实现Utilman.exe Hack的PowerShell脚本ADK PE盘符适配求助
解决ADK PE环境下Utilman.exe Hack脚本的盘符适配问题
核心思路:自动识别目标系统盘
在ADK PE环境中,目标系统盘的核心特征是存在Windows目录且盘符不是X:(X:是PE自身的运行盘)。用以下PowerShell代码可以自动定位该盘符:
# 遍历本地文件系统盘符,筛选出存在Windows目录的非X:盘 $systemDrive = (Get-PSDrive -PSProvider FileSystem | Where-Object { $_.Name -ne 'X' -and (Test-Path -Path "$($_.Root)Windows" -PathType Container) }).Root # 校验是否找到有效系统盘 if (-not $systemDrive) { Write-Host "ERROR: 未找到目标系统盘,请手动确认磁盘盘符后重试" -ForegroundColor Red pause exit }
修改后的完整自动化脚本
将盘符识别逻辑整合到你的菜单脚本中,替换固定的C:路径:
# 自动识别目标系统盘 $systemDrive = (Get-PSDrive -PSProvider FileSystem | Where-Object { $_.Name -ne 'X' -and (Test-Path -Path "$($_.Root)Windows" -PathType Container) }).Root if (-not $systemDrive) { Write-Host "ERROR: 未找到目标系统盘,请手动确认磁盘盘符后重试" -ForegroundColor Red pause exit } # 定义核心路径变量 $utilmanPath = "$systemDrive\Windows\System32\utilman.exe" $utilmanBakPath = "$utilmanPath.bak" $cmdPath = "$systemDrive\Windows\System32\cmd.exe" # 菜单循环 while ($true) { Clear-Host Write-Host "=== Utilman.exe Hack 自动化工具 ===" -ForegroundColor Cyan Write-Host "1. Load (替换Utilman为CMD)" Write-Host "2. Unload (恢复原始Utilman)" Write-Host "3. List Disk (列出所有磁盘盘符)" Write-Host "4. Create Account (创建管理员账户)" Write-Host "5. Exit (退出工具)" Write-Host "==================================" -ForegroundColor Cyan $choice = Read-Host "请输入选择的序号" switch ($choice) { 1 { # Load功能 if (-not (Test-Path $utilmanBakPath)) { Copy-Item -Path $utilmanPath -Destination $utilmanBakPath -Force Copy-Item -Path $cmdPath -Destination $utilmanPath -Force Write-Host "Load完成:已备份Utilman并替换为CMD" -ForegroundColor Green } else { Write-Host "WARN: 已存在Utilman备份文件,跳过Load操作" -ForegroundColor Yellow } pause } 2 { # Unload功能 if (Test-Path $utilmanBakPath) { Remove-Item -Path $utilmanPath -Force Rename-Item -Path $utilmanBakPath -NewName "utilman.exe" -Force Write-Host "Unload完成:已恢复原始Utilman文件" -ForegroundColor Green } else { Write-Host "ERROR: 未找到Utilman备份文件,无法恢复" -ForegroundColor Red } pause } 3 { # List Disk功能 Write-Host "`n当前所有本地磁盘盘符:" -ForegroundColor Cyan Get-PSDrive -PSProvider FileSystem | Select-Object Name, Root | Format-Table -AutoSize Write-Host "`n识别到的目标系统盘:$systemDrive" -ForegroundColor Green pause } 4 { # Create Account功能(示例框架,可自行补充逻辑) $accountName = Read-Host "请输入要创建的账户名" $accountPass = Read-Host "请输入账户密码" -AsSecureString # 此处添加创建账户的代码,注意使用$systemDrive定位系统盘的SAM数据库路径 Write-Host "账户创建功能待实现,需结合PE环境下的账户创建逻辑" -ForegroundColor Yellow pause } 5 { Write-Host "工具退出中..." -ForegroundColor Cyan exit } default { Write-Host "ERROR: 无效输入,请重新选择" -ForegroundColor Red pause } } }
代码放置与执行注意事项
- 存储位置:将脚本保存为
UtilmanHack.ps1,放在U盘根目录或ADK PE镜像的可访问目录(如X:\Scripts),确保PE启动后能读取到。 - 权限要求:必须以管理员权限运行PowerShell,否则无法修改
System32目录下的系统文件。在PE中,右键PowerShell图标选择"以管理员身份运行"即可。 - 校验步骤:执行脚本后先选择
3. List Disk,确认识别的目标系统盘是否正确,避免操作错误磁盘。 - 风险提示:该操作涉及系统文件修改,仅用于合法的系统维护场景,请勿用于未经授权的设备访问。
内容的提问来源于stack exchange,提问作者WillyNull
相关产品推荐
相关产品推荐

