±Your Account


Nickname
Password


Forgotten password/username?


Membership:
New Today: 0
New Yesterday: 4
Overall: 24360
Visitors: 53

Data recovery software for formatted USB stick

EnCase, FTK, X-Ways Forensics etc. and open source/freeware discussion. Strictly no advertising of commercial products, please.
Reply to topicReply to topic Printer Friendly Page
Forum FAQSearchView unanswered posts
Go to page Previous  1, 2 
  

Re: Data recovery software for formatted USB stick

Post Posted: Thu Jul 05, 2012 2:38 am

Jaclaz you've just shown me how far I've let my basic knowledge slip to not be aware of that!!!

Just tested and confirmed on a Win7 machine, I never thought I'd see the day that Windows would implement something thorough like that Razz  

Adam10541
Senior Member
 
 
  

Re: Data recovery software for formatted USB stick

Post Posted: Thu Jul 05, 2012 5:10 am

- XCell

It was done under Win 7.

If the format hadn't taken place, and the memory stick was still RAW, would there have been any chance of data recovery?

Sure, after a "new quick" format (or "old normal") you can usually recover 100% or nearly 100% of data (you may have issues with fragmented files).
Basically a new format (with the same filesystem, such as FAT32 on FAT32) overwrites only some parts of the bootsector and the FAT tables, the actual data is still entirely there.

- XCell

Again, the hex data showed nothing was saved on the stick, but could that be because the software couldn't find it due to the RAW system?

No.

Sometimes - no offence intended Smile - I wonder if before operating (at a "certain level") a PC/OS, the proper instructions have been given and understood.

If you open a disk with a hex editor, go to the MBR and write *anything* over the last two bytes, the disk will become "needing to be initialized".
If you open a disk with a hex editor, go to the MBR and write *anything* over the partition table entry, the volume will become "RAW".
If you open a volume with a hex editor, go to the PBR and write *anything* to the last two bytes or in several other places connected with the BPB, the volume will become "RAW".

Of course apart the very little modifications made, at the most two sectors, all the other sectors are exactly as they were before.

If anything is changed in the MBR or the PBR, you can normally use a "partition level" recovery, the volume (and all it's contents is practically unmodified and it can be recovered 100%.
If anything is changed in the MBR or the PBR AND in the FAT tables or the $MFT you can try "filesystem level" recovery, with somewhat (depending on the extension of the changes) lower percentage of success.
If also the FAT tables or $MFT have been overwritten/wiped extensively or totally, your only chance is "file level" recovery with an expected result of 100% or nearly 100% for contiguous files and a much lower rate for heavily fragmented files.

With sticks, however, I have seen more than one case where the "becoming RAW" was an issue within the controller (or the actual flash/whatever) and after having become "RAW", independently from whether data recovery was successfull or not (in hwole or part) a simple re-format was not enough to have the stick working, and the use of the Manufacturer Tool was needed.
In some of these cases the only "way out" to recover the data is to by-pass the controller and read data directly from the flash, through "specialized" hardware and software.
Same happens with conventional disks, but un these cases usually there are other issues (like the disk being "busy" or not detected at all.

The rule of the thumb is - if you find that a volume becomes RAW and you value the data on it - to power down/disconnect the device as soon as you can and ask for help/support BEFORE doing ANYTHING to it.

You might like this thread:
www.forensicfocus.com/...pic/t=5150


@Adam10541
Well, you are not the first one to fall in this nicely laid trap, been there, done that Shocked , JFYI:
www.msfn.org/board/top...-question/


jaclaz
_________________
- In theory there is no difference between theory and practice, but in practice there is. - 

jaclaz
Senior Member
 
 
Reply to topicReply to topic

Share this forum topic to encourage more replies



Page 2 of 2
Go to page Previous  1, 2