Scammer locked PC with Syskey startup password

  1. Posts : 26
    Windows 10

    Scammer locked PC with Syskey startup password

    My older, non-computer savvy Dad was just taken by the oldest trick in the book. Hoping someone can help out.

    System: Toshiba Laptop. Windows 10 Home.

    Scammer from "AOL" calls my dad and says his computer is corrupted. My Dad (sadly) gave him remote access. Scammer installed a password using Syskey startup. Now, on startup, Dad gets a black screen with message "This computer is configured to require a password in order to start up. Please enter the startup password below."

    He's tried to get into the F8 menu by turning on PC and pressing F8, but the system goes straight into the password.

    Can anyone help? Is there an easy fix I can help my Dad do remotely by talking him over it the phone? Scammer locked PC with Syskey startup password-scammer.jpg
      My Computer

  2. Berton's Avatar
    Posts : 11,282
    Win10 Pro Versions 2004 and 2009/20H2, Win10 Pro IP_Dev, Win10 Home 1909

    Without the password it usually means a clean reinstalling of Windows. Haven't seen or heard of it yet but possible the BIOS has been passworded, usually has 2, one for starting the computer and the other for entering the BIOS to make changes, they are separate where can have one but not the other.
      My Computers

  3.   My Computer

  4. essenbe's Avatar
    Posts : 12,599
    Windows 10 Pro

    First, do not try to boot into Windows again. It will depend on how aggressive the scammers were.

    You can boot to a Windows 10 installation USB/DVD drive and attempt to do a system restore. System Restore Windows 10 - Windows 10 Performance Maintenance Tutorials

    If that does not work, as a last resort you can try this. It will depend if the registry backup was altered by the scammer and if the backup was altered by trying to boot into Windows.

    You can use a Live Linux DVD/USB or another type USB. Many of us like the Windows 10 recovery ISO Windows 10 Recovery Tools - Bootable Rescue Disk - - Windows 10 Forums
    1.POWER OFF your PC immediately.
    2.Boot to external media of some sort (NOT your Windows installation) and navigate to the %SYSTEMROOT%\system32\config folder.
    3.Backup the registry hives in this folder to a temporary location. The files are:

    4.Navigate to %SYSTEMROOT%\system32\config\RegBack as mentioned earlier.
    5.Copy all registry hives from this folder (the same files as listed above) into the %SYSTEMROOT%\system32\config folder.
    6.Reboot the PC.

    EDIT: Looks like I was too slow
      My Computers

  5. Posts : 26
    Windows 10
    Thread Starter

    Thanks for the rapid replies. The Windows community is great!

    The only problems remain:

    * My Dad doesn't have a way to burn a recovery CD or USB. He only has one PC (the one that's infected).
    * I'm 2000 miles away from my Dad so must assist him over phone.
    * Sounds like there's no "simple way" to reset or reinstall Windows?
      My Computer

  6. essenbe's Avatar
    Posts : 12,599
    Windows 10 Pro
      My Computers


  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:29.
Find Us

Windows 10 Forums