|  | 
| yamingw那个大PE可以切换administrator 
 INSTALL.WIM中的SYSTEM注册表,按他这个就可以
 
 在WIN10PE中使用完整的SYSTEM注册表,从install.wim的注册表修改而来。
 修改步骤:
 1.        挂在SYSTEM注册表,获取权限,将C:\ ,D:\都替换成X:\
 2.        导入FBWF,Ramdisk,WimFsf这3个注册表
 3.        删除一些服务,这些服务在PE里不能正常启动,但可能会影响到PE启动。(有些可能是不必删除的)
 
 ##=== Delete Services : start=0 ===
 RegDelete, HKLM, pe-sys\ControlSet001\Services\PEAUTH
 RegDelete, HKLM, pe-sys\ControlSet001\Services\hwpolicy
 RegDelete, HKLM, pe-sys\ControlSet001\Services\WdBoot
 RegDelete, HKLM, pe-sys\ControlSet001\Services\WdFilter
 RegDelete, HKLM, pe-sys\ControlSet001\Services\storflt
 ##== reference to 2012doberman's PE, WFPLWFS is MUST for WLAN and PPPOE ===
 ##RegDelete, HKLM, pe-sys\ControlSet001\Services\WFPLWFS
 //== fix for rdyboost ==
 RegDelete, HKLM, pe-sys\ControlSet001\Services\rdyboost
 RegWrite,HKLM,0x7,pe-sys\ControlSet001\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f},LowerFilters,fvevol, NOWARN
 ##=== win10pe : start=0 ===
 RegDelete, HKLM, pe-sys\ControlSet001\Services\DPS
 RegDelete, HKLM, pe-sys\ControlSet001\Services\WindowsTrustedRT
 RegDelete, HKLM, pe-sys\ControlSet001\Services\WindowsTrustedRTProxy
 ##=== win10pe : start=1 ===
 RegDelete, HKLM, pe-sys\ControlSet001\Services\ahcache
 RegDelete, HKLM, pe-sys\ControlSet001\Services\FileCrypt
 RegDelete, HKLM, pe-sys\ControlSet001\Services\gencounter
 RegDelete, HKLM, pe-sys\ControlSet001\Services\sppsvc
 RegDelete, HKLM, pe-sys\ControlSet001\Services\npsvctrig
 ##=== Delete Services : start=1 ===
 RegDelete, HKLM, pe-sys\ControlSet001\Services\Beep
 RegDelete, HKLM, pe-sys\ControlSet001\Services\CSC
 RegDelete, HKLM, pe-sys\ControlSet001\Services\dam
 RegDelete, HKLM, pe-sys\ControlSet001\Services\NetBIOS
 RegDelete, HKLM, pe-sys\ControlSet001\Services\Psched
 RegDelete, HKLM, pe-sys\ControlSet001\Services\discache
 RegDelete, HKLM, pe-sys\ControlSet001\Services\Wanarpv6
 
 4. 修改SYSTEM\Setup的表项,看起来像个PE
 RegDelete, HKLM, pe-sys\Setup, RespecializeCmdLine
 RegDelete, HKLM, pe-sys\Setup, SetupPhase
 RegDelete, HKLM, pe-sys\Setup, CloneTag
 RegDelete, HKLM, pe-sys\Setup, Respecialize
 RegDelete, HKLM, pe-sys\Setup, OOBEInProgress
 RegDelete, HKLM, pe-sys\Setup, WorkingDirectory
 //
 RegWrite,HKLM,0x4,pe-sys\Setup,RestartSetup,0
 RegWrite,HKLM,0x4,pe-sys\Setup,SetupType,1
 RegWrite,HKLM,0x4,pe-sys\Setup,SystemSetupInProgress,1
 RegWrite,HKLM,0x4,pe-sys\Setup,FactoryPreInstallInProgress,1
 RegWrite,HKLM,0x1,pe-sys\Setup,CmdLine,PECMD.EXE MAIN %Windir%\system32\PECMD.INI
 
 5. 处理一些关于Lsa的注册表
 RegDelete, HKLM, pe-sys\ControlSet001\Control\LsaInformation
 RegDelete, HKLM, pe-sys\ControlSet001\Control\Lsa, SecureBoot
 RegDelete, HKLM, pe-sys\ControlSet001\Control, FirmwareBootDevice
 RegDelete, HKLM, pe-sys\ControlSet001\Control, LastBootShutdown
 RegDelete, HKLM, pe-sys\ControlSet001\Control, LastBootSucceeded
 RegDelete, HKLM, pe-sys\ControlSet001\Control, SystemBootDevice
 RegDelete, HKLM, pe-sys\ControlSet001\Control, SystemStartOptions
 
 这个需要PE的补充:
 RegWrite,HKLM,0x7,pe-sys\ControlSet001\Control\Class\{71a27cdd-812a-11d0-bec7-08002be2092f},LowerFilters,fvevol,
 
 所以两个加一下,再删除,再当做PE的处理就可以
 | 
 |