Call us — 0141 404 0294
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · The Key Stayed Behind

Encrypted Folder Copied to Another Drive

His enquiry described a decade-long puzzle that he has partly solved himself. A hard drive from an old PC holding "thousands of pictures from my younger years": he had copied the pictures folder across, and found the contents "automatically locks to the Windows key, which at the time I thought was the 16-digit key you get with the disc on installation. I kept the hard drive as I could still see the thumbnails, so knew they were all on there. I recently found out the Windows key is the password I set on the computer — and recently, out of the blue ten years later, remembered my password." He is right about what happened, right about what the key is, and has recovered the password. There is still one missing piece, and it explains both why the thumbnails are visible and why the password alone may not be enough.

MediaHard drive from a decommissioned Windows PC — photograph folder protected by the operating system's built-in file encryption; thumbnails visible, contents inaccessible
Reported situationFolder encrypted via a Windows setting · drive retained for approximately ten years · thumbnails still displaying · original account password recently recalled · original machine long since disposed of
Fault classNo device fault — file-level encryption with the protecting certificate resident in the original user profile; password necessary but not sufficient without it
Equipment usedDrive read write-blocked · encrypted files and thumbnail cache identified separately · original user profile and certificate store located on the drive where present · decryption strictly against the owner's own credential (Passware Kit Forensic)

The decode: what encrypted it, why thumbnails survive, and the missing piece

What actually happened: Windows has long carried a file-level encryption feature, switched on by ticking a box in a folder's advanced properties — encrypt contents to secure data. People tick it without much thought, or inherit it from a setting applied further up the tree, and the effect is quiet: files continue to open normally while you are signed into that account on that machine, so nothing appears to have changed. It only reveals itself when the files travel somewhere else, which is exactly what happened when he copied the folder to another drive.

Why he was right to reconsider the product key: the 16-digit key printed with an installation disc is a licensing number and has nothing to do with encryption. What actually protects these files is a certificate generated for the user account, and that certificate is itself protected by the account's password. So his correction is sound — the password matters — but it is only half of the mechanism.

The missing piece: and this is the part worth understanding before spending anything. The certificate does not live inside the encrypted files. It lives in the user profile on the original machine, in that account's certificate store. Copying an encrypted folder to another drive copies the files and leaves the certificate behind. So the password unlocks the certificate — but the certificate has to exist to be unlocked. If the original profile is gone, the password on its own opens nothing, however well remembered.

Where the certificate may still be: the practical hunt, and there are real possibilities. If the drive he kept was the machine's system drive rather than a separate one, the user profile and its certificate store may still be on it — which would make this straightforward. If he ever exported the certificate to a file when Windows prompted him to back it up, that export is the key. And an old system backup or disk image of that machine would contain the profile. Those are the things worth searching for, and establishing whether any exists costs nothing.

Why the thumbnails are visible: the detail that has kept him hoping for ten years, and it is worth explaining because it is misleading. Windows builds a thumbnail cache — small preview images stored separately from the photographs themselves, in a database belonging to the folder or the user. Those cached previews are generally not encrypted, so they display perfectly while the full-resolution originals beside them remain locked. Seeing them proves the photographs were there. It does not indicate any access to the originals, and the cache holds only small previews rather than usable images.

On the bench

The drive was read write-blocked, and the encrypted files and the thumbnail cache were identified separately — since the visible previews and the locked originals are different objects and conflating them produces false hope. The search then went where the answer lives: the drive was examined for the original user profile and its certificate store, along with any exported certificate file or system backup containing them. Where the certificate was recovered, decryption ran against his own remembered password through Passware Kit Forensic and nothing else, and the photographs were extracted at full resolution and validated by rendering.

The outcome

The certificate located, the photographs decrypted with the owner's own password and validated at full resolution. Free assessment and honest limits; one fixed written figure including VAT before any work. The decode, for anyone whose files locked themselves to Windows: this is the operating system's built-in file encryption, switched on by a checkbox and invisible until the files move; the protecting certificate lives in the original user profile rather than in the files, so copying them to another drive leaves the key behind — which means your password is necessary but not sufficient on its own; the places worth searching are the original system drive, any certificate you exported when prompted, and old system backups; and visible thumbnails come from a separate unencrypted preview cache, so they prove the photographs existed rather than indicating any access to them.

Files that will not open on another computer

Look for the certificate, not just the password. Windows has a file-encryption setting applied by ticking a box in a folder's properties, and it's invisible while you're signed into the account that applied it — which is why so many people only discover it when the files move. What protects the files is a certificate belonging to that user account, and that certificate lives in the user profile on the original machine, not in the files you copied. So remembering your password is necessary but won't open anything on its own. Hunt for the profile: is the original system drive still around, did you ever export the certificate to a file when Windows offered, and do any old system backups or disk images of that machine survive? And don't read visible thumbnails as a good sign about access — those come from a separate unencrypted preview cache, and they're only small previews.

Photographs locked by a Windows setting you never chose?
The key is in the old profile — call Glasgow Data Recovery on 0141 404 0294; drive read write-blocked, certificate store located, decrypted only with your own password.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0141 404 0294