Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Windows 7 encryption issues

Posted on 2014-04-14
11
Medium Priority
?
334 Views
Last Modified: 2014-05-18
Hello,

I had encrypted some files on a customers Windows 7 pc a few years ago using the windows encryption by right clicking and choosing advanced properties and then choosing encrypt files. I had recently used a program to copy the profile and join the pc to a domain. Well now the user can't open the encrypted files which are very important. Is there a program or something that I can get to decrypt these? When I try to decrypt them it just says I don't have permissions. I tried logging into the old local account but the files aren't there anymore as they have been copied to the domain profile now.
0
Comment
Question by:jands
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
11 Comments
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 39998810
When you encrypted the files, did it provide a decryption key that you saved somewhere?
0
 

Author Comment

by:jands
ID: 39998842
I don't remember.
0
 
LVL 4

Expert Comment

by:Niabingi
ID: 39998929
if the machine is on the domain it should have a recovery key in AD, are you able to find the pc in AD, if so right click and go to properties and select the bitlocker tab, the password should be there, see attached file.
bitlocker.JPG
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:jands
ID: 39998931
The files were encrypted prior to being joined to the domain.
0
 
LVL 4

Expert Comment

by:Niabingi
ID: 39998954
oh I see so it is file encryption not drive encryption, you may have to try a third party software or a file recovery service.
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 39999531
If you have the old PC good, you will not have the EFS keys in AD, they are on the old computer and you cannot recover without them. If you can't locate them, you really are out of luck, have a look at my articles here:
http://www.experts-exchange.com/Security/Encryption/A_12132-Microsoft-EFS-Recovery.html
-rich
0
 

Author Comment

by:jands
ID: 40000225
Ok let me explain better.

Windows 7 Professional computer name was Owner-PC and it was in a workgroup. The user logging into the PC was Bob. I then used ForensIT User Profile Wizard 3.5 to copy the profile and join it to the domain with PC Name OPTI05. I then logged into the machine as domainname\bobsmith and the profile was there. I tried to open the encrypted files and access was denied. I tried EFS recovery tools and nothing was able to be decrypted. I then changed the machine name back to Owner-PC and logged in with the original Bob account and the data was still not readable.
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 40000257
It sounds like the files actually did get encrypted when you used one of those software apps.
I have not used either one, but it appears the problem was created at that point.

Questions:

Do you take a backup of his data before starting?
Are there any previous versions of backups Bob may have taken?
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 2000 total points
ID: 40000267
I've never failed the recovery using AEFSDR, the trial version should be able to tell you if you can fully recover it or not. If AEFSDR scan's the HDD and can't find the certificates then I doubt a professional will do much better. Passware is about equal to AEFSDR, so if neither of those trials cannot find the certs, you will not recover those files. The certs are always on the machine however, in the personal certificate store, unless you delete them specifically or reimage the machine, even after joining or unjoining a domain. They aren't available to everyone, but typically you can import them and they will work.
-rich
0
 

Author Closing Comment

by:jands
ID: 40073598
AEFSDR worked like a charm.
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 40073708
I love that program :)
-rich
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are many Password Managers (PM) out there to choose from. PM's can help with your password habits and routines, but they should not be a crutch you rely on too heavily. I also have an article for company/enterprise PM's.
This article covers the basics of data encryption, what it is, how it works, and why it's important. If you've ever wondered what goes on when you "encrypt" data, you can look here to build a good foundation for your personal learning.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question