2011dingfei 发表于 2012-3-29 13:25:51

完美安装uwf,WES8 新版写过滤工具!非常牛逼!!超越一切

WES8 新版写过滤工具 Unified Write Filter !非常牛逼!!超越一切

说明文档下载地址:https://connect.microsoft.com/wi ... px?DownloadID=41774

翻译:
Unified Write Filter功能:
1.uses only RAM overlay。只使用 RAM 缓存
2.执行动态保护 — —在运行时 可以动态 添加和删除卷,以及 保留和回收叠加中的内存的能力。(回收内存!)
It also provides the ability to perform dynamic protection – adding and removing volumes at runtime, as well as the ability to preserve and reclaim memory in the overlay.
3.智能过滤功能 :在保护卷时,它允许某些文件和文件夹例外,; 同时它还允许某些要永久保存的注册表项。
      也就是说:允许甚至文件、文件夹、注册表 例外(比FBWF更强大!)

本人已经研究出三条命令,配合注册表,完美安装,不会再出错
注册:regsvr32 -s %SystemRoot%\system32\wbem\uwfwmi.dll
mofcomp %SystemRoot%\system32\wbem\uwfwmi.mof配置:(自动设置disksignature,partitionoffset,volumename等等注册表项)uwfmgr.exe unattend install-config
下载地址
34楼

[ 本帖最后由 2011dingfei 于 2012-7-28 07:50 编辑 ]

andos 发表于 2012-3-30 09:07:54

希望能把Unified Write Filter上传上来分享一下吧,谢谢!

2012qbtsgz 发表于 2012-3-30 08:06:54

找不到页面呢~ 能否提供另外的连接?

11ydy 发表于 2012-7-21 09:14:43

原帖由 嵐風 于 2012-7-21 08:51 发表 http://bbs.wuyou.net/images/common/back.gif
http://hiphotos.baidu.com/%E1%B0%B7%E7416/pic/item/fec879255c6034a8e1a13f13cb1349540b2376e7.jpg
fbwf移植win8 64bit成功,
但是uwf移植失敗了,
有大神成功把uwf移植去win8麼,
勞資功力不夠,
不知道am ...


这段就是复制SYS到驱动目录,注册表创建驱动服务

你这是64位系统吧,你试试这个注册表,还有文件及语言文件。是我在WES8中DISM UWF后提取出来了,但是我发现UWF能启动但是没起作用,不知道哪里还有问题,你试试吧


另外请问你在用WES8中的FBWF EWF时出现过启动系统时磁盘错误扫描的情况吗

[ 本帖最后由 11ydy 于 2012-7-21 09:19 编辑 ]

嵐風 发表于 2012-7-21 08:51:18

http://hiphotos.baidu.com/%E1%B0%B7%E7416/pic/item/fec879255c6034a8e1a13f13cb1349540b2376e7.jpg
fbwf移植win8 64bit成功,
但是uwf移植失敗了,
有大神成功把uwf移植去win8麼,
勞資功力不夠,
不知道amd64_microsoft-windows-e..-unifiedwritefilter_31bf3856ad364e35_6.2.8400.0_none_8184a38d182fd152.manifest,
這一段說神馬,

<memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootCritical" />
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Services" version="6.2.8400.0" publicKeyToken="31bf3856ad364e35" typeName="Service" />
      <categoryInstance>
      <serviceData name="uwfvol" displayName="@%SystemRoot%\system32\drivers\uwfvol.sys,-100" errorC group="PnP Filter" imagePath="system32\drivers\uwfvol.sys" start="boot" type="kernelDriver" description="@%SystemRoot%\system32\drivers\uwfvol.sys,-100" />
      </categoryInstance>
      <categoryInstance>
      <serviceData name="uwfs" displayName="@%SystemRoot%\system32\drivers\uwfs.sys,-100" errorC group="FSFilter Activity Monitor" imagePath="system32\drivers\uwfs.sys" start="boot" type="fileSystemDriver" description="@%SystemRoot%\system32\drivers\uwfs.sys,-100" depend />
      </categoryInstance>
      <categoryInstance>
      <serviceData name="uwfreg" displayName="@%SystemRoot%\system32\drivers\uwfreg.sys,-100" errorC group="FSFilter Activity Monitor" imagePath="system32\drivers\uwfreg.sys" start="boot" type="kernelDriver" description="@%SystemRoot%\system32\drivers\uwfreg.sys,-100" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="Storage Volume" />
      <categoryInstance subcategory="LowerFilters">
      <filter xmlns="urn:schemas-microsoft-com:asm.v3" name="uwfvol" position="first" />
      </categoryInstance>
    </categoryMembership>
</memberships>

