
两台旧电脑修复 —— 绕过WinXP密码登录、备份和恢复Win7数据、安装Win10前言国庆回家邻居有两台旧电脑一台是WinXP系统的台式机忘记了密码一台是Win7系统的笔记本电脑完全无法进入系统。故寻求我来帮忙修复这两台电脑。PE盘制作恰逢手中PE盘被某位格外讨人喜欢的同事征用故重做一枚。U盘数据备份临时找了一个U盘借助手中Mac制作一个镜像到Mac上待U盘重装的使命完成后再恢复。第一次使用了dd命令sudoddif/dev/rdisk4of~/Downloads/usb-backup.imgbs4m结果发现U盘里面只有几十M的文件而这个命令需要制作U盘总容量等大的DMG。故改用了hdiutil命令只保存已使用内容并带上一部分的压缩算法hdiutil create-srcdevice/dev/rdisk4-formatUDZO-o/Users/tisfy/Downloads/usb-backup.dmg启动盘制作Mac上制作PE盘使用了Ventoy使用第三方的fcjr/ventoy2disk-cli安装到U盘上。Ventoy启动盘占据U盘空间很小剩余空间则直接将ISO文件拷贝到根目录上即可自动识别。但是Ventoy官方只支持Windows和Linux系统所以可以使用第三方的fcjr/ventoy-mac在Mac上制作Ventoy启动盘。brewinstall--caskfcjr/fcjr/ventoy2disk-cli diskutil list external# 确认USB是/dev/disk4sudoventoy2disk-i/dev/disk4结果ventoy2disk下载最新版的Ventoy 1.1.17很慢故手动从Ventoy Releases下载了最新版ventoy-1.1.17-linux.tar.gz解压得到了ventoy-1.1.17文件夹之后指定ventoy的位置并制作启动盘sudoventoy2disk-i/dev/disk4--pack~/Downloads/ventoy-1.1.17stdout如下Password: ********************************************** ventoy2diskformacOS(0.1.2)Ventoy: https://www.ventoy.net ********************************************** Disk:/dev/disk4 Size:127GiB Style: MBR Ventoy version:1.1.17 Secure boot support: YES WARNING: All data on /dev/disk4 will be lost!Continue?(y/n)y WARNING: All data on /dev/disk4 will be lost!Double-check. Continue?(y/n)y Clearing old partition data... Formatting partition1(exFAT, labelVentoy)... Writing EFI partition image... Writing boot image... Writing partition table... Syncing... Install Ventoy1.1.17 to /dev/disk4 successfully finished. You can now copy ISO files to theVentoyvolume once macOS remounts it.之后把要安装的ios镜像拷贝到这个叫Ventoy的U盘根目录上就好了。我一共下载拷贝了三个镜像下文会详细说明来源和用途cd140201.isoWePE_64_V2.3.isoWin10_22H2_Chinese_Simplified_x64v1.isoU盘数据还原diskutil list external diskutil info /dev/disk4 diskutil info /dev/disk4|grepProtocol# 确认USB是/dev/disk4diskutil unmountDisk /dev/disk4看下要还原多少数据cat/tmp/restore-dmg-sparse.pyPY #!/usr/bin/env python3 import base64 import plistlib import struct import subprocess import sys DMG /Users/tisfy/Downloads/usb-backup.dmg SECTOR_SIZE 512 DATA_TYPES { 0x00000001, # raw 0x80000004, # ADC 0x80000005, # zlib / UDZO 0x80000006, # bzip2 0x80000007, # LZFSE } xml subprocess.check_output( [hdiutil, udifderez, -xml, DMG] ) plist plistlib.loads(xml) rf plist.get(resource-fork, plist) blkx_list rf[blkx] chunks [] for entry in blkx_list: mish entry[Data] if isinstance(mish, str): mish base64.b64decode(mish) if mish[:4] ! bmish: raise RuntimeError(发现无效的 BLKX/MISH 数据) image_sector struct.unpack_from(Q, mish, 8)[0] count struct.unpack_from(I, mish, 200)[0] for i in range(count): off 204 i * 40 typ, comment, sector, sector_count, compressed_offset, compressed_length \ struct.unpack_from(IIQQQQ, mish, off) if typ 0xFFFFFFFF: break if typ 0x7FFFFFFE: # comment continue if typ in (0x00000000, 0x00000002): # zero/free run不需要从镜像读取 continue if typ not in DATA_TYPES: raise RuntimeError( f遇到未处理的 chunk 类型: 0x{typ:08x} ) absolute_sector image_sector sector chunks.append(( absolute_sector, sector_count, typ, )) chunks.sort() total sum(count * SECTOR_SIZE for _, count, _ in chunks) print(f需要写入的实际数据: {total:,} bytes) print(f约 {total / 1024 / 1024:.2f} MiB) print(f数据块数量: {len(chunks)}) print() for sector, count, typ in chunks: print( fsector{sector:10} fcount{count:10} fbytes{count * SECTOR_SIZE:12} ftype0x{typ:08x} ) PYpython3 /tmp/restore-dmg-sparse.pyrm/tmp/restore-dmg-sparse.py运行结果hdiutil: WARNING: udifderez is deprecated 需要写入的实际数据: 49,443,328 bytes 约 47.15 MiB 数据块数量: 59 sector0 count1 bytes512 type0x80000005 sector32 count2048 bytes1048576 type0x80000005 sector2080 count2048 bytes1048576 type0x80000005 sector4128 count2048 bytes1048576 type0x80000005 sector6176 count2048 bytes1048576 type0x80000005 sector8224 count2048 bytes1048576 type0x80000005 sector10272 count2048 bytes1048576 type0x80000005 sector12320 count2048 bytes1048576 type0x80000005 sector14368 count2048 bytes1048576 type0x80000005 sector16416 count2048 bytes1048576 type0x80000005 sector18464 count2048 bytes1048576 type0x80000005 sector20512 count2048 bytes1048576 type0x80000005 sector22560 count2048 bytes1048576 type0x80000005 sector24608 count2048 bytes1048576 type0x80000005 sector26656 count2048 bytes1048576 type0x80000005 sector28704 count2048 bytes1048576 type0x80000005 sector30752 count2048 bytes1048576 type0x80000005 sector32800 count2048 bytes1048576 type0x80000005 sector34848 count192 bytes98304 type0x80000005 sector754272 count8 bytes4096 type0x80000005 sector1122872 count8 bytes4096 type0x80000005 sector4749208 count8 bytes4096 type0x80000005 sector4773288 count2048 bytes1048576 type0x80000005 sector4775336 count2048 bytes1048576 type0x00000001 sector4777384 count2048 bytes1048576 type0x00000001 sector4779432 count2048 bytes1048576 type0x00000001 sector4781480 count2048 bytes1048576 type0x00000001 sector4783528 count2048 bytes1048576 type0x00000001 sector4785576 count2048 bytes1048576 type0x00000001 sector4787624 count2048 bytes1048576 type0x00000001 sector4789672 count2048 bytes1048576 type0x00000001 sector4791720 count2048 bytes1048576 type0x00000001 sector4793768 count2048 bytes1048576 type0x00000001 sector4795816 count2048 bytes1048576 type0x00000001 sector4797864 count2048 bytes1048576 type0x00000001 sector4799912 count2048 bytes1048576 type0x00000001 sector4801960 count2048 bytes1048576 type0x80000005 sector4804008 count1808 bytes925696 type0x80000005 sector4810896 count2048 bytes1048576 type0x00000001 sector4812944 count2048 bytes1048576 type0x80000005 sector4814992 count2048 bytes1048576 type0x80000005 sector4817040 count2048 bytes1048576 type0x00000001 sector4819088 count2048 bytes1048576 type0x00000001 sector4821136 count2048 bytes1048576 type0x00000001 sector4823184 count2048 bytes1048576 type0x00000001 sector4825232 count2048 bytes1048576 type0x00000001 sector4827280 count2048 bytes1048576 type0x00000001 sector4829328 count2048 bytes1048576 type0x00000001 sector4831376 count208 bytes106496 type0x80000005 sector9992088 count2048 bytes1048576 type0x80000005 sector9994136 count2048 bytes1048576 type0x80000005 sector9996184 count424 bytes217088 type0x80000005 sector10007328 count24 bytes12288 type0x80000005 sector10011120 count1168 bytes598016 type0x80000005 sector10023688 count1336 bytes684032 type0x80000005 sector10029416 count744 bytes380928 type0x80000005 sector10046472 count120 bytes61440 type0x80000005 sector10617384 count400 bytes204800 type0x80000005 sector11040712 count8 bytes4096 type0x80000005写入数据cat/tmp/restore-dmg-sparse-write.pyPY #!