Have you ever been locked out of a Windows system by either a forgotten password or maybe someone left the company and wasn’t kind enough to put the password on a sticky note on their monitor or under their keyboard?
Well, I have a method for you that will help! Following these steps has saved my clients and me more than once. All kinds of situations have come up, especially when someone leaves a company on bad terms and thinks they will get one over on the team by locking their work behind a crazy password. Not too long ago, a local company called after the owner forgot his password after being on vacation for two weeks. I saved the day by having backups of their Bitlocker Keys and using this trick to reset the password.
For this, you will need a bootable Linux system. I recommend Puppy Linux as it is tiny, and you can put it on a flash drive and keep it with you easily. It is also a Linux distro that will work out of the box to read and write to NTFS, where I have had issues with others.
If you need help getting a bootable Linux drive setup, check out my article about that: Setting Up Bootable Linux USB.
Resetting Windows Passwords Using Linux
data:image/s3,"s3://crabby-images/8b9b3/8b9b36e2ba929e4c74e8ff7da8f22a5abe49d71f" alt=""
- Plug the USB drive into a USB port on your computer.
- Restart or turn on your computer.
- Press the key to enter the BIOS or UEFI firmware settings; this key can vary depending on the computer and BIOS/UEFI firmware; common keys include F1, F2, F10, Delete, Esc, etc.
- Locate the boot options menu and select the option to boot from USB. The key to enter this option varies by the BIOS/UEFI firmware and computer.
- Save your changes and exit the BIOS/UEFI settings.
- Your computer should now boot from the USB drive.
- Puppy system can take several minutes to boot and have text that looks like this:
data:image/s3,"s3://crabby-images/f4035/f403574daf129197b38979dd9267cbb22ea47a6f" alt=""
- The booted system will look like this, and you will see several drives listed in the bottom left of the screen:
data:image/s3,"s3://crabby-images/58ad2/58ad23cd12df8798d14d479eb95903ddecf0d9cd" alt=""
- Click the drives till you find the one that shows Windows System Files it will look like this:
data:image/s3,"s3://crabby-images/1c860/1c8607c10f1c4f644ca899973ef1039e55bd0c39" alt=""
- Open Windows > System32 Folders, and you will get a list of system programs:
data:image/s3,"s3://crabby-images/66b15/66b15aefe6f69ef4b87ae6d4499f4c4230346b91" alt=""
- Scroll down and find the file named Utilman.exe:
data:image/s3,"s3://crabby-images/acf65/acf65943dc9b78c5640a738ced058622c578cd45" alt=""
- Right click the file and select Rename in the File Options:
data:image/s3,"s3://crabby-images/7ddd2/7ddd24d2116be8f5a1c3ecd59448782cb76b69c4" alt=""
- Change the name to Utilman.exe.bak
data:image/s3,"s3://crabby-images/8920d/8920dd7a97873376a8bfbae4435e649ae819ba50" alt=""
- Now scroll up and find cmd.exe, and this time we will duplicate the file renaming it in the process:
data:image/s3,"s3://crabby-images/c6273/c6273e000e95dd0ede9164e002ed0efc59fc6495" alt=""
data:image/s3,"s3://crabby-images/81e35/81e3528b7c0e1231a7c3094bc1db5b5a5ef2f74d" alt=""
- Rename the duplicate file to Utilman.exe:
data:image/s3,"s3://crabby-images/cadd7/cadd7c26ce77caf3d4625b4b528b6bccf542014a" alt=""
- Shutdown puppy by selecting the menu and power option, then shut down don’t worry about saving anything (unless you make customizations)
- Reboot.
- On system login, you will see the ease of access icon in the lower right-hand corner of the screen:
data:image/s3,"s3://crabby-images/6bd5e/6bd5e7b2b1da02597198f91bbb22a015dda6d874" alt=""
- A command window will open, and you can type the command to change the password for a user. The command is: user <username> <Password>
As you can see in the picture, the username is “user,” and the password is “TEST”
data:image/s3,"s3://crabby-images/1e9f3/1e9f3fb4a3a5b7ce28504fa0ff69cca9c9edb614" alt=""
- Login using the new password you just set:
data:image/s3,"s3://crabby-images/e5965/e5965d8b44b9079fb21ab266b115cbdc0dd3f5ca" alt=""
- To clean up the file changes, the easiest way is to run an administrative command prompt and run the command:
SFC /scannow
Each time the command runs, it will clean the system files, replacing the ones we changed. Run it until it tells you no integrity violations were found.
data:image/s3,"s3://crabby-images/62270/62270d0b9c0c2bcf2feb1f6960f1c2c43f023f54" alt=""
This “trick” is great in a pinch and I hope it helps you as it has helped me so many times.