786
|
Chapter 23: Exploring the Windows Boot Environment
The Windows Boot Loader entry has parameters that track the status of the No Exe-
cute (NX) policy, integrity checking, kernel debugger mode, and Emergency Man-
agement Services (EMS). Although the Windows Boot Manager, Windows Legacy
OS Loader, and Windows Boot Loader are the primary types of entries that control
startup, the BCD also stores information about preoperating system boot environ-
ment utilities and settings. If you want to view the BCD entries for utilities and set-
tings, you use the following command line:
bcdedit /enum all /v
This command line enumerates all BCD entries, regardless of their current state, and
lists them in Verbose Mode. Example 23-2 shows the verbose entries. It is important
to note that Verbose Mode provides the actual value of the Globally Unique Identifi-
ers (GUIDs) needed to manipulate entries in the BCD data store.
Boot debugger: No
Windows device: partition=D:
Windows root: \Windows
Resume application: {23432149-a32e-132a-ba28-ed8322b34395}
No Execute policy: OptIn
No integrity checks: Yes
Kernel debugger: No
EMS enabled in OS: No
Example 23-2. Viewing extended BCD entries
Windows Boot Manager
--------------------
identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device partition=C:
description Windows Boot Manager
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
bootdebug No
default {263bf496-4ab4-11db-b478-c0671802252f}
resumeobject {263bf497-4ab4-11db-b478-c0671802252f}
displayorder {263bf496-4ab4-11db-b478-c0671802252f}
{0c728e1b-d009-11da-b18b-9dc1d02cdda0}
toolsdisplayorder {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout 30
Windows Boot Loader
-------------------
identifier {0c728e1b-d009-11da-b18b-9dc1d02cdda0}
device unknown
path \Windows\system32\winload.exe
description Microsoft Windows
locale en-US
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
bootdebug Yes
osdevice unknown
Example 23-1. Examining the contents of the BCD data store (continued)