Status
Not open for further replies.
Tutorial  Updated

Admin Access on any Windows 7 Machine

This one's an oldie, and if you don't have access to the BIOS for some reason then this is perfect. It takes some time, but yeah.

So the first thing you want to do is get the recovery options menu (see below)
There's multiple ways of doing this, such as force shutting down your PC, pressing CTRL + ALT + DELETE until you get it, or holding down the F8 key during boot.

2g6BK2e3DiXe0Ff_h3lgJTT-SBgeh0_vfKU9mDDi6J0nOPtOF8grXFRpyubdwCSgupxyBo_efm_PG_HzhvQud68BsJ2NQN4HxlAbLjiZA29-TUAx1AYkg94wT1L4EWLruC9hDhd18SNMtmcMHHck5w_NBE_olXZUssZWqkJIbWN7gOZrk0gU3feZjiHjeTkJNDn0X4ArsWpsJEEjlpvZjsdzQDb2SY1YNsQR3sJGEpCdUQAjjNSLgxNs9nwQ6jShD_d__MZXt6rTfcV8QA5rmmFMxOaJDglQpss0ZeAWtn50DgoSyE1QJ8A9JkGfIWMk7_Xe3-DCXJyI1WL6-yyK2ceayjnK5cWpe1rP-E-eRQC41NnOI0ZWf10neOM3UrgJhjDFv_627hDgSC1tsDfuvYdcoWO47EyGH_ZcOsEBEED4JVuE3iYwceeuLLhKUq82yTJRnvwer3KuZlk28ZAJ8FjSSqr2s3kpYeDPwprDxuMdKdcGGsF-fm4XQc2N3PjoTZUnFI99DCqiXOylcnqiPmvB3frpQBucQJZ4lJzYMCORYqbnPfI-y7vD5Jihlwl0Td0hDrSQcQ-CazP-68gHgbUu7HQCo1S9ztAc9h3_0EQ71ek2xdDO=w640-h315-no


However you manage to get it, you're gonna want to select "Launch Startup Repair" as shown above.

Wait for it to "search for problems". This'll probably take awhile, so just give it a few minutes.If a popup that says "Do you want to restore your computer using System Restore" comes up, press CANCEL.

Wait for the "Startup Repair cannot repair this computer automatically" popup to show. This is where the fun begins!

Click "view problem details" and scroll to the bottom, where there'll be a link to a text file (should look like "X:\windows\blahblahblah"). Click on it and it'll open up notepad with some useless jabber. You can ignore all of this, it's not important.

Now, go to "File > Open". Now go to the "Computer" tab and navigate to "C:\Windows\" and make sure that the file type is changed from ".txt" to "all files". Next, scroll down and locate "cmd.exe". This is the command prompt, and we need this to give ourselves admin access. Next, make a copy of it (right click > copy, CTRL + C, whatever.) and then right click and paste it. This will make "cmd.exe - Copy".

Now, you're gonna want to find "sethc.exe". This is the program that executes the "Sticky Keys" popup (that annoying program that comes up when you press shift too many times). We're going to replace this with our copy of cmd.exe, so instead of the sticky keys popup, we'll get the Command Prompt. Neat, right? So all you need to do is rename "sethc.exe" to... anything that isn't "sethc.exe".

Once that's all done, go back to the copy of cmd.exe you made. Rename it from "cmd.exe - Copy" to "sethc.exe" (make sure it's "sethc.exe", not "sethc.exe.exe"!)

We're done here! Now close out of everything, click "don't send" and then "finish". Restart your machine into regular windows. If any error recovery prompt comes up, select "Start Windows Normally".

Once you're at the login screen, don't log in. You're going to click shift until the Command Prompt window comes up. Success! If it doesn't come up, you did something wrong. Repeat the steps until you get it.

Now, we enable the default "Administrator" account, giving us admin access. We can do this because at the login screen, we're actually using a user account called "SYSTEM" that has full privileges. This is what's used to log users in and some other stuff. (You can type "explorer.exe" into the command prompt and the start menu will show up. Neat!)

Now, let's set a password for the administrator account. Type "net user Administrator *", and enter your desired password.

