Could someone help me on this,
I'm not sure about the encryption state of an hdd where the system crashed, I use wintech to remove SB client and encryption.
using safeboot safeboot 5.1.
I supect that the partiton table is corrupt, I use the disk information utility to find the encrypted part of the hdd.
but the result is :
Logical disk Number 1
disk information (error=e002000a)
crypt list - region count 0
powerfail status - status=inactive
error e0020007 getting partition info
I would like to know if the disk can be encrypted and the wintech/safetech tools cannot find the encrypted part of the disk
I have used the .sdb file to authenticate within the wintech tools, always same result.
I would like to try to reconstruct the partition table, but would like to know if the disk is encrypted..
or if I missing something?
disk 1 - are you sure that's the right disk?
if so, the disk information does not show a crypt list, so I am guessing the boot code is broken? You'll have to work out the crypt range by inspection - load up a sector in the workspace, view it, then decrypt it, and see if it looks any less "encrypted".
luckily there is usually blank space at the end of partitions, so it should be either all zeros, or a partition marker sector.
You can't manually reconstruct the partition table, but there are tools you can get online which will try to work it out for you once you've decrypted the disk.
What makes you think the part table is corrupt though?
Try to use partinfo.exe to dump your hard disk partition table from MBR.
If that makes sense, use SafeTech to inspect first and last sector of potentially encrypted partition. You would need to use SDB file to decrypt workspace of loaded first and last sectors. If you see them in clear, then whole partition is encrypted and you have right SDB. If you can see workspace in clear without decryption, then that part of partition is not encrypted. Other combinations can indicate partially encrypted partition, wrong SDB or improper sector info.
You can learn original partition table if you restore MBR to any test (scratch) disk and run partinfo on it.
Only when you know for sure what is encrypted and with what key, you can proceed with (forced) decryption\removal attempt. Still, prior to that, make a sector image of your disk, to be safe.