求大神解讀/將uwf移植到win8方法公諸同好Orz

xiyun0769 发表于 2012-7-14 15:31:38

回复 #9 11ydy 的帖子

希望顺便能把64位的上传上来分享一下吧,谢谢!

md5 发表于 2012-5-19 10:32:31

回收内存智能过滤功能 允许甚至文件、文件夹、注册表 例外 真是够给力的
要是wes7也能用这个就好了

419788808 发表于 2012-4-10 09:30:36

肿么使用呢、亲。。。。

2011dingfei 发表于 2012-4-7 09:25:22

回复 #12 2010yuhongxi 的帖子

自己测试了便知,64位超过了。32为不知

2010yuhongxi 发表于 2012-4-7 04:24:56

请问超越1gb限制没有?

hkmore 发表于 2012-4-4 03:04:55

好強的功能

2011dingfei 发表于 2012-3-30 09:52:01

回复 #4 andos 的帖子

得自己下载 wes8 ,提取,研究

20101030 发表于 2012-4-1 20:33:08

请问超越1gb限制没有 没有的话那不但疼

2011Yukari 发表于 2012-4-3 15:29:00

支持uefi gpt么

2011dingfei 发表于 2012-4-3 20:05:37

回复 #7 2011Yukari 的帖子

和分区表类型无关吧,win8支持,就当然也支持

11ydy 发表于 2012-4-3 21:22:45

原帖由 andos 于 2012-3-30 09:07 发表 http://bbs.wuyou.net/images/common/back.gif
希望能把Unified Write Filter上传上来分享一下吧,谢谢!



