Windows 7 Locked after scam call - SYSKEY

Anonymous
2014-07-09T06:15:35+00:00

I have had a couple for customers fall for the "This is So and So from Windows 7 Tech support, we have detected malicious software on you PC. The customers have given the scamers access to the PC and its now locked with What looks like the XP Syskey lock screen. There are reports the Password are 123 or 1234 or abcd. But that all failed. If you have this problem:

THIS IS FOR WINDOWS 7 ONLY, MAY WORK ON OTHER OS!!!!

I have repaired the syskey issue when created by scam call from “Windows 7 Tech Support” in windows 7. I repaired customers computers (1 32-bit and 1 64-bit) successfully, To remove following the steps below:

1.     Boot from windows 7 install cd.

2.     When the Install Windows page appears, click Repair your computer to access system recovery options.

3.     Run System Restore to last point before syskey password blocked access. (This will fail, but must be done). Click run system restore again (this will take you back to the options list)

4.     Open Command Prompt from the options list.

5.     Open Regedit (Type regedit into the command prompt). Regedit will open.

6.     Navigate to: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa, and change 'SecureBoot' value to 0.

7.     HKEY_LOCAL_MACHINE \SAM\SAM\Domains\Account Change F value to 0000

8.     Reboot and Login

This has worked for me on two machines. After reboot I ran Super-anti Spyware, Ad-Aware and Hitman Pro to confirm, found 68 items on Super-Anti Spyware, 5 more on ad aware and no further detection's on Hitman Pro. The PC now runs fine with not Lockouts or Passwords.

Hope this helps everyone with this problem.

MICROSOFT / WINDOWS 7 SUPPORT WILL NEVER RING YOU UNLESS YOU HAVE REQUESTED THEM TO DO SO!!!!!!!!!!!!!!!!

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

64 answers

Sort by: Most helpful
  1. Anonymous
    2017-03-22T09:08:52+00:00

    You need to assertain a monetary value on data lost contact you're state attorney generals office chances are it's out of country and would require a federal subpoena to trace and locate the offenders.

    If by some chance they are in the US and using a spoofed number depending if their in you're state you can take them to court there but if their out of state you need the state attorney generals office still.

    I found this out when a company scammed me from Kansas I was in PA at the time needless to say it turned class action and they had to pay a heck of a lot in  reparations which would be the case here also.

    Edit

    I also forgot to mention even though they are using a bogus number it can still be traced.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Monkey57 3,535 Reputation points
    2017-02-24T05:47:14+00:00

    Known recent actions of Scammer/Blackmailer ->

    -Initiated contact of victim with a 'Browser HiJack'  

    -Identified themselves as a Microsoft Representative.

    -Victim's Credit card was immediate compromised and suspicious additional charges were caught, and cc was canceled by cc fraud department(these charges were reversed by the fraud department).

    -Scammed/scared victim into paying for unnecessary services (twice) ($600 per cc fraud department, cc fraud department credited victim, after being informed of timeline of scam.)

    -A respected Antivirus companies software was installed, as one of the methods, to maintain continued remote access by the scammer.

    Scammers (granted suspicious remote access) have been found to use a combination of legitimate tools and hacker tools (RATS) to maintain a direct connection to your device and/or con you with ...   Scans will not necessarily remove or find their compromises;  to the safety, security, and stability of your computer.

    "I hunt down these people "-> consider using a cheap Win10 device, that is easy to Clean Install...The Scammers know if you are using a virtual machine, and unfortunately you don't get to see the continuing scam, as they extort money from those unsuspecting....

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2016-06-18T12:05:52+00:00

    I just fixed this problem on a Win 7 desktop this week. I could not get into it at all. After reading the responses here I didn't see what I did to fix it listed...You have to physically be there to do this, I pulled the hard drive from the desktop & put it in a usb enclosure. Then I copied the contents of the RegBack as described earlier. After I finished I put it back in the desktop & started the computer. Worked like a charm!    The scammer on this one deleted all restore points also.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2016-05-05T15:10:40+00:00

    I have seen this type from scammers online. They lock up all your browsers so they can trick you in believing that your computer is locked up. Any time my browsers are locked up, the first task I do is to go to ctrl-alt-delete to bring up the task manager and click on the web browser and close the process. This might have to be done a few times. Run a virus and malware scan. Many times, it is the web browser that gets locked up and there is no virus in your system. I just open the web browser again and do not go back to that website that got your browser(s) locked up !

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2016-03-13T12:27:06+00:00

    I think MS should exclude this syskey tool as far just few people know it meanwhile it is a widespread scam for the last years. Where can we make such suggestions to MS?

    The tool is still useful in some environments where the additional layer of security can prevent unauthorized access to computers, requiring a 128-bit encryption key stored on a USB key can stop casual access from the inside.  If we have to make everything naive-proof we will be locked in our own homes for our own safety...without internet access because the internet is full of scams!

    John

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments