Possibly a permissions issue on the keys?
John
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have had a couple for customers fall for the "This is So and So from Windows 7 Tech support, we have detected malicious software on you PC. The customers have given the scamers access to the PC and its now locked with What looks like the XP Syskey lock screen. There are reports the Password are 123 or 1234 or abcd. But that all failed. If you have this problem:
THIS IS FOR WINDOWS 7 ONLY, MAY WORK ON OTHER OS!!!!
I have repaired the syskey issue when created by scam call from “Windows 7 Tech Support” in windows 7. I repaired customers computers (1 32-bit and 1 64-bit) successfully, To remove following the steps below:
1. Boot from windows 7 install cd.
2. When the Install Windows page appears, click Repair your computer to access system recovery options.
3. Run System Restore to last point before syskey password blocked access. (This will fail, but must be done). Click run system restore again (this will take you back to the options list)
4. Open Command Prompt from the options list.
5. Open Regedit (Type regedit into the command prompt). Regedit will open.
6. Navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa, and change 'SecureBoot' value to 0.
7. HKEY_LOCAL_MACHINE \SAM\SAM\Domains\Account Change F value to 0000
8. Reboot and Login
This has worked for me on two machines. After reboot I ran Super-anti Spyware, Ad-Aware and Hitman Pro to confirm, found 68 items on Super-Anti Spyware, 5 more on ad aware and no further detection's on Hitman Pro. The PC now runs fine with not Lockouts or Passwords.
Hope this helps everyone with this problem.
MICROSOFT / WINDOWS 7 SUPPORT WILL NEVER RING YOU UNLESS YOU HAVE REQUESTED THEM TO DO SO!!!!!!!!!!!!!!!!
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Possibly a permissions issue on the keys?
John
Friend rang in panic - suspected scam - windows 10.
Suggested switch off computer (hold start button 5 seconds).
Went round - syskey password required on restarting computer!
started again and used F8 key to get into other options. Eventually navigated to system restore and went back one week.
Everything OK - but it could have been worse.
Clearly users must be more suspicious - being phoned up by somebody unknown claiming to be from a well known organisation with the story that your computer is infected with X, Y, or Z is worrying - but people have to trust their anti virus program (if they have anti virus!!!!) to keep them safe and to know that reputable companies would not phone them in this manner. I always ask "if you have a report from my computer please tell me what operating system I'm using and whether its 16,32, or 64 bit, what processor I'm using and my installed memory". They can't answer - so its obviously a scam!
But do we think that its worth installing our own syskey password so that others can't?
When they call me my only goal is to keep the scammer on the phone as long as I can so the scammer has less time on the next victim.
I also was trustful enough to let them reach my computer.
I have restored my Windows 10 PC by replacing registry files from RegBack. It is good that windows automatically offers restoration options but when I tried to return to the original state of the windows (with keeping all personal files) syskey password still was required.
Check restore points and if not available peek built-in command line option and follow the instructions http://triplescomputers.com/blog/casestudies/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout/
I think MS should exclude this syskey tool as far just few people know it meanwhile it is a widespread scam for the last years. Where can we make such suggestions to MS?
I think MS should exclude this syskey tool as far just few people know it meanwhile it is a widespread scam for the last years. Where can we make such suggestions to MS?
The tool is still useful in some environments where the additional layer of security can prevent unauthorized access to computers, requiring a 128-bit encryption key stored on a USB key can stop casual access from the inside. If we have to make everything naive-proof we will be locked in our own homes for our own safety...without internet access because the internet is full of scams!
John