This is a read-only archive. No new posts or registrations. Privacy Page
Software

Accessing Encrypted Files on a Slave Hard Drive/Missing Exported Keys

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I have a set of about 20 media files that are on an old HD that is currently slave to a master HD (WinXP SP3) on my computer. The files were encrypted by an old WinXP installation in the slave HD; though this HD is good for data storage, I cannot boot into it as the WinXP installation in it was damaged by a virus in the past (when I try to boot using that HD, it says "Kernel.dll" is missing in the blue screen of death). Though I can still see the files in question, I cannot access them as they were encrypted using an account in the old WinXP installation. I did not back up the encryption keys, as I now know I should have done. I did not format/tamper with the slave HD's system files, and the old WinXP installation is still there. I can see the folders where the encryption keys/certificates are kept in the I:\Documents & Settings\\Application Data\Microsoft\Crypto, Protect and SystemCertificates folders. However, I don't know what to do with them, especially since I did not properly export the encryption keys/certificates using the necessary tools. Can anyone help me, and tell me how I can regain access to my encrypted files given my situation? Thanks!!
Hello and welcome to WhatTheTech..

This is a very cool question I must say. I really had to do some digging to find information on this. Because I knew what you were suggesting was possible I did keep on digging until I found something.

http://www.beginningtoseethelight.org/efsrecovery/index.php

This article will tell you exactly how, in detail, to recover the files.

It looks very complicated but is "technically" fairly straight forward.

First, you recover the encryption keys from the three specified folders.

Then, you create a user account on the new system with the same name as the old system and you set the same password.

Then, you modify the registry to give that user account the exact same SID as the user account on the old system.

Then, you copy those encryption keys to the new user's profile in the same location.

Now, you open your encrypted files like they were never lost in the first place. :)
Now hold our left hand out to the side, whirl around 3 times while whistling "Proud Mary" then spit …. :pullhair: Great find Appel dude! I added it to my tips database.

Hello and welcome to WhatTheTech..

This is a very cool question I must say. I really had to do some digging to find information on this. Because I knew what you were suggesting was possible I did keep on digging until I found something.

http://www.beginningtoseethelight.org/efsrecovery/index.php

This article will tell you exactly how, in detail, to recover the files.

It looks very complicated but is "technically" fairly straight forward.

First, you recover the encryption keys from the three specified folders.

Then, you create a user account on the new system with the same name as the old system and you set the same password.

Then, you modify the registry to give that user account the exact same SID as the user account on the old system.

Then, you copy those encryption keys to the new user's profile in the same location.

Now, you open your encrypted files like they were never lost in the first place. :)


AppleOddity, thank you for this extreme research! Sorry for not replying sooner, I wanted to look into it first to give you some results. It totally makes sense!

However, I am stuck in one part of the instructions (I am not really an advanced user, but have enough guts to try it out anyway). I am getting stuck here:

"check if a user account is already present of the orginal account number. if there is, check the username (\v) logon and create a profile and change the password to the one from the orginal machine. if there is not a user account of the same number, create one that is, you may want to modify hklm\sam\sam\domains\account\f offset 48 to the required number before you create. add the user to the admin group."

For one thing, what does it mean, "you may want to modify hklm\sam\sam\domains\account\f offset 48 to the required number before you create."? I looked in RegEdit and I cannot find anything under "hklm\sam\sam" - what happens is, I get as far as "sam" but after that there is nothing, no "domains" or "account." In any case even if there was I don't understand his terminology, "offset 48 to the required number before you create." Would you happen to know what he means?

The language after that paragraph is also equally as difficult for me to understand, but first things first…!

Thanks for all your help, Apple. :D
Hi everyone! I was wondering if anyone had any tips on my last question. I really appreciate this community's help! Thanks, guys.
Navigate to HKLM\Sam\Sam and right-click the SAM folder. Click permissions. Click the Advanced button. Under permissions, click the Administrators group and click Edit. Grant the administrators group full control, click OK. Check the option to replace "permission entries on all child objects…" and click OK, and click OK again to get back to the main registry editor window. Press F5 to refresh the screen and all the questionable registry keys will now be available.
You'll want to probably read and follow the directions in the BLUE section near the end of the article. It recommends a program called NewSID. I believe teh next generation of that program can be found here: http://technet.microsoft.com/en-us/sysinte…s/bb897418.aspx

To make a long story short, you are making your new Windows installation appear to be identical to the old installation by "cloning" the machine and user SIDs that are uniquely generated when each machine is installed and each user account is created. Once the machine and user appear identical to the one from the old installation, you can copy over the encryption keys to the user profile folder and the encrypted files will become accessible.

