{"id":217,"date":"2013-04-10T10:57:31","date_gmt":"2013-04-10T15:57:31","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=217"},"modified":"2015-06-26T13:37:43","modified_gmt":"2015-06-26T18:37:43","slug":"solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/casestudies\/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout\/","title":{"rendered":"SOLUTION: &#8220;This is Microsoft Support&#8221; telephone scam &#8211; Computer ransom lockout"},"content":{"rendered":"<p>A trend of the past couple of years has been for scammers to contact computer owners\u00a0<em>directly via telephone\u00a0<\/em>in the United States in an effort to convince them that there is a problem with their PC and they&#8217;ll need to pay to have it fixed. \u00a0In general, these people cannot fix anything, and instead they merely charge exorbitant fees for absolutely nothing. In other words, they scam you.<\/p>\n<p>The call generally goes something like this:<\/p>\n<ol>\n<li><span style=\"line-height: 15px;\">A foreigner with a thick Indian accent identifies himself as a member of Microsoft Support or similar.<br \/>\n<\/span><\/li>\n<li>He informs you that you have a number of critical problems with your PC and that you will need to have it fixed.<\/li>\n<li>To convince you, he offers to connect remotely and pulls up your Event Log (eventvwr.msc). \u00a0He then filters for Warnings, Errors, and Critical events and uses that as evidence that your PC will soon fail to work correctly if you do not pay him to correct it.<\/li>\n<\/ol>\n<p>The astute among you have probably already sensed that something here is seriously wrong, and it&#8217;s not your PC. It&#8217;s the fact that someone is <em>calling you\u00a0<\/em>to tell you there is a problem with your computer. <strong>No one will ever do that. The only way they could possibly know there is a problem is by hacking or guessing.<\/strong><\/p>\n<p>In this case, it&#8217;s mere guesswork, and it&#8217;s not even correct most of the time. The Event Log is <i>supposed\u00a0<\/i>to log warnings and errors, and even on the healthiest of PCs there are plenty of Error Events that can be safely ignored, as they often don&#8217;t amount to anything. The important thing to remember is to\u00a0<strong>never trust someone\u00a0<\/strong>who calls you about a problem with your PC, and\u00a0<strong>never, EVER\u00a0<\/strong>let them connect remotely to your PC.<span style=\"text-decoration: underline;\"><br \/>\n<\/span><\/p>\n<p>If you\u00a0<strong><em>do<\/em>\u00a0<\/strong>make the mistake of letting them connect, but then you happen to get cold feet and refuse to pay the $180+ they request via credit card, the next thing that happens isn&#8217;t pretty. This scammer proceeded to actually follow through on his promise of the PC &#8220;not working&#8221; if they don&#8217;t agree to have him fix it, and so in a few quick steps, behind the user&#8217;s back, he enacted what is known as SysKey encryption on the SAM registry hive.<\/p>\n<p>SysKey encryption is a little-known feature of Windows which allows administrators to lock out access to the Security Accounts Manager (SAM) registry hive so that login specifics cannot be stolen and the PC cannot be accessed without knowing the proper credentials. The problem is, unlike other scams, there is no way around the problem; you can&#8217;t simply remove the password, as the actual SAM hive has been encrypted entirely by the process. If your Windows installation has had SysKey activated, you&#8217;ll see the following message:<\/p>\n<blockquote><p>Startup Password<\/p>\n<p>This computer is configured to require a password in order to start up. Please enter the Startup Password below.<\/p><\/blockquote>\n<p>The window which appears looks like this:<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-220 aligncenter\" title=\"SysKey Encryption\" src=\"http:\/\/triplescomputers.com\/blog\/wp-content\/uploads\/2013\/04\/syskey.png\" alt=\"This computer is configured to require a password in order to start up. Please enter the Startup Password below.\" width=\"347\" height=\"171\" srcset=\"https:\/\/www.triplescomputers.com\/blog\/wp-content\/uploads\/2013\/04\/syskey.png 347w, https:\/\/www.triplescomputers.com\/blog\/wp-content\/uploads\/2013\/04\/syskey-300x147.png 300w\" sizes=\"auto, (max-width: 347px) 100vw, 347px\" \/><\/p>\n<p>The ONLY solution is to find a clean copy of the registry hives from before this occurred. This scammer knew this, however, and as such, he took an extra step to block any repair or recovery attempts: he\u00a0<strong>deleted all System Restore points on the machine<\/strong>, which normally house backup copies of the registry hives.<\/p>\n<p>Unfortunately for him, I&#8217;m a much better technician. When the customer suspected foul play and decided to call me instead of proceeding, I immediately instructed them to power off the PC. Here&#8217;s how I fixed the problem without having to reinstall Windows.