/usr/bin/env python3 import base64 import os import plistlib import re import struct import subprocess import sys DMG /Users/tisfy/Downloads/usb-backup.dmg TARGET /dev/disk4 SECTOR_SIZE 512 DATA_TYPES { 0x00000001, # raw 0x80000004, # ADC 0x80000005, # zlib 0x80000006, # bzip2 0x80000007, # LZFSE } def run(*args): return subprocess.check_output(args, textTrue) # ------------------------------------------------------------ # 1. DMG 保持未挂载先读取 blkx # ------------------------------------------------------------ xml subprocess.check_output( [hdiutil, udifderez, -xml, DMG] ) plist plistlib.loads(xml) rf plist.get(resource-fork, plist) chunks [] for entry in rf[blkx]: mish entry[Data] if isinstance(mish, str): mish base64.b64decode(mish) if mish[:4] ! bmish: raise RuntimeError(Invalid MISH block map) image_sector struct.unpack_from(Q, mish, 8)[0] count struct.unpack_from(I, mish, 200)[0] for i in range(count): off 204 i * 40 typ, comment, sector, sector_count, _, _ \ struct.unpack_from(IIQQQQ, mish, off) if typ 0xFFFFFFFF: break if typ 0x7FFFFFFE: continue # 空白块 / 0 填充块 if typ in (0x00000000, 0x00000002): continue if typ not in DATA_TYPES: raise RuntimeError( fUnsupported chunk type: 0x{typ:08x} ) chunks.append(( image_sector sector, sector_count )) chunks.sort() total sum(count * SECTOR_SIZE for _, count in chunks) print(fDMG: {DMG}) print(f目标: {TARGET}) print(f实际写入: {total:,} bytes ({total / 1024 / 1024:.2f} MiB)) print(f数据块: {len(chunks)}) print() # ------------------------------------------------------------ # 2. 卸载目标 U 盘 # ------------------------------------------------------------ subprocess.run( [diskutil, unmountDisk, TARGET], checkTrue ) # ------------------------------------------------------------ # 3. 挂载 DMG但不挂载其中的文件系统 # ------------------------------------------------------------ attach_output subprocess.check_output( [hdiutil, attach, -nomount, -readonly, DMG], textTrue, stderrsubprocess.STDOUT ) print(attach_output) match re.search( r^(/dev/disk\d)\sFDisk_partition_scheme\s*$, attach_output, re.MULTILINE ) if not match: raise RuntimeError( 无法从 hdiutil attach 输出中找到磁盘设备 ) source_disk match.group(1) source_raw source_disk.replace(/dev/disk, /dev/rdisk) print(f源虚拟磁盘: {source_raw}) print(f目标物理磁盘: {TARGET}) print() # ------------------------------------------------------------ # 4. 最后一次人工确认 # ------------------------------------------------------------ print(即将进行稀疏恢复。) print() print(f源 : {source_raw} ← usb-backup.dmg) print(f目标: {TARGET} ← U 盘) print() print(f将写入约 {total / 1024 / 1024:.2f} MiB而不是整个 8 GB。) print() answer input(确认目标确实是 U 盘并继续输入 YES) if answer ! YES: print(已取消没有写入 U 盘。) subprocess.run([hdiutil, detach, source_disk]) sys.exit(1) # ------------------------------------------------------------ # 5. 