ERD Commander
-------------
Copyright (c) 1998 Mark Russinovich and Bryce Cogswell
http://www.ntinternals.com

When problems arise in Windows 3.1 or Windows 95 that render a system 
unbootable, there is always the possibility of booting off of a DOS 
floppy disk so that the drives of the machine can be accessed for 
repair and salvage. This boot-floppy approach to system recovery is 
often the only way to correct problems that even "automatic" system 
repair utilities fail to correct. In the past, Windows NT administrators 
have gone without this recovery option. ERD Commander finally brings 
boot-floppy functionality to Windows NT.

ERD Commander is a utility that enables you to boot NT off of a floppy 
disk in order to access and repair a dead NT installation. ERD Commander 
is a command-line shell that runs off of a set of NT boot disks giving 
you full access to non-bootable NT systems with a robust set of familiar 
command-line file manipulation tools including copy, rename, delete, 
move and xcopy. Because ERD Commander relies on a standard set of NT 
boot floppies, any NT system is accessible, and because ERD Commander 
runs on top of NT, all NT file systems, including FAT, NTFS, and CDFS 
are visible. 

ERD Commander works on NT 4.0 only.

This read-only version introduces you to the capabilities of ERD 
Commander. Most commands that cause modifications, such as delete, 
rename, move, etc., are documented here, but are disabled. Mkdir and 
Rmdir are the two modification commands enabled in this version. 
Information on ordering the read/write version of ERD Commander is 
available at the Winternals Web site, http://www.winternals.com.


Using ERD Commander
-------------------
ERD Commander can be used to help you solve problems such as:

** Removing or Replacing Buggy Drivers
You can use ERD Commander to delete the image files of drivers or 
services that, because of a bug or misconfiguration, prevent NT from 
booting.

** Updating Out-of-Date System Files
Incorrectly applying service packs or system software updates can 
cause system DLLs to become out of sync with each other. In many 
cases this can prevent NT from booting successfully. ERD Commander 
can copy up-to-date versions of old files from floppy disks or CD-ROMs 
onto a system.

** Correcting Misconfigured NTFS Security
If security attributes that are too restrictive are applied to 
certain system files or directories on NTFS boot drives, NT will 
become unbootable. ERD Commander includes a special command, Access, 
which unlocks otherwise inaccessible files or directories so that NT 
can access them.

** Updating Locked Files
Once NT is up-and-running many system files cannot be replaced because 
the system keeps them locked. ERD Commander makes it possible to update 
such files because it runs when NT is off-line and the files are not 
open.

** Correcting Registry Problems
A number of NT boot problems are the result of misconfigured Registry 
values. With ERD Commander you can copy Registry hives (located under 
<winnt>\system32\config) off the system to a floppy disk or other 
writeable removable media for modification on another NT machine 
(using Regedt32's Hive loading capability). Modified hives can then 
be copied back.

* Copying Important Files off of a Dead System
ERD Commander enables you to access files on an NT system that fails 
to boot. Important files can be salvaged onto a floppy disk or other 
removable media.


Note that ERD Commander is not intended to resolve disk corruption 
errors, and that only drives that are consistent enough to be 
recognized by Windows NT file systems will be accessible with ERD 
Commander.


Sample Screen-shot
------------------
Below is a presentation of what a typical display looks like after 
ERD Commander has started.  ERD Commander presents information on the 
disk drives that are recognized and the drive letters it has assigned 
for them. Volume name, file system type, and drive size data should 
help you identify particular drives.

	Microsoft (R) Windows NT (TM) Version 4.0
	1 System Processor [128 MB Memory]

	ERD Commander V1.0
	Copyright (C) 1998 Mark Russinovich and Bryce Cogswell
	http://www.ntinternals.com

	Drive letter mappings:
	A: \Device\Floppy0\                       FAT
	C: \Device\Harddisk0\Partition1\ WINDOWS  FAT   1015744 KB
	D: \Device\Harddisk0\Partition2\ WINNT    NTFS   205600 KB
	E: \Device\Harddisk0\Partition3\ SRC      FAT    870640 KB
	F: \Device\Harddisk0\Partition4\ TEST     NTFS    20128 KB
	G: \Device\Cdrom0\                        CDFS

	C:\>


Setup Options
-------------
When you execute the ERD Commander Setup program it will allow you to 
create a set of Windows NT boot floppies configured with ERD Commander. 
Optionally, you can supply an existing set of floppies to be configured. 

