. Again after some time, wifi gets auto enabled and starts trying to connect.
    8. I tried running Windows Defender offline, but it runs till 91% and then system restarts. I do not see it ran completely.
    9. Since the malware is not getting eradicated even after reinstalling OS, i tried to reset BIOS to factory defaults. However, when i went to BIOS, it shows that BIOS is locked and i need BIOS admin password to unlock which i have never set. Note that to unlock BIOS, its asking for BIOS Admin password which is different than BIOS system password which i mentioned earlier. I went to Dell service center with the hope that they can reset BIOS admin password. But they told they cannot reset BIOS admin password and told me to replace entire motherboard and hard disk.

    So, now i am not sure how to get rid of this malware. Any help/suggestions would be really helpful.

    :)
     
    Saurabh_3601, Feb 12, 2021
    #1
  2. Winuser Win User

    Suspicious Activity - Yahoo Mail


    I had a notice from Comcast once that they noticed suspicious activity on my email account. I checked my online account and couldn't find anything wrong. I changed my pass word and haven't received any notices since.
     
    Winuser, Feb 12, 2021
    #2
  3. n-ster Win User
    n-ster, Feb 12, 2021
    #3
  4. Suspicious activity on my laptop

    Windows Has Been Blocked Due To Suspicious Activity

    Hi,

    My Laptop is Windows 10.It's not even a month since i bought it and frequently this "Windows Has Been Blocked Due To Suspicious Activity"thing is coming up within 15 minutes of uaing my laptop.It freezes the laptop and makes a 'Beep Beep' Noise.I can't
    do anything when it pops up and i have to restart.I saw this:Remove "Windows has detected some suspicious activity from your IP address" Fake Alert from Browser - YooCare How-to Guides - YooCare Blog


    But I don't know how do i do them step by step because it gives a solution for a PC,but i have a laptop.Suppose it says 'restart the comuter and press f8 repeatedly when pc is booting again.'I don't know if this is possible in a laptop or not because
    those 2 screens that pop up in a computer while turning it on doesn't pop up in a laptop we all know that.


    Also,THis error tells me to call a number which i didn't call thinking this might be a spam.So guys,plz help me out with this.I am in a big trouble i can't use my laptop more than 15 mins.Your help will be highly appreciated.T.I.A.
     
    Nihal NafizMichelle, Feb 12, 2021
    #4
Thema:

Suspicious activity on my laptop

Loading...
  1. Suspicious activity on my laptop - Similar Threads - Suspicious activity laptop

  2. Suspicious activity on behalf of my email

    in Windows 10 Gaming
    Suspicious activity on behalf of my email: I received a message from *** Email address is removed for privacy *** is written in russian language and it says my "password has been changed" at least google translated "Ваш пароль изменен" to thisThe strange part is microsoft says, that there is no account associated with...
  3. Suspicious activity on behalf of my email

    in Windows 10 Software and Apps
    Suspicious activity on behalf of my email: I received a message from *** Email address is removed for privacy *** is written in russian language and it says my "password has been changed" at least google translated "Ваш пароль изменен" to thisThe strange part is microsoft says, that there is no account associated with...
  4. Suspicious activity on network and suspicious something

    in Windows 10 Gaming
    Suspicious activity on network and suspicious something: Suspicious He made temp and try send somewhere and somebody have super user I'm not give any permission and I'm use safe network WiFi with strong password reported to PoliceRegards Jakub...
  5. Suspicious activity on network and suspicious something

    in Windows 10 Software and Apps
    Suspicious activity on network and suspicious something: Suspicious He made temp and try send somewhere Regards Jakub https://answers.microsoft.com/en-us/windows/forum/all/suspicious-activity-on-network-and-suspicious/9cc70962-09f3-4d8e-821c-3256bf32ceef
  6. Suspicious disk activity

    in Windows 10 Gaming
    Suspicious disk activity: I have no user applications open, and the resource monitor shows the system using my disk, which is doing a lot of seeks. The process I found was ksecdd.sys. Should it be using a lot of disk activity when the rest of the system is at rest? I tried disabling the ethernet...
  7. Suspicious disk activity

    in Windows 10 Software and Apps
    Suspicious disk activity: I have no user applications open, and the resource monitor shows the system using my disk, which is doing a lot of seeks. The process I found was ksecdd.sys. Should it be using a lot of disk activity when the rest of the system is at rest? I tried disabling the ethernet...
  8. Suspicious account activity

    in AntiVirus, Firewalls and System Security
    Suspicious account activity: I rarely use my ages old hotmail account, but I do have it set up for POP access from my PC - Windows 10, with Outlook 2010, so it's is poked at least once a day. I received a notice of suspicious activity and when I checked the log, I found: Device/platform Windows...
  9. Suspicious Activities in My System

    in AntiVirus, Firewalls and System Security
    Suspicious Activities in My System: Sometimes I feel that there is suspicious activity going on, there are some things in my computer files that I cant go into, (files that I didn't download) it asks for a password, but if I didn't put it on here, how am im going to know that password? There are some things...
  10. Suspicious Activity

    in AntiVirus, Firewalls and System Security
    Suspicious Activity: Hey There, See email below about a service I paid for. I was a Microsoft office home user 18 months ago and experienced issues with my computer, I googled Microsoft Tech Support called the number and they told me I would need a third party to fix the issue. They then...