只写 blkx 中实际存在的数据区域 # ------------------------------------------------------------ src os.open(source_raw, os.O_RDONLY) dst os.open( TARGET.replace(/dev/disk, /dev/rdisk), os.O_RDWR ) try: done 0 for index, (sector, sector_count) in enumerate(chunks, 1): offset sector * SECTOR_SIZE remaining sector_count * SECTOR_SIZE os.lseek(src, offset, os.SEEK_SET) os.lseek(dst, offset, os.SEEK_SET) while remaining: size min(1024 * 1024, remaining) data os.read(src, size) if len(data) ! size: raise RuntimeError( f读取源失败: sector{sector}, fexpected{size}, got{len(data)} ) written 0 while written len(data): n os.write(dst, data[written:]) if n 0: raise RuntimeError(写入目标 U 盘失败) written n remaining - size done size print( f[{index:2d}/{len(chunks)}] f{done / 1024 / 1024:7.2f} / f{total / 1024 / 1024:.2f} MiB, flushTrue ) os.fsync(dst) print() print(恢复完成。) finally: os.close(src) os.close(dst) subprocess.run( [hdiutil, detach, source_disk], checkFalse ) PY再确认一次diskutil info /dev/disk4 | grep Protocol确认是目标USB运行sudopython3 /tmp/restore-dmg-sparse-write.pyrm/tmp/restore-dmg-sparse-write.py运行结果sudo python3 /tmp/restore-dmg-sparse-write.py hdiutil: WARNING: udifderez is deprecated DMG: /Users/tisfy/Downloads/usb-backup.dmg 目标: /dev/disk4 实际写入: 49,443,328 bytes (47.15 MiB) 数据块: 59 Unmount of all volumes on disk4 was successful 预计CRC32 $168A17EE hdiutil: WARNING: hdiutil attach -nomount -readonly ... is deprecated. Please use diskutil image attach --noMount --readOnly ... instead. /dev/disk5 FDisk_partition_scheme /dev/disk5s1 DOS_FAT_32 源虚拟磁盘: /dev/rdisk5 目标物理磁盘: /dev/disk4 即将进行稀疏恢复。 源 : /dev/rdisk5 ← usb-backup.dmg 目标: /dev/disk4 ← U 盘 将写入约 47.15 MiB而不是整个 8 GB。 确认目标确实是 U 盘并继续输入 YESYES [ 1/59] 0.00 / 47.15 MiB [ 2/59] 1.00 / 47.15 MiB [ 3/59] 2.00 / 47.15 MiB [ 4/59] 3.00 / 47.15 MiB [ 5/59] 4.00 / 47.15 MiB [ 6/59] 5.00 / 47.15 MiB [ 7/59] 6.00 / 47.15 MiB [ 8/59] 7.00 / 47.15 MiB [ 9/59] 8.00 / 47.15 MiB [10/59] 9.00 / 47.15 MiB [11/59] 10.00 / 47.15 MiB [12/59] 11.00 / 47.15 MiB [13/59] 12.00 / 47.15 MiB [14/59] 13.00 / 47.15 MiB [15/59] 14.00 / 47.15 MiB [16/59] 15.00 / 47.15 MiB [17/59] 16.00 / 47.15 MiB [18/59] 17.00 / 47.15 MiB [19/59] 17.09 / 47.15 MiB [20/59] 17.10 / 47.15 MiB [21/59] 17.10 / 47.15 MiB [22/59] 17.11 / 47.15 MiB [23/59] 18.11 / 47.15 MiB [24/59] 19.11 / 47.15 MiB [25/59] 20.11 / 47.15 MiB [26/59] 21.11 / 47.15 MiB [27/59] 22.11 / 47.15 MiB [28/59] 23.11 / 47.15 MiB [29/59] 24.11 / 47.15 MiB [30/59] 25.11 / 47.15 MiB [31/59] 26.11 / 47.15 MiB [32/59] 27.11 / 47.15 MiB [33/59] 28.11 / 47.15 MiB [34/59] 29.11 / 47.15 MiB [35/59] 30.11 / 47.15 MiB [36/59] 31.11 / 47.15 MiB [37/59] 32.11 / 47.15 MiB [38/59] 32.99 / 47.15 MiB [39/59] 33.99 / 47.15 MiB [40/59] 34.99 / 47.15 MiB [41/59] 35.99 / 47.15 MiB [42/59] 36.99 / 47.15 MiB [43/59] 37.99 / 47.15 MiB [44/59] 38.99 / 47.15 MiB [45/59] 39.99 / 47.15 MiB [46/59] 40.99 / 47.15 MiB [47/59] 41.99 / 47.15 MiB [48/59] 42.99 / 47.15 MiB [49/59] 43.09 / 47.15 MiB [50/59] 44.09 / 47.15 MiB [51/59] 45.09 / 47.15 MiB [52/59] 45.30 / 47.15 MiB [53/59] 45.31 / 47.15 MiB [54/59] 45.88 / 47.15 MiB [55/59] 46.53 / 47.15 MiB [56/59] 46.90 / 47.15 MiB [57/59] 46.95 / 47.15 MiB [58/59] 47.15 / 47.15 MiB [59/59] 47.15 / 47.15 MiB 恢复完成。 