All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: Weird files
PostPosted: January 12th, 2012, 8:19 
Offline
User avatar

Joined: July 12th, 2010, 4:38
Posts: 1364
Location: Portugal
Hi guys

I received a flash drive with some crazy files on it.

The client doesn't know what happened to it.
All the files are renamed "D" with no extension.

With Winhex, I can see the sectors filled, so the info should be in there.

Any idea how the get these files out?

Thanks


Attachments:
winhex view.JPG
winhex view.JPG [ 311.34 KiB | Viewed 9075 times ]
Properties view.JPG
Properties view.JPG [ 36.91 KiB | Viewed 9075 times ]
explorer view.JPG
explorer view.JPG [ 157.52 KiB | Viewed 9075 times ]

_________________
http://www.pclab.com.pt facebook.com/PCLAB.A.T
ACELab partner
Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 8:36 
Offline

Joined: May 1st, 2011, 5:02
Posts: 101
Location: Jakarta, Indonesia
date of file is xx-xx-1980 each, correct ?


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 8:43 
Offline

Joined: May 6th, 2008, 22:53
Posts: 2138
Location: England
@pclab,

pclab wrote:
The client doesn't know what happened to it.
All the files are renamed "D" with no extension.

The filesystem would not allow that - so this is not simple "user error". I expect that the FAT has been overwritten with something else which is then being interpreted as a FAT (hence silly file dates, as freakzy also mentioned), and I would start looking at that area for clues. Any difference between FAT1 & FAT2?

pclab wrote:
With Winhex, I can see the sectors filled, so the info should be in there.

But is the data which you are finding actually correct for the type of files which the user had stored on this drive - or is it random garbage?


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 9:19 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3408
Location: Greece
This looks encrypted.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 9:34 
Offline

Joined: May 1st, 2011, 5:02
Posts: 101
Location: Jakarta, Indonesia
northwind wrote:
This looks encrypted.


It's probably encrypted or just scrambled chars caused by mismatch in something :), what brand is this flash memory ? Sandisk ? (I'm just guessing)


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 9:49 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2776
Location: Kuwait
did u try raw recovery test and see if you are able to get something?

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 10:26 
Offline

Joined: November 9th, 2006, 15:15
Posts: 2991
Vulcan wrote:
I expect that the FAT has been overwritten with something else which is then being interpreted as a FAT


I agree, or at least that the problem is with the file system.

FAT has always been prone to corruption, and often can be difficult to recover from in many commercial softwares.


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 10:38 
Offline
User avatar

Joined: July 12th, 2010, 4:38
Posts: 1364
Location: Portugal
Thank you all for the answers.

freakzy wrote:
date of file is xx-xx-1980 each, correct ?


This is correct.

Vulcan wrote:
@pclab,

pclab wrote:
With Winhex, I can see the sectors filled, so the info should be in there.

But is the data which you are finding actually correct for the type of files which the user had stored on this drive - or is it random garbage?


There's a part that says: missing or corrupted.. I'll post a new picture of it.

freakzy wrote:
northwind wrote:
This looks encrypted.


It's probably encrypted or just scrambled chars caused by mismatch in something :), what brand is this flash memory ? Sandisk ? (I'm just guessing)


The brand is a Emtec. Not gonna disassemble the plastic cover for now, to see the memory chip.

einstein9 wrote:
did u try raw recovery test and see if you are able to get something?


Gonna try this now.

_________________
http://www.pclab.com.pt facebook.com/PCLAB.A.T
ACELab partner


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 11:47 
Offline
User avatar

Joined: July 12th, 2010, 4:38
Posts: 1364
Location: Portugal
The other winhex view.


Attachments:
winhex view-2.JPG
winhex view-2.JPG [ 297.86 KiB | Viewed 9021 times ]

_________________
http://www.pclab.com.pt facebook.com/PCLAB.A.T
ACELab partner
Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 12:16 
Offline
User avatar

Joined: July 12th, 2010, 4:38
Posts: 1364
Location: Portugal
Already getting the files out with GDB.

Thanks All.

_________________
http://www.pclab.com.pt facebook.com/PCLAB.A.T
ACELab partner


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 12th, 2012, 16:36 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 14945
Location: Australia
Your last screenshot shows the first sector of a 32-bit FAT immediately following a FAT32 boot sector. I believe that the FAT follows the boot sector in a FAT16 file system. AIUI, the second sector in a FAT32 volume should be an FS INFO sector.

An Examination of the MSWIN4.1 OS Boot Record:
http://thestarman.pcministry.com/asm/mbr/MSWIN41.htm

Offset 0x0e in the boot sector contains the first sector of the FAT, ie logical sector 0x181. It may be an idea to examine this sector to see if it does indeed contain a FAT structure.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Weird files
PostPosted: January 13th, 2012, 5:50 
Offline
User avatar

Joined: July 12th, 2010, 4:38
Posts: 1364
Location: Portugal
Thanks Franc

For now, problem solved.

_________________
http://www.pclab.com.pt facebook.com/PCLAB.A.T
ACELab partner


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: gold6565, Rudra and 12 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group