The Setup program will install two versions of the boot floppy creator 
onto your hard drive. The 32-bit version is the program that is run 
during the initial Setup. The 16-bit program allows you to configure 
boot floppies with ERD Commander from a DOS boot floppy or from Windows 
3.1. This is necessary in cases where your Windows NT installation is 
non-bootable and you do not have access to a second NT machine or to 
Windows 95.

After the disks are loaded, a stripped-down version of Windows NT will 
start, displaying the familiar boot-time Blue Screen that presents the 
NT version number, system memory size, and number of processors present. 
ERD Commander then starts automatically and enters a command-line 
environment nearly identical to the one NT implements in Command-Prompt.


The Command-line Environment
----------------------------
ERD Commander has a sophisticated command-line processor and it 
implements a large subset of NT's command-line command set, complete 
with all standard file-related commands. The environment mirrors the 
standard NT command-line environment so that using ERD Commander is 
intuitive - if you're familiar with the commands and command-line 
editing capabilities present in NT, then you already know how to use 
ERD Commander. 

The command-processor's editing features include:
* Arrow key navigation (e.g. left-arrow to move back, right-arrow to 
  move forward)
* Special key navigation (e.g. Home to go to the start of a line, 
  End to go to the end)
* Insert mode
* Command history

A sample of the commands available in ERD Commander includes:
* Rmdir 
* Mkdir
* Move
* Rename
* Delete
* Copy and Xcopy

Subsequent pages describe the command processor in greater depth.


Command-line Editing
--------------------
The command-line editing capabilities of ERD Commander are very similar 
to those supported by NT's command-line processor. Below is a reference 
of recognized special keys.

ESC             Resets the input line.
HOME            Moves the cursor to the start of the input line.
END             Moves the cursor to the end of the input line.
LEFT, RIGHT     Moves the cursor left or right one character.
DEL             Deletes the character under the cursor.
BACKSPACE       Deletes the character to the left of the cursor.
UP, DOWN        Navigates through the command-history buffer, which 
		is 30 commands deep.
INSERT          Toggles between insert and overwrite mode. The default 
		is overwrite.    

Note that the ENTER key that is part of numeric keypads is disabled.


The Command Set
---------------
The command set of ERD Commander, like its command-line editing 
features, is similar to those in NT. The command set includes all 
standard file-related commands, and virtually all support the same 
options as their NT counter-parts. This list shows the full set, with 
each command linked to its documentation. This list can be obtained 
inside of ERD Commander by entering the HELP command, and detailed 
information on the syntax of a particular command can listed by typing 
"command /?" or "HELP command". Note that the commands are interpreted 
in a case-insensitive manner so that "HELP" is the same as "help".

Commands marked with an asterisk (*) are disabled in the read-only 
version of ERD Commander:

ACCESS      Gives Everyone full access to a files or directories.
ATTRIB      Displays or changes file attributes.
CD          Displays the name of or changes the current directory.
CHDIR       Displays the name of or changes the current directory.
CLS         Clears the screen.
COPY*       Copies one or more files to another location.
DEL*        Deletes one or more files.
DIR         Displays a list of files and subdirectories in a directory.
ERASE*      Deletes one or more files.
EXIT        Quits ERD Commander and reboots the system.
HELP        Provides Help information for ERD Commander commands.
MAP         Displays drive letter to partition mapping.
MD          Creates a directory.
MKDIR       Creates a directory.
MOVE*       Moves one or more files from one directory to another directory.
QUIT        Quits ERD Commander and reboots the system.
RD          Removes a directory.
REN*        Renames a file or files.
RENAME*     Renames a file or files.
RMDIR       Removes a directory.
XCOPY*      Copies files and directory trees.
VER         Displays ERD Commander version number.
VERSION     Displays ERD Commander version number

 
Access
------
This command is disabled in the read-only version of ERD Commander.

Gives Everyone full access to directories or files.

ACCESS [[drive:][path]filename] [/S]

  /S  Processes files in all subdirectories in the specified path.

This command is a custom ERD Commander command. It is possible to render 
a NT system unbootable by inadvertently applying security restrictions 
to NTFS files or directories that prevent NT from loading files it 
requires. The ACCESS command will add a security entry to the security 
attributes of specified files or directories which gives the Everyone 
group full access. The Everyone group includes all groups and accounts, 
so this is the most permissive security setting possible. 

