Navigation

TrueCrypt system drive encryption

By . Last modified: 2014-08-14.

How to encrypt or decrypt system drives with TrueCrypt in Windows XP, Vista, 7, 8 and 8.1

While encrypted volumes are meant for protecting sensitive data, encrypting whole hard disk might be more useful in many cases. If you want to prevent unauthorized local (physical) access to your computer, TrueCrypt is the program you need. If you encrypt whole system drive (the drive where Windows is installed), no one can boot your computer or access any files on the encrypted drive without entering a correct password.

Reserve several hours for one-time encryption process. You can pause and resume the process, but it will not help it finish sooner. The process will not delete any files or folders, everything will be encrypted on the fly.

You must have a CD/DVD-writer and a blank CD-R or CD-RW to complete the system encryption process - this is required to create a TrueCrypt Rescue Disk.

Possible limitations of encrypting system drive

Please do not use system encryption on computers that already feel sluggish - while there is no noticeable slowdown on PC-s that are up to 5 years old, system encryption will certainly affect negatively those ones that are already slow.

Remember, you cannot access your files if you boot from a CD, DVD or external drive, such as Windows installation/repair disc or Recovery Drive, Linux Live CD-s, etc. You can use Windows Advanced Boot Options after entering your decryption password, but recovering files using bootable media requires drive decryption first.

Windows 8 and 8.1 cannot create Custom recovery images, because TrueCrypt locks the drive after encryption is complete.

Be aware that if you copy or move a file or folder from an encrypted system drive to some other disk or drive, the file will not be encrypted on the destination disk. If you copy an unencrypted file to an encrypted system drive, the file will become encrypted on that system drive.

Encrypting Windows system drive with TrueCrypt

Make sure you have a recent and valid full backup of your computer first! See, I warned you... Wink

Open TrueCrypt from Start menu/Start screen or by right-clicking its icon in Taskbar Notification Area (aka System Tray) and clicking Show TrueCrypt.
In the program window, open System menu and click Encrypt System Partition/Drive.
TrueCrypt main window, System menu. Click 'Encrypt System Partition/Drive' to protect your Windows drive from unauthorized access.

In the Type of System Encryption screen of TrueCrypt Volume Creation Wizard, leave Normal selected and click Next.
TrueCrypt Volume Creation Wizard, Type of System Encryption. Click Next.

In the Area to Encrypt screen, select Encrypt the whole drive and click Next.
TrueCrypt Volume Creation Wizard, Area to Encrypt. Select 'Encrypt the whole drive' and click Next.

Always select No in the Encryption of Host Protected Area window. There might be some required tools or drivers in the area.
Click Next.
TrueCrypt Volume Creation Wizard, Encryption of Host Protected Area. Select 'No' and click Next.

Select the correct option in the Number of Operating Systems dialog.
If you have only one version of Windows installed on the disk you want to encrypt (and no additional operating systems), select Single-boot.
If you have several versions of Windows, or Windows and an alternate OS (Linux or Mac OS) installed on the drive, select Multi-boot.
Click Next.
TrueCrypt Volume Creation Wizard, Number of Operating Systems. Select 'Single-boot' if only one version of Windows is installed on the disk (true in most cases). If multiple OS-s are installed, select 'Multi-boot'. Click Next.

In the Encryption Options screen, leave defaults (AES and RIPEMD-160) selected to ensure best performance. These algorithms are strong enough to protect from brute-force attacks.
TrueCrypt Volume Creation Wizard, Encryption Options. Leave AES for Encryption Algorithm and RIPEMD-160 for Hash Algorithm. Click Next.

In the Password screen, create a strong and unique password for the encrypted drive - and make the passphrase longer than usual (at least 20 characters).
Please note that most PC-s use U.S. keyboard layout at boot-time - do not use special or international characters here if you have a different layout!
Keyfiles are not supported on system drives, so click Next.
TrueCrypt Volume Creation Wizard, Password. Type a strong and unique password and click Next.

If you specified a password shorter than 20 characters, TrueCrypt will warn you that such passwords are easy to crack. If your password is at least 15 characters long, it is safe to click Yes here.
TrueCrypt Volume Creation Wizard, WARNING: Short passwords are easy to crack using brute force techniques! Click Yes only if your password is at least 12 characters long AND you have added at least 3 keyfiles.

Move your mouse inside the Collecting Random Data dialog randomly for at least 2 minutes. This will make the protection stronger.
After this, click Next.
TrueCrypt Volume Creation Wizard, Collecting Random Data. Move mouse pointer inside the window for at least two minutes. Then click Next.

Click Next in the Keys Generated window.
TrueCrypt Volume Creation Wizard, Keys Generated. Click Next.

In the Rescue Disk dialog, click Browse first. Select the folder where to save the disc image (in ISO format) and specify a name for it.
Rescue Disk becomes very helpful in case some program or malware damages boot loader or critical data of TrueCrypt on the disk, or if Windows is unable to boot despite troubleshooting and you need to rescue your files and folders from the drive. If possible, back up the .iso file to a free cloud service to have it available if a CD appears faulty. The Rescue Disk does not provide any access to the encrypted disk without correct password.
Click Next.
TrueCrypt Volume Creation Wizard, Rescue Disk. Browse to the folder where you want to store the Rescue Disk image. Then click Next.

