Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
CarForumPoster
Jun 26, 2013

⚡POWER⚡
My old motherboard died. The hard drive works fine but there are files which were encrypted (possibly even from an earlier computer) and I no longer have the encryption key. Is there any way to recover it from the old hard drive or can I use my computer password to decrypt the files?

When I try to decrypt it just says access is denied.

Adbot
ADBOT LOVES YOU

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!
Did you export the key when asked when you originally turned on encryption for those files? If not I think you're boned. I'm not at work to check my doco but EFS is pretty strong and I think your decryption key is tied to your user account and that changes if you reinstall.

CarForumPoster
Jun 26, 2013

⚡POWER⚡

Gromit posted:

Did you export the key when asked when you originally turned on encryption for those files? If not I think you're boned. I'm not at work to check my doco but EFS is pretty strong and I think your decryption key is tied to your user account and that changes if you reinstall.

womp womp :(

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!
If I remember I'll check my password crackers to see what they need to hit EFS. I'm almost certain it'll want registry data (ntuser.dat or the like) from the old installation though.

fake edit - I'm looking at the help file for Password Recovery Toolkit and it says you need the SAM and SYSTEM Registry hives which it will attack to try and get the syskey/login password. I think it's safe to say that if all you have is the files themselves and no other data from that old installation then you are not going anywhere. However, if you have all the old data including the user folders with the registry poo poo in it then we could get somewhere. I'm happy to crack stuff for you if you care that much and have all the data we need.

real edit - this is part of my job but I haven't cracked EFS for a long time so sorry I can't be more specific.

CarForumPoster
Jun 26, 2013

⚡POWER⚡

Gromit posted:

If I remember I'll check my password crackers to see what they need to hit EFS. I'm almost certain it'll want registry data (ntuser.dat or the like) from the old installation though.

fake edit - I'm looking at the help file for Password Recovery Toolkit and it says you need the SAM and SYSTEM Registry hives which it will attack to try and get the syskey/login password. I think it's safe to say that if all you have is the files themselves and no other data from that old installation then you are not going anywhere. However, if you have all the old data including the user folders with the registry poo poo in it then we could get somewhere. I'm happy to crack stuff for you if you care that much and have all the data we need.

real edit - this is part of my job but I haven't cracked EFS for a long time so sorry I can't be more specific.

Is there any freeware available to do the cracking? I think the old install should be there so I could recover the files. I have the login password from the account, just not the file you're supposed to save when you encrypt stuff. I appreciate the offer to do it for me but the password and the files both contain a lot of privacy sensitive info.

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!
Sorry, I've no idea. Hopefully someone else might know as all my tools are paid for, and not at all cheap.

scavok
Feb 22, 2005

Gromit posted:

Sorry, I've no idea. Hopefully someone else might know as all my tools are paid for, and not at all cheap.

So I have a very similar problem. However have the entire C drive of the computer with the encrypted files slaved to a PC.

There was no backup certificate made of the EFS before the user was unable to log in.

I tried going to the user certificates at C:\Users\username\AppData\Roaming\Microsoft\SystemCertificates\My on the slaved HD, and importing them to the personal store in certmgr.msc on the desktop, but this is just a system file and not the proper certificate backup and it is still unable to open the encrypted files.

Is there any easy action to resolve this, or I take it this type of file copying is what EFS was designed to prevent?

CarForumPoster
Jun 26, 2013

⚡POWER⚡

scavok posted:

So I have a very similar problem. However have the entire C drive of the computer with the encrypted files slaved to a PC.

There was no backup certificate made of the EFS before the user was unable to log in.

I tried going to the user certificates at C:\Users\username\AppData\Roaming\Microsoft\SystemCertificates\My on the slaved HD, and importing them to the personal store in certmgr.msc on the desktop, but this is just a system file and not the proper certificate backup and it is still unable to open the encrypted files.

Is there any easy action to resolve this, or I take it this type of file copying is what EFS was designed to prevent?

This is my situation but better explained.

Adbot
ADBOT LOVES YOU

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!
I'm happy to receive an EFS-encrypted file from anyone if you just want me to test to see if I can crack it? Hopefully you have something small and innocuous that you don't care I'd have, like a binary data file that is part of a program install or an ini file or anything at all.
I'll probably need the password and/or SAM file as well, but loading the file into my cracker should tell me what's needed and that might help you decide to buy something. You could try the EFS key recovery tool on Passware yourself in demo mode (I've got it licensed at home here, and other stuff at work) and if it worked you could decide if it's worth the $200.
The page says it supports only up to XP, but I imagine it'll be fine for Win 7 too. I don't think EFS changed significantly or at all, but I'm not 100% sure.

If you're interested in sending me something to try I'll post my email address, or you can point me to a cloud store somewhere via PMs or whatever you like.

  • Locked thread