<\/p>\n<p><strong>FIRST, ensure you don&#8217;t have any Restore Points to work with:<\/strong><\/p>\n<ol>\n<li>Check to ensure that the folder\u00a0<strong>%SYSTEMROOT%\\system32\\config\\RegBack<\/strong>\u00a0exists. \u00a0This is the folder which contains the last known good backup of the hives following a boot. \u00a0If it exists,\u00a0continue. \u00a0If not, stop and consider\u00a0contacting a technician instead.<\/li>\n<li>Reboot the PC and repeatedly press F8 to reach the\u00a0<strong>Advanced Startup Options\u00a0<\/strong>menu.<\/li>\n<li>Choose <strong>Repair your Computer<\/strong> from the menu.<\/li>\n<li><strong>Cancel\u00a0<\/strong>the automatic repair attempt and instead instruct the system to perform a\u00a0<strong>System Restore\u00a0<\/strong>to a date prior to the incident occurring.<\/li>\n<\/ol>\n<p><strong>If no Restore Points exist, your scammer intentionally removed them to prevent this from occurring. \u00a0If this happens to you, follow these additional steps to resolve the problem:<\/strong><span style=\"line-height: 15px;\"><br \/>\n<\/span><\/p>\n<ol>\n<li><strong>POWER OFF\u00a0<\/strong>your PC\u00a0<em>immediately<\/em>.<\/li>\n<li>Boot to external media of some sort (NOT your Windows installation) and navigate to the\u00a0<strong>%SYSTEMROOT%\\system32\\config\u00a0<\/strong>folder.<\/li>\n<li>Backup the registry hives in this folder to a temporary location. The files are:\n<ol>\n<li>SOFTWARE<\/li>\n<li>SYSTEM<\/li>\n<li>SAM<\/li>\n<li>SECURITY<\/li>\n<li>DEFAULT<\/li>\n<\/ol>\n<\/li>\n<li>Navigate to\u00a0<strong>%SYSTEMROOT%\\system32\\config\\RegBack\u00a0<\/strong>as mentioned earlier.<\/li>\n<li>Copy all registry hives from this folder (the same files as listed above) into the\u00a0<strong>%SYSTEMROOT%\\system32\\config\u00a0<\/strong>folder.<\/li>\n<li>Reboot the PC.<\/li>\n<\/ol>\n<p><strong>This solution only works if you have not already tried to reboot the PC subsequently<\/strong>. \u00a0If you have, it\u00a0<em>may\u00a0<\/em>still work, but that is entirely dependent upon whether or not Windows created a new RegBack copy following a successful boot.<\/p>\n<p>In the case of my customer, it worked, and they were back in Windows, just like it never happened. \u00a0Nice try, scammer. \u00a0You&#8217;ll have to try harder to beat me though. \ud83d\ude42<\/p>\n<p><strong>Addendum A (update 6\/26\/2015):<\/strong><\/p>\n<p>Thanks to FUScammers for pointing out this more involved, alternate method of actually\u00a0<em>removing\u00a0<\/em>the SAM encryption.<\/p>\n<ol>\n<li>Download <a href=\"http:\/\/www.triplescomputers.com\/files\/samreset.iso\">this file<\/a>\u00a0and burn the .iso to a CD.<\/li>\n<li>Boot to the CD on the affected system.<\/li>\n<li>Follow the instructions to select the proper system drive and partition (NTFS is the partition type you are looking for).<\/li>\n<li>Type the path to the registry files (it&#8217;s most likely <strong>Windows\/system32\/config<\/strong>).<\/li>\n<li>Choose option 1 for <strong>Password reset (sam system security)<\/strong>.<\/li>\n<li>Choose option 2 for <strong>Syskey status &amp;\u00a0change<\/strong>.<\/li>\n<li>Confirm that you wish to disable Syskey, then quit and confirm writing the new changes to the hive.<\/li>\n<li>Reboot the PC and check.<\/li>\n<\/ol>\n<p>For more detailed instructions, check out this link\u00a0(scroll down to \u201cHow to disable Syskey startup password\u201d):<\/p>\n<p><a href=\"http:\/\/computernetworkingnotes.com\/xp-tips-and-trick\/remove-administrator-password.html\" rel=\"nofollow\">http:\/\/computernetworkingnotes.com\/xp-tips-and-trick\/remove-administrator-password.html<\/a><\/p>\n<p>In Windows 8, the GPT partition type makes the use of this utility impossible. \u00a0However, you can still manually copy the hives to a supported filesystem (NTFS or FAT32), mount that filesystem instead, and follow the steps from there, then copy the hives back over the originals. \u00a0I\u00a0can confirm that this method\u00a0<em>does\u00a0<\/em>work and that even in Windows 8.1 recovery is possible using it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A trend of the past couple of years has been for scammers to contact computer owners\u00a0directly via telephone\u00a0in the United States in an effort to convince them that there is a problem with their PC and they&#8217;ll need to pay &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/casestudies\/solution-this-is-microsoft-support-telephone-scam-computer-ransom-lockout\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4,135],"tags":[],"class_list":["post-217","post","type-post","status-publish","format-standard","hentry","category-casestudies","category-security","category-recovery"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=217"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/217\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}