[KB8123] Decrypt a DEM CWA plugin managed Standalone system that is unable to start Windows in ESET Endpoint Encryption

Issue

ESET Endpoint Encryption (EEE) Client and EEE Server are separate products from ESET Full Disk Encryption (EFDE)

The article below applies only to the EEE Client or EEE Server and not EFDE.

Visit What's new in ESET Full Disk Encryption to view EFDE content.

Solution

Prerequisites

  • Ensure a full sector-by-sector backup of the existing hard drive has been created before attempting recovery.
  • Before decrypting, ensure you are following the appropriate instructions for your system. Visit Full Disk Encryption Recovery Overview for more information.

Use the ESET Encryption Recovery Media Creator

  1. Insert an empty USB drive into your computer.

  2. Download the ESET Encryption Recovery Utility.

  3. Run the utility and click Next to continue.

    Figure 1-1
  4. Click Win RE USB 64 bit.

    Architecture of system

    When creating a Win RE USB, the architecture (x86/x64) of the host system running the utility must match the target system needing recovery.

    Figure 1-2
  5. Select the Destination disk for the recovery media and click Next.

    Figure 1-3
  6. Click EEE Standalone.

    Figure 1-4
  7. Click Next. If instructed by ESET support, select additional support files.

    Figure 1-5
  8. Click Start.

    Figure 1-6
  9. Click Yes.

    Figure 1-7
  10. Allow the utility to complete the creation process.

    Figure 1-8
  11. Click Finish.

    Figure 1-9
  12. Safely eject the USB drive.


Decrypt the Workstation

  1. Insert the ESET Encryption Recovery USB drive and boot the Workstation from the USB.

  2. Select Decrypt all encrypted disks (using credentials).

    Figure 2-1
  3. Click Yes.

    Figure 2-2
  4. Select the FDE user you would like to use for decryption and press Enter.

    Figure 2-3
  5. If FDE user credentials are not available, select the admin user and press Enter. Open the DEM CWA plugin and click Computers. Right-click the computer name and click Encryption Recovery....

    Figure 2-4
  6. Copy the admin user password and click Cancel.

    Figure 2-5
  7. Type the password for the FDE User you selected and press Enter.

    Figure 2-6
  8. Choose from Secure or Performance mode to initiate the decryption process.

    Do not shut down

    Ensure that you allow the process to complete. Do not shut down or power the machine off.

    Figure 2-7
  9. After the computer has been successfully decrypted, click Ok.

    Figure 2-8
  10. Click Shutdown.

    Figure 2-9