I probably shouldn't need to tell you that messing with all this stuff could make your current installation defective if you mess something up. At the very least, be prepared to have to completely reinstall again if necessary. And, no matter what you do, do not modify data or files on the original installation with the encrypted files. Once the data is recovered, then you can determine if a reinstall is necessary.
Hi AppleOddity, Thanks again for the advice. I will follow these instrux and see what I can do, and post the results once they're done. I appreciate all your diligent help as always!
Hello to everyone, I have the similar problem, with the difference that my EFS files are totally gone :( Does anyone has tried to take the last option from the article linked above. ("the other way is matching the fek") Does that mean a brute force to the symetric key that is used for encrypting the file? Thanks in advance.
Hi gnomcho, and welcome to the WTT forums. Whilst we try to be as helpful as possible to folks who are in trouble with lost files and forgotten encryption keys, we always try to strike a balance between helpfullness and security, by remembering that files are encrypted for a purpose, and generally that purpose is to keep the files away from anyone who does not possess the encryption keys….. I am sure that as a fair minded person you will understand that we must not attempt to circumvent encryptions or assist others to do so, unless we can be 100% sure that they have a legitimate entitlement to open the files. If you are able to recover your files then I'm sure that you would not wish anyone not entitled to them, to be assisted in so doing. On a forum at long range there is no practical way for us to ascertain who has a legitimate right to open the files, and who might be trying to circumvent legitimate privacy arrangements…… ((I am sure you would not enquire unless you had the right to open your lost files) but the advice that has been provided in the topic is about as far as we feel able to go. I hope you are successful in recovering your lost files and finding your encryption keys. Regards paws
Hello gnomcho. Paws did sum up things nicely. And, as far as this thread goes that is as much as we can help. But, to determine if I can help you within the constraints of security, I need more information. When you say your EFS files are completely missing - are you saying that your encrypted files are gone? Some how deleted? Or, are you saying that you have the encrypted files but you do not have the EFS keys that are discussed in this thread? Because this article deals with the legitimate recovery of EFS files when a system is no longer bootable, you will have to have the original user account password, and all required EFS keys, as well as the complete EFS encrypted files. Without the original password and EFS keys the data is not recoverable and there is nothing further we can assist you with. However, if the EFS encrypted files have been accidentally deleted than you may attempt to use a file recovery program that you can download from the internet to recover deleted files from a hard drive and then, if you have all the necessary information you should be able to recover your EFS data.
Hello guys, sure I fully understand your policy and I believe it is the right one. Here is my case in more details: I had an install of WinXP and encrypted folder within it. I decided to move ot windows7 and copied the encrypted folder without considering it is copied with the encryption (at this time I had no idea about the EFS). I installed the new windows with a low level format on top of the WinXP (60GB partition). So when I try to use the files I got stucked in the problem. I found the above linked article and tried to recover the EFS files with a program for deleted files recovery. Then I tried with directly serching the peaces on the disc as described but I got lost on the first piece (the private key file). I found the PK guid at two places in the file, one was immediately followed by some stupid network info (domain names, .. etc.) and according to WinHEX it was in the hiberfil.sys file. The other occur of the guid was in the free space and it was just within some text that was nothing like a PK. Then I searched for CryptoAPI… and found one place with missign guid and a little above was a overrided section above which was the part of the path of the original XP user. When I extracted the locking file name I did not found anything like the described things (may some other PK). After all of that I wrote in this forum for help :) According to how I can proove I am the owner of these files: There are about 10-15 encrypted documents - some scanned documents in JPG (all after my name), one p12 packup for sites only I have password for the account, my CV in a word document and few XLS documents with my personal info I collect for the last 3 years. As a bottom line I have some of the original XLS files. All of these documents is not that much important to me as I can recover the info in other but decrypting ways. What really matters is the biggest XLS document that I spend 3 years filling with data (this I cannot recover in any other ways). If anyone can help in any way - that would be very good, otherwise sure I understand you guys (I will just move forward and forget about that XLS document).
Hi gnomcho. Unfortunately, if the encryption keys are not available in their entirety there is nothing we can do for you. It sounds like you are quite knowledgeable and you have tried to recover the keys using deleted file recovery software, but as you have discovered, your new installation of windows has most likely overwritten that data. Its unfortunate, but you are probably at a dead end on this. I know of no other way to recover an EFS file, and certainly if I did, those methods would not be supported here on the forum. So, I do apologize, but there isn't anything else I can do for you. For future reference, although I don't know much about EFS, there are ways to create an EFS recovery agent or store the encryption information on something like a floppy, etc. This way, if the hard drive fails, or the files are otherwise not accessible, your recovery agent will be able to get the files back for you.
HI applyoddity, Thanks for the time spent on my issue. The stupid fact is that this file has no value to anyone but and I shouldn't encrypt it at first place, but for the future if I decide to encrypt anything with windows I will surely know how to handle the EFS :). At least Windows7 suggests certificate backup as you use it for first time. Anyway this topic is very helpful, the only bad thing is I got here after I had already lost the important data :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI