Use regedit as offline Registry editor
1
2
4
4
6
2
Launch ragecit an the command prompt.
Chick HKEY_LOCAL_MACHINE
Inthe File manu, click “Loed Hive.”
pan the dataseso fla that cantalns tha Rogktry hive you nod:
» HKEY_LOCAL MACHINE \SAM\= sw indisaystemd2\confs\ SAM
» HKEY_LOCAL_JAACHINE \SYSTEM~ Siwindiv@haystemae\config\SYSTEM
» HKEY_LOCAL MACHINE \SOFTWARE = Swindii\system@2\config\SOPTWARE
»HKEY_USERS S.Dafnult = Swindi-theystem2\contig\EFAULT
» HKEY_CURRENT_USER = Suserprovlesintuser dat
Enteran erbitrary key namie when prompted, 4 newhade with your key nome appears
Edit the Registry entries in the new nade.
une ais al [Rw Tie Tose
SEneramorue “|New mse oo
Click the roat folder of your nade, and then click “Unload hive” in the File menu, Your
changes willbe written to the offline Registry.‘To offing enable the built-in administrator account, fellow there steps:
1. Load the SAM Reaistry hive ith regedit as described in my past about the cine Raciery
citer.
Novignte ta HKLMiligaur kay. namanSaaiDomminetdccountsisersNanas\
Click “Adminitrster® and nods tha valua in the type calc,
Navigete ta HRLMivour_key_nameNSawiDemainsidecountsserd\
Use the type value you rated before ta locate the Reglstry key of the admlnstrator
‘count (soe soreanch ot)
6, Edit the F entry of the administrator hey and navigate to the 0038 position.
7. IF the built-in administratar accounts disbled, the value of this position is “11%; reslace
it with 0% NOTE: Make sure to edit the correct position because editing binary values in
the Registry isa bit tricky: Mave the cursar to the beginning of position O28, press “DEL,”
388
828s
88S8k8883
ssseBsess
on
00 09
cA OL
G0 09
ee OL
00 09
00 09
90 09
38 00
ssne4s
88E8
i
i
and then type “10”,
8, Click S¥your_key_name® and then unload the hive through the correspending manu point in
the File manu,
‘After yau reboot, you can lag on using the built-in administrator and resst the paceword of other
pecounts,