Showing posts with label Win RE. Show all posts
Showing posts with label Win RE. Show all posts

Sunday, June 26, 2011

Anti-Malware Tools of Note

As promised, here is a resource-dump of some anti-virus/anti-malware tools I either use for came across in my recently documented battles that I thought would be helpful for reference.

As with many things in life, having the right tool for the particular job at hand can save much time and aggravation.   Hopefully most of these will already be well known to the GSD faithful readers. But I also hope that maybe one or two of these may be new finds as well to go into your toolbox.

Obviously this isn’t a complete list.  However they nicely supplement those I’ve already recommended. Check the side-bar to the left for many more that have been previously shared here.

While I do sometimes favor a direct frontal attack against malware while the system is running “live”, I typically find it much more productive to first whack-away at the infected system “off-line” having booted the system first in a WinPE environment.  I prefer to use my own custom Sexy USB Boots tools on a write-protected USB stick.  There are lots of flavors of WinPE including WinFE and WinRE and each bring their own benefits/drawbacks to the fight.

One important lesson I’ve learned is that the more scratch-space you can spare on your WinPE build, the better your apps will run in the WinPE operating environment.  Check out this WinPE and DISM/PEimg to boost Scratch Space (Ram Disk) post to option things out.  If you want to carry the option to boot from several different “boot.wim” files with different scratch-space settings, or maybe WinPE, WinRE, and WinFE boot options all on the same stick check out this WinPE Multi-boot a Bootable USB Storage device post for some thoughts.

Of course there are lots of different options for building your WinPE as well.  You can go “old-school” and use the Microsoft WAIK, there is WinBuilder, or you can check out TinyApps cool find to build a WinPE without any of those extra bits.  AgniPulse sets out a great tool and method to in his Beginners Guide to Creating Custom Windows PE.

My own preferred first-strike team is to boot the system with WinPE then toss the free tool VIPRE Rescue at the system.  There are two things that I think really make this anti-malware tool exceptional.  First it is easy to use and very thorough. But secondly, it creates some incredible logs and quarantines the files.  Both the logs and quarantined files helps me understand what was going on with the infection and possibly what vector it used.  That might help me secure the fixed system and submit the files for additional analysis.

Once the system is running “live” again, I also like to toss Malwarebytes Anti-Malware Free at the system.  It is a pretty aggressive anti-malware scanner with lots of options.

I also like SurfRight’s Hitman Pro 3 and have found it seems to do an exceptional job addressing issues that are missed by many other tools I have used. The plus is that you can use their product to get unlimited free scanning + 30 day removal.

Norton Power Eraser is a very powerful tool to root-out deeply embedded malware from a system Read their page carefully first.  I’ve had good experience with it myself.

I also keep handy and request a third-scan opinion from the still fairly new Microsoft Safety Scanner.  Being a “standalone” tool of sorts, it can be run in the WinPE environment or on the “live” system.  The trick in WinPE is to make sure your WinPE build has a large scratch-space value.  Check out this 4sysops post Offline Antivirus – How to run Microsoft Safety Scanner on Windows PE 3.0 for more details.

I do understand that for some folks, the thought of making a custom-spun WinPE boot tool could be quite intimidating.  With that in mind, you will want to keep a copy of the Microsoft Standalone System Sweeper Beta handy.  Of course you will need an uninfected “host” system to create the tool. Download the “builder” utility in either x32 or x64 flavor depending on your hardware and choose a blank CD, DVD, or USB drive with at least 250 MB of space. Execute the tool and build-away.

Of course, you may want to do more with this plain-Jane WinPE build that it lets you.  And you can if you know the tricks our dear TinyApps bloggist posts in his Extending Microsoft Standalone System Sweeper tips.

Maybe all you want is just to download and burn an ISO file to CD and use it to try to disinfect a system without all those extra bells-and-whistles that I love so much in WinPE.

Well, many reputable security product vendors offer their own tools as well in that same line.

Calendar of Updates has a page that is kept pretty updated Free Anti-Virus Rescue boot CDs including direct links to Avira Rescue CD & BitDefender Rescue CD.

F-Secure keeps their own Rescue CD resource updated. They also offer some fantastic Easy Clean, Online Scanner, and Blacklight rootkit tool.

Likewise, Kaspersky has their own Rescue Disk 10 tool as well as an Online Scanner, an incredibilly extensive toolbox of free Virus-fighting utilities to address specialized malware threats, a tool to remove banner from desktop, unlock Windows.  Kaspersky also offers valuable documentation on common malware information, viruses and solutions, as well as Rogue security software response guidance.

Dr.Web CureIt!! is another LiveCD solution worth knowing.  See also their Sysadmin First aid kit page for some additional resources.

Not “free” for everyone but a good LiveCD resource for Norton product users, check out the Norton Bootable Recovery Tool.  As explained on the page, “You will need your product key or PIN in order to use the Norton Bootable Recovery Tool.”

Likewise, if you are a Sophos customer, they also offer their customers the Sophos Bootable Anti-Virus tool. However, they do offer some Free Tools as well, including some specialized tools as well as Free Security Scan tools and their Sophos Anti-Rootkit tool.

Need more? Check out this GSD USB based AV/AM Tools post for many more options.

I have an extensive collection of highly-specialized sysadmin tools at my disposal. However the following tools are always the ones I keep coming back to over and over again. All free.

As malware (and particularly scareware/rogue-security “products”) gets more and more sophisticated, it seems even more highly-specialized tools are needed to fight and restore the damage done by them.

Broken EXE Association is a how to and REG files for fixing issues launching applications after an infection.

The Updated Combofix (5-23-11) is a highly specialized tool offered by the fine folks at bleepingcomputer.com forums.  It is not recommended to run on your own without guidance from their community unless you are already an advanced/professional Windows system specialist. Seriously.  Read their ComboFix usage, Questions, Help? page well and carefully before embarking on its usage.

See also their RKill utility. From that page:

RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then import a Registry file that removes incorrect file associations and fixes policies that stop us from using certain tools. When finished it will display a log file that shows the processes that were terminated while the program was running.

As RKill only terminates a program's running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again. Instead, after running RKill you should immediately scan your computer using some sort of anti-malware or anti-virus program so that the infections can be properly remove

And for any Mac users/caretakers who are still reading this post, they also have a BleepingComputer Mac Rogue Remover Tool. Check out that page for more info.

This Google redirect virus forum thread has a lot of great tips and steps to follow in addressing malware in general.

As I last posted, I feel remiss to not re-mention this guide Remove Windows Recovery (Uninstall Guide) over at BleepingComputer.com for a good review and walkthrough of a semi-automated recovery process.

Included in there are two noteworthy tools: RKill (Download Link) and Unhide.exe (Download Link). Rkill is a rouge-process killer of sorts and unhide.exe attempts to restore malware-relocated user files back to their original/rightful locations. See this Bleeping Computer Downloads: RKill page for more information as well as this one Question on 'unhide.exe' for more background information on them both.

