The system runs Windows 8.1 Embedded Industry Standard
- Auto logged in after boot, will execute
after login - Has only Network Configuration privileges
- Password protected
- Administrator user
- Used in
to executesgboot.exe
- Password can be found under
MMCSS is used to give multimedia more CPU time in scheduling to ensure multimedia performance (makes sense when the windows explorer runs so slowly)
EWF is a write filter that protects the OS drive and other drives from tamper, will redirect all writes to memory.
Just an ordinary filter to filter out breakout keys
Same as the keyboard filter, but for filtering windows 8 gestures
> $encryptedpassword = "PASSWORD FOUND IN XML"
> $dPwD= ([system.text.encoding]::Unicode.GetString([system.convert]::Frombase64string($encryptedpassword)))
> write-host $dPwD.Substring(0,($dPwD.length-8))
Found under C:\Windows\SEGA\tmp
, looks like it include the settings used to provision the machine in factory, it also incldue account information and service configuration.
<?xml version="1.0" encoding="utf-8"?>
<unattend xmlns="urn:schemas-microsoft-com:unattend" xmlns:wcm="" xmlns:ew="urn:schemas-microsoft-com:embedded.unattend.internal.v2">
<settings pass="windowsPE">
<component name="Microsoft-Windows-International-Core-WinPE" processorArchitecture="amd64" publicKeyToken="" language="neutral" versionScope="nonSxS" xmlns:xsi="">
<component name="Microsoft-Windows-International-Core-WinPE" processorArchitecture="x86" publicKeyToken="" language="neutral" versionScope="nonSxS" xmlns:xsi="">
<SystemLocale />
<component name="Microsoft-Windows-Setup" processorArchitecture="amd64" publicKeyToken="" language="neutral" versionScope="nonSxS" xmlns:xsi="">
<Disk wcm:action="add">
<ModifyPartition wcm:action="add">
<ModifyPartition wcm:action="add">
<ModifyPartition wcm:action="add">
<CreatePartition wcm:action="add">
<CreatePartition wcm:action="add">
<CreatePartition wcm:action="add">
<ew:answerFileInfo processorArchitecture="amd64" osVersion="6.2.9200.16384" />