Link to home
Start Free TrialLog in
Avatar of somthingscary
somthingscary

asked on

Windows xp administrator password forgottem

I forgot my adminstrator password and now i can't log into my account, i called the help people but they aren't allowed to hack into my computer, how do i find out or change my password, before tom.?
ASKER CERTIFIED SOLUTION
Avatar of CrazyOne
CrazyOne
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of anovickis
anovickis

I can't believe how many people ostentatiously suggest that reinstalling XP is a viable alternative.

Have you any idea how many installed programs need to be reinstalled and reconfigured ???????

XP (microsoft) has given absolutely 0 thought to this in a consumer friendly environment.

Almost makes me want to de-microsoft most of my hardware.




Avatar of zenlion420
No comment has been added lately, so it's time to clean up this TA.
I will leave the following recommendation for this question in the Cleanup topic area:

SPLIT: CrazyOne{7761822} & SunBow{7771111}

Please leave any comments here within the next seven days.
PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!

zenlion420
EE Page Editor
well, what you need to do is
1.download NTFSDOS
2. now format your floppys to a boot disk and extract NTFSDOS on it
3. put it into your computer, than start the computer
4. you computer will load up in NTFSDOS and you now need to make  directoy in dos
4. than go to C:/WINNT/system32/config and than copy the sam file to your new directory also in the same folder copy a file called system
5. you now need to download a bunch of programs. these programs are; LC4 or also called l0ftcrack, PWdump3, and Sam Inside.
6. open up sam inside and import sam and system.
7. now export them to a pwdump file.
8. import the pwdump file in LC4.
9. decrypt it, this could take an extreemly long time, depending on the speed of your computer, on an AMD athlon 2400 or a pentium 4 2.4 GHz it will go at about 5 million keys per second and take about 4 hours.
10. when all that is done you got your password

hope this helps |--Codac X--|
If you are a good Linux Developer, you can use the Linux boot floppy and then edit the SAM file found in the  C:/WINNT/system32/config folder This does not matter if you have an NTFS partition or FAT/16/32.
*** advertising removed by Netminder, Site Admin ***
See if this helps

Most of these are bootable floppies that give you a backdoor to the SAM registry hive and allows you change the admins password.

LC3 is the latest version of the award-winning password auditing and recovery application, L0phtCrack. It provides two critical capabilities to Windows® network administrators:
Free 15 day trial
http://www.atstake.com/research/lc3/index.html

Scott
http://www.avidware.net/MAS-90-Consultant.asp

depending on how strong a password you chose it could take weeks or even months to brute-force it, the easiest way to do this is to get out your dos boot disk, navigate to the appropriate folder (C:\WINDOWS\SYSTEM32\CONFIG) then type the following command
**before you do this note that it will reset all the passwords and remove all of the accounts**

REN C:\WINDOWS\SYSTEM32\CONFIG\SAM AAA (you can rename it to any three letter word) then you can delete it
DEL C:\WINDOWS\SYSTEM32\CONFIG\AAA (it doesn't really matter you can leave it there if you want)

This works for windows 2000 anyway, i'm not entirely sure of the WINDOWS XP default passwords i assume they are just Administrator and guest both with blank passwords. By the why LC5 is the latest version of l0phtcrack it also costs a lot of money, (if you are not a network admin etc.)you'd be better off with cain and abel (www.oxid.it)
in order to use a brute-forcer or password cracker you are going to need to get a copy of the sam and system files, the problem is that when you are in windows mode the sam and system files cannot be accessed the solution to this is to boot in an alternate operating system, you could use MS-DOS but the problem is that the system file is around 2/3 megabytes and will never fit on a floppy disk (that's not entirely true, you could compress it) also if you have a second hard drive lying around you could try copying the files you need to that.
In my opinion the best way to do this is to use a linux live distro. This is an entire operating system that fits on a single cd, it also boots from the cd so there is no need to install or partition your hard-drive, i recomment knoppix, it can be downloaded from www.linuxiso.org for free naturally. once you have knoppix you can put it into your computer and reboot, then open up your windows partition, navigate to C:\WINDOWS\SYSTEM32\CONFIG then copy the SAM and system file to a flash drive.  Once you have done that you can go to another computer running windows, get a copy of SAMinside this is a program that breaks the syskey protection that prevents you from accessing the SAM file (by the way you don't need the full version of SAMInside you can just copy the LM and NT hash to a text file in the following format. USERNAME:500(may not be 500):LMHASH:NTHASH::: then you can import it into a password cracker, or you could use this site: http://sarcaprj.wayreth.eu.org/ you just put your nt and lm hash into the boxes provided along with you  email, your password will be cracked within a few hours, well it'll only take a few minutes for it to b cracked but the password has to be sent to you as well etc. The reason that this is so fast is that it uses rainbow tables which are precomputated hashes. By the way if you didn't pick a secure password eg. a dictionary word or a password with less 7 characters and only one character set i would advise you to run a dictionary attack and a brute-force yourself before using the link above. hope this helps :)

If you have a user with admin rights got to: control panel Administrative Tools, computer management, local users and groups, users, right click administrater, select set password, proceed, enter the password, confirm it and click ok.