You can also take the manual restoration approach offered by “colsearle”

Try navigating to the following path: (make sure you have the hidden files and folders visible)
C:\Documents and Settings\your user name goes here \Local Settings\Temp\smtmp
Inside the smtmp folder you will see three folders named 1, 2, 4
1 = Start Menu Program shortcuts
2 = Current User Quick Start shortcuts
4 = All Users Desktop folders and shortcuts
Simply copy the shortcuts back to the original path.

I also found this guide over at SmartestComputing written by “Broni” to be very helpful as well and full of specialized remediation tools and links How to restore files hidden/deleted by Windows Recovery virus.

Although most of what I see now-a-days is Windows 7 and Vista systems for most of my home/family/friends systems. More than a few still have XP systems. One trick still in my bag from days ago is when a system is cleaned of a internet-browsing redirector infection the internet doesn’t work anymore is that in many cases it requires the network sockets to be “reset” by running a tool like LSP-Fix or WinSock XP Fix 1.2 (via MajorGeeks mirror site).  This only should be run on XP systems.

Coming full-circle again in this post, some of these tools and techniques require working on a live running system and others can be done “off-line” using a LiveCD/WinPE/otherOS approach.

If you do go with a “off-line” boot method such as WinPE from a bootable USB flash or HDD, you want to be very careful you avoid potential cross-infection in your response/rescue efforts. Yes a bootable CD/DVD does offer greater protection but at the same time, it can severely reduce the number of options or other tools you can bring to bear on assessing and cleansing the system.

If you have a LOT of bootable ISO files (as I do for specialized situations), then I seriously recommend the awesome iodd device for sysadmins and incident responders as well as you semi-pro malware busters.  It allows you to carry many, many, many different bootable ISO files on a portable HDD and pick between them on the fly for off-line system booting.  Couple that with a physical write-block switch and the ability to partition the hard disk drive you cram into it, and you can carry many portable apps on there as well to access if you are booting in, say, a WinPE environment.

If that seems like way too much (and it never could be) firepower, then at least consider a USB flash drive with a write-block switch.  My personal preference is the Kanguru Flashblu II (NewEgg product link).  It is a great value for a reasonably sized USB drive with a write-block switch.  Sony also offers write-block switches on some of their USB flash drives (Alvis has one in fact) but they are getting harder and harder to find.

If you don’t have the option or resources to pick up either one, but do have a bootable USB flash drive that you have already loaded up with all your scanners, tools, and other response files, consider this simple and free tool usbdummyprotect. The trick to using it is to download the tool and unzip, then copy it directly onto your USB drive.  There, run it.  It creates a “dummy” file to fill up all the remaining free-space on your flash-drive.  In theory, this should prevent malware from copying any files to your drive.  When you want your free-space back, just delete the clearly identified dummy file.

Not quite the same thing, but noteworthy is Document Solutions free DSi USB Write-Blocker. You need to download and install this on your own clean-system first. Then run the tool BEFORE connecting a USB flash device.  Basically it keeps your own running system from writing TO the USB device once you plug the device onto your PC.  This should preserve time/date stamps and other file modifications.  It doesn’t necessarily protect your host system from anything bad on the device itself if you choose to either run anything directly or copy off the device and run locally. So understand how it works first then use it when the situation calls.

Finally, in some cases, the malware might have actually damaged or modified the Windows bootloader itself. If this is the case and any of the specialized tools already mentioned didn’t work to restore the Windows boot loader, then you may need to do it yourself.

See this GSD post Partition and Disk Management: Part II – Free and Useful Tools for a rich roundup of resources.

For a really nice and trusted freeware GUI tool check out EasyBCD 2.1 from NeoSmart Technologies.

I also recently discovered MBRWizard which is not a free product (but it is offered dirt-cheap) and has a great GUI as well.  However, for your value-expecting fans not afraid of a little command-line ninja work, they do offer a CLI Freeware version! Check out the Command line reference page for more information.

Effectively responding to a malware/rogue-ware infection is never an easy task. It takes careful assessment, planning, research, tool/utility/scanner gathering, off-line booting in many cases, and lots and lots of tedious, patience-requiring work.  It takes time, experience, and for the non-technical, lots and lots of help from a devoted community.

Obviously, this post can’t even really begin to scratch the surface of the tools and techniques out there. However, I hope it is a good starting point or comes to be a return-to resource source to collect valuable materials as you go forth and battle.

Cheers.

--Claus V.

Sunday, March 13, 2011

Quick Tip: Fatal Error C0000034 installing Windows 7 SP1

Got to the church-house early this morning to bring up the systems we use to run the presentation and lighting-control software.

Booted the Windows 7 x64 system up.

Was surprised to see this error during the boot up process:

Fatal Error C0000034 applying update operation 282 of 117183….

Oh Noes…Really?  A few hours before before services? Nice.

Head fogged from DST “Spring Forward” madness, I set to work with the rest of the technical crew watching (and Mr. D kindly bringing me a fresh styro of Joe).

A reboot didn’t help.

I brought up the sister-system (also Win 7 x64), crossing my fingers and hoping for the best.  Fortunately it booted fine.

Some quick Google work off of it quickly found a lot of additional material on the webs about others encountering this issue.

Funny thing.  I’ve upgraded both our home Win 7 x64 systems as well as our Win 7 x32 system with SP1 and had no issues.  Nor have I heard (in the tech news) of any major issues with the Win 7 SP1 upgrade…but suddenly I felt like I turned over a rock and discovered a major creepy-crawly!

Once I had done some research and felt I had a good plan of solution, I set to work:

  1. Not having my USB-based “off-line” boot drive with me left me at a disadvantage.  I dashed out the house too quickly this morning and left it on the mantle.  Bother.  What I did have was a working Win 7 system hooked to our sound-board system.  In other words a functioning system with a optical media burner and a ton of blank CD/DVD media. Score.
  2. I hopped over to NeoSmart and their Download Windows 7 System Recovery Discs page.  I then downloaded the x64 version of the Win 7 Recovery disk ISO file and burned it to CD.
  3. I rebooted the borked system with the disk and dropped into the CMD line option.
  4. Following this Windows Servicing Guy post by Joseph Conway (Senior Support Escalation Engineer Microsoft Enterprise Platforms Support), I manually loaded the main system’s off-line “System” registry hive file, dug down to the indicated reg-key and cleared it as instructed.   Unloaded the hive and rebooted.
  5. System booted up (after rolling back the SP1 install) OK with no apparent damage done.
  6. Immediately upon deciding the system was operating stabling, created a manual System Restore point on all our machines (even the working one!).

The services went off without a hitch and no-one but us “back-desk-pew geeks” knew this mornings pre-service preparations were much more exciting than normal!

Oorah!

