While attempting to decrypt a laptop, a colleague of mine restarted the laptop and we are now unable to boot into the pre-boot screen or into Windows. All I see after the BIOS page is a blank screen with a blinking cursor. I tried analysing the disk using GetBackData and it seems as if Drive C was partially decrypted.
I have created a sector by sector copy of the hard disk and I wish to perform a manual decryption starting with the sector in which GetBackData found the last valid file (I turned on the log deature and after x sectors, there weren't any other readable files).
Would appreciate if anyone could help me on this. Thanks in advance!
Can you find out EXACTLY what option your colleague used in the first place?
EEPC5 works in blocks of around 2k sectors, it's unusual for a block to be split though as reads and writes are so fast. The thing to check is to read some sectors before your marker into the workspace and see if they are encrypted, and of course, some after to make sure they are not. Then you (luckily) know the end point.
Also, the disk information on the box will have the correct range information as long as force decrypt was not used (and if it was, why?)