There is a program that goes on a floppy disk and will reset the password but it may screw your computer up

from knoppix (linux on a cd) is free and can be downloaded copy the sam file to a floppy disk, usb flash drive or network place.
Use a program like lc5 to crack it
hacking FUN!
Although this can legally be determined as Illegal, there are times when administrators must get into a machine when all the passwords have been changed. I do not believe that the tone of this forum is to do illegal things, just administraive tasks, so Robnhood, chill out man!!!
My comment was directed very specially at someone who at first glance appeared to be looking for the imformation in an unethical fashion.

Robnhood - I ap[ologize for the comment, I did not see that and I should have read your comments above. Thank you for replying and watching out for everyone else!!
No problem.
There is an alterntive, but you might lose all of your data.. The solution is to re-install it.
Instructions
http://home.eunet.no/~pnordahl/ntpasswd/bootdisk.html

image files
http://ntpass.blaa.net/bd011022.zip  (1.4MB - Bootdisk image, date 011022)
http://ntpass.blaa.net/sc011022.zip (~700KB) - SCSI-drivers (011022)
This is a utility to (re)set the password of any user that has a valid (local) account on your NT system, by modifying  the crypted password in the registrys SAM file.
http://home.eunet.no/~pnordahl/ntpasswd/

image writer
http://home.eunet.no/~pnordahl/ntpasswd/rawrite2.zip

Another one
Change administrator password on NT/2000, without knowing it!!! Bootdisk...
http://www.thomasmathiesen.com/itak/html/software.html

image file
http://www.thomasmathiesen.com/filez/sw/external/linuxbootimage.zip

image writer
http://www.thomasmathiesen.com/filez/sw/external/imagewriter.zip
--------------------------------------

Another one
http://www.pc-pipeline.com/modules.php?op=modload&name=Downloads&file=index&req=getit&lid=6

Run it to create a boot floppy then follow the instructions. If you choose to do this then you are doing this at your own risk. Just change the admin pw and login then change the account pw's that you desire. Make sure you have a floppy disk in the floppy drive and let the program create the boot floppy. Now restart the machine a let it boot from the floppy. Now follow what it instructs you to do.

Use it like a bootdisk.

----------------------------------
NTAccess can replace the administrator password of a Windows XP, Windows NT or Windows 2000 system by rebooting the computer with a special set of boot disks or CD-ROM (XP only). This is useful if you forgot the administrator password and cannot access the Windows XP/2000/NT system.
http://www.sunbeltsoftware.com/product.cfm?id=265


LC3 - The Password Auditing and Recovery Application
Award-winning password auditing and recovery application. Free trial available
http://www.atstake.com

Locksmith
http://www.winternals.com/products/repairandrecovery/locksmith.asp

Windows XP / 2000 / NT Key is a program to reset Windows XP / 2000 / NT security if Administrator password, secure boot password or key disk is lost.
http://www.lostpassword.com/windows-xp-2000-nt.htm

Or you could, if you have a FAT32 file system, just boot to a Win98 bootdisk and rename the SAM file (registry Hive) in the C:\WINNT\system32\config folder to something else. Of course this will remove all accounts on the system and you will need to rebuild them. If you are using NTFS then boot to the Win2000 CD and do this from the Recovery console. This potentiall destructive so use only as a last resort

For XP
Windows XP Tip: Password Recovery Disk
Take preventive measures against losing user-level passwords
http://www.techtv.com/callforhelp/answerstips/story/0,24330,3356093,00.html


yes ,! now we have lc5! This is a real good!
Get yourself a copy of Hirens boot cd. Amongst the 100's of utilities it has for troubleshooting and repair it also comes with ntfs4dos and the tools to reset the password. Basicly it is a linux boot cd with a bunch of utilities. Hint  when you change the password leave it blank. Then reboot and change it to what you want.

http://62.253.162.19/hiren.thanki/bootcd.html

here is a list of thinks it can do

Partition Tools
 
Partition Magic 8.2
Best software to partition hard drive

Paragon Partition Manager 5.5
Universal tool for partitions

Partition Commander 8.01
The safe way to partition your hard drive,with undo feature

Ranish Partition Manager 2.44
a boot manager and hard disk partitioner.