If the file or directory specified is inaccessible because the System 
account or Administrators group is denied access, ERD Commander will 
first take ownership for the Administrators group. This allows it to 
then modify the security settings to give Everyone full access.

The command can even be applied to root directories of drives that have 
been totally locked down. Such drives will show up in the drive mapping 
as having a file system type of "<?>". Simply specify the directory, 
e.g. "G:\", as the parameter to allow Everyone full access to the root 
directory. Files and directories within the drive can then be unlocked 
through subsequent applications of the ACCESS command.

NOTE: Because this command makes files and directories fully accessible 
to any user, which opens potential security holes, you should lock-down 
files and directories on which it is used after the system is booted 
normally.


Attrib
------
This command is disabled in the read-only version of ERD Commander.

Displays or changes file attributes.

ATTRIB [+R | -R] [+A | -A] [+S | -S] [+H | -H] [[drive:][path]filename] [/S]

  +   Sets an attribute.
  -   Clears an attribute.
  R   Read-only file attribute.
  A   Archive file attribute.
  S   System file attribute.
  H   Hidden file attribute.
  /S  Processes files in all directories in the specified path.


Cd/Chdir
--------
Displays the name of or changes the current directory.

CHDIR [drive:][path]
CHDIR[..]
CD [drive:][path]
CD[..]

  ..   Specifies that you want to change to the parent directory.

Type CD drive: to display the current directory in the specified drive.
Type CD without parameters to display the current drive and directory.


Cls
---
Clears the screen.

CLS


Copy
----
This command is disabled in the read-only version of ERD Commander.

Copies one or more files to another location.

COPY source [destination]

  source       Specifies the file or files to be copied.
  destination  Specifies the directory and/or filename for the new file(s).

Wildcards can be used in both the source and destination file name 
specifications.


Del/Erase
---------
This command is disabled in the read-only version of ERD Commander.

Deletes one or more files.

DEL [/P] [/F] [/S] [/Q] [/A[[:]attributes]] [[drive:][path]filename
ERASE [/P] [/F] [/S] [/Q] [/A[[:]attributes]] [[drive:][path]filename

  [drive:][path]filename
		Specifies the file(s) to delete.  Specify multiple files 
		by using wildcards.
  /P            Prompts for confirmation before deleting each file.
  /F            Force deleting of read-only files.
  /S            Delete specified files from all subdirectories.
  /Q            Quiet mode, do not ask if ok to delete on global wildcard
  /A            Selects files to delete based on attributes
  attributes    R  Read-only files      S  System files
		H  Hidden files         A  Files ready for archiving
		- Prefix meaning not

The display semantics of the /S switch are reversed in that it shows you 
only the files that are deleted, not the ones it could not find.


Dir
---
Displays a list of files and subdirectories in a directory.

DIR [drive:][path][filename] [/P] [/W] [/A[[:]attributes]]
  [/O[[:]sortorder]] [/S] [/B] [/L] [/V]

  [drive:][path][filename]
	      Specifies drive, directory, and/or files to list.

  /P          Pauses after each screenful of information.
  /A          Displays files with specified attributes.
  Attributes   D  Directories                  R  Read-only files
	       H  Hidden files                 A  Files ready for archiving
	       S  System files                 -  Prefix meaning not
  /O          List by files in sorted order.
  Sortorder    N  By name (alphabetic)         S  By size (smallest first)
	       D  By date (earliest first)     -  Prefix to reverse order
  /S          Displays files in specified directory and all subdirectories.
  /X          This displays the short names generated for non-8dot3 file
	      names. If no short name is present, blanks are displayed
	      in its place.

Use the /P switch to cause DIR to pause after each screen of information. 
Use CTRL-C to exit from DIR output back to the command prompt. If you 
inadvertently omit this switch you can pause DIR's output with CTRL-S or 
terminate it with CTRL-C. 


Exit/Quit
---------
Exits ERD Commander and reboots the system.

EXIT
QUIT

Be sure to remove the boot floppy from the floppy disk drive before the 
system reboots.


Help
----
Provides Help information for ERD Commander commands.

HELP [command]

  Command        Displays specific information on the specified command.


Map
---
Displays drive letter to partition mappings.