Now, chances are if you try logging in with the Administrator account and its new password, it'll probably say "the account has been disabled", so we'll have to re-enable it. Bring up your cmd again, and continue.

To activate it, type "net user Administrator /Active:yes". The account will be activated! You can verify by typing "net user Administrator".

That's it! Now log in and do whatever you want to the computer. I take no responsibility for any damage you do to school/work/public property! Have fun!

TL;DR?
No. Read it.


**EDIT**
If anyone wants I'll make a video on it
 
Last edited by ,

richrard

Member
Newcomer
Joined
Dec 15, 2013
Messages
13
Trophies
0
Age
34
XP
1,380
Country
United States
I do the same thing with utilman.exe instead of sethc.exe, which makes the ease of access button before sign-in launch cmd. I do local computer repair and it comes in handy. Can also be done from installation DVD as long as you aren't locked out of boot options, but sometimes the recovery partition is missing or not registered properly. Works in Vista-Win10
 
Last edited by richrard,
D

Deleted User

Guest
OP
I do the same thing with utilman.exe instead of sethc.exe, which makes the ease of access button before sign-in launch cmd. I do local computer repair and it comes in handy. Can also be done from installation DVD as long as you aren't locked out of boot options, but sometimes the recovery partition is missing or not registered properly. Works in Vista-Win10
Thanks for confirming that, I've only actually tested it in Windows 7. Wasn't quite sure.
 

RandomUser

Rosalina in Plush Form
Member
Joined
May 9, 2010
Messages
967
Trophies
1
XP
1,042
Country
United States
If you want to access administrator account even faster, you can use Kon-Boot. Bypasses all Windows passwords and can log you into Admin.
Actually this is a nice find and a free way to access administrator account.
 
D

Deleted User

Guest
OP
If you want to access administrator account even faster, you can use Kon-Boot. Bypasses all Windows passwords and can log you into Admin.
Actually this is a nice find and a free way to access administrator account.

From what I see here you need to pay for this, and there's some much better free alternatives. However, this guide assumes that the BIOS is locked down (meaning you can't change the boot settings) as many schools / corporations do lock down their machines with BIOS passwords. This doesn't require anything special, just some time.
 

Seliph

Best Girl ʕ •ᴥ•ʔ
Member
Joined
Jul 11, 2016
Messages
1,760
Trophies
0
Location
The People's Republic of Revachol
Website
twitter.com
XP
4,149
Country
United States
Heh, I remember I did this once when I was 11 because my dad would make it so I was force logged out past 9 pm and all programs I downloaded had to go through him because it wouldn't let me download anything without a password.
I'm pretty sure this method doesn't work on Hp computers because when you get to the repair part or something, hp redirects you to a custom repair program made by Hp and you need the default repair program for this method to work.
 
Last edited by Seliph,

RandomUser

Rosalina in Plush Form
Member
Joined
May 9, 2010
Messages
967
Trophies
1
XP
1,042
Country
United States
From what I see here you need to pay for this, and there's some much better free alternatives. However, this guide assumes that the BIOS is locked down (meaning you can't change the boot settings) as many schools / corporations do lock down their machines with BIOS passwords. This doesn't require anything special, just some time.
I was mentioning your method is a nice find, not Kon-Boot, sorry for the confusion.
Also who said you need to pay for Kon-Boot, you can download it for free, it just takes some time and searching:tpi:. Not exactly legal though.
 

richrard

Member
Newcomer
Joined
Dec 15, 2013
Messages
13
Trophies
0
Age
34
XP
1,380
Country
United States
I'm pretty sure this method doesn't work on Hp computers because when you get to the repair part or something, hp redirects you to a custom repair program made by Hp and you need the default repair program for this method to work.

That's when booting from an installation DVD or USB works better. Shift + F10 to bring up a cmd window, then you can just find the partition with your install, use the 'cd' command to navigate to Windows\System32\ and copy cmd.exe over utilman.exe or sethc.exe. I usually just do this first, because sometimes there is an alternative recovery or no recovery partition set at all.
 

DaniPoo

Well-Known Member
Member
Joined
Jan 2, 2013
Messages
925
Trophies
1
Age
35
XP
2,291
Country
I assume that this will work fine even on Bitlocker protected PC's (and such) with password locked Bios?
 
