Article ID: 928201 - Last Review: July 3, 2009 - Revision: 9.0 How to use the BitLocker Repair Tool to help recover data from an encrypted volume in Windows Vista or in Windows Server 2008On This PageINTRODUCTIONThis article describes how to use the BitLocker Repair Tool. You can use this tool to help access encrypted data if the hard disk has been severely damaged. This tool can reconstruct critical parts of the drive and salvage recoverable data. A recovery password or recovery key is required to decrypt the data. Use this command-line tool if the following conditions are true:
933246
(http://support.microsoft.com/kb/933246/
)
Description of the BitLocker Drive Preparation Tool
How to obtain the BitLocker Repair Tool for Windows Vista Enterprise, for Windows Vista Enterprise Service Pack 1, and for Windows Server 2008If you are using Windows Vista Enterprise or Windows Server 2008, visit the following Microsoft Web site to obtain this tool:http://www.microsoft.com/downloads/details.aspx?FamilyID=4ffd0d16-a51b-48b1-9042-ae1fb2de40c6
(http://www.microsoft.com/downloads/details.aspx?FamilyID=4ffd0d16-a51b-48b1-9042-ae1fb2de40c6)
MORE INFORMATIONOverviewYou may experience a problem that damages an area of a hard disk on which BitLocker stores critical information. This kind of problem may be caused by a hard disk failure or if Windows Vista exits unexpectedly.Windows Vista can no longer startIf a drive is damaged, Windows Vista may no longer start. In this situation, you may be prompted to repair the computer. Some computers are configured to enter a recovery environment automatically in this situation. However, if the computer is not configured to enter a recovery environment automatically, you receive the following error message:Windows failed to start. A recent hardware or software change might be the cause. To fix the problem: 1. Insert your Windows installation disc and restart your computer. 2. Choose your language settings, and then click "Next." 3. Click "Repair your computer." If you do not have this disc, contact your system administrator or computer manufacturer for assistance. File: \Windows\system32\winload.exe Status: 0xc00000001 Info: The selected entry could not be loaded because the application is missing or corrupt. Windows Vista can no longer read the driveDamage may occur on a drive that is not used to start Windows Vista. In this situation, you cannot unlock the damaged drive even when you use the correct recovery password or recovery key. Therefore, you cannot use another computer or another copy of Windows Vista to access the encrypted contents of the drive. In this scenario, the damaged drive may not appear in the BitLocker Drive Encryption Control Panel.Note Damage to the volume may not be related to BitLocker. Therefore, we recommend that you try other tools to help diagnose and resolve the problem with the volume before you use the BitLocker Repair Tool. The Windows Vista DVD includes the Windows Recovery Environment (WinRE) together with an option to repair the computer. For more information about how to troubleshoot Windows Vista startup problems, visit the following Microsoft Web site: http://windowshelp.microsoft.com/Windows/en-US/Help/f768809f-ed90-415f-a83f-89b42108b3551033.mspx
(http://windowshelp.microsoft.com/Windows/en-US/Help/f768809f-ed90-415f-a83f-89b42108b3551033.mspx)
To use the BitLocker Repair ToolTo use the BitLocker Repair Tool, follow these steps.Step 1: Gather required materialsObtain the following items to help you recover encrypted data from the affected volume:
Step 2: Download and install the BitLocker Repair ToolDownload and install the Bitlocker Repair Tool that is appropriate for the recovery DVD that you plan to use. When prompted, click Accept to accept the license terms.Step 3: Copy the BitLocker Repair Tool files to a removable deviceCopy the BitLocker Repair Tool files to a removable device After installation, copy the following files to the root of the USB flash drive that will be used for the recovery:
%windir%\system32\en-US\repair-bde.exe.mui
Step 4: Open a Command Prompt window
Step 5: Determine which drives are present
An encrypted volume has the file system label of RAW. Use this label to help establish the identification of the damaged volume. The following example output illustrates some of the information that may be generated when you run the diskpart list volume command: DISKPART> list volume Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- ----- Volume 0 E LR1CFRE_EN_ UDF DVD-ROM 2584 MB Healthy Volume 1 F Flash-1 FAT Removable 243 MB Healthy Volume 2 C SYSTEM NTFS Partition 1500 MB Healthy Volume 3 D RAW Partition 73 GB Healthy Volume 4 G EMPTY VOL NTFS Removable 149 GB Healthy
Step 6: Locate the BitLocker Repair Tool filesAt the command prompt, change directory to the drive on which the BitLocker Repair Tool files are located. For example, change to drive F.Step 7: Use the BitLocker Repair Tool to decrypt the dataTo decrypt the encrypted data, type the following command, and then press ENTER:repair-bde InputVolume OutputVolume -RecoveryPassword NumericalPassword In this command, replace the placeholders with the following drive letters and password:
repair-bde D: G: -RecoveryPassword 111111-111111-111111-111111-111111-111111-111111-111111 Step 8: Verify and then examine the decrypted dataWhen the data decryption operation is complete, follow the instructions to run the chkdsk command. After the chkdsk tool examines the hard disk for errors, you can then connect the external hard disk to another computer to view the data.BitLocker Repair Tool recovery optionsSometimes, you cannot recover the data from the damaged volume by using the steps in the "To use the BitLocker Repair Tool" section. Sometimes, the data may be unrecoverable, regardless of the recovery effort. Therefore, we recommend that you perform regular backups of all the data on the hard disk.To use the BitLocker Repair Tool without a Windows Vista DVDYou can use a Windows Vista DVD to provide a command prompt to run the BitLocker Repair Tool. You can also use other ways to start a command prompt. But the command prompt that you use must be running in a Windows Vista-based environment. Command prompts that you start from Microsoft Windows XP or from other environments that are not running Windows Vista are not supported. If another computer that is running Windows Vista is available, you can remove the damaged drive from the original computer and attach it to the Windows Vista-based computer to perform repairs.To use the BitLocker Repair Tool without an external hard diskWe recommend that you use an external hard disk as the destination location for the data that you recover from a damaged encrypted volume. The steps described in the "To use the BitLocker Repair Tool" section enhance the ability to recover the data. This is because the steps in the "To use the BitLocker Repair Tool" section do not modify the damaged encrypted volume.You can also use the BitLocker Repair Tool without using an external hard disk. This kind of repair may be successful if the damage is limited to the drive locations that are used to start Windows. However, there is an increased risk of data loss if you use this kind of repair operation on a volume that is extensively damaged. To perform this kind of repair, use the -NoOutputVolume option when you run the repair-bde command. For more information about how to use this option, see the "References" section. To use the BitLocker Repair Tool together with a key packageSometimes, if you use a key package, this gives you another opportunity to recover data from a damaged volume. In this scenario, you receive the following error message when you run the repair-bde command to perform a standard repair operation:ERROR: The input volume has suffered damages to critical information related to the decryption key.
