All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 25 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 13:21 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
Greetings! Looking for some advice on next steps for getting data off of a dead drive.

In 2006 I had a Windows xp machine with it's own ide Bootable drive. I had a 2nd IDE drive (a Seagate barracuda) attached via an inexpensive usb enclosure. The drive/enclosure was used as a network drive on my windows machine. The drive died unexpectedly one day. No clicking, no warning, just dead. I was not at a point financially where I could afford a data restoration so I just put the drive to the side.

Fast forward to last year, I decided to get the restore done and I send it in to a company. After taking a LONG time to evaluate the drive, they asked for me to send in the old enclosure (which I still had) so I was hoping that was the key but apparently it wasn't. They claimed that the drive had an electronic issue and that the drive was fully encrypted and therefore could not get to the data. They sent me back the dead drive and an ISO image of the drive that cost me $500. They sent me a gif of the mbr and I saw an "invalid partition" error. (The snapshot is attached)

My confusion lies here: While it had been years since I used that pc and drive combination, I don't ever recall encrypting the entire drive. On the off chance that I did, I would hardly know even what program was used to perform such encryption. Moreover, I have no idea how to even possibly decrypt an iso file. My first instinct is to send the drive to another restoration shop but before I do I wanted to get more informed.
1) is it even possible for me to possibly decrypt this iso file myself and if so what tool could I use?
2) is there any value in sending the drive to another shop?
3) is it possible the drive was already encrypted at purchase time? (probably not but I'm really grasping at straws) encrypting an entire drive is nearly a day long operation today, much less 8 years ago and while I don't have an elephant's memory, I think I'd remember spending a whole day not being able to use my drive while saying to myself "just think, if I forget this password I'll never be able to use this drive again! "

Any kind words of advice would be helpful, even if they are "sorry mate but you're fucked". I'm just a bit floored that what I thought was going to be an easy restoration turned into a mess. Thanks for your time!


Attachments:
D55DD9 MBR.JPG
D55DD9 MBR.JPG [ 199.79 KiB | Viewed 8804 times ]
Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 14:13 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
First of all the screenshot you attached shows perfectly normal MBR, there is nothing wrong with it. It shows that your drive has 4 partitions (all 4 are most likely NTFS partitions)
Second, based on that screenshot it is impossible to say if your drive has any encryption at all

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 14:53 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
Doomer wrote:
First of all the screenshot you attached shows perfectly normal MBR, there is nothing wrong with it. It shows that your drive has 4 partitions (all 4 are most likely NTFS partitions)
Second, based on that screenshot it is impossible to say if your drive has any encryption at all

Thanks Doomer - with that in mind, are you aware of a tool that can examine/mount these partitions from an ISO file?


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 15:37 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
R-Studio can

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 15:45 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 15528
Location: Australia
Both 7-Zip and IsoBuster can extract files from ISOs.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:03 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
fzabkar wrote:
Both 7-Zip and IsoBuster can extract files from ISOs.

You probably referring to CDFS ISO 9660 file (regular Windows compatible ISO)
I don't think that's a regular ISO file, it seems to be a drive image

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:08 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
Doomer wrote:
fzabkar wrote:
Both 7-Zip and IsoBuster can extract files from ISOs.

You probably referring to CDFS ISO 9660 file (regular Windows compatible ISO)
I don't think that's a regular ISO file, it seems to be a drive image


Yes you are right this is a drive image


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:10 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 15528
Location: Australia
7-Zip and WinImage can extract files from disc images.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:40 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3844
Location: Adelaide, Australia
why not re-image a similar drive and work with it directly?


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:42 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
HaQue wrote:
why not re-image a similar drive and work with it directly?

HaQue - not sure what you mean by re-image a similar drive - please enlighten me


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 18:44 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
fzabkar wrote:
7-Zip and WinImage can extract files from disc images.

I cannot find that 7-zip supports NTFS file system
Do you know that 7-zip supports it?

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 19:59 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 15528
Location: Australia
http://www.7-zip.org/history.txt

Quote:
9.04 beta 2009-05-30
-------------------------
- 7-Zip now can unpack NTFS, FAT, VHD and MBR archives.

Here are several test images:
http://dftt.sourceforge.net/

I have verified that 7-Zip ver 9.20 extracts the files from the following NTFS image (I'm booting from a FAT32 volume):
http://dftt.sourceforge.net/test3/index.html

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 20:08 
Offline
User avatar

Joined: December 4th, 2012, 1:35
Posts: 3844
Location: Adelaide, Australia
You said you have a drive image, can you get a drive of same size and write the image to it. Though you might not gain anything except not having to fing image-freindly software


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 6th, 2014, 23:33 
Offline
User avatar

Joined: August 26th, 2012, 19:18
Posts: 293
Location: England
hi Stozin
just to throw another program in the pot:
http://findandmount.com/ util : small, free and thorough.