Important Notes and Observations:

Post Update #1: Found an amazing post from Günter Born that goes into awesome detail with various solution options, outstanding details and helpful screen-grabs, and even some technical root cause analysis thoughts.  Only problem is that his blog/post is in German so probably, what, 99% of the US may not ever discover this Günter’s amazing work and help with this issues (lots of supporting Links also!).  Too bad.  Google Translate version here and it handles it pretty well. Windows IT guys and gals shouldn’t have any issue following it despite a few auto-translation oddities.  Original page: SP1-Installation hängt, Error C0000034/C000009A - Born’s Windows IT Blog.   Maybe also useful from Günter: Buglist's collateral damage by Service Pack 1 (Google Translate version offered) original language page link.   Actually, Günter’s site is very amazing with his detail in trouble issues noted. I’m going to be keeping an eye on this blog for a while to come! Born’s Windows IT Blog.  Additional recent helpful tips/notes from Günter below (all linked via Google Translate service):

Post Update #2: Back at the church-house again this afternoon. Original system was running fine so turned my attention to the second one.  When it shut down this morning it did apply 4 pending updates. Apparently Win 7 SP1 was indeed one of them.  When I brought it up again this afternoon, it also failed with the exact same Fatal Error C0000034 applying update operation 282 of… issue.  Hmmm. Interesting.  What’s more, the manually created system-restore I specifically did this morning on it was no-where to be found. That’s serious.  I again had to revert to the same solution I previously mentioned.  Worked fine.  System recovered and it claimed (as did the first) to have rolled back the SP 1.  I rebooted and it came up fine.  I then had downloaded the SP 1 package file and tried to put it on that one.  Curiously, it would not install saying there were missing components. I tried again but no dice. When I went to the System window via Control Panel, it does claim to be running at SP 1 level.  However when I check “Programs and Features” and check the Microsoft updates listing carefully, I don’t see it listed anywhere.  So now I am left in a conundrum.  They system thinks SP 1 is installed, I don’t find it actually listed as installed, and a manual download and install attempt of SP 1 fails as it is missing required components.   This is looking a bit more dire.  I really, really hope MS gets to the bottom of these issues very soon and offers some kind of roll-back/repair cleanup fix.  I’m really not looking forward to rebuilding these systems.

First things first.  I don’t ever do updates on our key production systems before services for just this reason.  However, I came to find out that the update was pushed via AD settings earlier this past week and the person on the system at the time just walked away from it at day’s end without validating it took on the reboot.

I really should have remembered to grab my USB-boot “offline" drive.  I rarely leave home without it for just this reason.  I just lucked out that the 2nd system didn’t also crash and I had both internet access and a CD-burner to make the rescue disk in the pinch.  The disk is now safely taped to the side of the case for future reference.

Fatal Error C0000034 applying update operation was a KB article under Vista. Now it has had Win 7 added to it as well; MS KB Article ID: 975484  - Your computer may freeze or restart to a black screen that has a "0xc0000034" error message after you install Windows 7 Service Pack 1 or a Windows Vista service pack

I’m still not sure I fully understand the root-cause of this error.  There is a lot of speculation in the forums at the moment.  I did discover I am not the only one who had the error happen on update operation “282”; Fatal Error C0000034 installing Windows 7 SP1 - Gary Davis’ Blog.   Coincidence?  Our two production-systems are high-end Dell Inspiron desktops; one took the SP 1 fine and the other did not.

x64 -bit Win7 systems seem to be succumbing the most to the issue, but there could be x-32-bit Win7 systems also impacted.

There are at least three primary solutions I uncovered that other smarter folks have previously worked out.  I reviewed them all carefully before implementing one.

Joseph Conway of Microsoft offers two as does the MS KB Article 975484 I linked earlier.

Error 0xC0000034 during Service Pack 1 installations for Windows 7 and Windows 2008 R2 - The Windows Servicing Guy

The first is to simply attempt to roll back to a previous “System Restore” point.  That’s usually a safe bet, however in my case, although System Restore was set to “on”, there were no System Restore points found on the impacted system.  Some others also report finding this to be true also.

The second is to (via CLI or GUI) remove a specific registry key value from the PC’s SYSTEM hive.  That worked for me.

Critical Tip!  If you follow Jeff or the MS KB’s steps after having “off-line” booted the impacted system with a Win 7 System Recovery disk (like I did rather than directly off the ailing Win 7 System Restore boot process) you have to get your drive letter bearings in your brain set first.  It will use a RAM-drive “X” for the running recovery system.  However (in my case at least) the C: was actually referring to the Rescue disk and the D: was actually my “real” system’s “C:” volume.  Confused?  I was at first.

See the instructions (Joseph’s are clearer) talk about navigating/loading items from the C: (your local system volume).  But if you are off-line booting, then that may not necessarily be correct.  In my particular case, I ended up having to navigate and load the SYSTEM hive from the D:\Windows\System32\config\ location.

If neither of those work, I also found mention of a third solution in a Windows TechNet forum: Windows 7 Ultimate SP1 installation fails with error code c0000034 posted by “thiswoot”.

Basically it involves restarting the system, waiting for it to time-out on the fail and go into a system-recovery routine.  Log in and hunt down a very specific pending.xml file, finding and cleaning some specific lines out, resaving the file, then restarting again.

It is clever and appears to be a home-brewed solution before it was clear that MS had a preferred KB solution and the MS blog guys started posting their solutions. 

I was going to do it first until I kept reading the follow-on thread posts and eventually found Jeff Hughes’ Ask the Core Team blog re-post of Joseph Conway’s solutions.

Joseph Conway then then did a follow-on post Why you don’t want to edit your pending.xml to resolve 0xC0000034 issues - The Windows Servicing Guy blog.  You may want to read it first before proceeding with that method.  It’s not that Joseph isn’t saying it won’t work and don’t do it under any circumstance. He is just adding additional background info so you can know the consequences of getting your system going with that solution pathway.

That said, if the first two “official” solutions don’t work, and you (like many other Win 7 admins and users) are desperate to get the system up and going, it does appear to have a high success ratio.

There seems to be some regularity in various comment threads that the issue could be linked to using WSUS to push out the Windows 7 SP1 to systems, coupled with the end-user choosing the “install downloaded-updates/Shutdown” option when they log off.  That’s not a certain thing.  I suspect Joseph Conway and the MS guys are still working on the true root-cause identification.  I’d recommend keeping an eye in the rolling comments of this post of his as he is responding to comments very kindly and actively.

As for getting Windows 7 SP 1 successfully on the system post-C0000043 failure?  I'm going to (mid-week) download the Win7 SP1 standalone installer file and give it a try: Windows 7 and Windows Server 2008 R2 Service Pack 1 (KB976932).  Most reports are that this seems to work OK on a re-load.

Cheers.

--Claus V.

Sunday, July 11, 2010

iodd : Multi-boot madness!

Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash media, etc.

Each one allows me to “off-line” boot a Windows system to service it, image it, pen-test it, or examine it.

The end result is a large CD-carry case and a handful of USB sticks along with one or more USB external hard drives.

There are a couple of note-worthy multi-boot Linux distros out there, and with some clever work you can make a USB stick able to multi-boot various WIM files.

However there really isn’t an all-in-one solution to conquer them all.  You know, a “…one-ring to rule them all…” solution.

I had wondered for some time if it was worth the effort to spend working on a custom “Super-Boot” USB-based HDD system, based  perhaps on the GRUB bootloader or maybe one of the myriad other boot loaders.  I had collected a wealth of links and then promptly put off even addressing the headaches this might bring.

