Menu

Veracrypt backup header recovered, drive mounts with no data

2017-07-11
2017-07-11
  • Veracrypti20

    Veracrypti20 - 2017-07-11

    After accidentily connecting a 1.8TB JBOD drive with EFI + a verarypt ntfs partition and a 1TB unencrypted MBR+NTFS in RAID-0 mode to a machine on a Icy BOX IB-RD3662U3S through USB 3.0, my partitions were lost and showed up as unpartitioned. Using testdisk, on the unencrypted 1TB HDD partitions were recovered. For the 1.8TB veracrypted HDD, I Selected a recovery of the EFI in testdisk. It seems empty.

    Using dantz's steps of opening the 1.8TB disk, copying a file with winhex at the beginning block, I succesfully mounted that new small file. After that, I selected to create a backup of the volume header and it worked.
    Restoring the volume header to the lost partition worked as well, after I had selected in Disk Management for Windows 7 to mark the partition as RAW and not unpartitioned space, without selecting quick formatting.

    The final point where I am at now, is that I mounted the 1.8TB veracrypt partition on Z: with the original password, after recovering the volume header onto it. It succesfully mounts, but does not show any data, the partition is asking for formatting in Windows 7 - at this point I would see my data. Are there any further steps I can take?
    Opening this mounted Z: veracrypt drive in Winhex shows a lot of random numbers, so I hope the data is still there.
    Please let me know if I am close, or if it's a dead end. EDIT: I have an image.dd of the veracrypt partition (2), made in testdisk, after rewriting the EFI to partition 1 on the HDD itself.

    *dantz's steps: https://www.wilderssecurity.com/threads/truecrypt-missing-partition-table.336671/

     

    Last edit: Veracrypti20 2017-07-11
  • Veracrypti20

    Veracrypti20 - 2017-07-12

    The TL;DR version:

    Lost veracrypt partition. Recovered volume header with winhex.
    Restored volume header to partition. Mounts in veracrypt, but no data.
    Any suggestions please?

    Details, step by step

    1. Lost a veracrypt data partition (not boot). Did not have a backup of the volume header.
    2. Ran testdisk, found only EFI, rewrote it. Not smart.
    3. Made an image.dd with testdisk of the partition.
    4. Followed dant'z steps to recover a volume header with winhex that works with the original password
    5. Selected the 'unpartitioned area' to be shown as RAW in Disk Management (no formatting)
    6. Recover that volume header to the lost partition that now shows as RAW
    7. partition mounts on windows with the original password, But I see no data. on mac i cannot select the
      partition at all.

    Did I do it correctly? What else can I do? Would decrypting the partition make sense?
    I have a backup of the files, but this partition is better organised, spent a lot of time on it.
    Drive was scheduled for full backup a few hours later.

    Please let me know.

     

    Last edit: Veracrypti20 2017-07-12
  • Veracrypti20

    Veracrypti20 - 2017-07-18

    I think I did not input the correct offset. Drive mounts but does not decrypt.
    Any suggestions how to go further?

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.