MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]


Switch to mobile style

Forum rules


Please do not post questions about data recovery cases here (use this forum instead). This forum is for topics on finding new ways to recover data. Accessing firmware, writing programs, reading bits off the platter, recovering data from dust...



Post new topic Reply to topic  [ 9 posts ] 
Author Message
 Post subject: How to deal with drives that are whole drive encrypted
PostPosted: April 23rd, 2011, 9:57 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
Had a call from a client where a virus had compromised an encrypted (software based whole drive) drive. With correct password entered the keyboard would lock out preventing them from entering safe mode to do a system restore. I relize I have no information on dealing with a recovery of this type! Fortunatly the clients data was all saved onto the server- so they reinstalled. If this had been a data recovery job I assume I would first clone the 'failing' drive but then... what would be some methods to use where we know the encryption program used and its password?


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 24th, 2011, 7:15 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2821
Location: Kuwait
what was the encryption software name? the one they used?

freeware/cracked ver. or they bought it?

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 25th, 2011, 13:56 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
Commercial software- sophos safeguard. Intresting problem as the malware they say infected the computer 'disabled the keyboard'. Encryption at boot Password on entered but client could not enetr safe mode. Under this combination I can not think of what else to do as the client had not generated a key disk- so a theoretical data recovery job on the failing drive would be useless. Am I missing something?


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 26th, 2011, 7:14 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2821
Location: Kuwait
which ver. was it? 5.5?

i had a similar case with the TrueCrypt - Free Open-Source Disk Encryption Software and i managed to solve it

interesting subject for me, and working on it.

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 26th, 2011, 9:23 
Offline

Joined: August 12th, 2008, 13:11
Posts: 3235
Location: USA
In general, if the PBE is irreparably broken, you are out of luck unless the manufacturer has created some recovery tool(s)

Even then you can still be out of luck if the customer does not have some sort of backup of the key (like he is supposed to), it all depends on how badly the encryption system's internal data has been damaged

_________________
You don't have to backup all of your files, just the ones you want to keep.


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 28th, 2011, 9:45 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
It is likely an up to date version- so your guess is possible. In this case the encription boot started, you could enter password, but the next step- pressing f8 to simply use system restore was not avaiable. The client says the keyboard became locked out. The reason for system restore was a maleware intrusion. No key- so I figgured thats endgame. Dont know what other methods would be worth trying if there had been data to recover. This is only a software bad case.


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 28th, 2011, 14:04 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2821
Location: Kuwait
look i have a suggestion here for you which you may try

its like Apple MAC Slogan " Think Different"

try to boot normally when the OS is booting n passes the stage of the F8

remove (unplug) the power from the PC to make it look like power failure

after that when u start again the windows will go by it self to safe mode ( I hope )

what do u think?

sounds good? :idea:

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: April 29th, 2011, 9:33 
Offline

Joined: February 13th, 2010, 9:44
Posts: 208
Location: san diego, ca.
thats oughtright funny! Would have been worth a try in that clients case. If data recovery had been needed then a backup image just in case. Dealing with onboard hardware encription has got to be difficult on failing drives! From posts seems pc3000 is of some help on drives working with modules- my Atola is great for imaging, but havent found it very usefull in firmware areas ( what used to be there main target when it came out.) So much to learn!


Top
 Profile  
 
 Post subject: Re: How to deal with drives that are whole drive encrypted
PostPosted: August 30th, 2011, 8:27 
Offline
User avatar

Joined: September 5th, 2010, 12:29
Posts: 1038
Location: South Africa
I had a case a few months back, laptop drive which had bad sectors and Windows wouldn't load, no safe mode, recovery option for Safeguard didn't work. I forget which version of Safeguard it was, but I made a BartPE disc with the Safegaurd recovery plugin and managed to access the drive (had the user password obviously). Had some hurdles with copying data off the drive but I got around it eventually.

_________________
Death is nothing, but to live defeated and inglorious is to die daily.
Data Recovery Cape Town


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group