Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 204
  • Last Modified:

Windows 7 Password recovery and OS mirrored drives

A new client called today and asked if I could recover there password on a Win 7 machine with mirrored drives on a workgroup.  The last tech they called tried to use a Password Recovery tool but it did not work.  He told them it was because the drives where mirrored.  If I use the "Sticky Key" solution or tried copying cmd.exe to another program using Ubuntu or a Windows PE disk do I run the risk of data corruption?
0
genusys
Asked:
genusys
2 Solutions
 
John HurstBusiness Consultant (Owner)Commented:
If they forgot the password and if the admin account remains enabled as it should be, then you cannot recover it with Windows itself.

Some people have had success with PogoStick but I have not tried it myself.

http://pogostick.net/~pnh/ntpasswd/
0
 
andreasSystem AdminCommented:
The pogostick / pnordahl thing is worth a try. According to the changelog they support dynamic disks and disk mirroring at least in some cases.

You should make a backup of the machine beforehand in case it goes wrong and cause data corruption.

If it fails with drives mirrored you might try to remove one disk (simulate failure) and the ntry tu run the pogostick tool again on the broken mirror. then try to boot your windows and see if it was successful. if yes, blank out the removed disk, e.g. with linux, then re add to the windows machine and re mirror again.
0
 
genusysAuthor Commented:
Thank you for the advise. I am supposed to be at the client on Tuesday. I will update everyone after. I will also download Pogostick and play around with it before I go. I too, was thinking about removing one disk and acting as if there was a disk failure.  Then I could use either Pogostick or windows repair + copy cmd.exe to easy access or stickykeys to fix it.
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
VB ITSSpecialist ConsultantCommented:
If the default local Administrator account was never used or modified then you can also try booting up the machine in Safe Mode as this will enable the account. The password is blank by default.
0
 
genusysAuthor Commented:
I will try that as well. Thank you
0
 
nobusCommented:
0
 
McKnifeCommented:
Some important notes:
Under normal circumstances, "pogostick utility" always works. I have never seen a single case where it didn't. But: if you have software mirrored drives (dynamic disks), then there might be a small chance that it will fail. The documentation mentions dynamic disk support since 2008 but it is unclear if it works flawless. Worth a try anyway.
The "sticky key method" you mention - what should that be, the utilman.exe, you mean? That always works. And would be my second best option.
Then finally a comment on safe mode: no, safe mode does not activate ANY account. The difference is simply that on safe mode of win xp, the local admin account is being displayed on the logon screen, but it won't activate. If it is deactivated before, it still won't display.
0
 
genusysAuthor Commented:
My Sticky Key/Utilman/Magnifyer are the same thing.  I've used it before with success.Thanks for the info on Pogostick.
0
 
Rob GMicrosoft Systems EngineerCommented:
I used/use KonBoot which works fine with most versions of windows, though it will not display the previous password, it will allow you to login as an admin and change the previous password to something else, so that you can log into the system.

I believe the x86 version.. windows Xp and prior is free, while the x64 version vista and newer is a paid version.

I would look into that.. It does work, and is a great tool for any office admin..
0
 
genusysAuthor Commented:
Went to the client yesterday. Windows repair would not boot to Advanced Repair options. Pogostick could not load it's kernal. Both options where tried with a USB and CD.  Told client they need to rebuild the PC. Managed to get a data backup using a Ubuntu distro. Thanks to all for their help.
0
 
McKnifeCommented:
Ok, for the next time: "utilman.exe" is the most reliable method and it can be used right awy from any setup (win7/8.x).
0
 
genusysAuthor Commented:
Went to the client yesterday. Windows repair would not boot to Advanced Repair options. Pogostick could not load it's kernal. Both options where tried with a USB and CD.  Told client they need to rebuild the PC. Managed to get a data backup using a Ubuntu distro. Thanks to all for their help.  Clearly there was an underlying issue. Rather than waste client $'s futzing around a rebuild of what is essentially a data store makes the most sense.
0

Featured Post

The Lifecycle Approach to Managing Security Policy

Managing application connectivity and security policies can be achieved more effectively when following a framework that automates repeatable processes and ensures that the right activities are performed in the right order.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now