This is the point where you need a CD-writer. You can use either CDBurnerXP or Windows 7/8/8.1 Disc Image Burner to burn the .iso file created in the previous step to a blank CD-R/CD-RW.
You can fool TrueCrypt here by mounting the .iso file as a virtual CD using free tools such as DaemonTools, but you will need a real CD/DVD reader if you want to use Rescue Disk at boot-time.
Click Next.
TrueCrypt Volume Creation Wizard, Rescue Disk Recording. Burn the disc image to a blank CD and click Next.

In Windows 7, 8 and 8.1, TrueCrypt offers to start Disc Image Burner automatically. Click OK.
TrueCrypt Volume Creation Wizard, Rescue Disk Recording on Windows 7. Click OK to launch Windows Disc Image Burner.

In Windows Disc Image Burner, enable the Verify disc after burning option and click Burn to create the Rescue Disk.
Windows Disc Image Burner. Enable the 'Verify disc after burning' option and click Burn.

After you've created the disc, leave it in CD/DVD device and click Next back in TrueCrypt Volume Creation Wizard.
This should open the Rescue Disk Verified screen. Click Next again.
TrueCrypt Volume Creation Wizard, Rescue Disk Verified. Click Next.

In most cases, select None (fastest) and click Next in the Wipe Mode screen.
If your Windows installation is on an SSD (Solid-State Drive) that has no hardware encryption, you should enable wiping here to prevent recovering unencrypted data.
TrueCrypt Volume Creation Wizard, Wipe Mode. Click Next.

After this, TrueCrypt needs to perform a test to verify that everthing works correctly. Click Test in the System Encryption Pretest screen.
TrueCrypt Volume Creation Wizard, System Encryption Pretest. Click Test.

Read the useful information about using TrueCrypt Rescue Disk in case the test goes wrong. Then click OK.
TrueCrypt, using Rescue Disk. Read the info before clicking OK.

To start the System Encryption Pretest, your computer must be restarted. Click Yes.
TrueCrypt Volume Creation Wizard, Your computer must be restarted. Click Yes.

If everything works fine, TrueCrypt Boot Loader appears after your computer restarts. Type the password you specified and press Enter key. Windows should start now.
TrueCrypt Boot Loader, authentication screen. Type your password and press Enter.

In case you did not care about the warning that most PC-s use U.S. keyboard layout at boot-time, here's the layout if your correct password turns out to be wrong.
Standard U.S. keyboard layout

If you cannot remember the password you specified, you can press Esc key to boot to Windows anyway - nothing is encrypted yet.
If you do not see TrueCrypt Boot Loader and Windows will not start, boot your computer from TrueCrypt Rescue Disk and restore original boot loader. Verify that your computer is set to boot from CD first.

After the pretest passes (Windows starts and you log in), TrueCrypt Volume Creation Wizard appears automatically. Click Encrypt in the Pretest Completed window.
TrueCrypt Volume Creation Wizard, Pretest Completed. Click Encrypt.

Another set of useful instructions on Rescue Disk appears. Read it and click OK.
TrueCrypt, using Rescue Disk. Read the info before clicking OK.

And the long encryption process begins. You can use the Pause/Resume button to stop the process temporarily, but you can actually use your computer while TrueCrypt encrypts the drive.
If you accidentally restart your computer, the process continues automatically.
After the system drive has been encrypted, click OK in the notification dialog.
TrueCrypt Volume Creation Wizard, The system partition/drive has been successfully encrypted. Click OK.

Then click Finish in the Encryption screen.
TrueCrypt Volume Creation Wizard, Encryption. Click Finish.

From this point on, you can only start Windows after you enter a correct password in the TrueCrypt Boot Loader screen. No unencrypted data will be written to the system drive - TrueCrypt encrypts all unencrypted data in memory (RAM) and only then writes it to the disk.

Changing system drive password in TrueCrypt

If you want to specify a different password for your encrypted system drive later, open TrueCrypt main window as usual. Then open System menu and click Change Password.
TrueCrypt main window, System menu. Click 'Change Password' to set a different password for encrypted system drive.

Change Password or Keyfiles window opens. Type your present system encryption password in the Current section and set a different one in the New section.
Then click OK. As said before, system encryption does not support keyfiles.
TrueCrypt, Change Password or Keyfiles. Type your current password. Then specify and confirm a new passphrase. Click OK.

Again, move your mouse randomly for at least 2 minutes in the TrueCrypt - Random Pool Enrichment dialog. Then click Continue.
TrueCrypt - Random Pool Enrichment. To complete password change, move your mouse randomly for at least two minutes. Then click Continue.

Click OK in the success dialog.
TrueCrypt, Password and/or keyfile(s) successfully changed. Click OK.

