Help to Decrypt the "D" Drive without recovery Key

Dipil Kumar Vasu 11 Reputation points
2020-09-26T18:29:32.807+00:00

Team,

I am writing to you to check to get a possible resolution on an existing case with Microsoft O365 & Windows Tech Team. I am not getting a possible solution. Hence, I am writing here to check if anyone in the broader arena can help me to come out from this difficult situation.

Let me summarize the issue here:

My system no boot issue started on 16th of Aug’2020 when an Office 365 Tech Team member trying to help me with the upgradation of E1 to E3 and in the process he deleted some registry files.
System got irresponsive and on force restart, the system showing an error Stop Code: Critical Process Died.
Please note that Office 365 Tech Team member not taken the back up of my registry before did the Registry Edits. This major software changes triggers the bit locker
Further many trouble shoots were tried by various Office 365 Tech Team members.
With the help of Office 365 Tech Team member, we talk to Windows Tech Team and they suggested to perform the BIOS downgrade to solve this issue.
I contacted Dell and perform BIOS downgrade (downgraded BIOS to 2.6.1.) on 23rd August 2020. Still system shows the error Stop Code: Critical Process Died.
Further, connected in conference with Office 365 Tech Team, Windows Tech Team and Dell Tech Team. No solution to bring back to the boot situation. Finally decided to re-install the Operating System.
Reinstallation was successful deleting my complete data in the C Drive.
When trying to access the "D" drive, it's showing encrypted.
When clicking the “D” Drive, its asking for Recovery Key. We don’t have the key.

Screen showing “No Bit Locker Key” found under the Device Management of Microsoft. To recover the bitlocker key, tried with basic CMDs on bitlocker which is not supporting & proceeded with Intune MDM to recover the key. So went ahead & created, assigned the trial EMS license. Implemented Intune to O365 tenant and enrolled the laptop for Intune. Enrolment is successful but no key recovered from device management since the response found as "No Bitlocker Recovery Key Found for this Device".

Now anyone has a solution for me? Can anyhow help me to access my "D" Drive?

I am ready to pay for this service as well as the data is very precious for us. So please help me to get connect to the right resource who can help me to come out from this difficult situation. I contacted Microsoft to get a solution and made my life easy, and I am ending up in this deep trouble. Awaiting to get a positive response from this forum.

Thanks & Regards,

Dipil

<PII REMOVED>

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,840 questions
{count} vote

9 answers

Sort by: Most helpful
  1. MTG 1,201 Reputation points
    2020-09-28T09:21:12.817+00:00

    Too bad.
    Let me tell you how this works: The automation sees if you are logged on with a cloud account. If so, it creates and saves the key. Only if successful, it continues and starts encryption. So definitely, the key is saved somewhere. Problem is, if you cannot locate the correct account that was used, you would need to rely on Microsoft to do that and MS does not see it's their responsibility to keep track of their (billions of) users and their Microsoft-/Azure AD accounts and eventual recovery keys.

    I don't know if they even have lists that match some recovery key ID to a certain account - sure, that association is used to display what you just put in your screenshot, but I don't think there is any support personnel with access to all these keys, since that would be extremely costly material, if you understand what I mean.


  2. MotoX80 32,911 Reputation points
    2020-09-28T14:18:13.68+00:00

    For what it's worth.... my thoughts/opinion...

    It seems like every few days I hear about some company that is paying the hackers because they got hit with ransomware and there is no way to decrypt the data. This is nothing new. Everyone should be aware of that threat.

    Don't you have a backup?

    If there was critical data on your pc, what was your recovery plan if you got hit with ransomware? What was your plan to recover from a failed SSD/hard drive. What if your pc got stolen?

    I'm sorry for your situation, but your comment "So its a mistake at Microsoft end which leads to this problem" is not correct. It's your responsibility to insure that your critical data is backed up and is recoverable.

    If you don't have a backup, or didn't take one before you let some unknown support tech start messing with the registry, then that's not Microsoft's problem.


  3. Falcon IT Services 226 Reputation points
    2020-09-28T15:12:05.47+00:00

    Hello Dipil,

    Trusted security vendors don't add back doors. If it ever leaked, all systems from that vendor would become instantly vulnerable and nobody would trust the vendor again. Even if they did, they would never give it to a tech support phone agent so that they can decrypt your files. This thread is becoming absurd.

    It's unlikely that MS changing a registry key triggered this event. The more likely cause was the BIOS firmware change. Here is a list of what can trigger bit locker recovery mode.

    https://specopssoft.com/blog/what-causes-bitlocker-recovery-mode/

    Nobody else is going to say it so I will: move on. Unless you can find the key, your data is gone. Your only options are (1) to find the key, (2) ask the Oak Ridge National Laboratory to lend you some CPU power to try and brute force it or (3) call the g-men to see if there is a secret vulnerability that can be exploited and hope they share it with you.

    So really, option 1 is the only feasible option. Either that, or move on...

    Don't waste time and money trying to crack it or get scammed by someone claiming they can do it. The last time something like this was done it cost 1.3M US$


  4. Falcon IT Services 226 Reputation points
    2020-09-28T16:45:37.257+00:00

    "Automatic device encryption only starts after the Out-Of-Box Experience (OOBE) is completed and a Microsoft Account (MSA) is used on the system (e.g. use MSA for Windows login, add MSA as email, app, and work or school account, log in to the Microsoft Store app with MSA, redeem or activate Microsoft Office or other Microsoft applications with MSA)."

    https://www.dell.com/support/article/en-us/sln299056/automatic-windows-device-encryption-bitlocker-on-dell-systems?lang=en

    Gotta be another MS account you used somewhere... Find it, or move on...

    0 comments No comments