I am trying to recover from a "unable to mount SBFS" error. This occurred after capturing an image from an encrypted PC. Here's the flow:
1. I had booted into WinPE and tried to authorize using the Code of the Day, which kept telling me was incorrect.
2. chose to Log in using the SBFS, which accepted my login
3. Ran Gimagex and captured an image of the C drive.
4. Tried to reboot, but got the Unable to mount SBFS error
5. Booted into WinPE again and got into SBWintech and noticed that the date for SBWintech was 1 day ahead, which may explain why the COD would not work
6. checked the PC bios and the Win PE environment and verified that the dates were set correctly.
How do I change the date/time that SBWintech sees? Why would I get an unable to mount SBFS error from capturing an image?
the error is because you didnt put things back where they came from - the sector locations are important. Either that, or your image is of the partition, not the drive - you need the WHOLE drive, from sector 0 on - most partition tools skip the partition gap, but that's important as well.
As to the date, it uses the bios clock, nothing else.
You can set time in BIOS of that computer. In Windows, time also depends on time zone.
If File System is corrupted pointers to SBFS are lost, you will get that message. You did not elaborate how you captured disk image.
thanks for the replies...
first of all, I did check the date in BIOS and WinPE and they were correct, showing 5/14/10; the SBWintech console was showing 5/15/10.
As for my imaging process, admittedly I am a novice at using WinPe and GImagex (gui plug in for Imagex commands in winPe) and am more comfortable at using ghost. However, I was able to successfully use the same process with Gimagex on another machine, but did not have the COD problem in that case.
For this case, I was not applying the image, merely capturing it and then rebooting the system. Would capturing a .wim of the C drive make changes to the Safeboot file system?
Also, I am curious: since I was not able to use the COD and only authenticated using the SBFS, would that allow me to capture an uncrypted .wim or ghost of an encrypted hard drive?
As the the affected machine, I decided to scrap it and use an old ghost image to overwrite the entire hard drive...
Sorry it's been a while. Thanks for the confirmation about needing bother authorization and authentication.
I never figured out why the sbwintech date was ahead. What I noticed that it would be correct until after 5 PM. I did a workaround by changing the BIOS date when this situation occurs.