File Share Encryption

 View Only
Expand all | Collapse all

PGP Recovery disk is not working properly

  • 1.  PGP Recovery disk is not working properly

    Posted Sep 10, 2014 01:21 AM

    I am using PGP recovery disk as my HDD is crashed.
    When I started PGP decryption by using this disk it went well. I got message of "Decryption completed successfully...Press any key to continue..", I pressed a key then it showed me message like "Error in loading operating system..."
    I rebooted my machine and it was again started to ask me PGP password and when enter PGP password there was the same "black screen".
    I connected that disk to another laptop which is having PGP, but still it is also not able to detect the disk in it's command:
    -----------------------------------------------------------------------------------------------------------------------
    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --enum
    Total number of installed fixed/removable storage
    device (excluding floppy and CDROM): 1
    Managed disks:
      Disk Group 3bd1e107-5b1d-41fd-89ed-9ab62cbfcf20:
        Disk 0 has 1 online volumes:
          volume C:\ SYSTEM is on partition 1 with offset 2048
    Request sent to Enumerate disks was successful
    -----------------------------------------------------------------------------------------------------------------------

    Disk is visible in device manager, which says Disk -1: "Unallocated space"

    How should I have to proceed?

    If recovery DVD is working fine, I am getting message of successful completion then why it is still showing me as decrypted?



  • 2.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 10, 2014 04:18 AM

    Hi digambaringale333,

    Once you slave the drive can you post a feedback from other commands as well:

    pgpwde --status --disk 1  (presuming the slave drive is Disk 1)
    pgpwde --list-users --disk 1

    Can you post the Device Manager screenshot of the disk (Disk -1: "Unallocated space")

    Can you run diskpart and show the
    --list disk
    --list volumes

    *how to use diskpart - http://helpdeskgeek.com/windows-xp-tips/diskpart-windows-xp-help-use/

    Using a PGP BOOT ISO in frist palce was not a right choice. You should slave the drive and trying to decrypt and especially do a backup if not having as yet.

    Somehow your disk is still instrumented and as well as it shows unallocated space in device manager which means is visible as clean for Windows OS ready to be partitioned.

    Most probably you will have to think about the Partition Recovery software like http://www.cgsecurity.org/wiki/TestDisk or EASYUS Partition Recovery but before doing this post above reqeuested information.

     

     

     

     



  • 3.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 04:47 AM
      |   view attached

    Hi Adam, Thanks for reply.

    pgpwde output:
    ==================================================================================================
    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --status --disk 1
    Disk 1 is not found.
    Operation disk status failed:
    Error code -11984: item not found

    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --list-users --disk 1
    Disk 1 is not found.
    Operation list users on disk failed:
    Error code -11984: item not found

    C:\Program Files (x86)\PGP Corporation\PGP Desktop>
    ==================================================================================================

    DISKPART OUTPUT:
    ==================================================================================================

    DISKPART> list disk

      Disk ###  Status         Size     Free     Dyn  Gpt
      --------  -------------  -------  -------  ---  ---
      Disk 0    Online          465 GB      0 B
      Disk 1    Online          465 GB   465 GB

    DISKPART> list volume

      Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
      ----------  ---  -----------  -----  ----------  -------  ---------  --------
      Volume 0     D                       DVD-ROM         0 B  No Media
      Volume 1     C   SYSTEM       NTFS   Partition    465 GB  Healthy    System

    DISKPART>
    ==================================================================================================



  • 4.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 04:49 AM

    Hey, Please help me, how can slave the drive as I am not able to access the drive?



  • 5.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 04:55 AM

    Detailed output of disk part with currupted disk:(Disk -1 is the one which is having issues.)

    DISKPART> list disk

      Disk ###  Status         Size     Free     Dyn  Gpt
      --------  -------------  -------  -------  ---  ---
      Disk 0    Online          465 GB      0 B
    * Disk 1    Online          465 GB   465 GB

    DISKPART> select disk 1

    Disk 1 is now the selected disk.

    DISKPART> list volume

      Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
      ----------  ---  -----------  -----  ----------  -------  ---------  -------
      Volume 0     D                       DVD-ROM         0 B  No Media
      Volume 1     C   SYSTEM       NTFS   Partition    465 GB  Healthy    System

     



  • 6.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 10, 2014 07:51 AM

    Hi digambaringale333,

    As I see your disk 1 is fully unallocated which means is visible for OS like a brand new disk which require initialization and partition setup (setup from scratch) I see the only option to use is to install any Partition Recovery Software like provided before:
    http://www.cgsecurity.org/wiki/TestDisk
    or EASYUS Partition Recovery
    and see if you can run recovery process on it to recover partition structure.

