File Name: Extents
File Submitter: erwan.l
File Submitted: 26 May 2013
File Updated: 24 Mar 2019
File Category: Tools
This is a simple GUI to FSCTL_GET_RETRIEVAL_POINTERS .
The idea is to read all clusters belonging to file, then map these clusters on the logical drive where this file is located, and from there re assemble all clusters and save them to a new destination file.
Thanks to this method, one can save/copy a file which is in use since we "raw" read clusters from a logical drive.
This has been tested with success on \boot\bcd and \windows\system32\config\sam .
Files which you cannot copy in a normal mode.
zip file contains source file next to the binary.
Click here to download this file