Admin rights issue

silverdale

VIP Member
VIP Member
Joined
Aug 2, 2007
Messages
5,413
Reaction score
7,025
My computers on windows 10 and I scanned today and it found a few bits and removed them, they were from a program I installed that turned out to be dodgey. I rebooted but I no longer have admin rights. When I boot there's a new ADMIN~1 account below my name in the bottom left. I cant delete the account it wont let me and I don't know the password for the ADMIN~1.

My hard drives encrypted and I cant decrypt to go f8 as I don't have admin rights to decrypt. I cant uninstall anything even with Revo as it says dont have admin rights. When I go into user accounts I select my account then change permissions to admin but it doesn't save and I cant change the ADMIN~1 as well. Any way round this ?
 
Try go to the boot drive and select probities , then select security and see if you can allow control back ?
 
I normally would but I have my hard drive encrypted. I only do this incase I'm broken in then the computer is useless. So I thought, F8 Hirens USB but, I can't unencrypt the drive simply because I don't have admin rights.
I went in program files and right clicked and ran the encryption program .exe as admin. Thinking I'd cracked it I then got a message saying you don't have permission to read write files on this system.
If I could unencrypt the drive I'm sure I could sort it but that's a job on its own.

It's as though this new ADMIN~1 is running the show.
I tried housecall online scan and F secure both failed saying no Internet but I can use Google fine.
If I can grant the encryption program full read write rights I'll be able to unencrypt then tackle it then.
Is there anyway in the registry to add admin rights to my account ?. I've tried in user accounts but when I click on properties for my named account and change to administrator it let's me but doesn't save when I exit.
Done my tree in this
 
I've just manage to dig out the encryption rescue disc I made and booted to it. It's given me the option to decrypt from the disc which will take about 4 hours.
Hopefully I can then access F8 or boot to Hirens. What an utter ball crunch
 
If you can eventually get to boot from Hirens you should be able to reset the new Admin~1 password then recreate your own Admin account and delete the fake one.
 
It's took an eternity but I've managed to decrypt and remove the boot leader for it.
I've booted to
Hirens BootCD PE Windows 10 but I can't find administrator tools any ideas ?
 
Right I found the program in hirens and I brought up the accounts.
Mine
Administrator
ADMIN~1

The program in Hirens let me change the passwords of all the accounts but there's no button to delete any.

I rebooted back into windows and went into user account and tried to change mine to admin but it won't let me and when I say delete ADMIN~1 account it goes through the motions but it doesn't delete it.
I still can't uninstall anything as I don't have admin rights and I can't change it.
Going to scan in hirens see what it brings up
 
Try deleting it via Command Prompt (Admin).

Use command ;

net user ADMIN~1 /delete

Or

net localgroup Administrators ADMIN~1 /delete
 
Last edited:
Will Hiren's not let you change your account to admin ?
Or can you do it in safe mode ?
Basically no,
I go security in Hirens use Security and use the program there to access the config/SAM file.
The accounts all pop up and you can only change passwords you can't delete, there's no tab to delete.
I've tried everything in Windows itself to delete it or give my user admin rights but I just get
Access denied
Or
You do not have privileges. I can't even uninstall anything. PC won't go in safe mode and run/misconfig Access denied tapping F4 F5 F8 does rag all.

I'm not the worlds best but I do have decent knowledge.
I do have a Sam file back up in system32 I saw it while running Hirens dated last year
 
I think I'm getting there. I used an old Hirens CD as I seemed to remember there been a prog on it that granted admin rights to accounts and there was.

I targeted the Windows folder on my hard drive and granted my user name from the drop down list Admin rights, I rebooted and it let me delete the user account ADMIN~1
Just a quick question,
I have 4 accounts listed in User Accounts
Me
Administrator
DefaultAccount
Guest

Do I need these 2? DefaultAccount & Guest ? I'm not sure were they've appeared from
 
Ok, so from a security POV you should have 2 accounts. And admin account, that is used to configure the other users and stuff. Set a long and complex password so it cannot be bruteforced.

Then use the admin account to setup a user account with lower priviliges, and that should suffice. Never user the admin account as your normal user account on windows.
 
The Guest account is standard set up. That account is if you were giving use of your PC to another person. It is the basic setup with no access to your files and loaded programs.
 
Thanks, well that was a pain in the trumper. The hardest bit was decrypting the drive with no admin rights, this in turn meant Hirens was useless. Just a good job I'd made a bootable recovery disc for the encryption program so I could decrypt the drive
 
Thanks, well that was a pain in the trumper. The hardest bit was decrypting the drive with no admin rights, this in turn meant Hirens was useless. Just a good job I'd made a bootable recovery disc for the encryption program so I could decrypt the drive
Personally, after all the hassle you have had I think I would be looking to rescue whatever files/info I needed from the boot drive, now you have access to it again, onto a sepatate drive, whether internal or usb, then thoroughly blank/wipe the boot disk and reinstall windows. Who knows what other tricks or files might be lying dormant from that "dodgey" program you installed?
Just a thought, I couldn't rest knowing what had happened. Better safe than sorry 🤞
 
a backup image should be a priority saves the hassle personally always have a backup as soon as i am setup to my liking
 
Got a good image backup now with my windows 11 and all the programs and drivers i need

Using Macrium Reflect free version and works amazing With your M.2 Drives ;)
 
Back
Top