TinyApps.Org bloggest Miles was also apparently struggling with this model of multi-boot image management.

In his post  Boot any and all ISO images from USB drive he outlined a smorgasbord of possible solutions to the same issue.

In the end he met with success via the iodd 2501 hardware device.

And in an added surprise, kindly sent one to me as well, just last week.

Here are my thoughts.

Hello iodd! 

imageThe iodd is a little bit larger than two decks of playing cards placed side by side. (image on left captured from iodd web-site page and used solely for illustrative product purposes.) 

It accepts a 2.5” SATA “laptop” hard disk drive.

It can be connected to a system via USB (y-cable included) or SATA2 connection (with power draw from co-cabled USB port).

Is has a physical “write-block” switch.

At this point it sounds like most any other external USB drive….but wait!  There is more!

If you create two partitions, the first being a FAT32, and create a “_ISO” folder in that partition, and then dump any bootable ISO file image into that folder, guess what?  Amazing things happen.

You can plug it into a system, use the toggle switch to jog to the ISO image you wish to use to boot (it will display on a LED readout all the file-names present in the _ISO folder) and the press in the toggle button to select it.  Then boot the system (assuming BIOS USB-based boot support is present) and the ISO will load and run!

It can also operate on a “live” system as an external HDD like you are used to, or as a virtual CD emulator, or both.

If you happen to have an ISO image of say, a movie, you can play that too.

That means if you have installation media converted to ISO format, you can load them up, and change them, for installations.

Simply amazing.

In one fell swoop, you can do away with almost all of your CD/DVD media and keep them all on accessible from this single device.

Assembly

The device itself consists of a hardware/display component with a plastic “hanger” skeleton to hold to drive.  The front and back plates are aluminum and slide on/off the hanger to encase the skeleton and drive.

Here’s a video on the disassembly:

Disassembling the iodd

Once apart, load in your SATA drive, carefully.

Since I don’t have a spare 2.5” SATA drive lying around, I went out and picked up a WD 640 GB drive, with 8 MB cache and 5400 RPM.  That was a mistake.  Although it did fit, it seemed a bit “thicker” and the case covers were very difficult to slide on.  It was tight as all get-out.  That coupled with the fact that no matter what I did or which additional hardware tool I used to try to connect to the drive, the drive just didn’t spin up, meaning I possibly pulled a bad drive from the store shelf.

Upon return/exchange, I then went with a Seagate 320 GB drive, with 16 MB cache and 7200 RPM speed.  I understand that “smaller” drives tend to not be as power hungry as well so hopefully the smaller size will be offset by the faster RPM and larger cache for performance.  It did fit into the enclosure much easier and the case lids slid closed much easier as well, for what it’s worth.

Then reassemble, carefully!

Assembling the iodd

One thing that is easy to miss is that at each of the corners of the long-sides are tiny molded plastic pins that snap into the side screw mount holes on the drive itself.  If you aren’t careful you could bend/break them.  So pay attention!  They might also bend and not fully snap in during the process so make sure they are correctly seated before you attempt to install the case lids.

Drive Prep

Depending on the condition of the SATA drive, you can either prep it (format) inside the iodd device or outside the device before installation if you happen to have an USB-external drive cable connector kit handy.

The current requirements seem to be that you can have multiple partitions on the device with multiple format types. However, the first must be FAT32.  Note TinyApps found that doing a FAT32 using OS X’s disk utility didn’t work.

I myself used Windows 7’s own storage management tool to make mine.

However, if you want to make your primary FAT32 partition larger than the stock 32 GB limit, we both unequivocally recommend using the free FAT 32 Formatter utility from Ridgecorp.  Even easier for the masses is their Windows GUI version of fat32format.  Want a 100 GB FAT32 partition? It’s yours with this great tool!

I was a bit OCD and used this GB to MB unit converted to make mine exactly 32 MB reported size.

I stuck with the 32 GB partition because, really, I don’t need more than that many ISO images to store on it (doubt I will even come close) and besides on a more practical level, the more you get on there, it takes a long time to toggle through them all to find the one you wish to select.

I used the remaining space to create a second simple volume and formatted it NTFS so I could land large (over 4 GB) image files if needed.

The product includes a foldout iodd2501_manual but it really is more than a little bit light for anyone but the really hard-core tech crowd who wouldn’t bother reading the manual anyway.

Instead download the full iodd manual (english) which covers everything (and then some) that you need to know about the device, from field-dressing the parts to software, to drive prepping, to usage, all in incredible detail for an overseas product.

Spend some time also acquainting yourself with the following additional on-line support resources:

Final Device Prep

Once the drive is formatted and installed, and connected, you will need to go to the first partition (your FAT32 one), and create a folder called “_ISO” on the root of that drive letter.  It is into this folder you may next place all your ISO files.

Next I wanted to update the firmware to the latest version.

However, the executable isn’t support (apparently) on x64 bit systems, of which mine are.

So instead I went the easier way and downloaded the latest firmware in ISO format (Firmware Upgrade v1.42.24 (iso) ), copied the ISO file to the _ISO folder on the iodd, then selected that one.  Bam…it loaded the ISO, installed the firmware directly, and was done!  Easy and all internal to the device.

There are three “modes” of operation, CD-Mode, HDD-Mode, and “Dual-Mode”.

To use the device to pick/load an ISO, just toggle through the list of your “installed” ISO files (it appears arranged by the order copied to the folder rather than alphabetically) and once it appears on the bright blue LED readout, press the toggle switch “IN” to select/load it.

Because the ISO holding drive is FAT32, you can’t use/store/access ISO’s larger than the 4 GB file size limit, which is a drag if you have a Blu-Ray movie ISO or a distro image file that is DVD-sized.

However, you can use a File Splitter (Windows) offered by iodd or any other so long as you stick with the proper file-splitting naming convention it expects.

More Videos

Here are some more videos (mostly in Korean) that show the device in action:

 

iodd in hdd mode

 

 

iodd cold-booting a Fedora 9 LiveCD ISO

 

 

iodd in video disk (ISO) emulation mode

 

Where do I get one?

TinyApps secured his from LinITX.com, but they appear to be out of stock at the current time.  I’m confident with some Google or Bing work you can track down a source. 

A forum source linked to I-Odd USA as the company’s US web-presence location, but it doesn’t seem to be linked from the mothership web page, so I cannot (for now) certify it’s authenticity but it seems legit at this point.  Use your web-spidey-sense accordingly.

Currently listed at the time of this post at $70 USD there.

Where do I begin with ISO’s to load on it?

Here is a lineup of the ISO’s I’m loading on mine, each in various grouping of need.

I’m obviously not including installation/setup disks, but examples might include Windows OS installation media, MS Office setup disks, various programs requiring installation from optical media, etc.

Look over them closely and come back often, I was surprised to see that many have newer release versions!

All are free, unless specifically noted.

System Administration/Support Distros

All of these are tools I keep at hand for response to troubleshooting/stress-testing/repair-response to Windows systems.