WES832位里面的

不知道怎么能把XML 格式 相关添加注册表的内容转换成REG格式


比如 这个组件包里面的 x86_microsoft-windows-e..-unifiedwritefilter_31bf3856ad364e35_6.2.8250.0_none_245371b72d96676f.manifest<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
<assemblyIdentity name="Microsoft-Windows-Embedded-UnifiedWriteFilter" version="6.2.8250.0" processorArchitecture="x86" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
<dependency discoverable="no" resourceType="Resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-Embedded-UnifiedWriteFilter.Resources" version="6.2.8250.0" processorArchitecture="x86" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
</dependency>
<file name="uwfvol.sys" destinationPath="$(runtime.drivers)\" sourceName="uwfvol.sys" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">9apUXl8ls8y2j1sNxRA6S/+2EVO2vmnSzd+yu7WI4II=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfs.sys" destinationPath="$(runtime.drivers)\" sourceName="uwfs.sys" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">k7om/dXbrTEB4wqUdNqLQOW6/21BgIrn2qafxsHJIEU=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfreg.sys" destinationPath="$(runtime.drivers)\" sourceName="uwfreg.sys" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">ouzKYEtxpzU+DL5UhpnRUX4vJEqK+AwZFFZ1bOayW70=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfrtl.sys" destinationPath="$(runtime.drivers)\" sourceName="uwfrtl.sys" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">bNlr18oxBo5VmlEFYxNO/8C5Tk1yc2fJdCFeXv3/IDE=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfmgr.exe" destinationPath="$(runtime.system32)\" sourceName="uwfmgr.exe" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">jJ89Gs4eaMPKrtx1yBW4ur6FvGlJcUdFTneD16efeXk=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfwmi.dll" destinationPath="$(runtime.wbem)\" sourceName="uwfwmi.dll" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">IZMWodsjlnbb545+qM2/uZf0cRaGX5rggwAcwjhm+qE=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfwmi.mof" destinationPath="$(runtime.wbem)\" sourceName="uwfwmi.mof" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">0AsDjpDCVDy9koAQP+u8hYJrSMZA3xh11nq6KxZXNgk=</dsig:DigestValue>
    </asmv2:hash>
</file>
<file name="uwfwmi_uninstall.mof" destinationPath="$(runtime.wbem)\" sourceName="uwfwmi_uninstall.mof" sourcePath=".\" importPath="$(build.nttree)\Embedded\sys\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">vQhOnTqeizIpit3gKrbtG6bulV38ISZ+Dr0zP5e/INY=</dsig:DigestValue>
    </asmv2:hash>
</file>
<memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootCritical" />
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Services" version="6.2.8250.0" publicKeyToken="31bf3856ad364e35" typeName="Service" />
      <categoryInstance>
      <serviceData name="uwfvol" displayName="@%SystemRoot%\system32\drivers\uwfvol.sys,-100" errorControl="critical" group="PnP Filter" imagePath="system32\drivers\uwfvol.sys" start="boot" type="kernelDriver" description="@%SystemRoot%\system32\drivers\uwfvol.sys,-100" />
      </categoryInstance>
      <categoryInstance>
      <serviceData name="uwfs" displayName="@%SystemRoot%\system32\drivers\uwfs.sys,-100" errorControl="critical" group="FSFilter Activity Monitor" imagePath="system32\drivers\uwfs.sys" start="boot" type="fileSystemDriver" description="@%SystemRoot%\system32\drivers\uwfs.sys,-100" dependOnService="FltMgr" />
      </categoryInstance>
      <categoryInstance>
      <serviceData name="uwfreg" displayName="@%SystemRoot%\system32\drivers\uwfreg.sys,-100" errorControl="critical" group="FSFilter Activity Monitor" imagePath="system32\drivers\uwfreg.sys" start="boot" type="kernelDriver" description="@%SystemRoot%\system32\drivers\uwfreg.sys,-100" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="Storage Volume" />
      <categoryInstance subcategory="LowerFilters">
      <filter xmlns="urn:schemas-microsoft-com:asm.v3" name="uwfvol" position="first" />
      </categoryInstance>
    </categoryMembership>
</memberships>
<registryKeys>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{946531FF-05F8-4633-B44C-DCE38A24B2FD}\" owner="false">
      <registryValue name="" valueType="REG_SZ" value="UWF" operationHint="replace" owner="true" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{946531FF-05F8-4633-B44C-DCE38A24B2FD}\InprocServer32\" owner="false">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wbem\uwfwmi.dll" operationHint="replace" owner="true" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Both" operationHint="replace" owner="true" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfs\Instances" owner="false">
      <registryValue name="DefaultInstance" valueType="REG_SZ" value="uwfs" operationHint="replace" owner="true" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfs\Instances\uwfs" owner="false">
      <registryValue name="Altitude" valueType="REG_SZ" value="384900" operationHint="replace" owner="true" />
      <registryValue name="Flags" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfvol\Parameters\Dynamic" owner="false">
      <registryValue name="HormEnabled" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="OverlayWarningThreshold" valueType="REG_DWORD" value="0x00000200" operationHint="replace" owner="true" />
      <registryValue name="OverlayCriticalThreshold" valueType="REG_DWORD" value="0x00000400" operationHint="replace" owner="true" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfvol\Parameters\Static" owner="false">
      <registryValue name="CurrentSettings" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="UpdatedSettings" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfvol\Parameters\Static\Copy0" owner="false">
      <registryValue name="UwfEnabled" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="TSCALPersisted" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="DomainSecretKeyPersisted" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="RegistryExceptionsUserDefined" valueType="REG_MULTI_SZ" value="" operationHint="replace" owner="true" />
      <registryValue name="RegistryExceptionsUWFSpecific" valueType="REG_MULTI_SZ" value=""HKLM\SYSTEM\CurrentControlSet\Services\UWFVOL\Parameters"" operationHint="replace" owner="true" />
      <registryValue name="OverlayType" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="OverlayPreAllocated" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="OverlayMaximumSize" valueType="REG_DWORD" value="0x00001000" operationHint="replace" owner="true" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\System\CurrentControlset\Services\uwfvol\Parameters\Static\Copy0\Volumes" owner="false">
      <registryValue name="NumVolumes" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="NumVolumesEnabled" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
      <registryValue name="TotalNumFileExceptions" valueType="REG_DWORD" value="0x00000000" operationHint="replace" owner="true" />
    </registryKey>
</registryKeys>
<trustInfo>
    <security>
      <accessControl>
      <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
      </securityDescriptorDefinitions>
      </accessControl>
    </security>
</trustInfo>
<mof xmlns="urn:schemas-microsoft-com:asm.v3" name="$(runtime.wbem)\uwfwmi.mof" uninstallmof="$(runtime.wbem)\uwfwmi_uninstall.mof" />
</assembly>

