1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Program won't execute from "pure DOS" (Recovery Console)

Discussion in 'Legacy Windows' started by broni, 2007/09/05.

  1. 2007/09/05
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Mike,

    Lars states in his readme that the batch erdnt.con method only replaces the system hive. Has that been updated, as reflected in your article?

     
  2. 2007/09/05
    broni

    broni Moderator Malware Analyst Thread Starter

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Thanks again to all you nice people:D ;) :p
     

  3. to hide this advert.

  4. 2007/09/05
    mboesen

    mboesen Inactive

    Joined:
    2007/09/05
    Messages:
    3
    Likes Received:
    0
    noahdfear

    Covered by this statement (in 2 places): "Note that the BATCH copying process only restores the system registry. However, you should then be able to restart into XP Windows and from there you can run ERDNT.EXE to restore all user registries, if required. "
     
  5. 2007/09/05
    broni

    broni Moderator Malware Analyst Thread Starter

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I guess, I'm still loaded with this problem, and I can't go to bed before I post one more thing.
    I've noticed while using RC (and Mike confirmed it), that RC doesn't really act like "pure DOS ", so I had no problem to navigate there typing in over 8-letters long folderS/filenames, so apparently in your batch file, we can simply use:
    AUTOBACKUP
    instead of
    AUTOBA~1
     
  6. 2007/09/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I'm curious as to which hives are being included as the system registry. Would that be just the SYSTEM hive, or all five hives in the config folder?

    broni,

    Thanks for that bit of info in regards to 8+ characters in RC. Either will work fine for the batch in that case. If the batch erdnt.con method replaces all 5 hives though, there's no need for my batch at all. ;)
     
  7. 2007/09/06
    broni

    broni Moderator Malware Analyst Thread Starter

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're right. I'm getting tired, I guess...LOOOOOOL
    ...and...
     
  8. 2007/09/06
    mboesen

    mboesen Inactive

    Joined:
    2007/09/05
    Messages:
    3
    Likes Received:
    0
    If you have a look at the contents of ERDNT.CON in any plain vanilla text editor you can see what would be copied through BATCH ERDNT.CON There is an ERDNT.CON file amongst the set of files generated by any ERUNT run. 9 or 10 - I'm not sure. Could vary from PC to PC.

    My brain hurts. I'm going for a walk.
     
  9. 2007/09/06
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Yea, sorry, that's what you get when trying to research stuff at 02:17 (= 2:17AM in Yankee time).
     
  10. 2007/09/06
    broni

    broni Moderator Malware Analyst Thread Starter

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Don't worry, Arie.
    The most important thing is: problem solved:cool:
     
  11. 2007/09/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I suspect, based on Lars' instructions stating that only the system registry will be restored, probably due to the information Arie quoted here, that despite the erdnt.con batch containing instructions to replace all hives (be it 9, 10 or 15, according to how many user profiles there are), only the 5 in the config folder can be accessed from the Recovery Console.

    Think I'll probably end up running some tests :rolleyes:
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.