Another option? Slap a WinPE build with ImageX present, then use the other larger partition (NTFS) to acquire and apply ImageX WIM files of system images (you could do the same with Clonezilla as well)…heck!  Do both!  The iodd device makes it possible.

Forensics Distros

Couple that fact that the iodd can be set up with multiple partitions and can (in theory) support just about as large as a 2.5” SATA drive as you can cram into it, and that it has a hardware-based write/block switch to prevent accidental/malicious write-back to the device, the iodd might make a great forensic distro boot launcher and image file collection system.  OORAH!

And I’ve not mentioned the many commercial distros as well such as ForensicSoft, Inc’s SAFE (System Acquisition Forensic Environment) tool also based on WinPE.

Security/Pen-Testing Distros

Desktop Replacement Distros

Sometimes it’s handy to have a “LiveCD” bootable OS environment that isn’t based on the local HDD.  Very good if you’ve got a particularly dead system at hand.  These are my all-time favorites…

Converting Disk media to ISO files

Of course, sometimes you can’t just grab an ISO out of the box; you have to make one from, say, your setup installation media disks.

Assuming there isn’t any copy-protection preventing it, almost any of these great free utilites could be used to rip your optical media disk(s) to ISO format.

Don’t forget the FAT32 file size limit of appx 4GB still stand and you may have to use a File Splitter (Windows) offered by iodd or any other so long as you stick with the proper file-splitting naming convention it expects.

That said, I’ve had good luck with these.

Final Thoughts

While the iodd won’t replace my 32 GB custom WinPE bootable flash stick as my primary Windows support weapon, it has just rendered the piles of CD/DVD boot media I carry obsolete in one fell swoop.

Special thanks again to TinyApps bloggist Miles for making this journey possible!

And in the immortal words of a young neighborhood kid just down the street from your average superhero family…after looking into the capabilities of the iodd….I only have this to say…

Totally Valca Recommeded!

Cheers!

--Claus V.

Sunday, March 21, 2010

WinPE Multi-boot a Bootable USB Storage device

Amazing!

Things like this keep up my faith in blogging and the blogging scene.

I’ve posted a number of articles related to WinPE as well as making portable storage devices (USB HDD/ USB flash sticks) bootable for use as WinPE boot media.

It was under that last, most recent post that I mentioned a trick I do to carry multiple WinPE boot.wim varieties on my bootable USB stick:

On my own bootable USB flash stick, in addition to the required “SOURCES” folder and contents, I also have a “SOURCES-ALT” folder.  In there I keep all my additional and scratch-space-adjusted WIM files.  So I have a  Boot-32.wim, Boot-128.wim, Boot-256.wim, and a Boot-512.wim file stored in there.  Typically, I have the 512 MB set scratch-space boot.wim file in my SOURCES folder to boot with.  However, if I know I need to WinPE boot a system that that wouldn’t work on, then I can delete the boot.wim file out of my SOURCES folder on the USB stick, and copy another more appropriate version from my SOURCES-ALT folder over into it, say the Boot-128.wim one.  Then I rename it to boot.wim and I am good to go!

In fact, once the contents of the WIM file are loaded into the scratch-space/RAM Disk, it is then released.  That means if you are going from a system that uses the 512 MB scratch-space, and then progress on to one that will require the 64 MB scratch-space version, it seems you can do the boot.wim delete/copy/rename routine on your USB stick still from within your WinPE boot session!  I’ve done this on a number of occasions.

Even more fun is making up not just different scratch-space flavors of the boot.wim file, but even wholly different versions of the boot.wim file itself!  You could have a custom WinPE 2.0 boot.wim file, a custom WinPE 3.0 boot.wim file, an AntiVirus PE Disk to offline-scan a Windows system, or maybe, say, a Win(FE) forensics build boot.wim, and so on…limited only by the size of your USB storage device and your imagination and efforts.  Even different WIM files with different hardware drivers injected for various system platforms.  Instead of carrying a mess of optical disks, just a single large USB storage may do the trick (assuming the system BIOS supports USB based booting).

Of course, you do have to reboot the system to then load whichever WIM file you have swapped out…but I’m sure you knew that already.  Just keep the originals safely and alternatively named in your “storage” folder location and delete/copy/rename the original boot.wim file as needed.

Brilliance = Bret ?

Well, there I was thinking just how clever a trick this was to sort-of “multi-boot” the WinPE’s off my USB stick.

Then Bret came and visited the blog and dropped an “outside-the-box” kind of comment that was bloody brilliant.

Instead of copying and renaming your boot-*.wim files, have you thought about using bcdedit to add entries to display a bootmgr menu with choices of each wim? You could keep all of the wims in your sources folder, too. I like to have a menu with a 4-second timeout to the default.

I read it and just sat there stunned.

Seriously.

Simple and elegant…and something I was already familiar with (in concept) from my earlier boot to VHD work.

Crap.  Now I’ve got yet another fun project to work on tweaking my super-boot USB stick.

In case you haven’t caught what Bret proposed, he is saying that we can just set the BCD file in the \boot folder to point to additional wim entries as well as the default boot.wim.  You can name then whatever.wim you wish and then when you boot from the USB device, be offered a nice multi-bootloader menu and select which particular flavored wim you want to boot from.

No swapping out/renaming of the extra wim’s you carry.  No rebooting to get the one you want loaded.

See?

Simply brilliant.

How To Resources #1

Amazingly, I didn’t find all too many references to this trick on the Net and forums.  There are a few, and they all seem to be pretty recent.

Below are some of the best resources I located to help guide someone through the process.

Both of these techniques require comfort and skilled familiarity with the command-line bcdedit.

Just take a lot of notes and make sure you have pre-structured which wims you want to use before you get started.  Being organized first will save you a lot of headaches.

How To Resources #2

If you are just not a CLI person, then there is at least one GUI alternative to use: EasyBCD

The current version does allow you to work with PE files.

The trick is to first run the program then load the BCD (Boot Configuration Database) file on your portable WinPE boot stick located in the\boot folder.

However, I discovered that the EasyBCD 2.0 Beta Builds (free registration required to access) have even more robust and enhanced support.

With the latest version (2.0 Beta Build 86) You can actually not just add additional WIM files to your bootloader but VHD files as well. ISOs are another option but I’ve got enough on my hands for now to take in!

Using EasyBCD should allow you to back up your existing bootloader file before making changes.  Just be very sure you are on the USB drive \boot folder and not the one for your primary system.  If you get mixed up and start making incorrect changes, bad things could happen man.

Sure, with the base bcdedit application, you have all you need without extra software, but EasyBCD is very slick and just (basically) provides an advanced GUI wrapper for the bcdedit app at the core.

Choice is yours.

Here are some additional links that while not directly related to multi-booting of USB sticks, do have additional great examples of bcdedit in action for reference.

Final Thoughts

This is a really cool synthesis of concepts and even more could be extended from this on your USB device.  Really the only limits are the size of your storage device to hold the files, the memory of the system it is running on, and the speed of the hardware to make it usable.