The Partition Resizer v1.3.4
move and resize your partitions in one step and more.

Smart Fdisk 2.05
a simple harddisk partition manager

SPecial Fdisk
SPFDISK a partition tool.

eXtended Fdisk
XFDISK allows easy partition creation and edition
 
Disk Clone Tools
 
Drive Image 2002
Best software to clone hard drive

Norton Ghost 8.0
Similar to Drive Image

Partition Saver 2.80
A tool to backup/restore partitions.
 
Antivirus Tools
 
F-Prot Antivirus 3.14e
Very good virus scanner (with ntfs support and easy to use menu)

McAfee Antivirus 4.32
a virus scanner (with ntfs support and easy to use menu)
 
Recovery Tools
 
Offline NT/2K/XP Password Changer
utility to reset windows nt/2000/xp administrator/user password.

Active Partition Recovery 2.1
To Recover a Deleted partition.

Active Uneraser 2.1.1
To recover deleted files and folders on FAT and NTFS systems.

Ontrack Easy Recovery Pro 6.3
To Recover data that has been deleted/virus attack

Winternals Disk Commander 1.1
more than just a standard deleted-file recovery utility

TestDisk 4.5.
Tool to check and undelete partition.

Lost & Found 1.06
a good old data recovery software.
 
Testing Tools
 
DocMemory 2.0
RAM Test utility

GoldMemory 5.07
RAM Test utility

Memtest 2.00
PC Memory Test

System Speed Test 4.78
it tests CPU, harddrive, ect.

PC-Check 5.50
Easy to use hardware tests

The Troubleshooter 5.02
all kind of hardware testing tool

PC Doctor 3.0
a benchmarking and information tool

Test Cpu/Video/Disk 5.6
a tool to test cpu, video, and disk
 
Hard Disk Tools
 
Hard Disk Diagnostic Utilities
Seagate Seatools Desktop Edition 2.10
Western Digital Data Lifeguard Tools
Maxtor PowerMax 4.6
Fujitsu HDD Diagnostic Tool 6.10
Samsung HDD Utility 1.11
IBM/Hitachi Drive Fitness Test
MHDD 2.9

HDD Regenerator 1.41
to recover a bad hard drive

Ontrack Disk Manager 9.57
Disk Test/Format/Maintenance tool.

Norton Disk Doctor 2002
a tool to repair a damaged disk, or to diagnose your hard drive.

Norton Disk Editor 2002
a powerful disk editing, manual data recovery tool.

Active Kill Disk 1.1
Securely overwrites and destroys all data on physical drive.

SmartUDM 2.00
Hard Disk Drive S.M.A.R.T. Viewer.
 
System Information Tools
 
Aida16 2.12
a system information tool, extracts details of all components of the PC

PCI and AGP info Tool
The PCI System information & Exploration tool.

System Analyser version 5.3b
View extensive information about your hardware

Navrátil Software System Information 0.58
High-end professional system information tool

Astra 4.20
Advanced System info Tool and Reporting Assistant

HwInfo 4.93
a powerful system information utility

PC-Config 9.33
Complete hardware detection of your computer

SysChk 2.46
Find out exactly what is under the hood of your PC
 
Dos File Managers
 
Volkov Commander 4.99
Dos File Manager with LongFileName/ntfs support
(Similar to Norton Commander)

Dos Command Center 5.1
Classic dos-based file manager.

File Wizard 1.35
a file manager - colored files, drag and drop copy, move, delete etc.

File Maven 3.5
an advanced Dos file manager with high speed PC-to-PC file
transfers via serial or parallel cable

FastLynx 2.0
Dos file manager with Pc to Pc file transfer capability

LapLink 5.0
the smart way to transfer files and directories between PCs.

Mini Windows 3.11
Back to old days, use it as a file manager
 
Other Tools
 
DosCDroast beta 2
Dos CD Burning Tools

Ontrack Data Advisor 5.0
Powerful diagnostic tool for assessing the condition of your computer

Bootmagic 8.0
This tool is for multi boot operating systems

Picture Viewer 1.94
Picture viewer for dos, supports more then 40 filetypes.

QuickView Pro 2.51
movie viewer for dos, supports many format including divx.

