abeasst
asked on
Missing Partition
We have a coworker that has his drive partitioned to a C and D drive. I believe a rootkit virus has deleted or removed the D partition. Is it possible to recover this? If so, can anyone recommend recovery steps and/or software that can assist in retrieving this? I'm using Kaspersky to remove the rootkit. Any help would be appreciated.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Knopix is a little more complicated than I thought it would be. I'll try TestDisk while I wait for the torrent file to download.
In Testdisk, If the partition is found, you must choose W for write to restore the partition.
Hopefully you can restore the partition. Keep the Knoppix disk in your toolbox it can come in handy for other issues.
ASKER
Here's where I am in TestDisk:
1 P Dell Utility 204800 (size in sectors)
Bad Sector count:
2 * HPFS - NTFS 20480000 [recovery]
3 P HPFS - NTFS 122880000
4 E Extended LBA 1106694144
INvalid FAT boot sector
5 L FAT16 /32M 1106692096
5 L FAT16 /32M 1106692096
*=Primary bootable
P = Primary
L=Logical
E=Extended
D=Deleted
Where do I go from here?
1 P Dell Utility 204800 (size in sectors)
Bad Sector count:
2 * HPFS - NTFS 20480000 [recovery]
3 P HPFS - NTFS 122880000
4 E Extended LBA 1106694144
INvalid FAT boot sector
5 L FAT16 /32M 1106692096
5 L FAT16 /32M 1106692096
*=Primary bootable
P = Primary
L=Logical
E=Extended
D=Deleted
Where do I go from here?
ASKER
I hit quick search and the following comes up:
Partition Size in Sectors
*FAT16 >32M 204800 [DellUtility]
P HPFS - NTFS 20480000 [Recovery]
P HPFS - NTFS 122880000
L FAT16/32M 1106692096 (I'm pretty sure this is the partition that used to be present)
Partition Size in Sectors
*FAT16 >32M 204800 [DellUtility]
P HPFS - NTFS 20480000 [Recovery]
P HPFS - NTFS 122880000
L FAT16/32M 1106692096 (I'm pretty sure this is the partition that used to be present)
ASKER
I'm not really sure where to proceed from here. Any help would be greatly appreciated.
Sorry, I'm not familiar with that program so wouldn't know what to suggest next. Perhaps Eirman will be able to help.
How's the Knoppix download coming?
How's the Knoppix download coming?
ASKER
I've got the files downloaded. Do I just burn these to a disk and then try to boot to disc?
Yes. After burning, boot from your optical drive. You might be prompted for your language. I am assuming [EN]. The GUI will then boot up and you should see all of your drives.
From there click on the "bad" drive and see if you can access the missing partition.
The one thing I had to get used to was that everything is a sinle-click.
From there click on the "bad" drive and see if you can access the missing partition.
The one thing I had to get used to was that everything is a sinle-click.
ASKER
I have this loaded now (Knoppix) and I'm looking at the desktop. I clicked on the Knoppix folder icon and it brings up the equivalent to Windows Explorer. On the left I see the C partition (63 GB), my flash drive, and that's it. The drive capacity is 750 GB. I'm guessing the partition is toast if I don't see it in this window. What's next, if anything?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Ok well thanks for your help. The other utility states "no file found, file system may be damaged." I don't know enough about the utility to go any further.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
The computer boots into windows just fine. There is some residual windows damage from the virus (file allocations and registry issues). The D: drive is just gone. I've never seen a partition get removed by a virus before. This is a new one for me.
Oh, I know this computer boots into Windows fine. I was saying keep the Knoppix disk handy in case you run into a situation where it won't.
I use it for laptops quite frequently. That way I can backup the data files and not have to go through the trouble of removing the HD.
I use it for laptops quite frequently. That way I can backup the data files and not have to go through the trouble of removing the HD.
ASKER
Oh definitely. I'm sure having Knoppix will come in handy. Thanks for the tip.
is this a virus problem or issue with hard disk.
if you are using window, try you device manger and try to access your diskmanager and look do you have a drive is there which is not acceptable. before going any adviace step go and explore the drive or open it with run or or shell and confirm that your date is there,
if you are using window, try you device manger and try to access your diskmanager and look do you have a drive is there which is not acceptable. before going any adviace step go and explore the drive or open it with run or or shell and confirm that your date is there,
try the partition recovery soft from easus (free) : http://www.easeus.com/partition-recovery/
***be sure to NOT install anything on the partition to recover !
***be sure to NOT install anything on the partition to recover !
Can you take screen shot of Windows Disk Management (right click on My Computer - Manage - Disk Management) and load it here?
ASKER
It doesn't show up in Disk management. That's the first place I looked. The only thing there is unpartitioned space and the C drive.
ASKER
The solutions provided by ScottCha (Knoppix) and Eirman (Testdisk) both came back with the same results. Testdisk is a little easier to use but both do the trick. Unfortunately, I think I'm just out of luck. We're sending the laptop to a recovery service to see if they have any better luck. If they can resolve it, I will update the question.
bummer - you did not try the recovery i listed...
ASKER