Repairing NTFS MFT

ch33zw1z

Lifer
Nov 4, 2004
37,984
18,325
146
Have a laptop from a buddy and a virus has rendered NTFS FS unavailable for file recovery. I have run chkdsk /f and /r, both fix errors in FS. However, I still cannot access the contents of the drive. I believe the virus has destroyed the MFT and it's backup.

Anyone have experience with this situation? Tips or tricks for file recovery? Program recommendations? There's some photo's that I need to pull off of the drive if at all possible.

TIA...

***Update:*** After a few trial and error episodes, I managed to recover the entire NTFS partition using GParted 0.8.5...

I attached the 80GB virus ridden drive and a spare 500GB drive, both are SATA. Then, I booted the GParted live cd with default settings. I selected the source drive (sdb1, virus drive/partition). On the GParted menu bar is a pull down with a "Recover Data" option. I chose this option, the drive scan took about 20 minutes. GParted automatically mounts the NTFS partition to a folder in the /tmp directory. I then mounted the spare drive (sda1) to the /media folder. I then ran a "ls" in separate terminal windows and confirmed that I could see both partitions ok.

I used the sudo mkdir /media/xxxxxx to create a folder on the destination partition. Then reissued the "ls" cmd to display the newly created folder.

The command to copy the entire drive eluded for me a few, but after a little frustration and a quick google search I found what I needed.

sudo cp -r /tmp/gparted-roview-xxxxxx/* /media/xxxxxx (xxxxx's will vary with what you create and what gparted creates)

about ~45 minutes later the command completed and I could see everything in the selected folder on the 500GB drive.

Next, I shutdown and connected the Win 7 boot drive and the 500GB spare. I could see all of it, and of course the virus quickly tried to infect my system as well. I have been giving MS Security Essentials a try and it blocked/remedied the viruses before they could do any damage. I pulled the ~20GB of data that my buddy needed off the 500GB onto a couple more drives to ensure data redundancy

So far, it's all there. Unfortunately, any attempts made before this failed to recover data or the file system. I'm very happy that gparted kicks that much butt.
 
Last edited:

ch33zw1z

Lifer
Nov 4, 2004
37,984
18,325
146

razel

Platinum Member
May 14, 2002
2,337
90
101
testdisk will not write to the disk unless you tell it so. Did it error out after finding the partition and is trying to rewrite the MBR? If so, instead of rewriting the MBR, that maybe the best time for your buddy to copy his beloved files off it. After it finds the partition, it'll give you an option to list the files by pressing P, that's when you can then copy the contents.
 

stahlhart

Super Moderator Graphics Cards
Dec 21, 2010
4,273
77
91
Have a laptop from a buddy and a virus has rendered NTFS FS unavailable for file recovery. I have run chkdsk /f and /r, both fix errors in FS. However, I still cannot access the contents of the drive. I believe the virus has destroyed the MFT and it's backup.

Anyone have experience with this situation? Tips or tricks for file recovery? Program recommendations? There's some photo's that I need to pull off of the drive if at all possible.

TIA...

nm
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |