Windows 7 Locked after scam call - SYSKEY

Anonymous
2014-07-09T06:15:35+00:00

I have had a couple for customers fall for the "This is So and So from Windows 7 Tech support, we have detected malicious software on you PC. The customers have given the scamers access to the PC and its now locked with What looks like the XP Syskey lock screen. There are reports the Password are 123 or 1234 or abcd. But that all failed. If you have this problem:

THIS IS FOR WINDOWS 7 ONLY, MAY WORK ON OTHER OS!!!!

I have repaired the syskey issue when created by scam call from “Windows 7 Tech Support” in windows 7. I repaired customers computers (1 32-bit and 1 64-bit) successfully, To remove following the steps below:

1.     Boot from windows 7 install cd.

2.     When the Install Windows page appears, click Repair your computer to access system recovery options.

3.     Run System Restore to last point before syskey password blocked access. (This will fail, but must be done). Click run system restore again (this will take you back to the options list)

4.     Open Command Prompt from the options list.

5.     Open Regedit (Type regedit into the command prompt). Regedit will open.

6.     Navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa, and change 'SecureBoot' value to 0.

7.     HKEY_LOCAL_MACHINE \SAM\SAM\Domains\Account Change F value to 0000

8.     Reboot and Login

This has worked for me on two machines. After reboot I ran Super-anti Spyware, Ad-Aware and Hitman Pro to confirm, found 68 items on Super-Anti Spyware, 5 more on ad aware and no further detection's on Hitman Pro. The PC now runs fine with not Lockouts or Passwords.

Hope this helps everyone with this problem.

MICROSOFT / WINDOWS 7 SUPPORT WILL NEVER RING YOU UNLESS YOU HAVE REQUESTED THEM TO DO SO!!!!!!!!!!!!!!!!

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2017-02-24T05:30:28+00:00

    Honestly I have a virtual machine set up with Windows 7 I have one with windows 10 also and I hunt down these people and I still have not seen them compromise the machine other than me downloading the my virtual PC or whatever and punching in the pin it's been the same old same old Syskey bs.

     I have detailed loggers set up on all the virtual machines just to see if by some chance they do something totally different  and surprisingly have not come across anybody anymore intelligent than what I've seen  in the YouTube videos.

     Not saying there's not one out there  But I just haven't come across them yet  and the reason why I have all the loggers set up is basically to honeypot I check the passwords and add them to rainbow table files online so that people could just run the CD cracker run the rainbow tables and crack it.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2017-02-20T22:36:05+00:00

    All I want to know is a way to get 4 really tight screws on the laptop case out. I don't normally do laptops!

    I've opened up numerous Acer laptops. A screwdriver with the correct bit and a sufficiently large handle always did the trick.

    Ta Da!! Found where I hid the sets of little screw drivers for my work and first one I tried did! Thanks Guys!!

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2017-02-20T22:10:29+00:00

    I've had to deal with the Syskey issue previously.  I only know of one means of resolving it even though there may be more than one.  Unfortunately, I may not have all of the exact information, but you should be able to Google it.  You can restore the registry form the windows registry backup which will circumvent Syskey by booting into DOS from a windows PE USB or a windows DVD.  You can make the DVD by downloading a Windows ISO and copying to blank DVD.  That will do it.  Boot into DOS from the USB device or the DVD.  Then you use Windows Explorer to go to the Windows Registry folder "config".

    The path is C:\Windows,system32\config

    Backup the registry hives in this folder to a temporary location. The files are:

    1. SOFTWARE
    2. SYSTEM
    3. SAM
    4. SECURITY
    5. DEFAULT

    In that folder you will find a backup copy of some of the registry files in RegBack.

    The path is C:\Windows,system32\config\RegBack

    You need to copy all 5 of the backup registry files from RegBack to config.  The registry backup files are the files with no extensions.  I just googled this solution and a more detailed description can be found at:  http://triplescomputers.com/blog/casestudies/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout/

    Good luck.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2016-09-22T23:55:01+00:00

    Whoa, before this conversation gets off track, i thought this was a help community. No one having talk ed about changing anything. I was looking for help on a known problem that Microsoft haven't fixed. I dont think anybody is trying to go against Microsoft's Licensing. 

    Can you help me on this problem that won't go against the licensing?

    Thanks

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2016-03-12T15:32:35+00:00

    I also was trustful enough to let them reach my computer. 

    I have restored my Windows 10 PC by replacing registry files from RegBack. It is good that windows automatically offers restoration options but when I tried to return to the original state of the windows (with keeping all personal files) syskey password still was required.

    Check restore points and  if not available  peek built-in command line option and follow the instructions http://triplescomputers.com/blog/casestudies/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout/

    I think MS should exclude this syskey tool as far just few people know it meanwhile it is a widespread scam for the last years. Where can we make such suggestions to MS?

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments