P
Peter Boden
This question has two parts.
First, I did some registry modifications for an image off line (loaded the
XPe system hive on my dev station). I added a key to this hive, unloaded it
and booted the XPe drive again. This key was added to ControlSet1 in
HKLM... Funny thing happened... Even though the drive is protected by a RAM
based EWF, changes were committed to the drive. When I analyzed the drive
again on my dev station, a new control set had been created, and somehow had
persisted. All the registry files had new modified times, as well as some
of the logs in the windows folder (setupact.log...). This only happens this
one time. After this has happened, subsequent boots show no changes to the
registry, and the registry file modification times never change, indicating
the EWF is working properly.
So, my first question is: does the addition of a new registry key cause XPe
to do a check point on the registry (create a new control set)?
My second question is, if a new control set is created, is it possible for
this to happen before the EWF is enabled?
Thanks,
Pete
First, I did some registry modifications for an image off line (loaded the
XPe system hive on my dev station). I added a key to this hive, unloaded it
and booted the XPe drive again. This key was added to ControlSet1 in
HKLM... Funny thing happened... Even though the drive is protected by a RAM
based EWF, changes were committed to the drive. When I analyzed the drive
again on my dev station, a new control set had been created, and somehow had
persisted. All the registry files had new modified times, as well as some
of the logs in the windows folder (setupact.log...). This only happens this
one time. After this has happened, subsequent boots show no changes to the
registry, and the registry file modification times never change, indicating
the EWF is working properly.
So, my first question is: does the addition of a new registry key cause XPe
to do a check point on the registry (create a new control set)?
My second question is, if a new control set is created, is it possible for
this to happen before the EWF is enabled?
Thanks,
Pete