Windows 10: client had syskey installed on computer

Discus and support client had syskey installed on computer in AntiVirus, Firewalls and System Security to solve the problem; Hey, new guy here. Tom is my name. I have a client who's computer was hacked by a scammer, she allowed them access and then set a syskey on the... Discussion in 'AntiVirus, Firewalls and System Security' started by teebee, Oct 22, 2017.

  1. teebee Win User

    client had syskey installed on computer


    Hey, new guy here. Tom is my name.

    I have a client who's computer was hacked by a scammer, she allowed them access and then set a syskey on the computer. After she paid them they told her the password. They came back several times and extorted money from her. I've removed everything so they can't access the computer, but the syskey is still there.
    Questions:
    1) The data....is it encrypted through syskey? Or can it be copied to use on another computer or after a re-install of the OS (win10)?
    2) Can I remove the syskey, beings we know the password and un-encrypt things? (I'm thinking NOT)
    3) Being we have access and I have disabled all outside access, are we good to go as is? (again I'm thinking not as Win10 won't let me install the latest updates)

    Thank you in advance for the help.

    :)
     
    teebee, Oct 22, 2017
    #1

  2. Creators Update 1709 failing

    I am having the same problem failed update 1709. I have been told by troubleshooter that it has to do with a syskey. The syskey has to be removed so the version 1709 can be installed. I followed the directions to remove the syskey- but I'm not sure it
    worked. The upgrade keeps trying and failing - no error message. Anyway try checking the syskey.
     
    deborahcutone, Oct 22, 2017
    #2
  3. WiggeKing Win User
    Just enabled syskey on Windows 10 version 1703 stuck in boot screen

    So i enabled syskey on my windows 10 computer and no syskey doesent appear and its just stuck in the boot screen. What to do? I have no backups

    ***Post moved by the moderator to the appropriate forum category.***
     
    WiggeKing, Oct 22, 2017
    #3
  4. essenbe Win User

    client had syskey installed on computer

    What little I know, or think I know, about Syskey is, it is a registry feature of Windows for many years. It was originally designed for enterprise companies to restrict users from certain areas. If you have a system image of before someone installs the syskey, you can defeat it. If you have a registry backup from before syyskey was set, it can be restored. Windows keeps a backup of the registry. If you have not booted into Windows/ tried to boot into windows once it is realized that a syskey has been set, the backup registry can be restored. Once it is booted into, the syskey is usually a part of the backup registry.

    I would make sure we are dealing with a syskey and not something else. Even with a syskey installed, you should be able to boot into a rescue CD/USB and still have access to user files. Unless they have installed something else which gives them access to the machine, I wouldn't worry about them resetting it. I would recommend a good clean install to make certain. I know if it was my machine that would be the first thing I would do.

    The Registry Backup is located at C:\Windows\System32\config\RegBack and contains folders Default, SAM, Security, Software and System.

    Another option, while not foolproof, would be for you to set a syskey password. While a big pain, it would prevent others from setting one, in most cases.
     
    essenbe, Oct 22, 2017
    #4
  5. Brink
    Brink New Member
    Brink, Oct 22, 2017
    #5
  6. cereberus Win User
    The real issue is what else has been compromised. Advise your client, as an urgent prioriy, to change all online passwords (bank, amazon, paypal, ebay etc), and examine accounts for suspicious behavior.

    Your client may think that is overkill, but ask her if she can afford to take the risk.

    I also strongly advise clean installing from scratch, for same reasons.

    No amount of use of tools like malware removal can give you 100% certainty all is right.

    As you are undoubtedly a man of integrity, do you believe doing anything other than a complete reinstall is in your client's interests.

    You will (imo) provide a much better service if you help her backup valuable data, clean install and assist in reinstalling stuff if necessary. Do that and clients will always come back.
     
    cereberus, Oct 22, 2017
    #6
  7. teebee Win User
    Thank you so much for verifying what, I guess, I already knew.
     
    teebee, Oct 22, 2017
    #7
  8. cereberus Win User

    client had syskey installed on computer

    Data is usually ok. It is exe files etc that get infected. Infections of videos, photos etc is rare,word docs and excel etc less so.

    For most, it is photos that are the primary concern. You can scan data with a high degree of confidence.
     
    cereberus, Oct 22, 2017
    #8
  9. teebee Win User
    While copying her 'documents' file, I got a "Your infected" warning, while moving through the docs. A file with no real name ("file") or extension set it off. I shredded that file then proceeded to fine-tooth-comb all the copied files. Anything that looked suspect was shredded. I then did a clean install of Win10. I then Installed Malwarebytes, CCleaner and AVG, ran thorough scans before I copied her data back to the clean install. Then again once the data had been copied. I believe that we are clean and nearly back again to where she was before this all happened.

    Thank you all once again, for proving to me that my gut was telling me the right things to do.
     
    teebee, Apr 5, 2018
    #9
Thema:

client had syskey installed on computer

Loading...
  1. client had syskey installed on computer - Similar Threads - client syskey installed

  2. syskey and install / upgrade of windows 7 to 10

    in Windows 10 Installation and Upgrade
    syskey and install / upgrade of windows 7 to 10: I m trying to upgrade my operating system and am having difficulty in removing the syskey password on my machine to allow this. Is there a way to circumvent this?...
  3. syskey

    in Windows 10 Installation and Upgrade
    syskey: how do I remove Syskey from Windows 10 so that I can upgrade windows 10? https://answers.microsoft.com/en-us/windows/forum/all/syskey/43bbc64d-048f-49a9-94b7-99b4e1e84392
  4. Syskey Removal

    in Windows 10 Installation and Upgrade
    Syskey Removal: I activated SysKey and have the password on an early version of Windows 10 1703. Because Syskey is no longer supported I cannot upgrade to the latest version. Will windows refresh remove the syskey and is it the best procedure for removing Syskey and starting with a clean...
  5. Syskey virus

    in AntiVirus, Firewalls and System Security
    Syskey virus: Greetings all, My mother in law was hit by a phone scammer that resulted in her giving away her PW and the hooligan put a syskey on the computer. We can't even get to a log in screen and I have tried booting in safemode. Nothing happens. It just has that enter password box...
  6. i cant install updates due to something to do with a 'syskey'

    in Windows 10 Installation and Upgrade
    i cant install updates due to something to do with a 'syskey': can't install updates https://answers.microsoft.com/en-us/windows/forum/all/i-cant-install-updates-due-to-something-to-do-with/48002258-ba0c-4273-88b3-f1374463246e
  7. syskey removal

    in Windows 10 Installation and Upgrade
    syskey removal: how do I remove a syskey? https://answers.microsoft.com/en-us/windows/forum/all/syskey-removal/8cb86c91-f2e9-458c-beaf-83d5feebaba3
  8. windows syskey

    in Windows 10 Installation and Upgrade
    windows syskey: I received the following message when trying to update my windows 10 installation: PC configured with an external syskey the new OS no longer supports. Need to change PC configuration to use a locally stored syskey. Help is needed!!...
  9. Syskey

    in Windows 10 Installation and Upgrade
    Syskey: Hello, thanks for sparing time for my issue . I had syskey in my windows 10 operating system and I tried to update but in the final stage it did not go through because of the Syskey. so I tried to disable syskey but guess I did something wrong and it asked me to change my...
  10. inquiry on the SYSKEY feature

    in AntiVirus, Firewalls and System Security
    inquiry on the SYSKEY feature: ive never bothered to study about syskey until recently.. is it better to save the program onto flash drive? my pc was hijacked last year where a malicious program took control over it..so thats what got me thinking..*Shock 94468