But the password change is not yet complete! Your system drive can still be decrypted using the TrueCrypt Rescue Disk you created earlier (with the old password).
Click Yes to start creating a new Rescue Disk.
TrueCrypt, Do you want to create a new TrueCrypt Rescue Disk? Click Yes.

Click OK to store the .iso file in the folder you want.
TrueCrypt, select a filename for the new Rescue Disk ISO image. Click OK.

After saving the new disc image file, click OK and burn it to a blank CD using CDBurnerXP or Windows Disc Image Burner (only available in Windows 7 and 8/8.1).
TrueCrypt, The Resuce Disk image has been created and stored. Click OK and burn the .iso file to a blank CD.

After the new TrueCrypt Rescue Disk is ready, leave it in CD/DVD drive. Open System menu in TrueCrypt main window and click Verify Rescue Disk.
TrueCrypt main window, System menu. Click 'Verify Rescue Disk' to check if the new disc is fine.

Click OK in the disk insert dialog.
TrueCrypt, Please insert your TrueCrypt Rescue Disk. Click OK.

After the verification passes, click OK again.
TrueCrypt, The Rescue Disk has been successfully verified. Click OK.

If possible, back up the new .iso file to a free cloud service to have it available if a CD appears faulty. The Rescue Disk does not provide any access to the encrypted disk without correct password.

Decrypting system drive with TrueCrypt

If you need to discard TrueCrypt full disk encryption for some reason (maybe you're selling your PC), open TrueCrypt from Start menu or Notification Area icon.
Open System menu and click Permanently Decrypt System Partition/Drive.
TrueCrypt main window, System menu. Click 'Permanently Decrypt System Partition/Drive' to remove protection from system drive.

TrueCrypt will confirm the action. Click Yes.
TrueCrypt, Are you sure you want to permanently decrypt the system partition/drive. Click Yes.

TrueCrypt will give a final warning that all your data will be unprotected. Click Yes.
TrueCrypt, Are you really sure you want to permanently decrypt the system partition/drive. Click Yes.

The decryption process starts - this is usually quite a bit faster than the encryption process. You can use your computer normally during this, or use Pause/Resume button to free system resources temporarily. If your reboot your computer, the decryption process will continue automatically after you log in the next time.
After the process is complete, click OK in the success notification.
TrueCrypt Volume Creation Wizard, The system partition/drive has been successfully decrypted. Click OK.

As usual, you must restart your computer to complete the decryption process. Click Yes in the prompt.
TrueCrypt Volume Creation Wizard, Your computer must be restarted. Click Yes.

Using TrueCrypt Rescue Disk for troubleshooting

If you run into trouble with encrypted system drives or partitions, TrueCrypt Rescue Disk is your best friend.
First, make sure you set your computer to boot from CD/DVD-drive.
Second, you cannot use TrueCrypt Rescue Disk from another computer - each disc is unique to the specific computer.

After your PC starts from the disc, TrueCrypt Rescue Disk menu appears instead of TrueCrypt Boot Loader.
If you are using Rescue Disk due to failed System Encryption Pretest, you should press Esc key here to load Windows and let TrueCrypt restore the original bootloader.
Otherwise, press F8 key to access Repair Options.
TrueCrypt Rescue Disk. If System Encryption Pretest failed, press Esc key. If you see no boot loader or Windows is not able to start, press F8 key.

Available Repair Options menu appears.
In case your computer does not start at all due to a failed hard drive firmware upgrade or some nasty malware (TrueCrypt Boot Loader does not appear anymore and you see a blank screen), press 2 to Restore TrueCrypt Boot Loader.
Press Y to execute the command.
After the process is complete, reboot your PC without TrueCrypt Rescue Disk and see if the correct Boot Loader appears.
If not, use option 3 to Restore key data (volume header).
TrueCrypt Rescue Disk, Available Repair Options. To restore TrueCrypt Boot Loader, press 2. Then press Y key to modify drive. Reboot your computer and see if TrueCrypt Boot Loader appears.

If you see TrueCrypt Boot Loader, but Windows is not able to start despite extensive troubleshooting, the last resort is to decrypt the system drive.
Press 1 to Permanently decrypt system partition/drive and enter your encryption password.
TrueCrypt Rescue Disk, Available Repair Options. If Windows is unable to start and you need to recover files, press 1 to decrypt system partition or drive. Then enter encryption password.

TrueCrypt will warn you that the decryption process is much faster in Windows. Press Y to start decrypting the drive.
The process will probably take many hours and TrueCrypt displays the percentage of completion. Do not reboot or power off your computer without pressing Esc key first for safe interruption of the process, for you might lose all data on the drive!
After the "Drive decrypted" message appears, restart your computer without TrueCrypt Rescue Disk.
TrueCrypt Rescue Disk, Decryption under windows is much faster. Press Y to start decryption. After the process completes, 'Drive decrypted' is displayed.

 

Sub Navigation

Sub Navigation
Next: Enhancing Windows performance
Previous: Create and use TrueCrypt volumes
comments powered by Disqus