Win7PE-SE issue - Taking Ownership of Files
#1
Posted 17 October 2011 - 09:17 PM
This displays a dialog box with the following error:
Windows Security
-----------------------
Can't open access control editor. Invalid value for registry
As a result, I am unable to take the ownership of the files I need in order to set their permissions to make them accessible so that I can move them to another hard drive..
Any suggestions? Fixes?
#2
Posted 17 October 2011 - 10:00 PM
Don't know, if it works in any other Win7 based PE, but i doubt it.
#3
Posted 17 October 2011 - 10:45 PM
#4
Posted 17 October 2011 - 10:45 PM
Attached Files
#5
Posted 18 October 2011 - 01:15 AM
I tried the takeown and icacls commands from the .reg files on the folder I am having trouble with..
..takeown says:
"Error: No mapping between account names and security IDs was done"
..and icacls makes it through some of the files, then says:
"Access denied"
on one of the files and
"..Failed processing 1 files"
so unfortunately that didn't seem to get me any further..
#6
Posted 18 October 2011 - 05:11 AM
I assume these are "not" files within the PE?.
Please specify which ownerspermissions are currently set for these files?
Also are target systemfiles joined to a domain or workgroup
Have you changed any usernames on target systemfiles
More info needed Please.
#7
Posted 18 October 2011 - 05:31 AM
I've figured out enough now that I can say the issues I'm having with takeown and icacls is not limited to Win7PE-SE..
The files I'm working with are on an old hard drive apparently containing Windows 2000. The current owner on the files is indeed a domain administrator, granting only that user access..
What I have just figured out is the following:
booting into the command prompt from a Windows 2008 R2 DVD and using takeown and icacls gives the same errors!
I finally began to suspect and decided to try to shorten the folder names containing the files, and now by alternately using takeown and icacls commands from those .reg files, I am slowly making some progress. Its slow going as I'm only gaining access to one or a handful of files at a time per run of the commands, but it does not appear to be an issue related to Win7PE-SE..
#8
Posted 18 October 2011 - 10:22 AM
If you want to get access (copy the actual file contents of the files) you may want to try "direct access".
http://reboot.pro/15086/page__st__25
Wonko
#9
Posted 18 October 2011 - 02:44 PM
http://www.hobeanu.c...ccessgain-tool/
#10
Posted 18 October 2011 - 04:22 PM
I solved my issue completelly with Macrium Reflect PE (unfortunatelly commercial)
Peter
#11
Posted 18 October 2011 - 04:42 PM
See if this will do the trick
http://www.hobeanu.c...ccessgain-tool/
probably not. it won't run in vista/win7 because its an unsigned kernel mode driver.
I made a plugin for it (win7x86/x64) awhile ago but disabling checking PITA for a PE build.
#12
Posted 18 October 2011 - 04:45 PM
I don't think that orphaned directories is connected with ownership/permissionsI also have had a lot of troubles with orphaned mounted wims left as undeletable directories.
What actually did you do with the tool you mentioned?
I think that it is similar to the manual steps you can read in this .pdf :
http://accessdata.co...Files.en_us.pdf
Wonko
#13
Posted 18 October 2011 - 04:51 PM
Maybe that my issue was a different one. I could not delete the directories even after declaring "ME" as owner and gave full access to every user.I don't think that orphaned directories is connected with ownership/permissions
What actually did you do with the tool you mentioned?
In Macrium Reflect I used the explorer, and clicked "Delete" in the directories' context menu.
Peter
#14
Posted 18 October 2011 - 06:45 PM
Have fallen into that trap too.
- pscEx likes this
#15
Posted 18 October 2011 - 09:01 PM
See if this will do the trick
http://www.hobeanu.c...ccessgain-tool/
I do not know if it can do the job, there is "Access Gain" script in http://gena.cwcodes.net/ (Gena\Drivers\6 Other"), see http://gena.cwcodes.net/projectindex.php. the script is compatible to pe2/3, not personally used and tested.probably not. it won't run in vista/win7 because its an unsigned kernel mode driver.
I made a plugin for it (win7x86/x64) awhile ago but disabling checking PITA for a PE build.
May be good to have a try
#16
Posted 18 October 2011 - 09:46 PM
it won't run in vista/win7 because its an unsigned kernel mode driver.
I made a plugin for it (win7x86/x64) awhile ago but disabling checking PITA for a PE build.