K

_________________
Когда хочется кушать – съешь всё.
Голод не тётка!


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 7th, 2014, 6:46 
Offline

Joined: November 15th, 2012, 17:47
Posts: 226
As one can see, the boot sector is not encrypted. This means that there is no hardware encryption, and the drive is not fully encrypted. If there is any encryption, it must be an operating system induced one or software encryption. You might have to remember if you have activated NTFS encryption using Windows explorer.


stozin wrote:
Greetings! Looking for some advice on next steps for getting data off of a dead drive.

In 2006 I had a Windows xp machine with it's own ide Bootable drive. I had a 2nd IDE drive (a Seagate barracuda) attached via an inexpensive usb enclosure. The drive/enclosure was used as a network drive on my windows machine. The drive died unexpectedly one day. No clicking, no warning, just dead. I was not at a point financially where I could afford a data restoration so I just put the drive to the side.

Fast forward to last year, I decided to get the restore done and I send it in to a company. After taking a LONG time to evaluate the drive, they asked for me to send in the old enclosure (which I still had) so I was hoping that was the key but apparently it wasn't. They claimed that the drive had an electronic issue and that the drive was fully encrypted and therefore could not get to the data. They sent me back the dead drive and an ISO image of the drive that cost me $500. They sent me a gif of the mbr and I saw an "invalid partition" error. (The snapshot is attached)

My confusion lies here: While it had been years since I used that pc and drive combination, I don't ever recall encrypting the entire drive. On the off chance that I did, I would hardly know even what program was used to perform such encryption. Moreover, I have no idea how to even possibly decrypt an iso file. My first instinct is to send the drive to another restoration shop but before I do I wanted to get more informed.
1) is it even possible for me to possibly decrypt this iso file myself and if so what tool could I use?
2) is there any value in sending the drive to another shop?
3) is it possible the drive was already encrypted at purchase time? (probably not but I'm really grasping at straws) encrypting an entire drive is nearly a day long operation today, much less 8 years ago and while I don't have an elephant's memory, I think I'd remember spending a whole day not being able to use my drive while saying to myself "just think, if I forget this password I'll never be able to use this drive again! "

Any kind words of advice would be helpful, even if they are "sorry mate but you're fucked". I'm just a bit floored that what I thought was going to be an easy restoration turned into a mess. Thanks for your time!


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 7th, 2014, 11:20 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
All,
First and foremost, I wanted to say thank you to all of you that responded. Just getting the links for software and insight on the MBR and partitions has been eye opening and whether this ends in success or not, I truly appreciate your efforts.

Here's an update - I spent a brief hour installing R-Studio demo and running simple scans . It recognized three NTFS partitions and one teeny tiny one. R-Studio was unable to recover a few small files that were under 64kb (the limit of the demo) but that may have been because it was a simple scan? Not sure. Tonight I will spend a few hours scanning and getting results. I hope that it can at least grab some image files I haven't seen in ages.

Question - if the partitions were encrypted using EFS or NTFS windows based encryption, would I be able to see files & directories inside those partitions?


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 7th, 2014, 11:52 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
stozin wrote:
All,
Question - if the partitions were encrypted using EFS or NTFS windows based encryption, would I be able to see files & directories inside those partitions?

Yes, EFS encryption is file based, so you should be able to see at least file names, dates and sizes

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 8th, 2014, 15:10 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
Update:
I spent time using both R-Studio and Ultimate Restorer (looks like they are the same engine/software) and while the programs were able to scan the partitions, the data that it found was very minimal at best. Most folders & files come up as "?" and those that don't, when I attempt to restore them, generate logs such as "closing attribute parse allocated size differ from stored one." I haven't been able to restore not even the smallest of files. Is this a demonstration of encrypted data, or is it just fucked?


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 8th, 2014, 22:19 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 15528
Location: Australia
I would examine your image with a disc editor (eg DMDE freeware) in readonly mode. Start by uploading sector 0. Then we can see for certain what kind of file you have. You could also use HxD, depending on your version of Windows.

DMDE (DM Disk Editor and Data Recovery Software):
http://dmde.com/

HxD - Freeware Hex Editor and Disk Editor:
http://mh-nexus.de/en/hxd/

BTW, here is a standard Windows XP MBR:
http://thestarman.pcministry.com/asm/mb ... br.htm#CHS

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Looking for suggestions on recovering an encrypted drive
PostPosted: March 12th, 2014, 17:39 
Offline

Joined: March 5th, 2014, 16:42
Posts: 8
Location: New York
Spildit wrote:
Most likely you are dealing with file base encryption, and that explains why you can see the partition and the file names but they apear as if they don't have any valid content.
Also if you took the drive to a reputable data recovery lab (not an ordinary computer shop) and if they stated the files were encrypted, let's assume for now that their statment is correct.
Maybe you can extract some files from the image and post them here, so we can try to check the file content to confirm encryption ?
Regards.


Thanks for that offer - I should be able to post some files later tonight and we'll see


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 25 posts ]  Go to page 1, 2  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: ArmanoiD and 125 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group