D

Deleted User

Guest
OP
I assume that this will work fine even on Bitlocker protected PC's (and such) with password locked Bios?

Yes, it should work.

That's when booting from an installation DVD or USB works better. Shift + F10 to bring up a cmd window, then you can just find the partition with your install, use the 'cd' command to navigate to Windows\System32\ and copy cmd.exe over utilman.exe or sethc.exe. I usually just do this first, because sometimes there is an alternative recovery or no recovery partition set at all.

That might work. I used this method because it requires no extra setup or preparation.

BIOS passwords are the best!

Oh god, tell me about it. This company recycled a whole bunch of expensive laptops and I grabbed one because I could use it for work (6GB of RAM and an i5, who wouldn't?) But they had locked down the BIOS.
Luckily, I came across http://bios-pw.org, a site where they have all of the master BIOS keys for laptops stored. All you have to do is enter the serial number and you're in!

I was mentioning your method is a nice find, not Kon-Boot, sorry for the confusion.
Also who said you need to pay for Kon-Boot, you can download it for free, it just takes some time and searching:tpi:. Not exactly legal though.

You can always trust the Chinese for quality bootlegs ;)

Heh, I remember I did this once when I was 11 because my dad would make it so I was force logged out past 9 pm and all programs I downloaded had to go through him because it wouldn't let me download anything without a password.
I'm pretty sure this method doesn't work on Hp computers because when you get to the repair part or something, hp redirects you to a custom repair program made by Hp and you need the default repair program for this method to work.

That's quite interesting, I've never seen that before.
 

DaniPoo

Well-Known Member
Member
Joined
Jan 2, 2013
Messages
925
Trophies
1
Age
35
XP
2,291
Country
Heh, I remember I did this once when I was 11 because my dad would make it so I was force logged out past 9 pm and all programs I downloaded had to go through him because it wouldn't let me download anything without a password.
I'm pretty sure this method doesn't work on Hp computers because when you get to the repair part or something, hp redirects you to a custom repair program made by Hp and you need the default repair program for this method to work.

Startup repair is available on HP PC's as well, tho HP has some kind of boot software too for hardware diagnostics. Im working in an IT department for a company that mainly uses HP branded PC's, so I have seen both.
 
  • Like
Reactions: Seliph
D

Deleted User

Guest
OP
Startup repair is available on HP PC's as well, tho HP has some kind of boot software too for hardware diagnostics. Im working in an IT department for a company that mainly uses HP branded PC's, so I have seen both.
very interesting!
 

DaniPoo

Well-Known Member
Member
Joined
Jan 2, 2013
Messages
925
Trophies
1
Age
35
XP
2,291
Country
Last edited by DaniPoo,
  • Like
Reactions: Deleted User
D

Deleted User

Guest
OP
I always use a Ubuntu USB and chntpwn. Assuming the BIOS isn't locked.
 

MarioMasta64

hi. i make batch stuff and portable shiz
Member
Joined
Dec 21, 2016
Messages
2,297
Trophies
0
Age
26
Website
github.com
XP
2,106
Country
United States
here i thought everyone knew how to do this, btw a similar bug still exists in windows 10 however it doesnt work with a m$ft linked account
 

Seliph

Best Girl ʕ •ᴥ•ʔ
Member
Joined
Jul 11, 2016
Messages
1,760
Trophies
0
Location
The People's Republic of Revachol
Website
twitter.com
XP
4,149
Country
United States
https://support.hp.com/us-en/document/c01443317

Tho this is part of bios or UEFI so it runs before booting the hardrive and should not affect Windows in any way.
Is see no reason why this trick should not work on an HP PC, It should work on any PC that has access to startup repair right
Oh, I see. Guess I didn't try hard enough when I did it on the HP.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Xdqwerty @ Xdqwerty:
    good night
  • BakerMan @ BakerMan:
    as to you
  • K3Nv2 @ K3Nv2:
    How do you know if the night will be good when you're asleep
  • BakerMan @ BakerMan:
    because i didn't say i was asleep
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
    The Real Jdbye @ The Real Jdbye: never had that i don't think