I am assuming 10g Express on a windows machine.
Since you are the administrator (presumed) make sure that you are a member of the ORADBA group. If memory serves this is true for administrators by default.
Then you can always login without a valid password, as the system will fail your credentials, and then check to see if you're a member of ORADBA. If you are, it will grant you access anyway.
Since you will now be logged in as a DBA, use a standard "alter user" statement to reset the sys password.
Regards
Tharg
Grinding away at things Oracular