[ 本帖最后由 11ydy 于 2012-4-3 21:26 编辑 ]

xintiandi 发表于 2012-4-14 13:39:44

不知道这个cab包是否可以直接移植到wes7中使用

2011Yukari 发表于 2012-4-24 23:30:34

有没有gui管理界面

2010wfndh 发表于 2012-4-26 11:14:29

2010wfndh 发表于 2012-4-26 11:14:41

xiyun0769 发表于 2012-5-17 22:34:28

回复 #13 2011dingfei 的帖子

多大动态缓存。。求回答

2012noeyedragon 发表于 2012-5-18 11:03:12

wes8这个东西是免费使用吗,球一个虾载地址。谢谢

嵐風 发表于 2012-7-21 10:06:22

WES8裡沒開過ewf/fbwf.就試過uwf,
試下刪了bootstat看看

我也是把安了在wes8幾個檔案跟相關的reg提了出來,
改了下的volume也是不行,老是就說指令失敗(0x80041100E),
照我估計我不懂那段可能是一個系統服務

嵐風 发表于 2012-7-21 10:15:21

試了你那個uwf都不行Orz,
我試試把系統語言改成en-US看看=.=
畢竟那個UWF只有英文的....

嵐風 发表于 2012-7-21 10:47:42

好的,再次失敗Orz
求大神解讀memberships那部分

2011dingfei 发表于 2012-7-27 07:53:29

回复 #27 嵐風 的帖子

大神来了,据我分析,因为你少了一些东西,你试试
regsvr32 -s %windir%\system32\wbem\uwfwmi.dll
mofcomp %windir%\system32\wbem\uwfwmi.mof
导入注册表后用这两个命令注册下,然后看看有没用,汇报下情况

11ydy 发表于 2012-7-27 09:39:20

原帖由 2011dingfei 于 2012-7-27 07:53 发表 http://bbs.wuyou.net/images/common/back.gif
大神来了,据我分析,因为你少了一些东西,你试试
regsvr32 -s %windir%\system32\wbem\uwfwmi.dll
mofcomp %windir%\system32\wbem\uwfwmi.mof
导入注册表后用这两个命令注册下,然后看看有没用,汇报下情况


试了下用了这命令,UWGMGR不在出错,但是开启保护后没有作用,在开启保护的分区新建文件夹文件,重启后文件夹文件还在,不知道是开启命令不对还是哪里还缺失,大神给看看

注册DLL MOF
===========================================================
X:\Windows\system32>regsvr32 -s X:\Windows\system32\wbem\uwfwmi.dll

X:\Windows\system32>mofcomp X:\Windows\system32\wbem\uwfwmi.mof
Microsoft (R) MOF 编译器版本 6.2.8400.0
Copyright (c) Microsoft Corp. 1997-2006. All rights reserved.
Parsing MOF file: X:\Windows\system32\wbem\uwfwmi.mof
MOF file has been successfully parsed
Storing data in the repository...
完成!

===========================================================


开启UWF
===========================================================
X:\Windows\system32>uwfmgr.exe filter enable
Unified Write Filter Configuration Utility version 6.2.8400
Copyright (C) Microsoft Corporation. All rights reserved.

Unified Write Filter is enabled after system restart.

===========================================================



查看状态
===========================================================
X:\UWF_64>uwfmgr.exe get-config
Unified Write Filter Configuration Utility version 6.2.8400
Copyright (C) Microsoft Corporation. All rights reserved.

