Have key(s) for EFS files, still denied

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I’ve tried replying to other posts with my related question, but get no
response so I’ll start a new post.

I’m having trouble with my EFS files that I’ve had since October 2003. I’m
using XP After reading some other posts, I think I know what’s wrong but
before I spend any more time on this I want to make sure. Here are the
details.

In the fall of 2004 we bought a new Dell laptop and I moved/copied EFS data
from our Gateway to the Dell by network connection and USB drive. I don’t
remember if I moved any keys from the Gateway to the Dell, but I must have or
maybe just created a new key automatically when I turned on the Dell
encryption.

In October 2005 I reformatted our Gateway C partition and re-installed XP.
At the same time I exported the private key(s) from the Dell and imported
them on the Gateway. Then I created a D partition on our Dell and
“moved/copied†the data there from the C partition. I must have turned on
the encryption for the D partition folders then, but I’m not sure. Then I
reformatted and re-installed XP on the Dell C partition. I don’t remember
creating any new keys, but I think I re-imported the key(s) from the Gateway
back to the Dell (but can’t remember). All of the files that I wanted to use
opened fine after the XP install.

1-1/2 weeks ago our Dell HD stopped (I’m sending it to a data recovery
company.) I just installed XP on a new HD in the Dell. I restored my data
from backup DVDs. The data was backed up keeping EFS on it. I have three
private keys from the Gateway that I imported to the Dell with the new HD.
When I try to open the files, I get an access denied message.

== Here is the key info I imported to the Dell ==

name@SOLO (thumbprint starts with 48; valid from Friday, October 03, 2003
10:21:45 PM) (within a day of when I first started using EFS)

name@DELL8600 (thumbprint starts with 5d; valid from Tuesday, October 05,
2004 3:41:50 AM) (about the time I started using the new Dell)

name@@GATEWAY-SOLO (thumbprint starts with 13; valid from Monday, August 29,
2005 4:01:22 PM) (the current computer name is “GATEWAY-SOLOâ€, but I don’t
know what this date relates to, maybe a computer name change?)

==============================
The files on my computer (that won’t open) have encryption details as follows:

name@DELL8600 (thumbprint starts with C6). I don’t know how to get the date.

I’m assuming that in October 2005 when I moved/copied the data on the Dell
from the C partition to the D partition that it was still related to the
name@DELL8600 key with a thumbprint starting with “5dâ€.

1) When I installed XP after the data move, is it possible that at that time
XP created a new key “name@DELL8600†with a thumbprint of C6? Otherwise, I
don’t know why all of my restore data has that thumbprint.

2) When I send the HD to get the data recovered, is there anything special I
need to let the company know?

3) Is the private key just another data file somewhere? If they can’t get
the private key, there isn’t much sense in retrieving the data.
 
It sounds like you do not have the correct EFS private key to access your
EFS files from your description. It is hard to say what happened offhand but
yes the OS will generate a new EFS certificate/private key whenever it needs
to encrypt a file via EFS if it does not find one in the user's profile that
could be because one never existed, the user exported/deleted it, or the one
in the user profile became corrupted. Unfortunate this all happens
transparently to the user. EFS is best used in domain environments where a
Recovery Agent has been created that can then be used when there is a
problem with a user's access to EFS files. In your case I suggest that you
download the free version of EFS Recovery from Elcomsoft as it will search
your computer to see if there is a matching EFS private key for EFS files on
the computer. The full version can recover files as the free version will
recover only a small part to demonstrate it's ability to recover your EFS
files assuming you know the password that protects the EFS private key that
was used by the user account logon password that encrypted the files.

Steve

http://www.elcomsoft.com/aefsdr.html
 
Thanks Steven. I downloaded it and once I copy some files back from some
DVD's, I'll use it. Hopefully the data recovery company can get the key.

===================================
 
One more question. I have some backups of the C drive. Would the key be
anywhere I could get it? If so, where?

Thanks.

======================
 
Back
Top