Lost Data because of EFS in WinXP

W

WizZaRd

Guest
Hello,
I need help. Damn. Reinstalled Windows XP Professionnal because of a damn logon screens which wasn't the good ntoskrnl.exe version for my SP1 ... So I lost the user who encrypted the data, along with the keys used.

At this point, I have realised that I could extract theses keys and a Data Recovery Agent certificate, I've loaded both in my current user (so I should be the DRA and have the good keys to decrypt) ... I try to decrypt and it still says ACCESS DENIED.

What's wrong?

For more info, simply ask, or email me.

Thanx! That's for my documents =)
 
You can't, sorry.
The recovery agent master key will never be accepted from your reinstalled WindowsXP, the key is stricly connected to the system installation ID hash (which has changed).

The DRA is valid within a single system installation, you can't export its keys to another system or expect some other DRA to recover your files from another system.

Also... the user encryption key refers to a non-existing user account.

There's nothing you can do about it apart a brute force attack on your encrypted files...
but I never knew of such a hacking (and working) tool.

PS
For the future.
When a critical error prevents your computer from booting and you have encrypted files on that system, decrypt files with recovery console before reinstalling. The command line utility is *cipher* (see windows online help for switches).
...and always backup on CD/DVD/tape EFS data.:(
 
Damn Rootz, I am impressed. Cheers m8.
cheers.gif
 
Yeah yeah... brute forcing. I've only got a small file, only a text file, that would REALLY be important. If anyone hears about such a tool, please reply!
 

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,494
Members
5,623
Latest member
AndersonLo
Back