3

I am trying to recover files from an old laptop where the Windows 10 installation broke. The drives (system drive C: and data drive D:) were encrypted using BitLocker, but the recovery key for D: was unretrievable. As I understand it, only the system drive uses the TPM to store the BitLocker keys.

When the system booted, D: could be decrypted using the "auto unlock" feature, and the key is saved in the registry (see e.g. Windows Bitlocker and automatic unlock password storage safety).

Now, since the installation on C: is unable to boot, I can no longer use that key to retrieve the files. Since the C: drive is fully recovered (but not bootable), is there any way of retrieving the original keys offline? Failing that, could I somehow reinstall Windows on the target hardware and transplant the keys back to that? (Since the keys are encrypted using the SYSTEM account, I suppose I must make sure that this stays the same, as well as anything else that Windows uses for salt).

Krumelur
  • 717

0 Answers0