Solved

Can the restoration of hard drive data be made without a MS restore point?

Posted on 2015-02-10
8
125 Views
Last Modified: 2015-04-16
Hi Experts,

Recently a staff member left our organisation and the laptop had the restore point removed. Also all the emails from his mailbox were permanently deleted.

I was wondering if anyone has come across any off the shelf software that could delve deep into the hard drive to restore the OST and other files from a previous date, about 2 months.

Or is this something that can only performed from a company with special forensic hardware/software?

Thanks in Advance,
0
Comment
Question by:Hec C
8 Comments
 
LVL 5

Expert Comment

by:ChopOMatic
ID: 40602116
You might try Shadow Explorer to look at any existing shadow volumes:

http://www.shadowexplorer.com/

You could also try RecoverMyFiles for recovery of deleted files. It lets you see exactly what it would recover before you pay for it.

All that said, do know that if this is a hard drive with potentially important evidence on it, any tinkering you do yourself alters that evidence and could render it inadmissible in future legal proceedings. If it's important and could turn into a legal case, don't be pennywise and pound-foolish. I see it all the time in DF cases.
0
 
LVL 63

Accepted Solution

by:
btan earned 333 total points
ID: 40602166
can try to do a quick check on Volume Shadow Copies (turned on by default). VS services  monitors a volume for any changes to the data stored on it and will create backups only containing those changes. Tool like  Shadow Explorer program can show what if VSCs are available for a given mounted volume.
Another few are
 Testdisk to undelete files from an NTFS file system.
 Recuva that does undelete and deep scan as well
 PC Inspector that recover also other file types

Side note - May be good to check out audit trail of what the actions done so to focus on the "recovery" trails.  Exchange 2010 SP1 introduced "Auditing Mailbox Access", which allows administrators to record operations on a mailbox such as the deletion or copy of e-mails. You can find out here on the use in steps

also other such as restoring from an OST after Deleting the Mailbox
0
 
LVL 92

Assisted Solution

by:nobus
nobus earned 167 total points
ID: 40602589
i found the best by far being getdataback : https://www.runtime.org/data-recovery-software.htm
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 63

Assisted Solution

by:btan
btan earned 333 total points
ID: 40604652
there is also the systools suite for recovery and in particular for the OST recovery, it attempts to recover deleted OST Files http://www.systoolsgroup.com/ost-recovery.html
0
 

Author Comment

by:Hec C
ID: 40611661
Thanks for the feedback!!

Unfortunately Windows inbuilt Shadow Explorer was switched off so the option to recover previous versions was not available. Getdataback, RecoverMyFiles  and recuva did or could retrieve deleted data but they didn't give me the option to retrieve data from an OST file at an earlier restore point.

I will try systools OST recovery then reply back to this post.
0
 
LVL 63

Expert Comment

by:btan
ID: 40611698
actually if there is no OST file found from the undeleted recovery I doubt there may be such existence or the employee has purpose secure erase that. the systool work on OST file if it exist as far as I understand. Regardless, OST files can be recreated as long as the Exchange server and that user mailbox is intact. OST will also be unlike PST file in which the latter is used for archival and will be more valued compared to the former.
Just in case of interest to still search OST here is another (it also has others for PST etc) - http://www.nucleustechnologies.com/exchange-ost-recovery.html
0
 

Author Comment

by:Hec C
ID: 40728802
Hi again, apologies for the late feedback.

In the end I ended up getting quotes for a forensic restore to retrieve the ost file as it does appear that the employee did purposely remove the file as OST recovery did not work for me.  I sent the quotes to the boss to retrieve the data, which may not have had what he is after, would not have been worth it.  

There are definitely some good products out there, we just have to tighten up on exchange backup procedures.

thanks again!
0
 

Author Closing Comment

by:Hec C
ID: 40728811
Although I was unable to retrieve the data the information provided was very helpful in researching my options and then taking the necessary steps to move forward.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
In this step by step procedure, you will come to know the details of creating an Outlook meeting in 2007, 2010, 2013 & 2016.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question