Universal TCP/IP Network 4.80
MSDOS Network Client to connect via TCP/IP to a Microsoft based
network. The network can either be a peer-to-peer or a server based
network, it contains 67 different network card drivers

NTFS Dos Pro 5.0
To access ntfs partitions from Dos
 
Dos Tools
 
NTFS Dos Pro 5.0
To access ntfs partitions from Dos

USB CD-Rom Driver 1
Standard usb_cd.sys driver for cd drive

Universal USB Driver 2
Panasonic v2.06 ASPI Manager for USB mass storage

Interlnk support at COM1
To access another computer from COM port

Interlnk support at LPT1
To access another computer from LPT port

and too many great dos tools
very good collection of dos utilitiesextract.exe pkzip.exe pkunzip.exe unrar.exe rar.exe
ace.exe lha.exe gzip.exe scandisk.exe scanreg.exe
attrib.com deltree.exe xxcopy.exe diskcopy.com dskimage.exe
undelete.com edit.com editbini.exe fdisk.exe fdisk2.exe
freefdsk.exe lf.exe killdisk.exe delpart.exe wipe.com
zap.com format.com mhdd.exe find.exe sort.exe
move.exe more.com hex.exe debug.exe regedit.exe
split.exe label.exe mem.exe mi.com mhdd.exe
xmsdsk.exe doskey.exe duse.exe sys.com mbrwork.exe
bootpart.exe bootsave.exe bootrest.exe bootfix.com sbminst.exe
cmos.com cmospwc.exe cmospwd.exe ibios.exe biosdtct.exe
killcmos.com cpuid.exe smartdrv.exe loadlin.exe guest.exe
intersvr.exe interlnk.exe mouse.com lfndos.exe doslfn.com

 
Windows Tools
 
SpaceMonger 1.4
keeping track of the free space on your computer

Drive Temperature 1.0
Hard Disk Drive temperature meter

Disk Speed1.0
Hard Disk Drive Speed Testing Tool

MemTest 1.0
a Memory Testing Tool

PageDfrg 2.21
System file Defragmenter For NT/2k/XP

Split Join 1.3.3
a Small File Split-Join Tool

Ghost Image Explorer 7.0
to add/remove/extract files from Ghost image file

DriveImage Explorer 5.0
to add/remove/extract files from Drive image file

Active File Recovery 2.0
a tool to recover deleted files

Restoration 2.5.14
a tool to recover deleted files

Startup Control Panel 2.8
a tool to edit startup programs

TCPView 2.34
a detailed listings of all TCP and UDP endpoints

Unknown Devices 1.2
helps you find what those unknown devices in Device Manager really are

Ad-Aware 6.181
find and remove spyware, adware, dialers etc. (a must have tool)
 
all you have to do is go to the command prompt, then type in the command > net user administrator password <- password being the new password :)
~DeMyNtEd~
Regarding the length (both time and size ) of this thread. It has made the top of the list on expertsexchange website and is way up there on page views.. They probably have not closed the thread because it is bringing in new people.  Despite the fact that solutions have been posted to death, this thread will most likely exist as long as it serves the website. Even as i viewed this page tonight the previous post appeared when i refreshed. I hope those who 'subscribed' to get email notification have found a way un unsub. or filter out because this thread may be here awhile. If Fall : Happy Thanksgiving else if Winter: Happy Christmas else if Spring: Happy Easter else if Summer: Happy Independence Day.
What if I can't change the boot sequence at the BIOS directory to move off the hard drive and boot from a floppy or a cd drive?  

I am an adminstrator who changed the password, and misstyped in the darn thing and now can't get in.  I have a utility that will let me change it, but it requires being able to change the boot sequence, and the cd and floppy choices are not in the bios list.

Thanks,

Andrea
how was windows installed if you can't boot from cd?

the only way i can see to solve our problem is to put the harddrive into another computer (slave) and then just delete the sam file from your drive.

C:\WINDOWS\system32\config\SAM
Props for at least locking down your BIOS. All too often admins forget to do that. Nice one with mistyping the password though. :D

I suggest looking up your motherboard's manual on the web and resetting your BIOS. You'll have to temporarily move a jumper for sure and possibly remove a CMOS battery.

After that the boot disks/cd's are the way to go.
Er - upgrade and flash your BIOS and/or recheck to see ifyou're actually toggling the other options in the Boot-up sequence.
I am quite amazed at the length people will go to in order to reset the Admin password. Thought I would post this article that has been around for quite some time, and is much, much easier, although Knoppix is a good tool as well.

 
 
I Forgot My Administrator Password!
by Vic Ferri
 
Can't Log On to Windows XP?