MAP

This command's purpose is to help you determine the drive letter 
assignments ERD Commander has made. ERD Commander does not rely on 
Disk Administrator drive letter mappings because there may be multiple 
NT installations on the hard disks, each with their own mappings. For 
each drive you'll see the device name, volume label, file system type 
and drive size. 

If the System account or Administrators group is denied access to a 
NTFS drive because of the security settings applied to the drive's 
root directory, the file system type will be <?>. Use the ACCESS 
command to unlock the drive.

An example mapping is shown below:

Drive letter mappings:
A: \Device\Floppy0\                       FAT
C: \Device\Harddisk0\Partition1\ WINDOWS  FAT   1015744 KB
D: \Device\Harddisk0\Partition2\ WINNT    NTFS   205600 KB
E: \Device\Harddisk0\Partition3\ SRC      FAT    870640 KB
F: \Device\Harddisk0\Partition4\ TEST     NTFS    20128 KB
G: \Device\Cdrom0\                        CDFS


Mkdir/Md
--------
Creates a directory.

MKDIR [drive:]path
MD [drive:]path

MKDIR creates any intermediate directories in the path, if needed. For 
example, assume \a does not exist then:

   mkdir \a\b\c

is the same as:

   mkdir \a
   mkdir \a\b
   mkdir \a\b\c


More/Type
---------
Displays the ASCII contents of a file.

MORE filename
TYPE filename

The MORE/TYPE command automatically pauses after each screen of data. 
If you wish to terminate a MORE/TYPE output before the entire contents 
of a file are displayed, enter CTRL-C at the pause prompt.


Move
----
This command is disabled in the read-only version of ERD Commander.

Moves one or more files from one directory to another directory.

MOVE Source [Target]

  Source        Specifies the path and name of the file(s) to move.
  Target        Specifies the path and name to move file(s) to.


Rename/Ren
----------
This command is disabled in the read-only version of ERD Commander.

Renames a file/directory or files/directories.

RENAME [drive:][path][directory1 | filename1] [path][directory2 | filename2]
REN [drive:][path][directory1 | filename1] [path][directory2 | filename2]

Note that you cannot specify a new drive for your destination.


Rmdir/Rd
--------
Removes (deletes) a directory.

RMDIR [/S] [/Q] [drive:]path
RD [/S] [/Q] [drive:]path

  /S      Removes all directories and files in the specified in addition 
	  to the directory itself.  Used to remove a directory tree.
  /Q      Quiet mode, do not ask if ok to remove a directory tree with /S


Xcopy
-----
This command is disabled in the read-only version of ERD Commander.

Copies files and directory trees.

XCOPY source [destination] [/A | /M] [/P] [/S] [/W]
			   [/C] [/I] [/Q] [/F] [/H] [/R] [/T] [/U] [/K]

 source         Specifies the file(s) to copy.
 destination    Specifies the location and/or name of new files.
 /A             Copies files with the archive attribute set,
		doesn't change the attribute.
 /M             Copies files with the archive attribute set,
		turns off the archive attribute.
 /P             Prompts you before creating each destination file.
 /S             Copies directories and subdirectories except empty ones.
 /W             Prompts you to press a key before copying.
 /C             Continues copying even if errors occur.
 /I             If destination does not exist and copying more than one 
		file, assumes that destination must be a directory.
 /Q             Does not display file names while copying.
 /F             Displays full source and destination file names while copying.
 /H             Copies hidden and system files also.
 /R             Overwrites read-only files.
 /T             Creates directory structure, but does not copy files.  
		Includes empty directories or subdirectories. 
 /U             Copies only files that already exist in destination.
 /K             Copies attributes. Normal Xcopy will reset read-only 
		attributes.


Version/Ver
-----------
Displays ERD Commander's version number.

VERSION
VER


Submitting a Bug Report
-----------------------
If you encounter a problem while using ERD Commander, first go to 
http://www.ntinternals.com  and see if a newer version has been 
released that might correct the issue. If not, please determine if 
the problem is reproducible and record the steps necessary to reproduce 
it. In addition, record the following information about your system:

* Version of Windows NT
* Version of ERD Commander
* Memory size, disk types, drive file system types

and e-mail this information to: 

	mark@ntinternals.com and
	cogswell@winternals.com 


Ordering
--------
You can order the fully enabled read/write version of ERD Commander 
at the Winternals Web site, http://www.winternals.com. 
