|
yamingw那个大PE可以切换administrator
INSTALL.WIM中的SYSTEM注册表,按他这个就可以
在WIN10PE中使用完整的SYSTEM注册表,从install.wim的注册表修改而来。
修改步骤:
1. 挂在SYSTEM注册表,获取权限,将C:\ ,D:\都替换成X:\
2. 导入FBWF,Ramdisk,WimFsf这3个注册表
3. 删除一些服务,这些服务在PE里不能正常启动,但可能会影响到PE启动。(有些可能是不必删除的)
##=== Delete Services : start=0 ===
RegDelete, HKLM, pe-sys\ControlSet001\Services\PEAUTH
RegDelete, HKLM, pe-sys\ControlSet001\Services\hwpolicy
RegDelete, HKLM, pe-sys\ControlSet001\Services\WdBoot
RegDelete, HKLM, pe-sys\ControlSet001\Services\WdFilter
RegDelete, HKLM, pe-sys\ControlSet001\Services\storflt
##== reference to 2012doberman's PE, WFPLWFS is MUST for WLAN and PPPOE ===
##RegDelete, HKLM, pe-sys\ControlSet001\Services\WFPLWFS
//== fix for rdyboost ==
RegDelete, HKLM, pe-sys\ControlSet001\Services\rdyboost
RegWrite,HKLM,0x7,pe-sys\ControlSet001\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f},LowerFilters,fvevol, NOWARN
##=== win10pe : start=0 ===
RegDelete, HKLM, pe-sys\ControlSet001\Services\DPS
RegDelete, HKLM, pe-sys\ControlSet001\Services\WindowsTrustedRT
RegDelete, HKLM, pe-sys\ControlSet001\Services\WindowsTrustedRTProxy
##=== win10pe : start=1 ===
RegDelete, HKLM, pe-sys\ControlSet001\Services\ahcache
RegDelete, HKLM, pe-sys\ControlSet001\Services\FileCrypt
RegDelete, HKLM, pe-sys\ControlSet001\Services\gencounter
RegDelete, HKLM, pe-sys\ControlSet001\Services\sppsvc
RegDelete, HKLM, pe-sys\ControlSet001\Services\npsvctrig
##=== Delete Services : start=1 ===
RegDelete, HKLM, pe-sys\ControlSet001\Services\Beep
RegDelete, HKLM, pe-sys\ControlSet001\Services\CSC
RegDelete, HKLM, pe-sys\ControlSet001\Services\dam
RegDelete, HKLM, pe-sys\ControlSet001\Services\NetBIOS
RegDelete, HKLM, pe-sys\ControlSet001\Services\Psched
RegDelete, HKLM, pe-sys\ControlSet001\Services\discache
RegDelete, HKLM, pe-sys\ControlSet001\Services\Wanarpv6
4. 修改SYSTEM\Setup的表项,看起来像个PE
RegDelete, HKLM, pe-sys\Setup, RespecializeCmdLine
RegDelete, HKLM, pe-sys\Setup, SetupPhase
RegDelete, HKLM, pe-sys\Setup, CloneTag
RegDelete, HKLM, pe-sys\Setup, Respecialize
RegDelete, HKLM, pe-sys\Setup, OOBEInProgress
RegDelete, HKLM, pe-sys\Setup, WorkingDirectory
//
RegWrite,HKLM,0x4,pe-sys\Setup,RestartSetup,0
RegWrite,HKLM,0x4,pe-sys\Setup,SetupType,1
RegWrite,HKLM,0x4,pe-sys\Setup,SystemSetupInProgress,1
RegWrite,HKLM,0x4,pe-sys\Setup,FactoryPreInstallInProgress,1
RegWrite,HKLM,0x1,pe-sys\Setup,CmdLine,PECMD.EXE MAIN %Windir%\system32\PECMD.INI
5. 处理一些关于Lsa的注册表
RegDelete, HKLM, pe-sys\ControlSet001\Control\LsaInformation
RegDelete, HKLM, pe-sys\ControlSet001\Control\Lsa, SecureBoot
RegDelete, HKLM, pe-sys\ControlSet001\Control, FirmwareBootDevice
RegDelete, HKLM, pe-sys\ControlSet001\Control, LastBootShutdown
RegDelete, HKLM, pe-sys\ControlSet001\Control, LastBootSucceeded
RegDelete, HKLM, pe-sys\ControlSet001\Control, SystemBootDevice
RegDelete, HKLM, pe-sys\ControlSet001\Control, SystemStartOptions
这个需要PE的补充:
RegWrite,HKLM,0x7,pe-sys\ControlSet001\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f},LowerFilters,fvevol,
所以两个加一下,再删除,再当做PE的处理就可以 |
|