My Book Live Total Data Loss

144 views
Skip to first unread message

Philip Shaw

unread,
Jun 25, 2021, 8:30:23 AM6/25/21
to DataRecoveryCertification
I got a call this morning from a potential customer who has a WD My Book Live that has been factory reset due to a "malicious software" update. Apparently this is a widespread problem. Has anybody encountered one of these yet? 

It apparently happened worldwide on June 23rd so it is very new. He should be bringing it over this morning and I will let you know what I find.

Virus-free. www.avast.com

jpv...@gmail.com

unread,
Jun 25, 2021, 8:35:24 AM6/25/21
to datarecovery...@googlegroups.com

Not personally but it's all over the place. From what found sofar partitions were wiped, recreated and then reformatted. You're dealing with an EXT4 data partitions. I read mixed results on PhotoRec raw recovery.


__________________________________
Sent from eM Client | www.emclient.com
--
Data Recovery Certification Group / for issue with google group please email sc...@myharddrivedied.com
---
You received this message because you are subscribed to the Google Groups "DataRecoveryCertification" group.
To unsubscribe from this group and stop receiving emails from it, send an email to datarecoverycertif...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/datarecoverycertification/CAPG2QkYrgM9c6yiVTnhWbK-rZskzQFK2Bh3Wf3uE949V5HKoew%40mail.gmail.com.

Paulo Braga

unread,
Jun 25, 2021, 8:51:41 AM6/25/21
to datarecovery...@googlegroups.com

Philip Shaw

unread,
Jun 25, 2021, 10:47:53 AM6/25/21
to DataRecoveryCertification
I am running this drive on R-Studio and it appears that the folder structure has been blown away but the data is definitely out there. No encryption (nefarious or WD) and no full format. Reclaime didn't find folder structure after about 10 minutes but I will try that again when R-Studio is done.

Virus-free. www.avast.com

Desert Data Recovery

unread,
Jun 25, 2021, 10:57:58 AM6/25/21
to datarecovery...@googlegroups.com
You need UFS Explorer to recover the data. The File system is a hybrid SQL lite and EXT. 




Philip Shaw

unread,
Jun 25, 2021, 11:37:19 AM6/25/21
to DataRecoveryCertification
Very nice. Do you think there is any concern of putting this drive on an important computer? Could this malware propagate or is it just limited to screwing up these particular units?

t...@desertdatarecovery.com

unread,
Jun 25, 2021, 12:05:04 PM6/25/21
to datarecovery...@googlegroups.com

I think it’s highly unlikely that it is a virus, but who knows at this stage.

 

Tim Homer - Lead Engineer

Desert Data Recovery

t...@desertdatarecovery.com

www.desertdatarecovery.com

 

From: datarecovery...@googlegroups.com <datarecovery...@googlegroups.com> On Behalf Of Philip Shaw
Sent: Friday, June 25, 2021 8:37 AM
To: DataRecoveryCertification <datarecovery...@googlegroups.com>
Subject: Re: My Book Live Total Data Loss

 

Very nice. Do you think there is any concern of putting this drive on an important computer? Could this malware propagate or is it just limited to screwing up these particular units?

 

On Fri, Jun 25, 2021 at 10:57 AM Desert Data Recovery <t...@desertdatarecovery.com> wrote:

You need UFS Explorer to recover the data. The File system is a hybrid SQL lite and EXT. 

 

 

 

 

On Fri, Jun 25, 2021, 7:47 AM Philip Shaw <shawcomput...@gmail.com> wrote:

I am running this drive on R-Studio and it appears that the folder structure has been blown away but the data is definitely out there. No encryption (nefarious or WD) and no full format. Reclaime didn't find folder structure after about 10 minutes but I will try that again when R-Studio is done.

 

Image removed by sender.

Virus-free. www.avast.com

 

On Fri, Jun 25, 2021 at 8:51 AM Paulo Braga <pauloa...@gmail.com> wrote:

Em sex., 25 de jun. de 2021 às 13:35, <jpv...@gmail.com> escreveu:

 

Not personally but it's all over the place. From what found sofar partitions were wiped, recreated and then reformatted. You're dealing with an EXT4 data partitions. I read mixed results on PhotoRec raw recovery.



__________________________________
Sent from eM Client | www.emclient.com

 

On 6/25/2021 2:30:11 PM, "Philip Shaw" <shawcomput...@gmail.com> wrote:

 

I got a call this morning from a potential customer who has a WD My Book Live that has been factory reset due to a "malicious software" update. Apparently this is a widespread problem. Has anybody encountered one of these yet? 

 

It apparently happened worldwide on June 23rd so it is very new. He should be bringing it over this morning and I will let you know what I find.

 

Image removed by sender.