    HTH

     

     

     

     

     



  • 7.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 08:16 AM

    Hi Adam,

    My HDD has too much IMP data which I dont want to loose... Using this recover partition tool cause any harm ? can I take backup like bit by bit of my HDD before trying any recovery?



  • 8.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 09:21 AM

    My HDD will have PGP MBR right as it is encrypted? Will this reovery tool will be able to recover PGP MBR?
     



  • 9.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 10, 2014 09:32 AM

    Do a bit by bit copy of the disk. This is MUST. Use CloneZilla or any other tool like "dd" for this purpose.



  • 10.  RE: PGP Recovery disk is not working properly

    Posted Sep 10, 2014 09:53 AM

    Yeah.. Thats waht I was also thinking , I will connect my HDD to one of the server and will do dd, so that will have one clone of it.. Thanks Adam, will let you know how it goes..



  • 11.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 11, 2014 05:26 AM

    After you run a bit by bit copy of the disk making sure that is correct and before running any Recovery tools let's check if we can find a bootguard backup records BGFS and in fact Bootguard itself.

    1. Download any of the HEX tools like WinHex or HxD or Disk Editor
    ( http://www.x-ways.net/winhex/ or http://mh-nexus.de/en/hxd/ )

    2.  Slave the drive with PGP installed (original one)

    3. Install WinHEX ( as example ) and run as administrator

    4. Navigate to Tools > Open Disk and chose affected Drive Disk 1 from Physical Media

    5. You should see Offset (000000000) sector 0 and in fact PGPGUARD which will tell us that PGP bootguard is in place

    6. Menu Search > Find Text > type capital letters BGFS and leave Match case ticked.
    Search will take time depending on the size of the disk and we will try to find all places on the disk were BGFS records are stored. You might have to click F4 (search next)

    7. If you see that BGFS records are found in many places on the disk I would take the snapshot of each place where it finds making sure that you take a screenshot with sectors as well. Then what you should do is open a case with Symantec to help you further. Potentialy it might be the way to recover the disk but I can't guarantee.

    8. If NO BGFS records are found on the disk  (in our case disk is unallocated) then you can run a Recovery Software on (original disk) to see if this helps.

    HTH



  • 12.  RE: PGP Recovery disk is not working properly

    Posted Sep 11, 2014 11:57 PM
      |   view attached

    Hi Adam, Good Morning...

    I tried with "PGPDesktop10.2.1MP2Win32_WDE_Recovery.iso", as my HDD was having 10.2.1 Build (4869) PGP. This time it worked..
    10.2.1 Bulild (4869), worked! Now my HDD dont asks me any PGP password at boot time.

    I guess it's PGP has been decrypted successfully.

    So now the latest status is that, I able to manage one SATA--> USB cable. I have connected my HDD to my another Think Pad, now I able to see my HDD in My Computer but not able to access it.

    It is visible in Device Manager also, but says it has RAW partition table.

    I am attaching one screen shot of it, Please have a look.



  • 13.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 12, 2014 03:49 AM

    Hi,  digambaringale333

    1. Did you run a bit by bit copy of the disk as you stated before (before running a PGP BOOT ISO).

    I guess no, although it may be too late now, so please do bit by bit copy now before running any further steps

    2. Using a PGP Recovey Disk was not a right choice as per my first post.

    Anyway... let's see....

    3. Can you let me know when you Slave the drive to another machine with PGP - how the disk is visible in PGP Desktop. Send the screenshot please. You have to have a machine with PGP installed

    4. If the point 1) is met then try as follow please

    x32
    C:\Program Files\PGP Corporation\PGP Desktop>
    x64
    C:\Program Files (x86)\PGP Corporation\PGP Desktop>

    pgpwde --enum --disk 1   (if the affected drive is disk 1)
    pgpwde --status --disk 1
    pgpwde --list-users --disk 1

    pgpwde --auth --disk 1 -p "passprase"              

    *  - try passphrase for one of the users from --list-users

    or
    pgpwde --auth --disk 1 -p "passprase"  --ap
    or
    pgpwde --auth --disk 1 -p "passprase"  --aa       

    *  - here you need to have an AD WDE-ADMIN security group beforehand with the users

    or

    pgpwde --auth --disk 1 --wdrt "WDRT taken from SEMS"

    * - if you had a managed client connected to SEMS / encryption server you can see if you can generate a WDRT to use with abobve command

    5. Run

    pgpwde --recover --passphrase "passphrase" --disk 1

    * - this command might take a while to search a backup BGFS records on entire affected drive. Wait till it's finished and provide feedback. Screenshot

    6. Finally after above all steps run steps from my previous post about searching BGFS records manually via WinHEX tool and let me know the feedback.

