Modify the Screensaver file method
Principle: When Windows 2000/xp starts, if does not enter the system, will automatically start the screensaver, if uses CMD.EXE or EXPLORER.EXE replaces LOGON.SCR, starts starts when actually starts is the cmd command.
Steps
Copy system installation directory SYSTEM32\LOGON.SCR file backup (Dos required, if necessary ntfs4dos, or after Windows Pe/bart ' s PE startup);
Change cmd.exe or Explorer.exe name as LOGON.SCR file, replace the system32 directory LOGON.SCR of the system that needs to be cracked;
Start the system, press Ctrl+alt+del, do not do any action, wait a while the system will automatically run LOGON.SCR screensavers, in fact, this is Cmd.exe, and the current identity of the local system
Change the password at the command line (in effect, restore the system login user password with net user command)
NET User Administrator Your-new-password
If this is a domain controller, then enter the net user Administrator Your-new-password/domain
Landing system, the first step in the backup of the LOGON.SCR back to return.
Advantages: simple, safe.
Disadvantage: Wait time is long, originally did not start screensaver is not necessarily effective, can not find other administrator ID password, can only modify, if the use of EFS encryption, encryption damage, data loss.