SAM Hive Encryption

From Free Knowledge Base- The DUCK Project: information for everyone
Revision as of 11:05, 20 March 2017 by Admin (Talk | contribs)

Jump to: navigation, search

Most commonly associated with "This is Microsoft Support" telephone scam.

There is a feature built into Windows that can be used to add encryption to the SAM hive of the Windows registry. It is a legitimate feature of Microsoft Windows. However, it is now being used as part of a Ransom Scam where the caller poses as an employee of Microsoft reaching out to help you resolve some kind of security threat to your computer. Via remote access the caller, once permitted, enables in windows policy SAM hive encryption. Then the caller announces that you must pay money to regain access to your computer.