如何修改explorer.exe资源?替换通知图标后保留数字签名咨询
Hey there! Let's walk through what you need to know about digital signatures in your scenario—you’ve already crafted a more noticeable notification icon (nice touch matching the original byte size!) and modified explorer.exe with ResourceHacker, so let’s break down the signature piece clearly.
First, a critical reality check: you can’t retain the original Microsoft digital signature on your modified explorer.exe. Here’s why:
- Digital signatures work by hashing the entire file’s content and encrypting that hash with the signer’s private key (in this case, Microsoft’s).
- Even if your new icon has the exact same file size as the original, changing its pixel data alters the file’s overall content. This shifts the file’s hash value completely, making the original signature invalid. There’s no way to "reuse" or "preserve" the original signature once the file is modified.
Now, let’s cover your actionable options based on what you’re trying to do:
Option 1: Use the modified file for personal use (no valid signature)
If this is just for your own machine, you can bypass Windows’ signature checks:
- Temporary bypass: Restart your PC, press F8 during boot, and select "Disable Driver Signature Enforcement". This works until your next restart.
- Permanent bypass (with caveats): Run Command Prompt as Administrator and execute:
Restart your PC—you’ll see a "Test Mode" watermark in the bottom-right corner, but Windows will allow unsigned or self-signed system files to run. Note that this reduces system security, so only use it if you fully trust your modified file.bcdedit /set testsigning on
Option 2: Sign the modified file (for personal or limited distribution)
If you want Windows to recognize the file as "trusted" without bypassing checks, you’ll need to sign it yourself:
- Generate a self-signed certificate:
- You’ll need the Windows SDK (which includes tools like
makecertandsigntool). Once installed, open an elevated Command Prompt and run:makecert -r -pe -n "CN=Your Name" -ss MY -sr LocalMachine -eku 1.3.6.1.5.5.7.3.3 -len 2048 -sky signature -sy 12 MyTestCert.cer - This creates a self-signed code-signing certificate and adds it to your local machine’s certificate store.
- You’ll need the Windows SDK (which includes tools like
- Sign the modified
explorer.exe:- Still in elevated Command Prompt, run:
signtool sign /v /s MY /n "Your Name" /t http://timestamp.digicert.com explorer.exe - The timestamp server ensures the signature remains valid even after your certificate expires.
- Still in elevated Command Prompt, run:
- Trust the certificate:
- Open the Certificate Manager (
certmgr.msc), navigate to "Trusted Root Certification Authorities > Certificates", find your self-signed cert, and confirm it’s marked as trusted.
- Open the Certificate Manager (
Keep in mind: This signature will only be trusted on your machine (or any machine where you install the certificate). Windows will still flag it as not signed by Microsoft, but it won’t block the file from running.
Important Notes About Replacing explorer.exe
- Always back up the original
explorer.exebefore replacing it—if something goes wrong, you can restore it from a backup or Windows recovery media. - Since
explorer.exeruns as part of the Windows shell, you’ll need to replace it while it’s not running: either boot into Safe Mode, use a PE (Preinstallation Environment) USB, or terminate theexplorer.exeprocess temporarily (via Task Manager) before copying the modified file.
内容的提问来源于stack exchange,提问作者Luis Ferrao