Virus-free. www.avast.com

~WRD0000.jpg

jpv...@gmail.com

unread,
Jun 25, 2021, 12:07:27 PM6/25/21
to datarecovery...@googlegroups.com
But is that the same device even. Problem is about the MyBook Live.



__________________________________
Sent from eM Client | www.emclient.com

Data Recovery Guru

unread,
Jun 25, 2021, 3:24:32 PM6/25/21
to datarecovery...@googlegroups.com
Funny, a customer just called about this with a My Book Live drive here in Massachusetts.

Philip Shaw

unread,
Jun 25, 2021, 3:53:07 PM6/25/21
to DataRecoveryCertification

giftedte...@gmail.com

unread,
Jun 30, 2021, 4:31:29 PM6/30/21
to DataRecoveryCertification
Received one yesterday. Data is there. File system is gone. Ive tried every tool. Only raw so far. 

jpv...@gmail.com

unread,
Jun 30, 2021, 4:49:45 PM6/30/21
to datarecovery...@googlegroups.com
I think RAW is all you're gonna get.



__________________________________
Sent from eM Client | www.emclient.com

t...@desertdatarecovery.com

unread,
Jun 30, 2021, 4:53:48 PM6/30/21
to datarecovery...@googlegroups.com

That does seem to be the general consensus.

 

Tim Homer - Lead Engineer

Desert Data Recovery

t...@desertdatarecovery.com

www.desertdatarecovery.com

 

From: datarecovery...@googlegroups.com <datarecovery...@googlegroups.com> On Behalf Of jpv...@gmail.com
Sent: Wednesday, June 30, 2021 1:50 PM
To: datarecovery...@googlegroups.com
Subject: Re[4]: My Book Live Total Data Loss

 

I think RAW is all you're gonna get.

 



__________________________________
Sent from eM Client | www.emclient.com

 

On 6/30/2021 10:31:29 PM, "giftedte...@gmail.com" <giftedte...@gmail.com> wrote:

 

Received one yesterday. Data is there. File system is gone. Ive tried every tool. Only raw so far. 

On Friday, June 25, 2021 at 3:53:07 PM UTC-4 Philip Shaw wrote:

 The data should be there.

 

Image removed by sender.

Virus-free. www.avast.com

 

On Fri, Jun 25, 2021 at 3:24 PM Data Recovery Guru <proz...@gmail.com> wrote:

Funny, a customer just called about this with a My Book Live drive here in Massachusetts.

 

On Fri, Jun 25, 2021, 12:07 PM <jpv...@gmail.com> wrote:

But is that the same device even. Problem is about the MyBook Live.

 



__________________________________
Sent from eM Client | www.emclient.com

 

On 6/25/2021 4:57:44 PM, "Desert Data Recovery" <t...@desertdatarecovery.com> wrote:

 

You need UFS Explorer to recover the data. The File system is a hybrid SQL lite and EXT. 

 

 

 

 

On Fri, Jun 25, 2021, 7:47 AM Philip Shaw <shawcomput...@gmail.com> wrote:

I am running this drive on R-Studio and it appears that the folder structure has been blown away but the data is definitely out there. No encryption (nefarious or WD) and no full format. Reclaime didn't find folder structure after about 10 minutes but I will try that again when R-Studio is done.

 

Image removed by sender.

Virus-free. www.avast.com

 

On Fri, Jun 25, 2021 at 8:51 AM Paulo Braga <pauloa...@gmail.com> wrote:

Em sex., 25 de jun. de 2021 às 13:35, <jpv...@gmail.com> escreveu:

 

Not personally but it's all over the place. From what found sofar partitions were wiped, recreated and then reformatted. You're dealing with an EXT4 data partitions. I read mixed results on PhotoRec raw recovery.



__________________________________
Sent from eM Client | www.emclient.com

 

On 6/25/2021 2:30:11 PM, "Philip Shaw" <shawcomput...@gmail.com> wrote:

 

I got a call this morning from a potential customer who has a WD My Book Live that has been factory reset due to a "malicious software" update. Apparently this is a widespread problem. Has anybody encountered one of these yet? 

 

It apparently happened worldwide on June 23rd so it is very new. He should be bringing it over this morning and I will let you know what I find.

 

Image removed by sender.

Virus-free. www.avast.com

~WRD0001.jpg

Alandata Recovery

unread,
Jun 30, 2021, 5:23:43 PM6/30/21
to datarecoveryce.
linux reformat for the ext filesystem writes an new empty inode tables

so unless it changed the start of the partition its going to clear it all

delete also clears the inodes





--
Alandata Data Recovery -  (949)287-3282  
"Cleanroom Data Recovery of RAID, VMware, NAS, Linux, Tape, Disk, Forensics"

pbzcbf...@gmail.com

unread,
Jul 1, 2021, 1:12:44 AM7/1/21
to DataRecoveryCertification
Reply all
Reply to author
Forward
0 new messages