You almost certainly don’t have to limit yourself to just WinPE wim files.

Imagine also if you had a VHD file of a full-blown specialized Windows 7 system  or Sever 2008 to pick from your bootloader list, and not just the WinPE flavors.  Awesome.

Spend some time poking around on Mark Wilson’s blog.  He’s got a lot of research and lessons learned on his and other sites he found that we can benefit from there.

  • Running Windows from a USB flash drive– Mark Wilson blog. .

  • Windows 7 and Windows Application Compatibility : Boot from Windows 7 VHD Boot without having any native Operating System.

  • Booting Hyper-V R2 off a USB stick – Virtual PC Guy’s weblog.

  • Create bootable USB drive for Hyper-V Server 2008 R2 – MSDN Code Site.

  • Boot from VHD – the joy of BCDedit and a nice hyper-v gotcha or two – James O’Neill’s blog.
  • My Boot-to-VHD experiment: found some tips, like it, but still haven’t found VM nirvana - Jon Galloway.
  • Anyway…you get the idea.

    I’m likely to stick to WinPE / WinFE wims myself but I’ve already got a project in mind once I get my own USB boot stick squared away.

    We deploy to our techs a bootable WinPE portable HDD.  It boots from the base WinPE boot.wim (32 MB RamDisk). None of the extras and we use it for imagex system image deployments.  I’ve stuck with the base boot.wim as it will work dependably on most all our desktop systems.

    The techs have been clamoring for me to switch out to the heavier customized WimPE image I provide them on a CD-ROM disk.

    I’ve declined as it just doesn’t work on some of our system-RAM limited desktops/laptops while the CLI WinPE base would.

    Now I can give them their cake and let them eat it too.

    Sweet baby jebus.

    All this because of Bret….

    Cheers!

    --Claus V.

    Sunday, March 14, 2010

    WinPE and DISM/PEimg to boost Scratch Space (Ram Disk)

    Soon after I had posted this Custom Win PE Boot Disk Building: Step Four – Pulling it all together walkthrough binding all the elements on making a custom PE boot disk, I started getting comments that followers were unable to get CubicExplorer working in it.

    The solution was a long time coming, but revelation of the solution culminated in the Solved: Run CubicExplorer in Win PE with no Crashes... post.

    I’m not revisiting that one, but one path I and parities played with in the process was to fiddle with the PE Ram Disk size.

    As this may or may not be something amateur PE builders and hobbies may be familiar with (I really wasn’t fully) I thought I would take a few moments to post some related links about it for future reference.

    Very Basic info on RamDisk/ScratchSpace in PE

    By default, Windows PE builds “by the book” allocate 32 MB of writeable memory to the PE environment.

    I like to think of it (very roughly) like this.

    The space of my yard would correspond to the System RAM.

    The PE system (containing all the stuff in your PE wim-image file) would correspond to a kiddie-pool placed in the back-yard.

    The scratch space would correspond to how big the kiddie-pool is and, thusly, how much water fills it up for everyone to play in.

    Now generally, for most stock PE builds, 32 MB of scratch space works very well.  PE environments (base) run a CLI shell box and a simple background.  The services are simple and it’s not like you are running a lot of GUI apps.  This small and shallow pool is more than sufficient to let the kids play happily and safely.

    But say you then get a lot of neighborhood kids coming to join in.  And some of them aren’t five-year olds.  These are third and fourth graders.  Suddenly there isn’t enough water in the pool for everyone to feel comfortable in.  Kids get cranky and don’t behave.

    Under these circumstances you need to get a larger kiddie-pool!

    Microsoft describes it like this:

    If your Windows PE environment becomes unresponsive when running an application, you may have run out of memory. By default, Windows PE allocates 32 megabytes (MB) of writeable memory, known as scratch space.

    Typically, you don’t need to do anything as the standard 32 MB scratch space size is adequate.  But if you need to, you do have the option to manually set the scratch space size larger…assuming the yard (system RAM) is large enough to accommodate things…

    In WinPE, scratch space can be set at 32, 64, 128, 256, or 512 MB levels.

    It does make a difference, particularly with GUI-heavy applications running in the WinPE environs.  I’ve personally  observed some applications either not running at all, running very sluggishly, or even not fully displaying all the expected graphical elements.

    When I rolled out the larger kiddie-pool, they suddenly sprang to life and made things much more pleasant.

    The drawback is you have to know the systems you intend to deploy these specific solutions on, and ensure you find the sweet-spot.  If your supported desktop systems have just 256 MB of RAM, and you go to boot it with a WinPE disk set at a 512 MB scratch-space size, it won’t be pretty.  Then again, if you don’t really use a lot of additional memory-intensive applications in WinPE, then you also don’t probably need a 512 MB scratch space wrapped WinPE setup.

    In other words, your kiddie-pool can’t be larger than your yard or else it just won’t fit in there.

    WinPE 3.0 and Increasing Scratch Space

    WinPE 3.0 is based on the Windows 7 platform.  As such, you have to use a WinPE 3.0 specific tool to make changes to the default scratch-space settings.

    The beauty of it is that once you get this basic process down, the rest is gravy.  I’ll come back to that in a minute.

    Under WinPE 3.0 building, you must use the DISM.exe command tool.

    Go ahead and create your WinPE 3.0 “wim” file image using your own technique or the ones I outlined in the first link of this post.

    This assumes you have already installed and are familiar with the Windows® AIK for Windows® 7.  There are a few other related Microsoft WinPE building packages/tools as well that should include the tool (Microsoft Deployment Toolkit).

    Launch the “Deployment Tools Command Prompt” and use the following format to adjust the scratch-space of your wim file. (note in this case I am using standard locations to mount the wim file for servicing as well as using the name “winpe.wim” for this example. You will need to adjust to your own particular wim-file and mounting location accordingly.)

    Dism /Mount-Wim /WimFile:C:\winpe_x86\winpe.wim /index:1 /MountDir:C:\winpe_x86\mount

    dism /image:C:\winpe_x86\mount /Set-ScratchSpace:256

    Dism /Unmount-Wim /MountDir:C:\winpe_x86\mount\ /Commit

    In the second line of the example above I used the “256” value to set the scratch-space to 256 MB RAM.  Adjust the value you use accordingly (32, 64, 128, 256, or 512 MB levels).

    Then toss the updated wim image file either into the correct location of your USB-bootable storage device, or into the proper folder and build/burn your WinPE ISO file to optical media.

    To verify that you were successful, launch your PE build, navigate in a CLI window to the X: drive (RamDisk) and run a DIR command.  The size shown should equal the scratch-space size you set.

    Easy!

    Related WinPE 3.0 Resources:

    WinPE 2.0 and Increasing Scratch Space

    WinPE 2.0 is based on the Windows Vista  platform.  As such, you have to use a WinPE 2.0 specific tool to make changes to the default scratch-space settings such as the Windows Automated Installation Kit (AIK) for Vista or (even better) the Automated Installation Kit (AIK) for Windows Vista SP1 and Windows Server 2008.

