• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Windows Syskey: Any way around it?

Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
Hi everyone. Long story short, my elderly aunt and uncle were victims of a phone scam in which their financial information and computer were compromised. Luckily, the bank froze their accounts and credit files just in time.

I am tasked with trying to fix the smoking wreckage of a computer they have. Apparently, the scammer had my uncle allow remote access to his desktop and the scammer went to town. My first hurdle is that the scammer set up a windows syskey password. I have never seen this before to be quite honest. I learned that basically, the scammer encrypts the SAM database, which renders any password cracker useless (IE Hirens Boot CD, my go to in this situation). I was able to boot a live USB of Linux mint and copy some of their data over to a flash drive. I'm not sure what the scammer did to their pictures, but none of them will open. They have the proper file extension (jpeg) but bark at me that "the registry value is invalid" or something along those lines.

My gut tells me to blow away the OS and re-install windows 10 on it, but my morbid curiosity wants to know what that scumbag scammer did to this installation.

So tl;dr, any way to get past a syskey password?


Also, lol Microsoft will be getting rid of syskey because of ransomware and scammers in the creators update.
https://en.wikipedia.org/wiki/Syskey
 
Joined
Oct 17, 2012
Messages
9,781 (2.32/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
Found this..... maybe?

1. Boot from windows install cd.

2. When the Install Windows page appears, click Repair your computer to access system recovery options.

3. Run System Restore to last point before syskey password blocked access. (This will fail, but must be done). Click run system restore again (this will take you back to the options list)

4. Open Command Prompt from the options list.

5. Open Regedit (Type regedit into the command prompt). Regedit will open.

6. Navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa, and change 'SecureBoot' value to 0.

7. HKEY_LOCAL_MACHINE \SAM\SAM\Domains\Account Change F value to 0000

8. Reboot and Login
 

cdawall

where the hell are my stars
Joined
Jul 23, 2006
Messages
27,680 (4.27/day)
Location
Houston
System Name All the cores
Processor 2990WX
Motherboard Asrock X399M
Cooling CPU-XSPC RayStorm Neo, 2x240mm+360mm, D5PWM+140mL, GPU-2x360mm, 2xbyski, D4+D5+100mL
Memory 4x16GB G.Skill 3600
Video Card(s) (2) EVGA SC BLACK 1080Ti's
Storage 2x Samsung SM951 512GB, Samsung PM961 512GB
Display(s) Dell UP2414Q 3840X2160@60hz
Case Caselabs Mercury S5+pedestal
Audio Device(s) Fischer HA-02->Fischer FA-002W High edition/FA-003/Jubilate/FA-011 depending on my mood
Power Supply Seasonic Prime 1200w
Mouse Thermaltake Theron, Steam controller
Keyboard Keychron K8
Software W10P
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
I realize I could google it, but I wanted to see if you guys had any experience with it. Thanks for the suggestions, I will try some of those when I get home.
 
Joined
Oct 17, 2012
Messages
9,781 (2.32/day)
Location
Massachusetts
System Name Americas cure is the death of Social Justice & Political Correctness
Processor i7-11700K
Motherboard Asrock Z590 Extreme wifi 6E
Cooling Noctua NH-U12A
Memory 32GB Corsair RGB fancy boi 5000
Video Card(s) RTX 3090 Reference
Storage Samsung 970 Evo 1Tb + Samsung 970 Evo 500Gb
Display(s) Dell - 27" LED QHD G-SYNC x2
Case Fractal Design Meshify-C
Audio Device(s) on board
Power Supply Seasonic Focus+ Gold 1000 Watt
Mouse Logitech G502 spectrum
Keyboard AZIO MGK-1 RGB (Kaith Blue)
Software Win 10 Professional 64 bit
Benchmark Scores the MLGeesiest
I realize I could google it, but I wanted to see if you guys had any experience with it.

thats what i gave,,,, my experience however is (with no back up) your SOL . so i tried to help despite that sorry it wasnt good news
 
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
thats what i gave,,,, my experience however is (with no back up) your SOL . so i tried to help despite that sorry it wasnt good news
Hey man, I appreciate it! It's not a big deal so I may just go with my gut and blow it away.
 
Joined
Dec 6, 2005
Messages
10,881 (1.62/day)
Location
Manchester, NH
System Name Senile
Processor I7-4790K@4.8 GHz 24/7
Motherboard MSI Z97-G45 Gaming
Cooling Be Quiet Pure Rock Air
Memory 16GB 4x4 G.Skill CAS9 2133 Sniper
Video Card(s) GIGABYTE Vega 64
Storage Samsung EVO 500GB / 8 Different WDs / QNAP TS-253 8GB NAS with 2x10Tb WD Blue
Display(s) 34" LG 34CB88-P 21:9 Curved UltraWide QHD (3440*1440) *FREE_SYNC*
Case Rosewill
Audio Device(s) Onboard + HD HDMI
Power Supply Corsair HX750
Mouse Logitech G5
Keyboard Corsair Strafe RGB & G610 Orion Red
Software Win 10
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
Are you trying to open the jpegs on the encrytped PC, or another?

