If it was as you have said "Rebooted. Opened A43 first. Could see all 3 system drives/partitions.", why didn't you recover/copy your data at that time?
Which version of encryption product did you have installed?
Do you know how to use Disk Information and Workspace fuctions to determine which sectors are encrypted and which ones are not?
what do you mean by "manual decrypt"? Can you remember exactly what options you picked? It's very very important for your chances of success.
Yeah, what happened to that SafeTech.TRK file? That was better then relying on technician's memory.
Quote "Would freeze after a few seconds."
Version 5.2.3; Using 5.2.3 wintech.
And yes, I know how to use both of these funtions. Sorry about wrong terminology, I meant Force Decrypt, not Manual decrypt.
The problem I am having is determining which sector it stopped at. When I look at it in the Workspace, it still looks like scrambled text, even when I decrypt or encrypt the workspace.
1 of 1 people found this helpful
Then use binary tree search to inspect bigger sector range. Also load more than one sector to workspace at a time, I use 4.
Look at other patterns: multiple 00 or FF's are also indication of data being seen in clear.
Oh, I see what you asked peter. Because I had to authenticate and authorise as the drive was encrypted. I did try to copy the data at that point but it would freeze up. I have had success in the past when this happens by force decrypting.
I will try in the morning when I get in. Thanks!
yeah - force decrypt does not keep a record of where it got to - that's why you shouldnt use it unless absolutely necessary.
Your only hope is via inspection as you say, but if the user has compressed data, movies, videos, zips etc, you won't be able to tell the difference. As peter says, just binary chop through the drive until you have an idea of the beginning and the end, and hope the MFT is included in that. Then you might be able to use some file recovery tools to construct the rest.
Success! I did have to manually inspect using workspace to find out where it had stopped and started. Then force encrypt that which I had decrypted twice. Whew! Was like finding a needle in a haystack but I got it close enough. The MFT was at the front of the drive so once I got that back to a plain text state, I could see everything again with the A43 utility.
Thanks for the suggestions!
Message was edited by: curtandy on 2/10/11 11:24:40 AM GMT-06:00