Quantcast
Channel: Symantec Connect - Security - Discussions
Viewing all articles
Browse latest Browse all 203

Ran bootrec /fixmbr and lost PGP bootguard....please help!

$
0
0
I need a solution

Please help.....I am running PGP 10.3.2 MP8 on Windows 7.  I was stuck in a startup repair reboot loop and foolishly ran bootrec /fixmbr, thereby wiping out my PGP MBR and making a bad problem worse.  After that, the result upon booting was a black screen with a blinking cursor in the top left corner.

I pulled out my HDD and put in another HDD where I installed Win7 and PGP from scratch so that I could use pgpwde as I read it will be faster than running from recovery CD.  Question - do I have to encrypt the local drive to properly use pgpwde, or can I leave it decrypted?  I want to leave it decrypted as I am worried new keys will be generated and sent to my employer's server where they will wipe out the old ones for the original drive.  I don't really understand how the keys work but want to avoid clobbering anything remotely stored under my SSO company ID.

First thing I did my my MBR damaged HDD was attempt to clone it using Clonezilla since I didn't want to do anything that may destroy it further.  That failed initially due to bad sectors.  Then I ran Clonezilla with --rescue parm, skipping bad sectors, and it succeeded.  Subsequently, I read that DDRescue would have been a better choice as it will recover more data.  So, using yet another different drive, I ran DDRescue and got what seems like good results to me - 131K total error size and 16 errors.   I have the hex map of exactly where the errors are on the drive and their sizes.  Note that I am using 2TB external Seagate drives as the targets when doing this cloning - my originally drive is a 500GB SATA 6.0 2.5" with about 248GB used.

I played with pgpwde on the Clonezilla clone with the skipped sectors while waiting for the DDRescue to complete.  The good news is that pgpwde --recovery was successful.  It said it found the backup BGFS record on sector 3.  Then it reported "Recovery successful".  However, I tried booting off the cloned drive, and it said BootGuard loading stage 2... in the top left corner and hung.  I am looking at this tech article - https://support.symantec.com/en_US/article.TECH149631.html​  Should I have run PGP's --fixmbr before the --recover?  I ran pgpwde --status, and it showed the disk as offline and uninstrumented.  Shouldn't it have been online and instrumented after successsful recovery?

In any case, I have abandoned the Clonezilla drive for DDRescue - I am making a copy of the DDRescue clone right now so that I don't destroy that one and will try the "pgpwde --recovery" on it when it's done.  But can you please tell me if I should run "pgpwde --fixmbr" first?

And, of course, I would appreciate any other advice you have.

Thank you!!

0

Viewing all articles
Browse latest Browse all 203

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>