Kon-Boot for Windows GUIDE

If you have purchased Kon-Boot for Windows or Kon-Boot 2in1 license this is the right place for you.

What's Kon-Boot for Windows?

Kon-Boot is an application which will silently bypass the authentication process of Windows based operating systems. Without overwriting your old password! In other words you can login to your Windows profile without knowing your password. Easy to use and excellent for tech repairs, data recovery and security audits. Fast, tiny and gets your job done!

Kon-Boot in action:


Date Version
17.11.2018 Version 2.9 update released:
  • Installer changes & fixes (improved stability and protocol changes - mandatory update)

06.10.2018 Version 2.9 released:
  • Multiple fixes for Windows 10 October update (1809), UEFI.
  • Installer fixes (added monitoring for USB devices map changes).

12.05.2018 Version 2.8 released:
  • SSL support for Kon-Boot installer
  • Added "new local admin account" feature for Windows 10 S MODE (although we recommend you to avoid such systems)
  • Added experimental Windows 10 (UEFI Systems) ONLINE PASSWORD BYPASS right now for Commercial licenses only.

03.02.2018 Version 2.7 update released:
  • Multiple Kon-Boot installer fixes

01.01.2018 Version 2.7 released (2.6 version was skipped to match the 2in1 version):
  • Additional features for Commercial version (automatically executed powershell scripts!) (UEFI part only for Windows 8/Windows 10 x64)
  • Multiple fixes for kon-boot stability (UEFI part)
  • Multiple installer fixes (USB installer now requires online activation)
  • CD version is deprecated and will no longer be maintained (last version with CD support is 2.5)
  • UEFI support for x86 bit Windows system is deprecated and will no longer be maintained (there are virtually no x86 UEFI systems out there anyway)
  • Entire documentation updated and moved to online form

07.08.2015 Version 2.5 released
  • Support for Windows 10 (local bypass only + ability to create new system account)
18.01.2014 Version 2.4 released
  • Support for Windows 8/8.1 online password bypass
18.01.2014 Version 2.3 released
  • More stable support for Windows 8/8.1 (local mode)
14.04.2013 Version 2.2 released
  • New loader
  • Fixed UEFI bugs on Lenovo systems
  • New installer
27.08.2012 Version 2.1 released
  • Sticky keys feature
  • Initial Windows 8 support

System Requirements

General requirements:

Pentium III compatible processor, 100MB free space on the hard drive. USB flash drive (prefered USB pendrive size is 4GB, USB pendrive capacity must be not larger than 16GB , bigger ones are often causing serious problems with various BIOSes, such pendrives are not supported), keyboard. Compatibile BIOS version. Windows system is required for installer to run. USB flash drive is required for the UEFI version to work. Internet connection is required for the installer to work. Kon-boot can be only installed by using the original installer. One kon-boot license permits the user to install kon-boot on only one USB device (USB pendrive).

Disk encryption is not supported, secure boot must be disabled. Tablets are not supported. Multiple operating systems installed on target computer are not supported. No 3rd party loaders are supported (that includes DriveDroid and others). Kernel debugger, virtualization software (VMware, QEMU, VirtualBox) is not supported. CD and Floppy versions are deprecated.

Since version 2.7 kon-boot CD version is no longer available. We have left the old .iso images just for compatibility purposes. All versions starting from kon-boot 2.7 can be installed only on USB media.

Supported operating systems:

Operating system Supported?
Microsoft Windows XP (from SP2) Yes (FULL SUPPORT)
Microsoft Windows Vista Home Basic 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Vista Home Premium 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Vista Business 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Vista Enterprise 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2003 Standard 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2003 Datacenter 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2003 Enterprise 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2003 Web Edition 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2008 Standard 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2008 Datacenter 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows Server 2008 Enterprise 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows 7 Home Premium 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows 7 Professional 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows 7 Ultimate 32Bit/64Bit Yes (FULL SUPPORT)
Microsoft Windows 8 and 8.1 all versions (32Bit/64Bit) Yes (FULL SUPPORT (normal BIOS + UEFI BIOS)).
Local and online authorization.
Microsoft Windows 10 all versions (32Bit/64Bit) Yes (FULL SUPPORT (normal BIOS + UEFI BIOS)).
Local authorization bypass only. Local administrator account can be added automatically (USB only)

Important: Since kon-boot 2.7 there is a new feature present called automatic powershell script execution. This feature is present only in COMMERCIAL LICENSES (UEFI mode only (Windows 8 x64 / Windows 10 x64)).

Notable differences between personal and commercial version

Personal version Commercial version
Cannot be used by organizations, business entities and for any type of commercial work. Can be used for commercial purposes.
No Windows 10 online account bypass support. Yes! experimental Windows 10 (UEFI) online account bypass support.
No extra features. Yes! Extra feature present: automatic powershell script execution

Installation to USB

Since version 2.7 kon-boot can be installed only by using our GUI installer. Internet connecton is required for installer to work. Please note that all other installation options like CD installation are depracated (older kon-boot version is included in the package for compatibility reasons or in case of temporary lack of Internet connection).

We recommend using USB pendrive with less than 16 GB capactity, although it is not necessary (some older BIOSes have problems with kon-boot loading from larger USB pendrives).

