Posted 15 June 2010 - 06:17 AM
[*]What is your Windows drive letter in real disk, in disk image ?
-> c: and c:
[*]What is your real disk MBR signature and disk image MBR signature ?
-> c5 0a c3 76 / 80 cc 80 cc
[*]What values and data are in your MountedDevices keys when you boot real disk ?
->"\\DosDevices\\C:"=hex:c5,0a,c3,76,00,7e,00,00,00,00,00,00
[*]What values and data are in your MountedDevices keys in disk image ?
->"\\DosDevices\\C:"=hex:80,cc,80,cc,00,7e,00,00,00,00,00,00
[*]What values and data are in your MountedDevices keys when you boot in RAM ?
E and F are cdrom and a usbkey (mounted afterwards)
[HKEY_LOCAL_MACHINE\SYSTEM\MountedDevices]
[HKEY_LOCAL_MACHINE\SYSTEM\MountedDevices]
"\\??\\Volume{31de32ea-351c-11df-921a-806d6172696f}"=hex:80,cc,80,cc,00,7e,00,\
00,00,00,00,00
"\\DosDevices\\C:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,\
47,00,45,00,23,00,50,00,61,00,72,00,74,00,69,00,74,00,69,00,6f,00,6e,00,23,\
00,53,00,63,00,63,00,38,00,30,00,63,00,63,00,38,00,30,00,5f,00,4f,00,37,00,\
65,00,30,00,30,00,5f,00,4c,00,31,00,62,00,66,00,31,00,37,00,34,00,30,00,30,\
00,23,00,7b,00,35,00,33,00,66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,\
36,00,62,00,66,00,2d,00,31,00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,\
00,2d,00,30,00,30,00,61,00,30,00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,\
62,00,7d,00
"\\??\\Volume{cdcd8834-7844-11df-97fe-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,\
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,50,00,61,00,72,00,74,00,\
69,00,74,00,69,00,6f,00,6e,00,23,00,53,00,37,00,36,00,63,00,33,00,30,00,61,\
00,63,00,35,00,5f,00,4f,00,37,00,65,00,30,00,30,00,5f,00,4c,00,31,00,32,00,\
61,00,31,00,63,00,31,00,61,00,32,00,30,00,30,00,23,00,7b,00,35,00,33,00,66,\
00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,00,\
31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,30,\
00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00
"\\??\\Volume{cdcd8835-7844-11df-97fe-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,\
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,50,00,61,00,72,00,74,00,\
69,00,74,00,69,00,6f,00,6e,00,23,00,53,00,63,00,63,00,38,00,30,00,63,00,63,\
00,38,00,30,00,5f,00,4f,00,37,00,65,00,30,00,30,00,5f,00,4c,00,31,00,62,00,\
66,00,31,00,37,00,34,00,30,00,30,00,23,00,7b,00,35,00,33,00,66,00,35,00,36,\
00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,00,31,00,64,00,\
30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,30,00,63,00,39,\
00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00
"\\??\\Volume{cdcd8836-7844-11df-97fe-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,\
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,\
44,00,54,00,2d,00,53,00,54,00,5f,00,44,00,56,00,44,00,2d,00,52,00,4f,00,4d,\
00,5f,00,47,00,44,00,52,00,38,00,30,00,38,00,33,00,4e,00,5f,00,5f,00,5f,00,\
5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,30,\
00,4b,00,30,00,33,00,5f,00,5f,00,5f,00,5f,00,23,00,35,00,26,00,32,00,62,00,\
61,00,31,00,37,00,39,00,61,00,36,00,26,00,30,00,26,00,30,00,2e,00,30,00,2e,\
00,30,00,23,00,7b,00,35,00,33,00,66,00,35,00,36,00,33,00,30,00,64,00,2d,00,\
62,00,36,00,62,00,66,00,2d,00,31,00,31,00,64,00,30,00,2d,00,39,00,34,00,66,\
00,32,00,2d,00,30,00,30,00,61,00,30,00,63,00,39,00,31,00,65,00,66,00,62,00,\
38,00,62,00,7d,00
"\\DosDevices\\D:"=hex:c5,0a,c3,76,00,7e,00,00,00,00,00,00
"\\DosDevices\\E:"=hex:5c,00,3f,00,3f,00,5c,00,49,00,44,00,45,00,23,00,43,00,\
64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54,00,2d,00,53,00,54,00,5f,\
00,44,00,56,00,44,00,2d,00,52,00,4f,00,4d,00,5f,00,47,00,44,00,52,00,38,00,\
30,00,38,00,33,00,4e,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,\
00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,30,00,4b,00,30,00,33,00,5f,00,5f,00,\
5f,00,5f,00,23,00,35,00,26,00,32,00,62,00,61,00,31,00,37,00,39,00,61,00,36,\
00,26,00,30,00,26,00,30,00,2e,00,30,00,2e,00,30,00,23,00,7b,00,35,00,33,00,\
66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,\
00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,\
30,00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00
"\\??\\Volume{cdcd8837-7844-11df-97fe-d27ff786540c}"=hex:c5,0a,c3,76,00,7e,00,\
00,00,00,00,00
"\\??\\Volume{cdcd8838-7844-11df-97fe-beb39f73ee0f}"=hex:5c,00,3f,00,3f,00,5c,\
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
76,00,61,00,62,00,6c,00,65,00,4d,00,65,00,64,00,69,00,61,00,23,00,37,00,26,\
00,32,00,63,00,65,00,32,00,31,00,31,00,39,00,34,00,26,00,30,00,26,00,52,00,\
4d,00,23,00,7b,00,35,00,33,00,66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62,\
00,36,00,62,00,66,00,2d,00,31,00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00,\
32,00,2d,00,30,00,30,00,61,00,30,00,63,00,39,00,31,00,65,00,66,00,62,00,38,\
00,62,00,7d,00
"\\DosDevices\\F:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,\
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
00,65,00,64,00,69,00,61,00,23,00,37,00,26,00,32,00,63,00,65,00,32,00,31,00,\
31,00,39,00,34,00,26,00,30,00,26,00,52,00,4d,00,23,00,7b,00,35,00,33,00,66,\
00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,00,\
31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,30,\
00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00
[*]What values and data are in your MountedDevices keys when you boot in IMG (and currupt registry in real disk) ?
->no clue how to do that?
[*]Your boot.ini in disk image
[*]Try giving drive letters to all of real disk partitions by assigning values for them in MountedDevices key in image.
Make sure you have correct drive letter for partition that contain image file.
->can you explain more?
Can this problem be avoided if we make image that has its Windows drive letter > C (maybe U: V: W: ...) ?
->I'll try that later today
/Erwan