Anyway once you've persuaded the user to import a .reg file as administrator, it's game over. There are so many registry entries with exploitable possibilities. (It's similar to persuading a Linux user to unpack a tarball over /etc)
While I'm here...
hivex is a Linux library for accessing and modifying the Windows registry (https://github.com/libguestfs/hivex), and virt-win-reg is a Linux tool for modifying the registry of a VM (https://libguestfs.org/virt-win-reg.1.html). After many hours discovering how the registry works to write those, I also wrote this about why the registry sucks: https://rwmj.wordpress.com/2010/02/18/why-the-windows-regist...