无法找到conhost.exe,求获取其MD5哈希值的解决方法
解决无法找到C:\Windows\System32\conhost.exe的问题
问题原因
你的Windows 10 LTSB 2016是64位系统,当32位进程访问C:\Windows\System32目录时,Windows会自动通过WOW64文件系统重定向将请求指向C:\Windows\SysWOW64目录(存放32位系统文件)。而conhost.exe的64位版本仅存在于System32中,32位进程无法直接访问,因此出现"文件未找到"错误——哪怕用管理员权限也无法绕过这个默认重定向规则。
针对不同工具的解决方案
1. Windows窗体应用(你的C#代码)
有两种可行方案:
方案一:编译为64位程序
在Visual Studio中右键项目 → 属性 → 生成 → 平台目标选择x64,重新编译后运行即可直接访问System32中的文件。方案二:禁用WOW64重定向(适用于需保持32位的程序)
通过Windows API临时禁用重定向,修改后的代码如下:using System; using System.IO; using System.Security.Cryptography; using System.Runtime.InteropServices; using System.Windows.Forms; namespace HashConhost { public partial class Form1 : Form { [DllImport("kernel32.dll", SetLastError = true)] static extern bool Wow64DisableWow64FsRedirection(ref IntPtr ptr); [DllImport("kernel32.dll", SetLastError = true)] static extern bool Wow64RevertWow64FsRedirection(IntPtr ptr); public Form1() { InitializeComponent(); } private void Form1_Load(object sender, EventArgs e) { string filePath = @"C:\windows\system32\conhost.exe"; IntPtr wow64Ptr = IntPtr.Zero; try { // 仅对运行在64位系统上的32位进程禁用重定向 if (Environment.Is64BitOperatingSystem && !Environment.Is64BitProcess) { Wow64DisableWow64FsRedirection(ref wow64Ptr); } using (var md5 = MD5.Create()) { using (var stream = File.OpenRead(filePath)) { var hashBytes = md5.ComputeHash(stream); var hashString = BitConverter.ToString(hashBytes).Replace("-", ""); label1.Text = hashString; } } } catch (Exception ex) { label1.Text = $"错误:{ex.Message}"; } finally { // 恢复重定向,避免影响后续操作 if (wow64Ptr != IntPtr.Zero) { Wow64RevertWow64FsRedirection(wow64Ptr); } } } } }
2. PowerShell
- 如果当前运行的是32位PowerShell(路径通常为
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe),切换到64位PowerShell(路径C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe),执行命令:Get-FileHash -Path "C:\Windows\System32\conhost.exe" -Algorithm MD5
3. 批处理文件
- 使用
%SystemRoot%\Sysnative代替System32(这个路径仅对32位进程可见,直接指向64位的System32目录),命令如下:certutil -hashfile "%SystemRoot%\Sysnative\conhost.exe" MD5 - 或者确保运行的是64位CMD(64位系统默认打开的CMD即为64位,直接执行原路径命令即可)。
内容的提问来源于stack exchange,提问作者Josua Talatala
相关产品推荐
相关产品推荐

