Solved

Can the restoration of hard drive data be made without a MS restore point?

Posted on 2015-02-10
8
131 Views
Last Modified: 2015-04-16
Hi Experts,

Recently a staff member left our organisation and the laptop had the restore point removed. Also all the emails from his mailbox were permanently deleted.

I was wondering if anyone has come across any off the shelf software that could delve deep into the hard drive to restore the OST and other files from a previous date, about 2 months.

Or is this something that can only performed from a company with special forensic hardware/software?

Thanks in Advance,
0
Comment
Question by:Hec C
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 5

Expert Comment

by:ChopOMatic
ID: 40602116
You might try Shadow Explorer to look at any existing shadow volumes:

http://www.shadowexplorer.com/

You could also try RecoverMyFiles for recovery of deleted files. It lets you see exactly what it would recover before you pay for it.

All that said, do know that if this is a hard drive with potentially important evidence on it, any tinkering you do yourself alters that evidence and could render it inadmissible in future legal proceedings. If it's important and could turn into a legal case, don't be pennywise and pound-foolish. I see it all the time in DF cases.
0
 
LVL 63

Accepted Solution

by:
btan earned 333 total points
ID: 40602166
can try to do a quick check on Volume Shadow Copies (turned on by default). VS services  monitors a volume for any changes to the data stored on it and will create backups only containing those changes. Tool like  Shadow Explorer program can show what if VSCs are available for a given mounted volume.
Another few are
 Testdisk to undelete files from an NTFS file system.
 Recuva that does undelete and deep scan as well
 PC Inspector that recover also other file types

Side note - May be good to check out audit trail of what the actions done so to focus on the "recovery" trails.  Exchange 2010 SP1 introduced "Auditing Mailbox Access", which allows administrators to record operations on a mailbox such as the deletion or copy of e-mails. You can find out here on the use in steps

also other such as restoring from an OST after Deleting the Mailbox
0
 
LVL 92

Assisted Solution

by:nobus
nobus earned 167 total points
ID: 40602589
i found the best by far being getdataback : https://www.runtime.org/data-recovery-software.htm
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 63

Assisted Solution

by:btan
btan earned 333 total points
ID: 40604652
there is also the systools suite for recovery and in particular for the OST recovery, it attempts to recover deleted OST Files http://www.systoolsgroup.com/ost-recovery.html
0
 

Author Comment

by:Hec C
ID: 40611661
Thanks for the feedback!!

Unfortunately Windows inbuilt Shadow Explorer was switched off so the option to recover previous versions was not available. Getdataback, RecoverMyFiles  and recuva did or could retrieve deleted data but they didn't give me the option to retrieve data from an OST file at an earlier restore point.

I will try systools OST recovery then reply back to this post.
0
 
LVL 63

Expert Comment

by:btan
ID: 40611698
actually if there is no OST file found from the undeleted recovery I doubt there may be such existence or the employee has purpose secure erase that. the systool work on OST file if it exist as far as I understand. Regardless, OST files can be recreated as long as the Exchange server and that user mailbox is intact. OST will also be unlike PST file in which the latter is used for archival and will be more valued compared to the former.
Just in case of interest to still search OST here is another (it also has others for PST etc) - http://www.nucleustechnologies.com/exchange-ost-recovery.html
0
 

Author Comment

by:Hec C
ID: 40728802
Hi again, apologies for the late feedback.

In the end I ended up getting quotes for a forensic restore to retrieve the ost file as it does appear that the employee did purposely remove the file as OST recovery did not work for me.  I sent the quotes to the boss to retrieve the data, which may not have had what he is after, would not have been worth it.  

There are definitely some good products out there, we just have to tighten up on exchange backup procedures.

thanks again!
0
 

Author Closing Comment

by:Hec C
ID: 40728811
Although I was unable to retrieve the data the information provided was very helpful in researching my options and then taking the necessary steps to move forward.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Large Outlook files lead to various unwanted errors and corruption issues. Furthermore, large outlook files can also make Outlook take longer to start-up, search, navigate, and shut-down. So, In this article, i will discuss a method to make your Out…
In this step by step procedure, you will come to know the details of creating an Outlook meeting in 2007, 2010, 2013 & 2016.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question