#17
Posted 20 February 2012 - 06:53 AM
It's necessary, for example to delete/clear system restore points before creating a backup (on a windows drive)... This can save about 10 GB (or more)... in the size.
Nobody could make it work?
#18
Posted 20 February 2012 - 08:10 AM
If you use ExplorerXP.exe portable App then you are probably allowed to do anything you want.
Delete or Copy files without having permission. http://www.explorerxp.com/
If you want to take ownership you can try to use SetACL.exe as described here
http://helgeklein.com/
- u2o likes this
#19
Posted 22 February 2012 - 05:03 AM
Thanks wimb!Not a solution to change the permission, but ....
If you use ExplorerXP.exe portable App then you are probably allowed to do anything you want.
Delete or Copy files without having permission. http://www.explorerxp.com/
If you want to take ownership you can try to use SetACL.exe as described here
http://helgeklein.com/
But ExplorerXP don't allow delete files in System Volume Information, don't shows an error message, but not delete them... as with MS-Explorer.
Anyway that isn't the solution, since the permissions are managed by the system.
In Win7PE, we only have a user "Default". I remember BartPE ... the user was "SYSTEM", it had more permissions (all permissions) that "Admin user", so... allowed everything (and too allowed change permissions and the file owner).
But I don't think the problem is the user name or permissions of the Win7PE User (Default) . The problem is the owner of the file. With another files it works...
I was trying to load the default users of Windows 7, importing multiple registry keys for HKLM\SAM and HKLM\SYSTEM, but I haven't success...
Neither do I have managed to integrate "GPEDIT" as to enable "Group Policy Editor", or at least display the users and their policies (or portion thereof).
I'm recording every RegKey call to run the editing permissions in Windows 7 and trying to see if it works ... but it will take some time ...
But anyway ... I wish edit the file permissions, with Windows File Properties, only for some files... And so avoid terrible disasters...
#20
Posted 22 February 2012 - 10:51 AM
#21
Posted 22 February 2012 - 11:21 PM
I had that doubt. I am working to recognize all keys...
#22
Posted 28 April 2012 - 10:10 AM
#23
Posted 01 May 2012 - 04:55 AM
I can confirm that accessgain works like a charm in Win7pe x86.What i did is to mount the WIM and add accessgain service entry to the SYSTEM hive manually(via regedit-you also need to copy the accessgain.sys file to the drivers folder).After unmounting and booting it works without any problem.
Hi Agent47, accessgain.sys needs a script to work in Win7PE. I couldn't make it work. Can you copy your working registry keys?
#24
Posted 01 May 2012 - 12:19 PM
#25
Posted 02 May 2012 - 04:05 AM
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINEWINPE] [HKEY_LOCAL_MACHINEWINPEControlSet001] [HKEY_LOCAL_MACHINEWINPEControlSet001Control] [HKEY_LOCAL_MACHINEWINPEControlSet001ControlGroupOrderList] "FSFilter Activity Monitor"=hex:02,00,00,00,01,00,00,00,02,00,00,00 [HKEY_LOCAL_MACHINEWINPEControlSet001services] [HKEY_LOCAL_MACHINEWINPEControlSet001servicesAccessGainDriver] "Type"=dword:00000002 "Start"=dword:00000001 "ErrorControl"=dword:00000001 "Tag"=dword:00000002 "ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,58,00,3a,00,5c,00,57,00,69,00,6e,00, 64,00,6f,00,77,00,73,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32, 00,5c,00,64,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,61,00,63,00,63,00, 67,00,61,00,69,00,6e,00,2e,00,73,00,79,00,73,00,00,00 "DisplayName"="AccessGainDriver" "Group"="FSFilter Activity Monitor" "DependOnService"=hex(7):46,00,6c,00,74,00,4d,00,67,00,72,00,00,00,00,00 "Description"="File system access gain mini-filter driver" [HKEY_LOCAL_MACHINEWINPEControlSet001servicesAccessGainDriverInstances] "DefaultInstance"="AccessGain Instance" [HKEY_LOCAL_MACHINEWINPEControlSet001servicesAccessGainDriverInstancesAccessGain Instance] "Altitude"="370020" "Flags"=dword:00000000
After booting in to win7pe open CMD window and type 'fltmc'.If everything is ok,you can see accessgain driver in the list.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users