    HTH
     


     

     

    you SLAVE the drive to another machine without PGP please make sure that you do it with PGP

     

     



  • 14.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 12, 2014 03:51 AM

    Also please IGNORE my last sentence in previous post: Accidently It was hide in the window:
    "you SLAVE the drive to another machine without PGP please make sure that you do it with PGP"



  • 15.  RE: PGP Recovery disk is not working properly

    Posted Sep 12, 2014 05:17 AM
      |   view attached

    Hi Adam,
    Please find below replies, I have numbered them according to your questions:

    1: So I did couldn't run bit by bit copy as the disk was not visible on the linux box.
    So directly went for recovery disk. After recovery disk I able to see the drive in My computer but not able to access it, as it is having partition but I guess it's filesystem is corrupted.
    3: Yes I have PGP laptop, on that laptop itself I am trying to recover my HDD.
    I have attached screen of PGP desktop, please have a look.

    4: PGP commands output:
    ==========================================================================================================================================
    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --enum --disk 1
    Total number of installed fixed/removable storage
    device (excluding floppy and CDROM): 2
    Managed disks:
      Disk Group 3bd1e107-5b1d-41fd-89ed-9ab62cbfcf20:
        Disk 0 has 1 online volumes:
          volume C:\ SYSTEM is on partition 1 with offset 2048
    Unmanaged disks:
      Disk 1 has 0 online volumes:
    Request sent to Enumerate disks was successful

    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --status --disk 1
    Disk 1 is not instrumented by bootguard.==========================================> I guess PGP is decrypted.
    Request sent to Disk status was successful

    C:\Program Files (x86)\PGP Corporation\PGP Desktop>

     
    C:\Program Files (x86)\PGP Corporation\PGP Desktop>pgpwde --list-users --disk 1
    No users found!
    Request sent to List users on disk was successful
    ==========================================================================================================================================

    5: I dont have PGP anymore on my HDD, so cant run this command.
    6: I dont have PGP anymore on my HDD, so cant run this command.



  • 16.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 12, 2014 07:18 AM

    Hi,

    Try to run as per my previous post pgpwde --auth where passphrase is the WDE Administrator passphrase of your PGP disk 0 or passphrase of the SSO user of the machine with PGP where the drive is Slaved.

    Try all options:

    pgpwde --auth --disk 1 -p "passprase"         
    pgpwde --auth --disk 1 -p "passprase"  --ap

    then if it is not working please try to run:

    pgpwde --recover --passphrase "passphrase" --disk 1 (use passphrase for any current SSO user)

    then if it is not working try WinHEX to search BGFS records.

    Do you use an encryption Server SEMS or it is just a Standalone PGP Client without the server (unmanaged client) ?



  • 17.  RE: PGP Recovery disk is not working properly

    Posted Sep 12, 2014 07:45 AM

    Hi,

    when I try to copy it bit by bit, I am getting following error:

     

    suse245:~ # dd if=/dev/sdc1 of=/dev/sde bs=8192
    dd: reading `/dev/sdc1': Input/output error
    13310+0 records in
    13310+0 records out
    109035520 bytes (109 MB) copied, 5.92622 s, 18.4 MB/s

     



  • 18.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 12, 2014 09:33 AM

    Hi,

    dd has got some options as well if you check the man page.

    What if you run just

    dd if=/dev/sdc1 of=/dev/sde

    or

    dd if=/dev/sdc1 of=/dev/sde bs=8192 conv=noerror   (it ignores bad blocks)

    As per Wiki you can try as well:
    https://wiki.archlinux.org/index.php/disk_cloning

    Cloning an entire hard disk

    From physical disk /dev/sda to physical disk /dev/sdb

    dd if=/dev/sda of=/dev/sdb bs=4096 conv=notrunc,noerror,sync
    

    This will clone the entire drive, including MBR (and therefore bootloader), all partitions, UUIDs, and data.

