Home |  Log In  
Forensics and eDiscovery technologies for Mac OS X, Microsoft Windows, and Linux

Gain SYSTEM User Access in Microsoft Vista

Gaining SYSTEM user access in Microsoft Vista is a simple procedure and allows a forensic investigator higher level access then the administrator. This method of gaining access to a Microsoft Vista system doesn't require the investigator to know any of the usernames or passwords for the system.

  1. Boot the Vista machine with BackTrack or any other Live CD.
  2. Mount the NTFS partition.
  3. Rename C:WindowsSystem32Utilman.exe to anything else such as Utilman.old
  4. Copy C:WIndowsSystem32cmd.exe to C:WindowsSystem32Utilman.exe
  5. Reboot
  6. At the Vista login screen, press the Windows key + U to launch the Utility Manager.
  7. Start cmd.exe
  8. Start explorer.exe

You can view a video showing this procedure here.

Also, once a command prompt is obtained via this method, we can use it to create a new user, add this user to the administrators group via the net command and then use this account to rightfully log in using the following commands:

net user USERNAME /add
net localgroup administrators USERNAME


 | Home | 

Copyright © 2006 - 2010 MacForensicsLab Inc.
Phone +1 (510) 870-7883 - Fax +1 (510) 868 3407
Mac and the Mac logo are trademarks of Apple Computer, Inc., registered in the U.S. and other countries.

Forensics Technologies - designed to perform investigations, for law enforcement and eDiscovery professionals.

MacForensicsLab - The only effective cross-platform weapon in the war on Cyber Crime and Digital Terrorism,
with unique tools designed to combat identity theft and child pornography.