I am trying to open them on another. It is weird because other recovered files open on this other computer, but the pictures all seem to have this issue. It is hard to tell what's going on without being able to log into the OS on the affected PC, perhaps further damage occurred with these files. When I get home, I'll try some of the methods listed in this thread. If worst comes to worst, I have a new installation usb ready to go. Thanks for all the suggestions fellas.
 
Joined
Dec 6, 2005
Messages
10,881 (1.62/day)
Location
Manchester, NH
System Name Senile
Processor I7-4790K@4.8 GHz 24/7
Motherboard MSI Z97-G45 Gaming
Cooling Be Quiet Pure Rock Air
Memory 16GB 4x4 G.Skill CAS9 2133 Sniper
Video Card(s) GIGABYTE Vega 64
Storage Samsung EVO 500GB / 8 Different WDs / QNAP TS-253 8GB NAS with 2x10Tb WD Blue
Display(s) 34" LG 34CB88-P 21:9 Curved UltraWide QHD (3440*1440) *FREE_SYNC*
Case Rosewill
Audio Device(s) Onboard + HD HDMI
Power Supply Corsair HX750
Mouse Logitech G5
Keyboard Corsair Strafe RGB & G610 Orion Red
Software Win 10
I am trying to open them on another. It is weird because other recovered files open on this other computer, but the pictures all seem to have this issue. It is hard to tell what's going on without being able to log into the OS on the affected PC, perhaps further damage occurred with these files. When I get home, I'll try some of the methods listed in this thread. If worst comes to worst, I have a new installation usb ready to go. Thanks for all the suggestions fellas.

Combination scam AND ransom encryption? I'm curious to see what you find.
 
Joined
Aug 13, 2015
Messages
467 (0.15/day)
Location
South Africa ,Lions Everywhere..
System Name Ground Control
Processor Intel i5 2500k 4 Ghz
Motherboard MSI P67A-GD80 B3
Cooling Cooler Master Hyper 212x
Memory 2 x 4GB DDR3 1600mhz Apacer Black Panther
Video Card(s) Msi GTX 1060 OC 3Gb
Storage 2 x 250Gb WD Blue raid 0 + 1Tb Wd Green
Display(s) Samsung BX2450 24" Led
Case GMC X7 X-Station
Power Supply HEC Raptor 500watt
Mouse Logitech G9
Software Windows 8.1
Benchmark Scores Power Level over 9000
I would rather backup and format the PC .You never know what else they have done to the pc .Keyloggers ect
At least you know the Pc is clean then and no comebacks

The last syskey scam I battled to remove the syskey but after ,though a reload would be the best anyway
 
Joined
Nov 2, 2008
Messages
887 (0.16/day)
Processor Intel Core i3-8100
Motherboard ASRock H370 Pro4
Cooling Cryorig M9i
Memory 16GB G.Skill Aegis DDR4-2400
Video Card(s) Gigabyte GeForce GTX 1060 WindForce OC 3GB
Storage Crucial MX500 512GB SSD
Display(s) Dell S2316M LCD
Case Fractal Design Define R4 Black Pearl
Audio Device(s) Realtek ALC892
Power Supply Corsair CX600M
Mouse Logitech M500
Keyboard Lenovo KB1021 USB
Software Windows 10 Professional x64
It's not a big deal so I may just go with my gut and blow it away.

Whether you try to unlock Windows or not: save the data, erase the drive, and restore a system image (if you have one) or reinstall from scratch. If a scammer has screwed around with the PC, no one in their right mind would try to continue using it.
 
Joined
Jan 4, 2017
Messages
431 (0.16/day)
Location
Ohio
Oh I'm ultimately re-installing, I just am fascinated by what the scammer did. It is not connected to the network so I can explore freely if I get past. Just to be clear, no matter what I'm wiping.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
Definitely format and reinstall, without hesitation.

I think it's even possible to infect another Windows PC just browsing the files on the infected install in some cases, especially if not patched. Certainly opening any files can have a payload. Sounds like he didn't have a backup?

Sorry your aunt and uncle were scammed by those vile criminals. Hopefully the experience will make them more wary next time. A good idea is to instill in them that no one goes near their computer unless it's family or good friends that they know and who have decent computer knowledge. This should help to keep them safe.
 
Top