Re: HELP!: Decrypting Files After Partial System Crash

From: Karl Levinson [x y] mvp (levinson_k@despammed.com)
Date: 04/04/03


From: "Karl Levinson [x y] mvp" <levinson_k@despammed.com>
Date: Thu, 3 Apr 2003 17:07:24 -0500


I could be wrong, but I believe that page mainly mentions restoring the
files in a standalone workgroup environment. Restoring the files on Windows
2000 in a Windows 2000 Domain environment is trivial [as long as your only
domain controller did not crash]... you just use the DRA Domain Recovery
Account on the domain to decrypt the files. Check the page again. The
author of that document does include his email address and has recently been
posting messages here as well. I could be wrong, but I thought the document
mentioned changing the user SID manually in the Registry.

"EricMontague" <ericmontague25@yahoo.com> wrote in message
news:5ef6b53b.0304031031.edb9d30@posting.google.com...
> Pete,
>
> This is an excellent site, if only I had it a week ago, but I still
> can't decrypt my files, but I know why. While I managed to to change
> the machine SID using System Internals wonderful tool, the user ID
> needs to be set to that of the old machine, what I believe is called
> the RID. The web page you refered to talks about making changes to the
> keys on the SAM hive, but I don't have any keys there and I believe it
> is because the page was talking about restoring EFS in a
> Domain-account environment, where as I am in a standalone Workgroup.
>
> So the question is how can I change the the user ID?
>
> PS - I already tried sequentially creating accounts until my number
> came up, but apparently Windows remembers old, deleted numbers and
> simply skips over them when they are called back into the sequence.
>
> "Peter Clark" <clark@hushmail.com> wrote in message
news:<06eb01c2f971$40b6d5e0$a001280a@phx.gbl>...
> > http://www.beginningtoseethelight.org/efsrecovery/
> >
> >
> > >-----Original Message-----
> > >OK hot shots here's a real bear for you guys to wrap
> > yourselves
> > >around.
> > >
> > >This is the deal: recently my WIN2K hard drive suffered a
> > massive
> > >crash. Scan of the disk revealed permanent errors on the
> > drive and
> > >about 20-30 percent of the files were lost for good.
> > However I was
> > >able to salvage the remaining 80-70 percent (including
> > most of the
> > >Doc's & Settings, Prog Files, WINNT, System32\CONFIG, etc.
> > >directories) and back them up accordingly to a stable drive.
> > >
> > >However a number of my data files were encrypted with EFS
> > and while I
> > >was able to restore them to my new partition, they remained
> > >encrypted. My questions are thus:
> > >
> > >(1) Is there any way to use the old files to a create a
> > PKS file?
> > >(2) Where and what are the files and directories that
> > WIN2K uses for
> > >user EFS?
> > >(3) My last resort is to retroactively create a 'ghost'
> > image of my
> > >old WIN2K system and on the good drive. This very time
> > consuming and
> > >when I tried it, it didn't work. Specifically the system
> > booted and
> > >proceeded all the way to the login is screen but I was
> > unable to login
> > >as all of my input devices where not activated. So the
> > question is, if
> > >this procedure is the only recourse, what is the best way
> > to implement
> > >this so I can actually login on decrypt my old files?
> > >
> > >T I A !!!!!!!!!!!
> > >.
> > >



Relevant Pages

  • Re: The Ubuntu Experiment
    ... Windows run anywhere from 3 months down to only about a week, ... heard of reinstallation once a week, ... environment, before reinstalling and restoring the systems. ...
    (Ubuntu)
  • Re: nss_ldap using sasl with gssapi. Kerberos credentials cache problem[Scanned]
    ... First get a Windows 200x environment with the RFC2307 extensions added to the Schema. ... Next assign all of your *real* Unix users with AD accounts - make the user names conform to the Posix rules (Windows samAccountName) i.e. 8 characters starting with a letter, ... A further enhancement would be to try to access the directory using this file if readable, and if that fails or if the file is not readable then use the KRB5CCNAME environment variable if set and if that fails use the users credentials cache if that exists. ...
    (Fedora)
  • Re: Using PHP to parse specific XML tag content?
    ... XML --> HTML transformation in testing environment. ... run just fine under Windows using Cygwin, and, unless I'm ... but you have to learn XSLT or use whatever defaults ...
    (comp.lang.php)
  • Re: Managed vs Unmanaged Bare Bones Performance Test
    ... One of the reasons that things like Virtual PC (which runs Windows on pre-Intel Macintoshes) and Rosetta work so well is that the programs being run spend very little time in the code that needs to be translated. ... If your code only spends 1% or less of its time executing the code you actually wrote, and the rest of its time either waiting on i/o or executing libraries in the operating system, then even if you have a 20X difference in performance, you're only really looking at a 20% cost in the "slower" environment. ... There are a few classes of applications where this sort of difference matters. ... The biggest thing I notice in my applications is start-up time, as the .NET Framework imposes a relatively large burden with respect to application initialization as compared to a straight Windows application. ...
    (microsoft.public.dotnet.framework)
  • Re: Using PHP to parse specific XML tag content?
    ... XML --> HTML transformation in testing environment. ... run just fine under Windows using Cygwin, and, unless I'm ... And they aren't going to run cygwin on these systems, ... It's a programming language designed ...
    (comp.lang.php)