hdiutil: WARNING: hdiutil detach ... is deprecated. Please use diskutil eject ... instead. disk5 ejected.这样相当于是备份和恢复U盘都几乎只读写了实际使用的数据而不是整个U盘的容量。只是有些曲折罢了。绕过WinXP密码登录邻居家WinXP系统的古早台式机多年未使用忘记了密码无法登录。尝试一些常见密码无果尝试了CtrlAltDel两次进入经典登录界面仍然无法登录。在Offline NT Password Registry Editorchntpw官网下载了cd140201.zip解压得到了一个17.9MB的ISO文件cd140201.iso拷贝到Ventoy启动盘上。Windows XP 的本地账户信息主要存在C:\Windows\System32\config\SAMSAM全称是Security Accounts Manager它不是一个普通的文本文件而是 Windows Registry hive注册表配置单元。里面保存了本地账户相关的数据包括账户标识、密码验证所需的信息、账户状态等。而cd140201.iso自己启动的是一个非常小的 Linux 环境包含了 访问NTFS文件系统 和 操作SAM文件 的必要组件。Linux 可以直接把 NTFS 分区挂载起来然后读取这个文件chntpw 再按照 Windows Registry Hive 的格式解析它获取账户信息并清除掉密码。具体操作过程如下插入U盘并选择U盘启动后Ventoy 会先显示自身菜单。选择cd140201.iso后进入该镜像的引导菜单。┌─────────────────────────────────────────────────────┐ │ Ventoy 引导菜单 │ │─────────────────────────────────────────────────────│ │ Boot in normal mode ← 选择此项 │ │ Boot in grub2 mode │ │ Boot in memdisk mode │ │ File checksum │ │ Return to previous menu │ │─────────────────────────────────────────────────────│ │ 1.1.17 BIOS L:Language F1:Help F2:Browse │ │ F3:TreeView F4:Localboot F5:Tools F6:ExMenu │ └─────────────────────────────────────────────────────┘选择Boot in normal mode正常启动即可。进入 chntpw 的引导提示符后直接按回车使用默认参数启动┌─────────────────────────────────────────────────────┐ │ Windows Reset Password / Registry Editor │ │ (c) 1998-2014 Petter Nordahl-Hagen │ │─────────────────────────────────────────────────────│ │ DISCLAIMER: THIS SOFTWARE COMES WITH ABSOLUTELY │ │ NO WARRANTY... │ │─────────────────────────────────────────────────────│ │ CD build date: Sat Feb 1 17:35:02 CET 2014 │ │─────────────────────────────────────────────────────│ │ Press enter to boot, or give linux kernel boot │ │ options first. │ │ Some that I have to use once in a while: │ │ boot nousb - to turn off USB if not used │ │ boot irqpoll - if some drivers hang │ │ boot vgaask - if video mode problems │ │ boot nodrivers - skip automatic disk driver │ │─────────────────────────────────────────────────────│ │ boot: _ │ └─────────────────────────────────────────────────────┘之后系统会自动扫描磁盘列出所有分区并检测 Windows 安装位置┌────────────────────────────────────────────────────────────┐ │ Step ONE: Select disk partition where the Windows │ │ installation is located │ │────────────────────────────────────────────────────────────│ │ DISK PARTITIONS: │ │ 1 sda1 249856000 7 243996 │ │ 2 sda2 32768 3 32 │ │ 3 sdb1 52429072 7 51200 ← NTFS, 有Windows │ │ 4 sdb5 14575236 139 142336 │ │ 5 sdb6 14575236 139 142336 │ │ 6 sdb7 14445191 137 141066 │ │────────────────────────────────────────────────────────────│ │ 51200MB Partition sdb1 is NTFS: │ │ Found WINDOWS on: WINDOWS/system32/config │ │────────────────────────────────────────────────────────────│ │ Possible windows installations found: │ │ 1 sdb1 51200MB WINDOWS/system32/config │ │────────────────────────────────────────────────────────────│ │ Select: [1] _ │ └────────────────────────────────────────────────────────────┘其中sda1和sda2是U盘的两个分区sdb*是电脑硬盘的分区。