Re: EFS - Please help to unsecure data

From: Rock (rock_at_mail.nospam.net)
Date: 02/05/05


Date: Sat, 05 Feb 2005 14:10:56 -0800


   781 wrote:

> I have been formatting my HD for couple of times and did not have a problem
> like this.
> I have encrypted some folders with VERY important files on it and have never
> had access problems with it. After each format I would go into G partition
> and set myself as an owner.
> After that I would have access to my files.
> I have now reformatted my drive for the 3rd time. This time, somehow I am
> unable to gain access to my files: Access Denied.
> Please show me a way to get these before I pull all my hair off my head.
> Thank you, and appreciate your help.
> G
>
>

Without having a backup of the encryption key and/or having designated a
recovery agent, the files are probably not recoverable. The encryption
key is generated from the users SID. When a OS is reinstalled, even if
an account with the same name and password is created, the SID is not
the same hence it will not work with the original files unless the
encryption key was saved and then imported. See these links:

Best practices for the Encrypting File System
http://support.microsoft.com/?id=223316

How to back up the recovery agent Encrypting File System (EFS) private
key in Windows Server 2003, in Windows 2000, and in Windows XP
http://support.microsoft.com/?id=241201



Relevant Pages

  • Re: Decrypt windows files
    ... Iam using Windows XP joined to a Windows 2000 Domain, I encrypted the files using my domain user account so I need a help in decrypting my files. ... Since you forget to back up your certificate, unless you set a recovery agent you are most probably out of luck. ... There is no backdoor to encryption. ...
    (microsoft.public.security)
  • RE: cannot decrypt encrypted files
    ... install windows without decrypting those file.unfortunetly it can't.LOL. ... Windows will create a completely NEW random encryption key for that NEW user. ... I hope you kept some BACKUP files of your data (unencrypted or encrypted ...
    (microsoft.public.platformsdk.security)
  • RE: cannot decrypt encrypted files
    ... Reinstalling Windows WIPES OUT ... Windows will create a completely NEW random encryption key for that NEW user. ... Note that although you could take ownership of the encrypted files (with an ...
    (microsoft.public.platformsdk.security)
  • Re: Encrypting File System
    ... > personal encryption certificate ... > copies of your certificate (and no recovery agent certificates exist), ... Remove File Encryption in Windows XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: ENCRYPTED DATA RECOVERY
    ... 20/20 hindsight I should have decrypted those folders or if I had known to have had a Recovery Agent beforehand I wold not be in this mess. ... > personal encryption certificate ... Remove File Encryption in Windows XP ...
    (microsoft.public.windowsxp.security_admin)