Skip to main content

How to read SAM Hive?

More
16 years 11 months ago #21794 by puneetvig
I was doing sum crazy thg on the test machine....

I copied SAM hive frm Systemvolumeinfo folder.... Can anyone tell me abt the tools to read SAM hive :?:

I copied and save the SAM hive on d desktop :D

See Ya!!!!!! Cheers
Puneet
More
16 years 11 months ago #21801 by S0lo
Replied by S0lo on topic Re: How to read SAM Hive?
LCP can read SAM files:

www.lcpsoft.com

although I'm not sure I get you right. The SAM file is usually put in "C:\WINDOWS\system32\config" folder. You found it in Sysvolumeinfo :!: :?

Studying CCNP...

Ammar Muqaddas
Forum Moderator
www.firewall.cx
More
16 years 11 months ago #21805 by puneetvig
Replied by puneetvig on topic Re: How to read SAM Hive?
Yes Solo u r correct, SAM and other OS hives are located in system32\config folder. However, u can only copy OS hives through Recovery Console. Alternatively, what i did,

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.

You can find more info at
support.microsoft.com/kb/307545/

and solo for helping me..

Tk care...

See Ya!!!!!! Cheers
Puneet
More
16 years 11 months ago #21806 by DaLight
Replied by DaLight on topic Re: How to read SAM Hive?
Nice tip, puneetvig. You could also use a Live CD as well.
More
16 years 11 months ago #21810 by puneetvig
Replied by puneetvig on topic Re: How to read SAM Hive?
I tried LPC, it took 3 hrs. No result found....

See Ya!!!!!! Cheers
Puneet
More
16 years 11 months ago #21824 by S0lo
Replied by S0lo on topic Re: How to read SAM Hive?

1. Create a restore point.
2. Open C:\System Volume Information\_restore{0145FC50-D40A-42A0-A56A-275EF2B2493B} folder and locate the latest restore folder starting with RP**.
3. In RP** folder, open snapshot folder. Where u can find all 5 OS hives restored.


hmmm, clever idea, never thought of that.

Well, If LCP took 3 ours, (and it can take weeks). Thats good and means your login passwords are strong. try using a password with 5 or less characters.

Studying CCNP...

Ammar Muqaddas
Forum Moderator
www.firewall.cx
Time to create page: 0.151 seconds