Jump to content

Decrypting Windows Efs


MikeFromDenmark

Recommended Posts

Hi

Im trying to recover my girlfriends, tanked, Windows XP media center partition containing encrypted files.

My girlfriend tells me she had 5 passwords during the time of use on that particular harddrive so i dont think i'll be needing a bruteforce approach.

So here's how far i've gotten:

Used knoppix with dd to get a snapshot of the tanked laptop disk.

converted that to vmware and i am now able to mount the disk in any (virtual) enviroment.

blanked out.

Can anyone point me in the right direction recovering her data?

If i succeed i probably wont have to deal with dirty dishes and diapers for quite some time.

Any help would be highly appreciated.

Link to comment
Share on other sites

Link to comment
Share on other sites

You can mount it in another machine running XP, then take ownership of the files while logged in as admin, and then remove the EFS from the files. Can also copy to a fat drive and efs will be removed, since only NTFS will do the efs. Admins have access to windows efs as where normal users wont. Must be at least professional edition of XP to take ownership, as home edition doesn't let you do it(out of box anyway). You would have to escalate yourself to system if you only have home edition, which can be done from within windows home edtion using the at command in a cmd window to relaunch explorer.exe as system after killing it.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...