chntpw在sdb1分区找到了Windows安装位置输入1回车Selected 1 Mounting from /dev/sdb1 with filesystem type NTFS Yes, read-write, seems OK Success!┌─────────────────────────────────────────────────────┐ │ Step TWO: Select registry files │ │─────────────────────────────────────────────────────│ │ drwxrwxrwx 1 0 0 262144 May 17 2025 All Users│ │ drwxrwxrwx 1 0 0 262144 Dec 31 2025 DEFAULT │ │ drwxrwxrwx 1 0 0 131072 Dec 31 2025 SECURITY │ │ drwxrwxrwx 1 0 0 6553600 Dec 31 2025 software│ │ drwxrwxrwx 1 0 0 262144 Jan 1 2026 system │ │ drwxrwxrwx 1 0 0 6553600 Dec 31 2025 userdiff │ │─────────────────────────────────────────────────────│ │ Select which part of registry to load: │ │ 1 - Password reset [sam] ← 选择此项 │ │ 2 - RecoveryConsole parameters [software] │ │ 3 - quit almost any other parameter... │ │ Select: [1] _ │ └─────────────────────────────────────────────────────┘直接按回车默认选择1 - Password reset [sam]屏幕显示Loaded hives: SAM表示 SAM 数据库已成功加载。工具自动列出了所有本地用户┌──────────────────────────────────────────────────────┐ │ chntpw Edit User Info Passwords │ │──────────────────────────────────────────────────────│ │ RID User Name Admin? Lock? │ │ 01f4 Administrator ADMIN dis/lock │ │ 01f5 Guest - dis/lock │ │ 03eb HelpAssistant - dis/lock │ │ 03ea SUPPORT_388945a0 - dis/lock │ │──────────────────────────────────────────────────────│ │ Please enter user number (RID) or 0 to exit: [1f4] │ │──────────────────────────────────────────────────────│ │ RID: 0500 [01f4] │ │ Username: Administrator │ │ Fullname: Administrator │ │ Comment: **X │ │──────────────────────────────────────────────────────│ │ Account bits: 0x0214 │ │ [ ] Disabled [X] Normal account │ │ [ ] Temp duplicate [ ] Wks trust act. │ │ [X] Pwd dont expire [ ] Auto lockout │ │──────────────────────────────────────────────────────│ │ Failed login count: 276, while max tries is: 0 │ │ Total login count: 276 │ │──────────────────────────────────────────────────────│ │ User Edit Menu: │ │ 1 - Clear (blank) user password │ │ 2 - Unlock and enable user account │ │ 3 - Promote user to administrator │ │ 4 - Add user to a group │ │ 5 - Remove user from a group │ │ q - Quit editing user, back to user select │ │ Select: [q] _ │ └──────────────────────────────────────────────────────┘输入1f4回车选中Administrator发现已经尝试了276次失败登录Lock?列显示dis/lock表示账户已禁用且锁定。先输入2解锁账户再输入1清除密码┌──────────────────────────────────────────────────────┐ │ Select: [q] 2 │ │ Unlocked! │ │──────────────────────────────────────────────────────│ │ Failed login count: 0 ← 已归零 │ │ Account bits: 0x0214 │ │ [ ] Disabled [X] Normal account │ │ [X] Pwd dont expire [ ] Auto lockout │ │──────────────────────────────────────────────────────│ │ Select: [q] 1 │ │ Password cleared! │ │──────────────────────────────────────────────────────│ │ Select: [q] _ │ └──────────────────────────────────────────────────────┘之后需要逐级退出并保存更改输入q退出用户编辑菜单再次输入q退回到主菜单主菜单询问Write changes?