    • notrunc or 'do not truncate' maintains data integrity by instructing dd not to truncate any data.
    • noerror instructs dd to continue operation, ignoring all read errors. Default behavior for dd is to halt at any error.
    • sync writes zeroes for read errors, so data offsets stay in sync.
    • bs=4096 sets the block size to 4k, an optimal size for hard disk read/write efficiency and therefore, cloning speed. 

    I do hope of course that the disk is not damage and you will be able to do so.

    HTH



  • 19.  RE: PGP Recovery disk is not working properly

    Posted Sep 12, 2014 11:14 AM

    Hi Adam, It is running in loop:

     

    suse245:~ # dd if=/dev/sdc of=/dev/sde bs=4096 conv=notrunc,noerror,sync
    dd: reading `/dev/sdc': Input/output error
    26878+0 records in
    26878+0 records out
    110092288 bytes (110 MB) copied, 6.02624 s, 18.3 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+1 records in
    26879+0 records out
    110096384 bytes (110 MB) copied, 11.2129 s, 9.8 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+2 records in
    26880+0 records out
    110100480 bytes (110 MB) copied, 13.813 s, 8.0 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+3 records in
    26881+0 records out
    110104576 bytes (110 MB) copied, 19.0134 s, 5.8 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+4 records in
    26882+0 records out
    110108672 bytes (110 MB) copied, 21.6137 s, 5.1 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+5 records in
    26883+0 records out
    110112768 bytes (110 MB) copied, 26.8139 s, 4.1 MB/s
    dd: reading `/dev/sdc': Input/output error
    26878+6 records in
    26884+0 records out
    110116864 bytes (110 MB) copied, 29.4142 s, 3.7 MB/s

     



  • 20.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 14, 2014 05:14 AM

    Hi, digambaringale333

    I don't have a good news for you but it really looks like the drive is damage (it has got a bad sectors) as you see two "dd" commands run and second one with the noerror which should instructs dd to continue operation, ignoring all read errors which is not done apparently.
    Area of the disk with bad sectors are around

    109035520 bytes (109 MB) - sector - 13310
    110092288 bytes (110 MB) - sector(s) 26878 and above

    There is an option to manually relocate bad sectors as each disk has got a spare space for this purpose but currently we don't know if the bad sector area is not for example a BGFS record(s) while READING. Normally the disk should automatically relocate damage sectors during WRITE operation failure. In our case it is READING from the disk so that is why you see reading I/O error. If this area of the disk on sector level can’t be read it is really bad.

    What are you getting when you run the command to get the SMART status of the disk - can you post the feedback?

    #smartctl -a /dev/sdc | grep -i reallocated    (sdc is the affected drive)

    ( if you don't have smartctl  too install package on Ubuntu - sudo apt-get install smartmontools )

    If you see "0" at the end of the command it means that there are not reallocated sectors on /dev/sdc

    Also try after above command the following one below and post the feedback.

    #hdparm –read-sector 13310  /dev/sdc    (sdc is the affected drive)
    and
    #hdparm –read-sector 26878 /dev/sdc


    In my opinion our next step  if you can't run a successful "dd" disk clone should be to verify if you can use a ClonZilla tool.. Although CloneZilla will not cure damage bad sectors but it may work through or around those errors (again hoping that the area of bad sectors are not accidently a BGFS records). Even if the ClonZilla work around those errors the backup is not 1:1 If this is not going to help next step should be to use WinHEX to search for BGFS records anyway (nothing to lose). Searching is not harmful but we will find out if the records exists (specifically they sector location) or not. If not you will run Disk Recovery Tool as stated in my previous post. If exist you will have to open a case with Symantec. Recovering data and making changes to sectors is not a straight forward task.

    I need you to be aware please that your disk is in a bad state so it might be hard to recover data anyway.


    Also I don't know if you have ever run a chkdsk standard Windows tool while having drive encrypted before the issue occured, this could reveal and rectify/relocate bad sectors.

    Awaiting your feedback.



  • 21.  RE: PGP Recovery disk is not working properly

    Broadcom Employee
    Posted Sep 22, 2014 03:08 AM

    Hi, digambaringale333

    Did you manage to do any progress and check my last post ?