You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法找到conhost.exe,求获取其MD5哈希值的解决方法

解决无法找到C:\Windows\System32\conhost.exe的问题

问题原因

你的Windows 10 LTSB 2016是64位系统,当32位进程访问C:\Windows\System32目录时,Windows会自动通过WOW64文件系统重定向将请求指向C:\Windows\SysWOW64目录(存放32位系统文件)。而conhost.exe的64位版本仅存在于System32中,32位进程无法直接访问,因此出现"文件未找到"错误——哪怕用管理员权限也无法绕过这个默认重定向规则。

针对不同工具的解决方案

1. Windows窗体应用(你的C#代码)

有两种可行方案:

  • 方案一:编译为64位程序
    在Visual Studio中右键项目 → 属性 → 生成 → 平台目标选择x64,重新编译后运行即可直接访问System32中的文件。

  • 方案二:禁用WOW64重定向(适用于需保持32位的程序)
    通过Windows API临时禁用重定向,修改后的代码如下:

    using System;
    using System.IO;
    using System.Security.Cryptography;
    using System.Runtime.InteropServices;
    using System.Windows.Forms;
    
    namespace HashConhost
    {
        public partial class Form1 : Form
        {
            [DllImport("kernel32.dll", SetLastError = true)]
            static extern bool Wow64DisableWow64FsRedirection(ref IntPtr ptr);
    
            [DllImport("kernel32.dll", SetLastError = true)]
            static extern bool Wow64RevertWow64FsRedirection(IntPtr ptr);
    
            public Form1()
            {
                InitializeComponent();
            }
    
            private void Form1_Load(object sender, EventArgs e)
            {
                string filePath = @"C:\windows\system32\conhost.exe";
                IntPtr wow64Ptr = IntPtr.Zero;
                try
                {
                    // 仅对运行在64位系统上的32位进程禁用重定向
                    if (Environment.Is64BitOperatingSystem && !Environment.Is64BitProcess)
                    {
                        Wow64DisableWow64FsRedirection(ref wow64Ptr);
                    }
    
                    using (var md5 = MD5.Create())
                    {
                        using (var stream = File.OpenRead(filePath))
                        {
                            var hashBytes = md5.ComputeHash(stream);
                            var hashString = BitConverter.ToString(hashBytes).Replace("-", "");
                            label1.Text = hashString;
                        }
                    }
                }
                catch (Exception ex)
                {
                    label1.Text = $"错误:{ex.Message}";
                }
                finally
                {
                    // 恢复重定向,避免影响后续操作
                    if (wow64Ptr != IntPtr.Zero)
                    {
                        Wow64RevertWow64FsRedirection(wow64Ptr);
                    }
                }
            }
        }
    }
    

2. PowerShell

  • 如果当前运行的是32位PowerShell(路径通常为C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe),切换到64位PowerShell(路径C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe),执行命令:
    Get-FileHash -Path "C:\Windows\System32\conhost.exe" -Algorithm MD5
    

3. 批处理文件

  • 使用%SystemRoot%\Sysnative代替System32(这个路径仅对32位进程可见,直接指向64位的System32目录),命令如下:
    certutil -hashfile "%SystemRoot%\Sysnative\conhost.exe" MD5
    
  • 或者确保运行的是64位CMD(64位系统默认打开的CMD即为64位,直接执行原路径命令即可)。

内容的提问来源于stack exchange,提问作者Josua Talatala

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 17:45:24