ELCOMSOFT.COM » Advanced EFS Data Recovery

 

How AEFSDR works

 

Top  Previous  Next

There are three typical scenarios of AEFSDR usage:

 

You want to decrypt files from the disk(s) you boot operating system from, and you have Administrator privileges in the system. However, some certificates are corrupted (and so "standard" methods available in the operating system don't work), or some files have been encrypted by other users (and their passwords are not known).
For some reason, you cannot load operating system, or you don't have Administrator privileges in it.
You have got a disk (with encrypted files) from an 'alien' system.
The system has been reinstalled

 

In the first case, no additional steps (prior to AEFSDR installation and usage) are requited. If you cannot boot from the disk with encrypted files, simply install it as an additional one to any system with Windows NT/2000/XP/2003/Vista/2008/7 installed, where you have Administrator privileges (in the second case, you will have to detach the disk from the 'dead' system, of course).

 

Note: if you start AEFSDR on Windows Vista or Windows 7 under the account with administrator privileges, but not the Administrator itself, you may get the following message:

 

Cannot get direct access to the logical disk!

You must have Administrator rights to use this program.

 

Actually, this is the problem of UAC (User Account Control), that does not work correctly in certain circumstances. As a workaround, simply right-click on aefsdr.exe and select Run as Administrator from popup menu (you may have to supply Administrator credentials, though. The program will start normally.

 

Now you can use AEFSDR. The program does the following:

 

Search for encryption keys (at the file or sector level)
Decrypts (tries to decrypt) private keys all ones that are available in the system.
Find decrypted files on selected partition(s), and decrypt (try to decrypt) their File Encryption Keys.
Decrypt files using FEKs using keys received at the previous steps.

 

If you previously exported the recovery agent EFS private key (see KB241201 for details) but for some reason cannot import it back, AEFSDR can use it directly (so you will not have to search for encryption keys).

 

All these steps are described in details in the next chapters: Scan for encryption keys, Scan for encrypted files, Browse for encrypted files and Decrypting files.

 

The most easy way is to run the wizard. If appropriate option is enabled, wizard is shown automatically when the program starts; alternatively, you can call it any time by pressing Wizard button on program toolbar.


Get more information about Advanced EFS Data Recovery
Get full version of Advanced EFS Data Recovery

(c) 2014 ElcomSoft Co.Ltd.