[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Locked out

Posted on 2004-04-07
5
Medium Priority
?
151 Views
Last Modified: 2013-12-04
I have a windows 2000 machine that had the Administrator account renamed.  The owner has forgoten the password to all three local accounts on the system.  I copied the SAM ran LoPht against it and deciphered three passwords. I have attempted to log onto the machine using the three accounts and corresponding  passwords, however the OS will not authenticate.  I attempted ERD/Console recover, however that requires the Administrator account to be named administrator.  At all cost,  I need to avoid a re-install.  I have imaged the hard disk.  Any help most appreciated.

pmobley
0
Comment
Question by:pmobley
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 24

Accepted Solution

by:
R_Rajesh earned 2000 total points
ID: 10776778
0
 
LVL 6

Expert Comment

by:DanniF
ID: 10777926
I had the same problem the other day and this tool saved my a$$:

http://home.eunet.no/~pnordahl/ntpasswd/

Simple floppy boot diskette.

Real easy to use and I have now used it on 3 different machines and it has never failed.

Hope this helps,

Daniel F.
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 10780061
If you are unsure as to which account is the administrators... it has a SID of 500. You can use these tools to get that information, and you don't have to have any special privledges.
http://www.chem.msu.su/~rudnyi/NT/  The disk mentioned above an also linked in another thread above is a good util, and it will tell you what account has the SID of what. Little word of caution, DO NOT USE the "TURN OFF SYSKEY" feature of that disk. It is not necessary, ever. I suggest you try it on your ghosted image first, to get fimilar with the disk.

L0pht will also tell you I believe, the sid, it will crack the case sensitive pass (NTLM) as well as the case insensitive (lanman aka LM) hash's
-rich
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question