Current Session Settings

FILTER SETTINGS
    Filter state:    ON
    HORM state:      OFF
    Pending commit:N/A

OVERLAY SETTINGS
    Type:               RAM
    Maximum size:       1024 MB
    Warning Threshold:512 MB
    Critical Threshold: 1024 MB


VOLUME SETTINGS
    *** No volumes configured


REGISTRY EXCLUSIONS
    *** No exclusions

Next Session Settings

FILTER SETTINGS
    Filter state:    ON
=================================================



开启X盘保护
=================================================
X:\UWF_64>uwfmgr.exe volume protect x:
Unified Write Filter Configuration Utility version 6.2.8400
Copyright (C) Microsoft Corporation. All rights reserved.

The volume x: will be protected by Unified Write Filter after system restart.
=================================================


查看状态
=================================================
X:\UWF_64>uwfmgr.exe get-config
Unified Write Filter Configuration Utility version 6.2.8400
Copyright (C) Microsoft Corporation. All rights reserved.

Current Session Settings

FILTER SETTINGS
    Filter state:    ON
    HORM state:      OFF
    Pending commit:N/A

OVERLAY SETTINGS
    Type:               RAM
    Maximum size:       1024 MB
    Warning Threshold:512 MB
    Critical Threshold: 1024 MB


VOLUME SETTINGS
Volume Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}
    Volume state:   Protected
    Pending commit:   No
    Volume ID:      Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}

    File Exclusions:
      *** No exclusions


REGISTRY EXCLUSIONS
    *** No exclusions

Next Session Settings

FILTER SETTINGS
    Filter state:    ON
    HORM state:      OFF
    Pending commit:N/A

OVERLAY SETTINGS
    Type:               RAM
    Maximum size:       1024 MB
    Warning Threshold:512 MB
    Critical Threshold: 1024 MB


VOLUME SETTINGS
Volume Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}
    Volume state:   Protected
    Volume ID:      Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}

    File Exclusions:
      *** No exclusions


REGISTRY EXCLUSIONS
    *** No exclusions

=================================================




就是这样但是没有效果
把注册表里


"0"="STORAGE\\Volume\\{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}#00000000007D8200"


改成和

"VolumeName"="Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963}"
"DriveLetter"="x:"
"VolumeEnabled"=dword:00000001
"Binding"=dword:00000001
"PartitionStyle"=dword:00000000
"PartitionOffset"=hex(b):00,82,7d,00,00,00,00,00
"DiskSignature"=dword:85debc79
"FileExceptionsUserDefined"=hex(7):00,00,00,00
"NumFileExceptionsUserDefined"=dword:00000000


一样的 Volume{e120c6d9-ccef-11e1-a3d4-806e6f6e6963} 与#00000000007D8200 一样也不行
不知道问题出在哪里
原帖由 2011dingfei 于 2012-7-27 07:53 发表 http://bbs.wuyou.net/images/common/back.gif
大神来了,据我分析,因为你少了一些东西,你试试
regsvr32 -s %windir%\system32\wbem\uwfwmi.dll
mofcomp %windir%\system32\wbem\uwfwmi.mof
导入注册表后用这两个命令注册下,然后看看有没用,汇报下情况

11ydy 发表于 2012-7-27 11:18:01

回复 #28 2011dingfei 的帖子

可以正常使用了
少了条注册表
Windows Registry Editor Version 5.00



"LowerFilters"=hex(7):75,00,77,00,66,00,76,00,6f,00,6c,00,00,00,00,00

2012leeyy0124 发表于 2012-7-27 11:49:32

我是来做伸手党的,求完整打包。。。。+1

网路上看过测试,感觉还满强大

2010gudam 发表于 2012-7-27 15:47:38

原帖由 11ydy 于 2012-7-27 11:18 发表 http://bbs.wuyou.net/images/common/back.gif
可以正常使用了
少了条注册表
Windows Registry Editor Version 5.00



"LowerFilters"=hex(7):75,00 ...
求放出32位和64位版
页: [1] 2 3 4 5
查看完整版本: 完美安装uwf,WES8 新版写过滤工具!非常牛逼!!超越一切