gentilkiwi / mimikatz

A little tool to play with Windows security
http://blog.gentilkiwi.com/mimikatz
19.5k stars 3.74k forks source link

Decrypting folder - EFS Missing #285

Open mrahmany opened 4 years ago

mrahmany commented 4 years ago

Hi All

I have just came across this website after two weeks of research on how to resolve an issue that I have encountered. This is really affecting my work as I can't access my work folder on laptop due the issue below, any help would be highly appreciated. I am not a tech wizz, If anyone can resolve this issue for me I am willing to offer a small remuneration for their time.

I recently updated my laptop from windows 7 to windows 10, and I had backed up recent data on external hd by simply copying them over. After the update i realised that there is one folder (my main work folder) on the hard drive i cannot access, every single file and subfolder has a lock sign on it. I then found out that windows has a folder called, windows.old which has older files saved for a month after the update, and that has the same issue.

I tried all methods widely available online on how to decrypt it, by going to properties and changing attributes etc. none of them work.

After further reading I found that it could be due to 'encrypted certificate not being exported' I got no idea what this means, but everywhere i read it said it practically means the file cannot be opened. But I am persistent so kept researching thinking someone must have found a way also I disperately need to access my work, and I came across mimikatz after two weeks, after reading the post on tinnyapps.org, my hope has been restored. https://tinyapps.org/docs/decrypt-efs-without-cert-backup.html However the explanation and method described is way over my head.

Just to put it out there I am not a technical person, and neither do I understand codes, I just hope someone kind could offer their help to solve this issue for me, as I now come to know this is possible.

I look forward to hearing back from someone.

Kindest regard Mohammed

locked files

Papotito123 commented 4 years ago

Hello: For me,looks like user access rights.

Read this, https://www.groovypost.com/howto/microsoft/remove-lock-icons-folders-windows-7/

mrahmany commented 4 years ago

Hello: For me,looks like user access rights. Read this, https://www.groovypost.com/howto/microsoft/remove-lock-icons-folders-windows-7/

Unfortunately this doesn't work... :( I am quite sure it may have something to do with efs certificate https://tinyapps.org/docs/decrypt-efs-without-cert-backup.html

Papotito123 commented 4 years ago

Hello: When I had to open a Win 7 hdd with user password in other computer,sometimes U saw this lock.Also when doing a backup ,some files had this lock.Always was resolved with an NTFS file permissions tool. Also ,sometimes,I just boot an Ubuntu usb bootable and and see if files open. Just give a try.

Otherwise, you will need to recover the Masterkey according to the user password,among other files. Recently in issue #277 that is Closed ,a guy resolve some-kind of EFS issue with the help of the mimi developer. I'm also interested in how resolved it's issue.

Papotito123 commented 4 years ago

Hello: https://www.sevenforums.com/tutorials/320930-lock-icon-files-folders-remove-windows-7-a.html

Also has some .bat for resolving issue.

I also look at this forum that talks about files being shared while in Homegroup and then unsharing,leaving files only be opened with 1 user. Read carefully,there's some ways people managed this situation, https://www.sevenforums.com/network-sharing/8729-how-remove-lock-icon-over-my-folder.html