NJH7 Posted October 1, 2014 Posted October 1, 2014 Hi, temp at this Primary school, not sure what the last guy did exactly. 1) I tried to log on locally to try re-add the PC to the domain, wouldn't let me in. 2) Tried going into Domain Security Policy, adding the admin accounts to those who are allowed to login locally. 3) Looked in AD, he had removed the PC from there. Any ideas into how to get into this? Cheers,
chazzy2501 Posted October 1, 2014 Posted October 1, 2014 normally I'd log on locally to the client, move to a fake workgroup then back to the domain. 1
NJH7 Posted October 1, 2014 Author Posted October 1, 2014 normally I'd log on locally to the client, move to a fake workgroup then back to the domain. That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct).
X-13 Posted October 1, 2014 Posted October 1, 2014 That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct). Sounds like the password for the local account has been changed, then.
hallb15 Posted October 1, 2014 Posted October 1, 2014 Time to dig out a Hiren's boot disk? Active password changer anyone... 2
NJH7 Posted October 1, 2014 Author Posted October 1, 2014 That was the first initial plan, however it doesn't seem to be letting me login locally. Just says incorrect username/password (is correct). So it's fallen off the domain, he's deleted it from AD, then changed the admin pw... Is there a way around this?
Joanne Posted October 1, 2014 Posted October 1, 2014 Time to dig out a Hiren's boot disk? Active password changer anyone... ^ this
Dkeen94 Posted October 1, 2014 Posted October 1, 2014 Time to dig out a Hiren's boot disk? Active password changer anyone... ^^ This everytime ^^ the password changer has saved my life a couple of times!
NJH7 Posted October 1, 2014 Author Posted October 1, 2014 Time to dig out a Hiren's boot disk? Active password changer anyone... I'm unfamiliar?
X-13 Posted October 1, 2014 Posted October 1, 2014 So it's fallen off the domain, he's deleted it from AD, then changed the admin pw... Is there a way around this? Hiren's or an XP recovery disk if you're still using XP. [i love the XP exploit. ]
Joanne Posted October 1, 2014 Posted October 1, 2014 Hiren's BootCD Fan & Discussion Platform burn to disc, boot from disc, password and registry tools, active password changer. Follow onscreen instructions. like, scan for SAM, clear administrator password.
strawberry Posted October 1, 2014 Posted October 1, 2014 I'm unfamiliar? Your googleFu is weak young padawan. Download from this website and use it to change the admin password Hiren's BootCD 15.2 - All in one Bootable CD » www.hiren.info 1
tmoon-mint Posted October 1, 2014 Posted October 1, 2014 I'm unfamiliar? You can boot to the disk and change the local admin password. Saved my bacon on many occasions.
NJH7 Posted October 1, 2014 Author Posted October 1, 2014 Your googleFu is weak young padawan. Download from this website and use it to change the admin password Hiren's BootCD 15.2 - All in one Bootable CD » www.hiren.info Thanks everyone. My GoogleFu will develop with time, it will.
Norphy Posted October 1, 2014 Posted October 1, 2014 normally I'd log on locally to the client, move to a fake workgroup then back to the domain. You don't even need to fake move it to a workgroup, usually deleting the domain suffix (so domain.suffix.local would become just domain) from there and pressing OK will allow to rejoin it.
Oaktech Posted October 1, 2014 Posted October 1, 2014 Just a thought which may save you from Hiren's, try logging on as .\domainadminusername and password, it may let you log on with details cached locally.
Norphy Posted October 1, 2014 Posted October 1, 2014 putting .\ before a username makes the machine look to its own user database, not the domain.
Oaktech Posted October 1, 2014 Posted October 1, 2014 putting .\ before a username makes the machine look to its own user database, not the domain. I've seen some pretty odd behaviour from this depending on local group memberships, it's worth a 30 second shot.
chazzy2501 Posted October 1, 2014 Posted October 1, 2014 booted in safe mode to enable the local admin account?
NJH7 Posted October 1, 2014 Author Posted October 1, 2014 booted in safe mode to enable the local admin account? Yup tried that, along with the .\! Guess I'll have to go fishing with the disc!7 Thanks for the input guys
ghafoor Posted February 26, 2015 Posted February 26, 2015 is there a reason you would not re-iamge the PC?
Blue_Cookeh Posted February 26, 2015 Posted February 26, 2015 Boot into a WinPE or Linux live disk, rename c:\windows\system32\utilman.exe to utilman.exe.bak then copy cmd.exe to a file called utilman.exe and reboot as normal, this will give you a command prompt with SYSTEM privileges so you can use "net use" to add an admin account and fix trust issue. Then just reboot into WinPE/Linux, delete utilman.exe, rename utilman.exe.bak to utilman.exe and reboot, jobs done Took me about 5-10 mins this way.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now