    Under WinPE 2.0 building, you must use the PEimg.exe command tool.

    The principle is basically the same as before, and again assumes you already have build your WIM image file and now need to adjust its scratch space.

    I’d type it again, but fortunately, The Deployment Guys have already done the hard work so from their post Expanding the Scratch Space in Windows PE 2.1 we have the following:

    “With the introduction of Windows PE 2.1 (supplied with the Windows Automated Installation Kit (Windows AIK) 1.1), the scratch area can be changed from the command line. Below is the process for creating a larger scratch area.

       1. Create a temporary mount folder on your hard disk - MD c:\temp\mount
       2. Go to the Windows AIK tools folder for the platform of PE that you will be changing (ie x86/x64) - CD "Program Files\Windows AIK\Tools\x86"
       3. Mount the default Windows PE image supplied with Windows AIK to your temporary mount folder - imagex.exe /MOUNTRW "C:\Program Files\Windows AIK\Tools\PETools\x86\winpe.wim" 1 c:\temp\mount
       4. Go to the Windows AIK PETools folder - CD "C:\Program Files\Windows AIK\Tools\PETools"
       5. Run the PEIMG command to adjust the scratch size in the mounted image using /SCRATCHSPACE flag to set the size of the drive you want (in this case 128Mb)  - peimg.exe /SCRATCHSPACE=128 c:\temp\mount\windows
       6. Change back to the PETools directory - CD "Program Files\Windows AIK\Tools\x86"
       7. Unmount the image and commit the changes - imagex.exe /UNMOUNT /COMMIT c:\temp\mount

    “That's it - the scratch area will now be set at 128 Mb for all boot images based on this source - which means all boot images created by MDT will now have the set scratch space set….”

    Again, pretty easy stuff.  Just adjust your recipe accordingly.

    Related WinPE 2.0 Resources:

    Gravy

    So earlier in the post I said that once you get down the commands to modify your WIM boot image file, you can easily crank out various versions.

    If you are using optical media based WinPE builds, then you just have to carry a few disks in each of the scratch-space flavors you created.

    However, if you are using a bootable USB disk, and it has sufficient space, you can get all crazy!

    On my own bootable USB flash stick, in addition to the required “SOURCES” folder and contents, I also have a “SOURCES-ALT” folder.  In there I keep all my additional and scratch-space-adjusted WIM files.  So I have a  Boot-32.wim, Boot-128.wim, Boot-256.wim, and a Boot-512.wim file stored in there.  Typically, I have the 512 MB set scratch-space boot.wim file in my SOURCES folder to boot with.  However, if I know I need to WinPE boot a system that that wouldn’t work on, then I can delete the boot.wim file out of my SOURCES folder on the USB stick, and copy another more appropriate version from my SOURCES-ALT folder over into it, say the Boot-128.wim one.  Then I rename it to boot.wim and I am good to go!

    In fact, once the contents of the WIM file are loaded into the scratch-space/RAM Disk, it is then released.  That means if you are going from a system that uses the 512 MB scratch-space, and then progress on to one that will require the 64 MB scratch-space version, it seems you can do the boot.wim delete/copy/rename routine on your USB stick still from within your WinPE boot session!  I’ve done this on a number of occasions.

    Even more fun is making up not just different scratch-space flavors of the boot.wim file, but even wholly different versions of the boot.wim file itself!  You could have a custom WinPE 2.0 boot.wim file, a custom WinPE 3.0 boot.wim file, an AntiVirus PE Disk to offline-scan a Windows system, or maybe, say, a Win(FE) forensics build boot.wim, and so on…limited only by the size of your USB storage device and your imagination and efforts.  Even different WIM files with different hardware drivers injected for various system platforms.  Instead of carrying a mess of optical disks, just a single large USB storage may do the trick (assuming the system BIOS supports USB based booting).

    Of course, you do have to reboot the system to then load whichever WIM file you have swapped out…but I’m sure you knew that already.  Just keep the originals safely and alternatively named in your “storage” folder location and delete/copy/rename the original boot.wim file as needed.

    One more Bonus Find

    The real find on this tip comes at the bottom of the page.

    CatPawz has three helpful CLI sections documented that deal with “Build a Windows 7 AIO DVD”, “To Modify a Win7PE Disk”, and “To Create a Win7 Disk”.   If you aren’t familiar or comfortable with CLI usage in WinPE building and servicing, these could be great examples to follow and learn from.

    Cheers!

    --Claus V.

    Sunday, November 01, 2009

    Sexy USB Boots (Win PE style)

    sexy boots“Tiffany’s New Boots” flickr cc image by akseez

    Due to a generous birthday-fun contribution from my little bro I recently picked up a Patriot Xporter XT Boost 16GB flash drive stick for my personal use.  I’ve got a number of 512 MB ones scattered around, as well as my dependable 2 GB one, but after the latest round of family IT support service calls, I really wanted one with enough room that I could store all my portable utilities on; and still have enough room for a few ISO files.  More importantly I wanted a fairly-fast USB stick I could configure to use as a Win PE boot device.

    Not that I have anything against bootable CD/DVD media.  It certainly has its place, but having a Win PE boot stick is just so much more sexy.  Not only is it wicked-fast for off-line booting a Windows system for response and support, but it also allows me to save log data or recovered files directly to, rather than try to offload them to a network share, the Net, or a non-booting USB storage device.

    I’ve already covered this ground before at work with my current “for work purposes only” 8 GB USB stick.  For that I used PurvianceCS’s post on how to Create a Bootable VistaPE USB Hard Drive or Flashdrive.  Because this was based on my earlier VistaPE building work, it was a natural progression and worked flawlessly.  It does use GRUB as the bootloader for the Win PE WIM handoff.  That’s no problem and GRUB has an amazing amount of flexibility for multi-booting USB devices. However, to be honest, I never use any of the additional boot options it provides.  I just boot to the Win PE WIM file and continue on.

    I had in the past posted a few link round-ups to various ways and tools and techniques for making USB devices bootable.

    They all are good and provide lots of great background but I really wanted a solution that was dead-fast, simple, and rock-solid for setting up a (supported) USB storage device to be used as a boot device for Win PE builds.

    This was particularly important for me as well since in our IT shop we now have over twenty-five portable Western Digital external hard drives that I keep updated with ImageX-based WIM images of our various hardware systems.  When I hand them out on projects, a folder goes with them containing CD-ROM’s of my custom Win PE boot disk along with a Clonezilla disk as well (images for those are on the drives as well).  Wouldn’t it be nice if the CD drive was funky or problematic to allow the techs to boot directly from the same device the images were stored on? Yep.

    So after some brief work and experimentation, I found the following technique worked “bestest and fastest” for not only making my personal USB device quickly bootable, but all these external USB hard drives as well.  And all done with my own hands!

    The Technique

    This assumes a few things first, so let’s get those out of the way.