必须输入y并回车不保存的话前面操作相当于白做了继续按q退出直到能输入命令输入reboot重启电脑当系统完成关机拔掉U盘系统启动正常进入XinXP系统没有密码直接进入了桌面数据也都完好无损。坏得不能再坏的Win7-Win10系统重装邻居家还有一台坏得不能再坏的Win7系统完全无法进入系统需要备份重装。下载Win10镜像先访问官网选择版本选Windows 10多版本ISO选择产品语言找到简体中文点击确认可以获得两个有效期为24小时的下载链接选择64位下载即可。将得到的Win10_22H2_Chinese_Simplified_x64v1.iso拷贝到Ventoy启动盘上。笔记本为多年前联想ThinkPad启动按F8上下按键选中USB回车。进入Ventoy菜单选择Win10_22H2_Chinese_Simplified_x64v1.iso回车继续选择Boot in normal mode进入安装界面。数据备份在看到图形化界面后Fn Shift F10打开命令行E: mkdir FromC robocopy C:\Users\Administrator E:\FromC\Administrator /E /R:1 /W:1过一阵子发现开始递归了路径越来越长windows\system32\cmd.exe robocopy C:\Users\Administrator E:\fromC\Administrator /R:1 /W:1 目录 Data\Application Data 0 C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data 源目录 Filter\ Data\Application Data 0 C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data Data\Application Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data 新目录 Data\Application Data 0 C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data Data\Application Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data\Application Data 新目录 Data\Application Data 0 C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data 新目录 Data\Application Data 2 C:\Users\Administrator\AppData\Local\Application Data\Application Data Data\Application Data\Application Data C:\Users\Administrator\AppData\Local\Application Data\Application Data\Application Data 新文件 195.6 m CEF_AndrowsStore.log PC_YYB_SDK.logCtrlC终止尝试使用图形界面备份。在命令行输入notepad打开记事本点击文件-打开诶资源管理器出现了。在C盘找到C:\Users\Administrator右键复制在E盘删除重建FromC文件夹并右键粘贴还是卡死。X:\Windows\System32\taskkill.exe /f /im notepad.exe强行终止并删掉重建FromC文件夹改为只备份重要的数据robocopy C:\Users\Administrator\Desktop E:\FromC\Desktop /E /XJ /R:1 /W:1 robocopy C:\Users\Administrator\Documents E:\FromC\Documents /E /XJ /R:1 /W:1 robocopy C:\Users\Administrator\Downloads E:\FromC\Downloads /E /XJ /R:1 /W:1 robocopy C:\Users\Administrator\Pictures E:\FromC\Pictures /E /XJ /R:1 /W:1之后格式化C盘准备开始重装diskpart list disk select disk 0 clean好家伙忽然想起来三个分区在物理上是一块硬盘这一下子给全部格式化了。立刻停止操作关机回去做恢复盘。数据恢复于是想到了大名鼎鼎的微PE微PE默认只支持Windows系统官网无ios镜像官方的iso镜像获取方式是运行微PE的可执行程序.exe生成iso镜像。于是在网上找了个 微PE ISO镜像不知是否官方但实测可用。下载地址Internet Archive We PE 64 V 2.3 微PE工具箱结果下载下来 和 Ventoy Issue 以及 Ventoy 官网iso 列表 的sha值b687e3f3b6eb09e531fcf57eb8c5cf0d236925ea对不上我的是43b9ccf9024929ff4625cd3c3aa68b1435807770。这次铤而走险倒是没出现什么幺蛾子后续对应这么常用的东西还是在主机上也备份一份吧。镜像放入Ventoy启动盘在ThinkPad上进入Ventoy后选择WePE_64_V2.3.iso启动打开DiskGenius选中被格式化的硬盘上方菜单栏工具 - 搜索已丢失分区重建分区表选择整个磁盘开始搜索好在一点点搜索找到了原来的三个分区点击左上角保存更改之前的数据回来了。Win10重装继续在微PE里面格式化C盘由于该笔记本是比较老的Legacy BIOS和MBR分区模式所以也不需要一个额外的系统引导分区微PE的Windows安装器选择Win10_22H2_Chinese_Simplified_x64v1.iso、引导驱动器位置和安装驱动器位置都选择C盘点击安装。等进度条读完就好了。安装过程中我还遇到了好几次安装一般系统直接关机。一摸笔记本好烫家伙猜测是过热断电保护。于是使用一盒牛奶让笔记本底部悬空使用邻家小娃的小风扇吹着终于顺利安装完毕。End本文v1版本ASCII图绘制自DeepSeek。同步发文于CSDN和我的个人博客原创不易转载经作者同意后请附上原文链接哦~千篇源码题解已开源