Please use USB pendrive manufactured by reputable company like KINGSTON, SANDISK, SONY (max 16GB in capacity). Please don't use USB pendrives from "NO-NAME" companies - they may cause problems on various BIOSES.

Following video presents installation to USB pendrive media:

Manual installation to USB

Available for kon-boot v2.6 (if you use this feature in kon-boot v2.7 the older version (2.6) will be installed)


Please note: files located on your USB thumb drive may be overwritten! Installation steps:

  1. Insert your target USB pendrive
  2. If you are using Windows Vista or newer system please right click on "usb_install_RUNASADMIN.bat" and pick "Run As Administrator" option. Otherwise just double click on "usb_install_RUNASADMIN.bat" file (bat files are located in the "kon-bootUSB" directory, so by default the entire path is "c:\kon-boot\kon-bootUSB")
  3. Follow the displayed instructions. USB Tutorial video is available here

UEFI and Secure Boot feature

In order to use Kon-Boot in UEFI mode you need to make sure that the UEFI BIOS is not configured to use Secure Boot feature. Secure Boot feature is typically disabled however in case of any problems please enter the BIOS setup and disable the Secure Boot option manually (see examples below).

UEFI1 Above: UEFI Secure Boot option on ASRock motherboard

Above: UEFI Secure Boot option on Samsung motherboard

Disabling Secure Boot feature on Lenovo:

  1. Set Secure Boot option to disabled
  2. In the "Restart" tab, select "Disabled" for "OS Optimized Defaults" option and accept potential warnings
  3. In the "Restart" tab select "Load Setup Defaults" option and accept the displayed warnings
  4. Exit and save changes

Alternative approach:

  1. Set Secure Boot option to disabled
  2. Set the "OS Optimized Defaults" to "Other OS"
  3. Use the "Reset to setup mode" option in one of the BIOS tabs
  4. Exit and save changes

If you still have problems check out other youtube videos tutorials on this topic.

Disable virtualization support in BIOS

Newer Windows version use Virtualization-based Security (VBS) and/or hypervisor security. This can cause BSODs (Blue Screen Of Death) during loading Windows with Kon-Boot (Kon-Boot does not support virtualization). In order to prevent this from happening go to your BIOS setup and temporarily disable virtualization support (VT/VT-x) as presented on screenshots below.

This step is optional, try it if you experience Blue Screen of Death during booting your target Windows machine with Kon-Boot.

Following screenshots present how to disable virtualization support on various BIOSES (don't forget to SAVE the changed settings).






Automatic Powershell Script Execution Feature

Starting from version 2.7 (commercial edition only) kon-boot allows user to run automatic powershell script just after the boot of target operating system. Powershell script of user choice is being run with full system rights. This gives excellent and very powerful opportunity for the forensics team to gather all the necessary data from the target system. Right now the feature works only in UEFI mode and on Windows 8 / Windows 10 systems (x64).

Following video presents this feature at work:

In order to use this feature just edit the "auto.ps1" file on your kon-boot USB media.

Will this feature be added to normal (legacy) BIOS mode?

It seems rather unlikely. Legacy BIOS Kon-Boot loader is very hard to maintain, additional unscheduled constant Windows 8 / Windows 10 security updates do not make things easier. Finally UEFI is now recognized as the BIOS replacement. Check our faq for more detailed answer on this topic.

Sticky Keys Feature

What's Sticky Keys Feature? Sticky keys is a new Kon-Boot escalation feature which allows user to spawn a console window with system admin rights before the user is logged in. Kon-Boot allows you to get console window while the Windows login screen is still active.


Usage steps:

Video tutorial available below:

Following commands should be typed manually in the console:

net user /add [username] [password]
net localgroup administrators [username] /add

How to change profile password?

To change your password you can try the following way (after booting with kon-boot):

  1. Navigate the Start Menu to Control Panel
  2. Select "User Accounts and Family Safety"
  3. If the User Account Control window appears click "Yes" and leave the password field empty
  4. Select "Create a new account"
  5. Create the account (pick a name) and set the permissions (administrator).
  6. Disconnect Kon Boot and restart the computer to restore original Windows authentication functionality.

After restart:

  1. Select your new User Account (the account you have created)
  2. Navigate the Start Menu to Control Panel
  3. Select "User Accounts and Family Safety"
  4. Select the target User Account (the one you want to change)
  5. Select "Change the password"
  6. Input the new information for the account and click "Change password"
  7. You are done

Windows 10 Online Authorization Support

UPDATE 05.2018: Experimental Windows 10 online account authorization bypass was added to the 2.8 Kon-Boot Releases (commercial licenses only, UEFI systems only).

Due to additional protection mechanisms online authorization bypass is currently not supported by kon-boot in Windows 10 systems. However user can still access the system as local administrator. In fact in the kon-boot v2.5 administrator account can be added automatically, as presented in the following scenario:

  1. Boot your machine with kon-boot on USB (usb version is required)
  2. Wait until your Windows 10 machine boots up
  3. You should see following message displayed on the screen MSGBOX
  4. If you want to get your new administrator account added click YES and follow the rest of instructions displayed on the screen

In case of problems (i.e. when message box was not displayed) you can add the administrator account manually using the sticky keys feature. Please see the Sticky Keys Feature for further details.


Please visit the Contact us / Support page for details.