Please try the -KeyPackage option to specify a key package. The volume may not be recoverable. BitLocker helps protect against unexpected damage by scattering multiple copies of critical information on the volume. To decrypt data, the BitLocker Repair Tool scans the volume to locate a usable copy of this critical information. If all the copies of the critical information are lost, the only way for the BitLocker Repair Tool to continue the recovery operation is to use a copy of this critical information that has been exported as a key package. If you already save BitLocker recovery information to Active Directory Domain Services, the key package is stored in the same location in Active Directory Domain Services. Also, any user who has local Administrator rights can save the key package by running a script on the functioning encrypted drive. To use the -KeyPackage option, you must verify that the key package is available. Then you must provide this key package as a file to the BitLocker Repair Tool. To use the BitLocker Repair Tool on a partially-encrypted volumeYou can use the BitLocker Repair Tool on a partially-encrypted volume. This situation can result when the BitLocker encryption operation was not completed successfully. To do this, follow the same procedure that is described in the "To use the BitLocker Repair Tool" section.Note When you specify the -KeyPackage option to recover data from a partially-encrypted volume, the BitLocker Repair Tool considers all the data on the volume as encrypted data that must be recovered. Therefore, the BitLocker Repair Tool tries to decrypt all the data from the volume. If you do not specify the -KeyPackage option, the BitLocker Repair Tool differentiates between the encrypted data on the volume and the data on the volume that is not encrypted. BitLocker Repair Tool troubleshooting helpError message 1The system cannot execute the specified program. Error message 2Failed to open Drive_letter (0x80310000). Error message 3The file or directory is corrupted and unreadable. REFERENCESBitLocker Repair Tool usage informationThe following usage information is generated when you run the repair-bde -? command:Usage:
repair-bde[.exe] InputVolume
{ OutputVolumeOrImage | {-NoOutputVolume|-nov} }
{ {-RecoveryPassword|-rp} NumericalPassword |
{-RecoveryKey|-rk} PathToExternalKeyFile }
[{-KeyPackage|-kp} PathToKeyPackage]
[{-LogFile|-lf} PathToLogFile]
[{-?|/?}]
Description:
Attempts to repair or decrypt a damaged BitLocker-encrypted volume using the
supplied recovery information.
WARNING! To avoid additional data loss, you should have a spare hard drive
available. Use this spare drive to store decrypted output or to back up the
contents of the damaged volume.
Parameters:
InputVolume
The BitLocker-encrypted volume to repair. Example: "C:".
OutputVolumeOrImage
Optional. The volume to store decrypted contents, or the file
location to create an image file of the contents.
Examples: "D:", "D:\imagefile.img".
WARNING! All information on this output volume will be
overwritten.
-nov or -NoOutputVolume
Attempt to repair a BitLocker-encrypted volume by modifying the
boot sector to point to a valid copy of BitLocker metadata.
WARNING! To avoid additional data loss, use a sector backup
utility to back up the input volume before using this option.
If you do not have such a utility available, specify an output
volume or image instead.
-rk or -RecoveryKey
Provide an external key to unlock the volume.
Example: "F:\RecoveryKey.bek".
-rp or -RecoveryPassword
Provide a numerical password to unlock the volume.
Example: "111111-222222-333333-...".
-kp or -KeyPackage
Optional. Provide a key package to unlock the volume.
Example: "F:\ExportedKeyPackage"
If this option is blank, the tool will look for the key package
automatically. This option is needed only if required by the tool.
-lf or -LogFile
Optional. Provide a path to a file that will store progress
information. Example: "F:\log.txt".
-f or -Force
Optional. When used, forces a volume to be dismounted even if
it cannot be locked. This option is needed only if required by
the tool.
-? or /?
Shows this screen.
Examples:
repair-bde C: -NoOutputVolume -rk F:\RecoveryKey.bek
repair-bde C: D: -rp 111111-222222-[...] -lf F:\log.txt
repair-bde C: D: -kp F:\KeyPackage -rp 111111-222222-[...]
repair-bde C: D:\imagefile.img -kp F:\KeyPackage -rk F:\RecoveryKey.bek
APPLIES TO
| Article Translations
|

Back to the top
