Windows 7 Locked after scam call - SYSKEY

Anonymous
2014-07-09T06:15:35+00:00

I have had a couple for customers fall for the "This is So and So from Windows 7 Tech support, we have detected malicious software on you PC. The customers have given the scamers access to the PC and its now locked with What looks like the XP Syskey lock screen. There are reports the Password are 123 or 1234 or abcd. But that all failed. If you have this problem:

THIS IS FOR WINDOWS 7 ONLY, MAY WORK ON OTHER OS!!!!

I have repaired the syskey issue when created by scam call from “Windows 7 Tech Support” in windows 7. I repaired customers computers (1 32-bit and 1 64-bit) successfully, To remove following the steps below:

1.     Boot from windows 7 install cd.

2.     When the Install Windows page appears, click Repair your computer to access system recovery options.

3.     Run System Restore to last point before syskey password blocked access. (This will fail, but must be done). Click run system restore again (this will take you back to the options list)

4.     Open Command Prompt from the options list.

5.     Open Regedit (Type regedit into the command prompt). Regedit will open.

6.     Navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa, and change 'SecureBoot' value to 0.

7.     HKEY_LOCAL_MACHINE \SAM\SAM\Domains\Account Change F value to 0000

8.     Reboot and Login

This has worked for me on two machines. After reboot I ran Super-anti Spyware, Ad-Aware and Hitman Pro to confirm, found 68 items on Super-Anti Spyware, 5 more on ad aware and no further detection's on Hitman Pro. The PC now runs fine with not Lockouts or Passwords.

Hope this helps everyone with this problem.

MICROSOFT / WINDOWS 7 SUPPORT WILL NEVER RING YOU UNLESS YOU HAVE REQUESTED THEM TO DO SO!!!!!!!!!!!!!!!!

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Oldest
  1. Anonymous
    2017-02-20T21:41:34+00:00

    It is not a good idea to attempt to to evade security measures built into the software.  One bad key stroke, and/or using outdated info, or scratching a critical hardware component;  and you may never see your data again!

    See:

    https://www.youtube.com/user/LewissTech/videos

    Some of his videos show some of the common methods scammers use, in the initial phases of the scam;  consider posting/asking on his youtube channel.

    Look for the common syskey codes used by these malicious actors, in the large network of scammers.  Consider taking the computer/device to a local professional.

    I would like to know what makes you think I'm attempting to evade security measures built into the software? Go after the scammers that use it to block  the average  Joe that they are trying to take their hard earned way! My question was so I could get into the computer and remove the HD and put it in my external HD bay and save her some valuable files for her!!  I am a Tech and I use static protection! All I want to know is a way to get 4 really tight screws on the laptop case out. I don't normally do laptops!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2017-02-20T21:47:35+00:00

    All I want to know is a way to get 4 really tight screws on the laptop case out. I don't normally do laptops!

    I've opened up numerous Acer laptops. A screwdriver with the correct bit and a sufficiently large handle always did the trick.

    Was this answer helpful?

    0 comments No comments
  3. Monkey57 3,535 Reputation points
    2017-02-20T21:56:10+00:00

    "what makes you think I'm attempting to evade security measures?" - You are wanting to mess with the SAM, in an unconventional method..

     All I want to know is a way to get 4 really tight screws on the laptop case out.-> consult the MFG of your device.

    Go after the scammers-> I am:   I want to stop scammers/blackmailers access to users computers and users data, and passwords from a Tech Support scam.... see my many posts in answers....

    Consider going to the youtube link i posted, and look for some of the common syskey codes scammers use today.  

    But, consider your hard-drive(s) compromised, even if you do get in, via guessing (or reconfiguration).

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-02-20T22:03:08+00:00

    All I want to know is a way to get 4 really tight screws on the laptop case out. I don't normally do laptops!

    I've opened up numerous Acer laptops. A screwdriver with the correct bit and a sufficiently large handle always did the trick.

    I'm looking for one with a larger handle. After my Hubby pasted I had the son come and get all the stuff out of his shop and kept only what I thought I needed. Got the little bits but if I can't find a bigger handle by this evening will go bug some neighbors and see if they have anything, Maybe their stronger muscle will do it too!

    Thanks for the idea.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-02-20T22:10:29+00:00

    I've had to deal with the Syskey issue previously.  I only know of one means of resolving it even though there may be more than one.  Unfortunately, I may not have all of the exact information, but you should be able to Google it.  You can restore the registry form the windows registry backup which will circumvent Syskey by booting into DOS from a windows PE USB or a windows DVD.  You can make the DVD by downloading a Windows ISO and copying to blank DVD.  That will do it.  Boot into DOS from the USB device or the DVD.  Then you use Windows Explorer to go to the Windows Registry folder "config".

    The path is C:\Windows,system32\config

    Backup the registry hives in this folder to a temporary location. The files are:

    1. SOFTWARE
    2. SYSTEM
    3. SAM
    4. SECURITY
    5. DEFAULT

    In that folder you will find a backup copy of some of the registry files in RegBack.

    The path is C:\Windows,system32\config\RegBack

    You need to copy all 5 of the backup registry files from RegBack to config.  The registry backup files are the files with no extensions.  I just googled this solution and a more detailed description can be found at:  http://triplescomputers.com/blog/casestudies/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout/

    Good luck.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments