Taking work now — the first look is freeDrives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
BLKBitLocker Data Recovery 0800 6890668 Price my job

ASUS · ZenBook · VivoBook · ROG · MyASUS · AMD fTPM · recovery key

ASUS BitLocker recovery. An ASUS BIOS update, and the recovery screen on the other side of it.

ASUS laptops, the ZenBook and VivoBook lines and the ROG gaming machines, reach the BitLocker recovery screen the way other makes do: a BIOS or firmware update, through MyASUS or Windows Update, changes the boot measurements the TPM checks, the TPM withholds BitLocker's key, and the machine asks for the recovery key. The data is intact; the drive is sealed, not damaged. ASUS shares Lenovo's AMD angle, because many ASUS and ROG machines are AMD-based, and on AMD a firmware update or CPU change can reinitialise the firmware TPM, after which the machine will not boot without the recovery key; ASUS BIOS updates enabling or changing fTPM settings have prompted this for a good many owners. On a personal ASUS the key is usually in the owner's Microsoft account. The fix is to find and enter the key, and we are for lost keys and failed ASUS drives, which with the key are routine.

Owner-only, proof requiredFree first look£800 + VAT, one diskThe honest answer either way

Rather talk it through? An engineer answers the bench line
0800 6890668

Stop before you reinstall or reformat anything. If the machine is at the BitLocker recovery screen, the data is intact behind the key; reinstalling Windows, reformatting the drive or clearing the TPM again will not get you in and can overwrite what is there. Do not keep typing the wrong key until a device locks you out. If the machine is still running and unlocked, do not shut it down before you have read the lost-password pages. Find your recovery key first, and send nothing until you have.

Why ASUS machines hit the recovery screen, and the AMD angle.

ASUS delivers firmware updates through MyASUS and Windows Update, and a BIOS or firmware update changes the early-boot measurements the TPM seals BitLocker's key to. Change them and the TPM withholds its key, so BitLocker asks for the recovery key. It is the ordinary firmware story across ZenBook, VivoBook and ROG.

Like Lenovo, ASUS has an AMD angle, and it has been particularly visible. Many ASUS and ROG machines are AMD-based, and ASUS BIOS updates that enable or change the firmware TPM (fTPM) setting have sent large numbers of machines to the recovery screen, because changing fTPM reinitialises it and the machine then needs the recovery key to boot. It is the same cause as any firmware trigger, made more common by fTPM-related BIOS changes on AMD ASUS boards.

The data is intact. Enter the 48-digit recovery key, usually from the owner's Microsoft account on a personal ASUS, or the organisation's directory on a managed one. Suspending BitLocker before a BIOS update avoids the prompt, and is especially worth it on AMD ASUS machines. If the ASUS drive has also failed, we image it and decrypt the image with the key.

What to know about ASUS and BitLocker.

MyASUS and BIOS updates are the triggerMyASUS and Windows Update keep ASUS firmware current, and each firmware change alters the TPM's measurements, sending a BitLocker machine to the recovery screen. The recovery key opens it; suspending BitLocker before the update avoids the prompt.
AMD fTPM changes are a common ASUS causeMany ASUS and ROG machines are AMD-based, and BIOS updates that enable or change the firmware TPM setting reinitialise it, after which the machine needs the recovery key to boot. It has affected a lot of ASUS owners, and the recovery key is the way back in.
Suspend BitLocker before a BIOS updateASUS and Microsoft both advise suspending BitLocker before a firmware or BIOS update and resuming after, so the TPM re-seals cleanly. It is especially worth doing on AMD ASUS machines where fTPM changes are common.
A failed ASUS drive is routine with the keyASUS laptops fail like any other, and a failed ASUS drive with BitLocker on is imaged and decrypted with the recovery key. The failure is the problem; the key makes the encryption a non-issue.

What you see, and what is behind it.

Describe yours to us →
What you see The usual reason Where that leaves you
Recovery screen after an ASUS BIOS updateFirmware changed the TPM measurementsEnter the recovery key; the data is intact
ASUS will not boot after an fTPM BIOS changeThe firmware TPM was reinitialisedThe recovery key; nothing is wrong with the data
ROG machine asked for a key after MyASUSA firmware update via ASUS's toolSame cause; the recovery key opens it
Happens after enabling fTPM in the BIOSChanging fTPM resets itThe recovery key; suspend BitLocker next time
ASUS drive also failed, key heldA hardware job with the key availableImaged, then decrypted with the key

From the drive arriving to your files going back.

Work we have closed →
01

Logged the day it lands, and the first look costs nothing Free

A number goes on the parcel and the drive the day it is opened, matched to your enquiry by the booking sheet inside. Before anything is read we check the proof of ownership you sent. The drive is then connected through a write blocker, read-only, and examined: whether it is a healthy drive behind a lost key, or a failing drive behind a known key, is settled here, and so is whether what you want is possible. That first look is free, and you may stop at it owing nothing.

Nothing to pay for lookingProof of ownership checked firstRead-only, nothing written to the drive
02

Imaged at the sector level, before anything else

A drive that answers at all is imaged in full on a hardware imager, behind a write blocker, weak areas last, with a map kept of what could not be read. The image is a copy of the encrypted sectors, so it is useless to anyone without your key, which is a privacy gain in itself. Every later step is done on the image. The original drive is never decrypted, never written to, and never worked on directly.

Sector by sector, behind a write blockerNothing written to the original
03

The physical fault repaired on the clone, when there is one

A drive that has failed, that reads slowly or that drops out is stabilised and imaged in passes; a mechanically failed disk is repaired and read on the bench, a dead SSD controller read at the chip level, before any decryption is attempted. The aim at this stage is one clean image of the encrypted volume to decrypt from. Where the drive is healthy and the problem is only the key, this stage is skipped.

Mechanical and chip-level work where neededOne clean encrypted image to work from
04

The image decrypted with your key or password

With your recovery key, recovery password or the drive's password, the image is unlocked: the protector releases the Volume Master Key, the VMK releases the Full Volume Encryption Key, and the volume is decrypted from the clone. Where the metadata or header is damaged, repair-bde and the key package rebuild it at the block level onto a separate target. Where the key is lost but a memory image or hibernation file is available, the Volume Master Key is extracted from it with Passware. Without a key, a password to attack, or a memory capture, the volume cannot be opened, and you are told so at the free look.

Protector → VMK → FVEK → volumeDecrypted from the clone, never the original
05

The file system rebuilt, and the list before the bill

Once the volume is open it is an ordinary NTFS or exFAT file system, and any damage in it is repaired on the image and the files recovered. What was recovered is listed for you first, and only then does a bill exist. The files go home on fresh media. The original drive is returned, or securely destroyed at your request; we never send the key and the data by the same route.

Files listed before any invoiceFresh media, supplied with the job3–7 days at the bench

From the bench

  • Changing the fTPM setting on an AMD ASUS BIOS resets it, and the machine then needs the recovery key; have the key before touching fTPM.
  • Suspend BitLocker before an ASUS BIOS update, especially on AMD machines.
  • A failed ASUS drive is routine with the key. Do not reinstall over it; image and decrypt instead.

ASUS fTPM BIOS changes on AMD machines reinitialise the firmware TPM and have sent many owners to the recovery screen.

What helps, and what harms.

Do this much first

  • Find and enter the 48-digit recovery key
  • Have the key before changing fTPM or updating the BIOS
  • Suspend BitLocker before ASUS firmware updates
  • Send proof the drive is yours if it needs lab work

What sets us back

  • Changing the fTPM setting without the recovery key in hand
  • Reinstalling Windows over intact data
  • Rolling back the BIOS to try to get in
  • Assuming an fTPM reset destroyed your data; it did not
We recover BitLocker drives for the people who own them. Before any work begins we ask for proof that the drive is yours or that you are authorised to have it recovered: a purchase receipt, the device serial, a letter on company letterhead for a work machine, or written authorisation from the owner, together with photo ID and a signed authorisation. It is a condition of the work, not a formality, and it is what keeps the service on the right side of the Computer Misuse Act. A drive with no proof of ownership is returned unread.

Questions answered before you commit.

Why does my ASUS ask for a BitLocker key after a BIOS update?

Because ASUS delivers firmware updates through MyASUS and Windows Update, and firmware is part of the boot chain the TPM measures. An update, especially one that changes the AMD firmware TPM setting, changed those measurements, so the TPM withheld its key and BitLocker asked for the recovery key. Your data is intact; enter the key.

I enabled fTPM on my ASUS and now it wants a BitLocker key. Why?

Changing the firmware TPM setting reinitialises it, so the chip no longer holds BitLocker's key, and the machine asks for the recovery key to boot. The data is untouched; enter the 48-digit key. In future, suspend BitLocker before changing fTPM or updating the BIOS.

How do I stop my ASUS asking for a key when it updates?

Suspend BitLocker before the firmware or BIOS update, and especially before changing any fTPM setting, then resume after. It lets the TPM re-seal cleanly so no recovery screen appears. It is the best habit for an AMD ASUS with BitLocker on.

Where is the recovery key for my ASUS?

On a personal ASUS running Windows Home, usually in the Microsoft account you signed in with, at account.microsoft.com/devices/recoverykey. On a managed ASUS, escrowed in your organisation's directory, where IT can read it out.

What does it cost?

If the key is in your account and the ASUS drive is healthy, finding it costs nothing from us. A failed ASUS drive falls under single-disk recovery at £800 + VAT, 50% non-refundable on acceptance and 50% no fix, no fee.

The data is behind the key, not gone.

Looking at it is free, and it starts with whether you have the recovery key or can retrieve it. Tell us the make and model, what the recovery screen says, and what happened just before it, and send proof the drive is yours. Back comes a straight account of what is possible and the one price to do it. Until then, reinstall nothing and reformat nothing.

0800 6890668