Author Topic: How to make a Run Key in Current User  (Read 6962 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
How to make a Run Key in Current User
« on: March 27, 2014, 02:04:06 PM »
Hello All,

So this thread relates to the issue of the password protected Admin account. Some other people had an idea, presumably to hack the computer. My guess is it won't work.

If/when we get the password removed or wipe the computer, I will be making a Limited User account. My goal is to make a VBS file using x=msgbox("",0+16"") type thing, but I want it to autostart for that account only. Hence it only being in Current User.

Any ideas on the command I need for the reg key and what type? DWORD, String, Value etc. Thanks
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #2 on: March 27, 2014, 02:16:35 PM »
I will get the programs when I get home. Any idea on the range to boot? Don't forget, this is not Windows 8, it's windows 7 Starter Pack.

Any ideas on the run key?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: How to make a Run Key in Current User
« Reply #3 on: March 27, 2014, 02:43:54 PM »
No clue on that right now.

Maybe theres some tool in the Boot CD.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #4 on: March 27, 2014, 02:55:16 PM »
to make a reg key for a non-existent file? I wish
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: How to make a Run Key in Current User
« Reply #5 on: March 27, 2014, 03:03:03 PM »
Quote
If/when we get the password removed or wipe the computer, I will be making a Limited User account. My goal is to make a VBS file using x=msgbox("",0+16"") type thing, but I want it to autostart for that account only. Hence it only being in Current User.
Let's see.

1)
What do you mean with admin account?
A user with admin rights or the real admin account?

2)
Create a limited account? You already should have one and use that for daily usage.
If your system gets infected, the malware normally has the same rights as the user that is logged in at the moment of infection.
You really don't want malware to have admin rights.

3)
You do realize that when you set it to run for that specific limited account all other accounts with more rights can change it?

4)
Why removing a password? That doesn't make any sense at all.

5)
Ofcourse if you wipe the entire drive the os is one, the password is gone also.
But what use would that be unless it is the only way to solve a problem?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #6 on: March 27, 2014, 04:39:41 PM »
Quote
If/when we get the password removed or wipe the computer, I will be making a Limited User account. My goal is to make a VBS file using x=msgbox("",0+16"") type thing, but I want it to autostart for that account only. Hence it only being in Current User.
Let's see.

1)
What do you mean with admin account?
A user with admin rights or the real admin account?

2)
Create a limited account? You already should have one and use that for daily usage.
If your system gets infected, the malware normally has the same rights as the user that is logged in at the moment of infection.
You really don't want malware to have admin rights.

3)
You do realize that when you set it to run for that specific limited account all other accounts with more rights can change it?

4)
Why removing a password? That doesn't make any sense at all.

5)
Ofcourse if you wipe the entire drive the os is one, the password is gone also.
But what use would that be unless it is the only way to solve a problem?

1) I want the users limited to a Limited User account so they can't do this again. So the only admin would be me and the teacher.
2) I didn't know about this computer originally, or I would've said something. I agree, daily usage = Limited User.
3) Well Aware. That'd be why the Admin account would be limited too 2 people. Me and the teacher. Not the students who like throwing passwords on everything they see so we can't access it.
4) currently, the only user account is the admin account. Which was password protected by an unknown student. Therefore, since we don't know who did it, and what the password is, it needs to be removed so i can set it up so they can't do that anymore.
5) Any bright ideas on how to access a Admin user account with no means of getting through the password? other the Hirens Boot CD. Which may or may not work.

I should also mention, after goofing off for a while, I have figured out the way to make the VBS file run on start up. Now I just need to disbale the warning about opening it since it was created by a non-admin account on the domain. (The VBS file & reg key will be recreated on the other computer (Non-Domain) after we have it set up again, if it's wiped.
« Last Edit: March 27, 2014, 04:42:09 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: How to make a Run Key in Current User
« Reply #7 on: March 27, 2014, 07:03:27 PM »
Want a easy/fast solution?
Install everything from scratch.
Setup the user account(s) as you wish.
Create a image of the system.
If something happens, just put in the cd/dvd (or whatever) with the image and put it back.
Screw the students  ;D

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #8 on: March 28, 2014, 02:17:09 PM »
I would,

But some issues lay in that solution.

1) It's not mine, therefore reinstalling windows could delete files that they need.
2)I'd need a very large USB to fit an ISO of Windows 7 on.
3) I'd need a key for the ISO image. Unless Essex has an ISO image of a active Windows 7...

Essex? By chance? Windows 7 anything will do if you wish to share.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: How to make a Run Key in Current User
« Reply #9 on: March 28, 2014, 04:51:50 PM »
NTPassword should do the trick:  http://home.eunet.no/~pnordahl/ntpasswd/
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #10 on: March 28, 2014, 04:55:53 PM »
That site is blocked at school. Lol, silly tech's. good reason though, that way I can't change the password. (I can still access the registry) Hehe. Oh well,

Anyways, will take a look at that program when I get home. THanks, will it work on an admin account?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: How to make a Run Key in Current User
« Reply #11 on: March 28, 2014, 04:58:41 PM »
That site is blocked at school. Lol, silly tech's. good reason though, that way I can't change the password. (I can still access the registry) Hehe. Oh well,

Anyways, will take a look at that program when I get home. THanks, will it work on an admin account?
If one thinks about it, if not blocked at school, then every student so inclined could change the password....

It works outside of Windows, so, yes.

[EDIT:] (site has been moved, here is new site:)  http://pogostick.net/~pnh/ntpasswd/
« Last Edit: March 28, 2014, 05:01:09 PM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #12 on: March 28, 2014, 07:06:47 PM »
Merci,

Do I need to get Rufus or something for that? Or just stick it in a boot from it?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: How to make a Run Key in Current User
« Reply #13 on: March 31, 2014, 07:31:38 AM »
You figure it out?
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: How to make a Run Key in Current User
« Reply #14 on: April 04, 2014, 03:16:51 PM »
Yes, well kind of.

I've booted into Hiren's BootCD Version 15.3. I"ve changed, removed and modified every single "Admin" account. THe issue that is with me right now, is that the acer56 accounnt (Which the account needing the password removed) is not showing up in anything. I've tried Mini-XP and then C:\Users\X nothing, Hiren's PW changer, nothing. At this point I'm going to bite the bullet, pull the files needed off the computer, and set it to factory defaults. The computer looks like it may or may not have a few trojans and a **** ton of adware installed looking at the desktop alone.

At least it'll save her $50 bucks so she doens't have to take it back to the store.

Edit: I've also tried this from system32 CMD. net user administrator /active:yes

No luck.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.