    1. There is nothing now on the drive you want to save (or you have backed it up already).
    2. The drive is (or will be) NTFS formatted.  (I’m not sure this is a requirement but it seems to improve speed.)
    3. The USB storage device supports USB booting (not all do).
    4. You are reasonably comfortable with CLI work, including DISKPART.
    5. You already know that to use the thing, you may have to set your BIOS to the “boot from USB” option (or select it in a one-time boot option at BIOS startup…).

    I actually found this easiest to do while running under a Win PE 2.0 (Vista) or Win PE 3.0 (Win7) session, though you can do it from an administrator-elevated command prompt session under Vista or Windows 7 as well.

    Note: Please read this carefully, review the provided supporting cross-linked posts, and make sure you understand what you are doing in advance. Also be sure you have all the required ingredients ready and on the counter-top before you start cooking!  If you don’t or aren’t sure what you are doing, you run the risk of nuking your system, possibly un-recoverably!  Your Poodles might turn pink and your beloved family hamsters might escape in the night.

    Format the Drive

    1. Pop in your USB storage device.
    2. Open a command session (CMD.exe).  If not using a Win PE session, go to “Start” –> “Programs” –> “Accessories” –> “Command Prompt” and right-click and select “Run as administrator”
    3. Type DISKPART
    4. Let’s make sure you correctly identify which drive number your USB device is listed as!
    5. Type LIST DISK
    6. All storage devices will be listed.  You should be able to tell which yours is by the size. In most cases, mine shows up as “1” with my local hard-drive listed as “0”.  Yours may vary so check carefully and use your drive number accordingly in the next steps!
    7. Let’s clean up the drive first to avoid any issues.  Note: data loss will occur on the device at this point!
    8. Type SELECT DISK 1   (this makes the USB drive the focus of the actions to follow)
    9. Type CLEAN       (This deletes the MBR section of the storage device)
    10. Type CREATE PARTITION PRIMARY     (This creates a fresh, single partition out of the available space)
    11. Type ACTIVE      (This makes firmware see the partition as a “system” partition)
    12. Type ASSIGN     (This assigns the next available drive letter to the device)
    13. Type LIST VOLUME   (Take a look and make note of what drive letter got assigned to the USB device)
    14. Type EXIT

    Now type the following to actually format the USB device.  Make sure your drive letter is correct!

    Format <drive letter>: /fs:ntfs /q /y     (where <drive letter>: equals the USB device letter found from #13 above…in my case it was e:  )

    This formats the drive letter listed, with the NTFS file system, quick, without requiring confirmation checks.

    And yes…I know you can also do a format from within DISKPART.  I just like doing it this way.  It’s a personal preference thing….

    Pull on your USB Boots

    Now we need to do some mojo-jojo to make the USB storage device bootable.  To do so we need the BOOTSECT.EXE utility.  It is on Vista and Windows 7 setup disks as well as within the Windows AIK kits for both.

    I suppose you can find it available with Google as well, but I like to have the real thing from source.

    The simplest way I can recommend getting BOOTSECT.EXE is to download and install one of the following WAIK’s from Microsoft.  In fact, if you are bothering to read this post, and are a WinPE builder, I’d be surprised if you didn’t already have one of these installed.

    If you have already installed it, you can find the file in either of the following locations (depending on what flavor you want).

    C:\Program Files\Windows AIK\Tools\PETools\x86\bootsect.exe
    C:\Program Files\Windows AIK\Tools\PETools\amd64\bootsect.exe

    If you do, say, have a hand-me-down WinPE boot CD/DVD but don’t want to install the WAIK to get the tool, an alternative is to extract it from the downloaded WAIK ISO file.

    You can use various freeware utilities (SlySoft Virtual CloneDrive, or Pismo File Mount, or ImDisk) to mount the ISO as a virtual folder/drive.

    Then follow the tips in this handy NirSoft Blog post -- How to extract missing system files from the DVD of Windows 7/Vista -- and browse to the following location in the WAIK ISO:

    \KB3AIK_EN.iso\WinPE.cab\F1_WINPE.WIM\1\Windows\System32\bootsect.exe

    …and extract the file.

    Mkay?

    Now, in your command-line session browse over to the directory location where you have placed the BOOTSECT.EXE file and execute it with the following command:

    BOOTSECT /NT60 <usb drive letter>    (Where <usb drive letter> equals your USB device)

    again, in my case I would be typing BOOTSECT /NT60 E:

    If all goes well you will get a message about the process updating correctly.

    Type EXIT to close out the command window.

    Need more info on BootSect magic?

    Add your Win PE boot file.

    Last step is to copy over the required files from your pre-build WinPE CD/DVD disk.

    In my case I was using the Win PE 2.0/3.0 files from these previous GSD projects:

    Using your favorite Windows file manager program (with options enabled to see system/hidden files) pop your Win PE 2.0 or 3.0 boot disk into your system and then copy the following files/folders over to the root of your USB device:

    • BOOT (folder & contents)
    • EFI (folder & contents)
    • SOURCES (folder & contents)
    • bootmgr (file)

    At this point, you can also copy over any additional folders, (portable) programs, etc. that you might want to have available from the USB device when you boot into the Win PE environment.

    You should now be able to just pop the device into a system that supports USB device booting, and selecting that option (if not already configured in the BIOS) boot the system to test.

    Has worked like a charm on my devices and systems using this technique.  Sexy USB drive booting goodness, much faster and more convenient for system support than optical media based Win PE boot build can provide!

    More Stuff

    It seems like a lot of stuff to do to make your USB device bootable, but believe me. After making your tenth or eleventh USB storage device Win PE boot supported, you can do it in your sleep.  For me it now takes less than three or four minutes per device now to run down the steps.  Seriously!

    One of the cool things I have found is that by setting up your USB storage device this way, just about any WIM PE based boot.wim file will be supported.

    So what I did was create another folder SOURCES-EXTRAS and dumped other boot.wim file builds in it renamed with a descriptive hint.  Then when I want to boot using a particular Win PE build, I just have to first rename my primary WIM file in the SOURCES folder to something like boot.wim.x and then copy the alternative WIM out of by backup SOURCES-EXTRA folder into SOURCES folder, then rename it to boot.wim.  This gives me greater flexiblity when I need a particular Win PE build.  Like not using my primary one with the sexy Laura Croft background wallpaper when I am at the in-laws…just for example….but the one with a more appropriate wallpaper for that particular audience.

    Other boot.wim files I have stored are as follows:

    In all these cases, generally I just need to copy the boot.wim file out of the SOURCES folder and (after renaming it) drop it into the SOURCES-EXTRA folder.  Sometimes these do carry extra folders on the root, so take a look around and make sure you get any supporting folders you might need for them to work properly.  Generally those will go under the USB device root.

    I also make sure I have a copy of Imagex.exe taken from the WAIK was well. Note that the Win PE 3.0 IMAGEX version is more advanced (link to nice posts from 4sysops blog) than the Win PE 2.0 version.  While I like the added features in the PE 3.0 one, I still prefer using the PE 2.0 for image capture/application at work and home (for now).

    Odds-n-Ends

    Here are some more (mostly) related posts that might be of interest to you as you expand your USB WinPE booting device.

    Now go and enjoy those sexy boots!

    --Claus V.