MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 23 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 15:49 
Offline

Joined: March 28th, 2011, 17:45
Posts: 441
Location: italy
I am wondering to understand how it happened.
A customer bring me a 500GB WD with no phisical demages,no bad sectors,no demages in SA.
Analyzing the hard drive with hexeditor, it appears FULL FULL of datas.
BUT no softwares can recover anything, even in RAW!
i have tryed also to regenerate translator from plist, but no results still.
it is a system hard-drive from a computer with NTFS, the partition 2 is the one interesting.


Attachments:
no data.jpg
no data.jpg [ 291.54 KiB | Viewed 9650 times ]
Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 16:12 
Offline

Joined: May 6th, 2008, 22:53
Posts: 2138
Location: England
Several of your comments fit with expected results for an encrypted partition. I suggest further investigation of that possibility. Many approaches are possible - but first, ask the customer perhaps?


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 16:26 
Offline

Joined: November 29th, 2006, 10:08
Posts: 7864
Location: UK
Agree, looks like encryption of some sort.

_________________
PC Image Data Recovery
http://www.pcimage.co.uk

New!! HDD-PCB.COM for all your PCB and donor HDD requirements!


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 16:29 
Offline

Joined: November 29th, 2006, 10:08
Posts: 7864
Location: UK
Agree, looks like encryption of some sort.

_________________
PC Image Data Recovery
http://www.pcimage.co.uk

New!! HDD-PCB.COM for all your PCB and donor HDD requirements!


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 16:29 
Offline
User avatar

Joined: December 12th, 2005, 3:32
Posts: 709
Location: Belgrade
was it in external box?

_________________
HddSurgery - Professional Data Recovery Tools


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 18:08 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 16955
Location: Australia
Could we see the partition table? Perhaps the partition ID bytes might give us a clue.

Partition types: List of partition identifiers for PCs:
http://www.win.tue.nl/~aeb/partitions/p ... pes-1.html

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 21:02 
Offline
User avatar

Joined: June 8th, 2006, 19:44
Posts: 3144
Location: Atlanta, GA
It's obviously from A WD My Book. You will need the USB adapter from the enclosure to decrypt the drive.

_________________
http://www.datasaversllc.com


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 11th, 2012, 21:44 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 16955
Location: Australia
jono-ats wrote:
It's obviously from A WD My Book.

That's not what the OP appears to be saying.

positivebit wrote:
it is a system hard-drive from a computer with NTFS ...

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 0:10 
Offline
User avatar

Joined: June 8th, 2006, 19:44
Posts: 3144
Location: Atlanta, GA
fzabkar wrote:
jono-ats wrote:
It's obviously from A WD My Book.

That's not what the OP appears to be saying.

positivebit wrote:
it is a system hard-drive from a computer with NTFS ...


On closer inspection, you are right!

The encryption looks very similar.

My bad.

_________________
http://www.datasaversllc.com


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 2:41 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 16955
Location: Australia
jono-ats wrote:
The encryption looks very similar.

I can't see how you can conclude that.

My Books use 128-bit (or 256-bit?) AES encryption, but I can't see any repeating pattern of 16 bytes in the OP's data. In the absence of such patterns, I don't understand how you could infer anything about the nature of the data or the type of encryption.

Moreover, since at least three of the entries in the partition table appear meaningful, then LBA 0 would appear not to be encrypted. Since My Books encrypt every single byte in every sector of the visible user area, then this would suggest that the drive did not come from a My Book, even in the absence of confirmation from the OP.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 3:12 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3547
Location: Greece
This is definitely encrypted. Maybe Bitlocker or something similar (Safeboot crap?).

Or... client is lying? :mrgreen:

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 3:38 
Offline

Joined: March 28th, 2011, 17:45
Posts: 441
Location: italy
thanx guy for your suggestions.

I called my customer, a women :) she doesn't know what is encryption so i am in a difficoult position.

What she told me is this: she gave a kick at his PC (hp) and the pc didn't start again, so she called a informatic shop, they arrived, opened the pc and found that 1 module of ram was phisically demaged and removed it .
PC started, but windows (7) didn't boot.

To me looks like that this hp pc, maybe in his bios, has some encryption -??-

i am waiting the PC to check, just few days and i will know and let you know.


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:01 
Offline

Joined: March 28th, 2011, 17:45
Posts: 441
Location: italy
fzabkar wrote:
Could we see the partition table? Perhaps the partition ID bytes might give us a clue.


Attachments:
sector0.jpg
sector0.jpg [ 266.09 KiB | Viewed 9563 times ]
Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:03 
Offline

Joined: January 8th, 2008, 5:21
Posts: 927
Location: uk
If I remember correctly some HP pc's and laptops come with an HP security package. Partition encryption is one of the options and can be too easily activated by a user with administrative rights. Can't remember which one it is. Maybe like Mcafee Endpoint?


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:05 
Offline

Joined: January 8th, 2008, 5:21
Posts: 927
Location: uk
Yep thats the one!


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:28 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3547
Location: Greece
Safeboot.

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:34 
Offline

Joined: March 13th, 2005, 12:33
Posts: 872
Location: Dublin
Yep, it's clearly safeboot. A lot of HP machines come with it installed.

_________________
Data Recovery Ireland


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:41 
Offline

Joined: March 28th, 2011, 17:45
Posts: 441
Location: italy
there are solutions on how to decrypt it, but only if windows is running you can prepare a bootable device.

my issue is that windows is not longer booting.


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:52 
Offline
User avatar

Joined: January 28th, 2009, 10:54
Posts: 3547
Location: Greece
If I were you, i would image the drive and then i would try to repair windows. I think it is the easiest way. You said the machine won't start. BSOD?

_________________
http://www.northwind.gr
SandForce SSD Recovery
Ransomware Reverse Engineering - NoMoreRansom! partners


Top
 Profile  
 
 Post subject: Re: Hdd full of data, but no data recoverable
PostPosted: April 12th, 2012, 4:54 
Offline

Joined: March 28th, 2011, 17:45
Posts: 441
Location: italy
@ northwind

i will try it when i will get the hp PC from customer.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 23 posts ]  Go to page 1, 2  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 42 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group