- start RemoteRegistry services
- disable UAC
- import [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]
“LocalAccountTokenFilterPolicy”=dword:00000001 - allow firewall
- add creit to local host
cmdkey.exe /add:target /user:user /pass:passwd