If that’s your only problem, then you probably have nothing to worry about. As long as you have your Windows XP CD, you can get back into your system using a simple but effective method made possible by a little known access hole in Windows XP.

This method is easy enough for newbies to follow – it doesn’t require using the Recovery Console or any complicated commands. And it’s free - I mention that because you can pay two hundred dollars for an emergency download of Winternals ERD with Locksmith which is a utility for unlocking lost Windows passwords. See here http://www.winternals.com/products/repairandrecovery/locksmith.asp

ERD is an excellent multi purpose product, but you should know it is not a necessary one if you have a healthy system and your sole problem is the inability to logon to Windows due to a forgotten password. Not necessary because you can easily change or wipe out your Administrator password for free during a Windows XP Repair. Here’s how with a step-by-step description of the initial Repair process included for newbie’s.

1. Place your Windows XP CD in your cd-rom and start your computer (it’s assumed here that your XP CD is bootable – as it should be - and that you have your bios set to boot from CD)

2. Keep your eye on the screen messages for booting to your cd Typically, it will be “Press any key to boot from cd”

3. Once you get in, the first screen will indicate that Setup is inspecting your system and loading files.

4. When you get to the Welcome to Setup screen, press ENTER to Setup Windows now

5. The Licensing Agreement comes next - Press F8 to accept it.

6. The next screen is the Setup screen which gives you the option to do a Repair.

It should read something like “If one of the following Windows XP installations is damaged, Setup can try to repair it”

Use the up and down arrow keys to select your XP installation (if you only have one, it should already be selected) and press R to begin the Repair process.

7. Let the Repair run. Setup will now check your disks and then start copying files which can take several minutes.

8. Shortly after the Copying Files stage, you will be required to reboot. (this will happen automatically – you will see a progress bar stating “Your computer will reboot in 15 seconds”

9. During the reboot, do not make the mistake of “pressing any key” to boot from the CD again! Setup will resume automatically with the standard billboard screens and you will notice Installing Windows is highlighted.

10. Keep your eye on the lower left hand side of the screen and when you see the Installing Devices progress bar, press SHIFT + F10. This is the security hole! A command console will now open up giving you the potential for wide access to your system.

11. At the prompt, type NUSRMGR.CPL and press Enter. Voila! You have just gained graphical access to your User Accounts in the Control Panel.

12. Now simply pick the account you need to change and remove or change your password as you prefer. If you want to log on without having to enter your new password, you can type control userpasswords2 at the prompt and choose to log on without being asked for password. After you’ve made your changes close the windows, exit the command box and continue on with the Repair (have your Product key handy).

13. Once the Repair is done, you will be able to log on with your new password (or without a password if you chose not to use one or if you chose not to be asked for a password). Your programs and personalized settings should remain intact.

I tested the above on Windows XP Pro with and without SP1 and also used this method in a real situation where someone could not remember their password and it worked like a charm to fix the problem. This security hole allows access to more than just user accounts. You can also access the Registry and Policy Editor, for example. And its gui access with mouse control. Of course, a Product Key will be needed to continue with the Repair after making the changes, but for anyone intent on gaining access to your system, this would be no problem.

And in case you are wondering, NO, you cannot cancel install after making the changes and expect to logon with your new password.

Cancelling will just result in Setup resuming at bootup and your changes will be lost.

Ok, now that your logon problem is fixed, you should make a point to prevent it from ever happening again by creating a Password Reset Disk. This is a floppy disk you can use in the event you ever forget your log on password. It allows you to set a new password.

 
 Source: http://pubs.logicalexpressions.com/Pub0009/LPMArticle.asp?ID=305

<Note, I have also seen this work on XP using a Windows 2000 CD.>
I heard you can just boot up in safemode (F8, select safemode) and change it, but I haven't tried it before...
I'm trying to fix a friend's computer, but I need the Admin password to even use Repair, as it asked for it, and the friend doesn't have a clue what it is.
Best idea is if you can get hold of software called either..

Cia Commander

http://www.matcode.com/ciacmd.htm

Or

Erd Commander 2005

http://www.winternals.com/

Use it at work all the time students messing around works a treat.......
Three ways right off hand:

1) Use WinXP rescue option on install CD to access the C drive. Then use "copy" to copy SAM to floppy
2) Use bootable knoppix CD. Copy SAM to floppy
3) Use ReadNTFS floppy to mount c drive then use "copy" to copySAM  to floppy

Once you have SAM file boot into working PC and run through LC4.

dave
hic many many menthod ....
hi lc4 can crack but if password <15char u can user rainbow table with that can use lostest time
or use active password changer in hiren's boot cd << this fast