Data recovery and disk repair questions and discussions related to old-fashioned SATA, SAS, SCSI, IDE, MFM hard drives - any type of storage device that has moving parts
December 13th, 2025, 7:24
Now that you've swapped heads and seem to be better than previous head set, try to upload the correct DEK manually as i've suggested before.
https://forum.hddguru.com/viewtopic.php ... 88#p317888
December 15th, 2025, 0:55
Thanks for your response really appreciated, Unfortunately still getting the same error....
- Attachments
-

December 15th, 2025, 5:06
Sorry, i don't know what's wrong then.
Could it be a issue with translators?
Or, could it be a issue with mode 02?
Or someone else (computer shop or customer friend) tried to recover data by playing with WD software but he inserted a random password without telling it to customer ?
I don't know...
December 15th, 2025, 22:15
michael chiklis wrote:Sorry, i don't know what's wrong then.
Could it be a issue with translators?
Or, could it be a issue with mode 02?
Or someone else (computer shop or customer friend) tried to recover data by playing with WD software but he inserted a random password without telling it to customer ?
I don't know...
No worries, thanks for your help.
I checked 02 and it reads ok
I kept testing and noticed that T2 cannot be accessed, I tried both Obtain by command and From SA, when I try to open T2 editor an error come up: "Get Data Failed"
What's tested so far:
Tried Solve Slow Responding.
Managed to extract the key from the last 66K sectors (see attached photo).
extracted key from module 25.
tried to swap heads twice still same issue.
Closed SED lock in EDIT HDD ID.
- Attachments
-

December 16th, 2025, 3:55
T2 cannot be accessed: of course, coz this is a Zephyr, not SMR.
decryption has nothing to do with initing the drive, as it is done it MRT sw if you import the key. So as long as you have LBA access you should be able to decrypt it, except:
- the key is indeed corrupt (I have seen such case, client did not set up pwd and drive started asking pw out of the blue, i think there were discussions about such problem here on this forum like 10 yrs ago at least)
- I haven't met a zephyr with SED turned on OOB but it can be turned on, then the drive uses internal crypt engine with SED key stored in its keystore (D00x, 012x).
however, SED looks differently by looking at the data, so i would exclude this option.
on the first 2 pics in your first post it is clearly visible that the encrypted sector is an MBR, so translation is just fine, and anyway, this encryption is not LBA dependant, being simple ECB.
Pc3k also asks for a pwd when feeding it your JMS key blob, so it is likely the cuprit.
pepe
December 16th, 2025, 5:01
dump the contents of U14 and post here
December 16th, 2025, 12:26
pepe wrote:dump the contents of U14 and post here
Thanks for the detailed explanation, much appreciated.
here is the U14 dump, I had to change the format from bin to txt so I can upload it here, after download it has to be changed back to bin.
- Attachments
-
PM25LD0200.txt
- (256 KiB) Downloaded 68 times
December 16th, 2025, 18:18
the dump i checked has a copy of the key blob. This one doesn't :s
December 16th, 2025, 19:05
JM538S seem to be brute forced.
There was a topic about 10 years ago where a user called "roberto" had a tool to decrypt data.
https://forum.hddguru.com/viewtopic.php?f=1&t=34230
December 16th, 2025, 21:07
pepe wrote:the dump i checked has a copy of the key blob. This one doesn't :s
Thanks for trying to help
December 16th, 2025, 21:10
I've read the post and downloaded the tool now I've PMed them and hoping I can get the password so can give it a try.... Thanks again for your time
Powered by phpBB © phpBB Group.