Data Recovery Case File · Formatted & Logical Faults · A Different Goal
The System Was Repairing the Volume, Not Saving the Files
His enquiry is a sequence of instructions obeyed exactly. An external drive that stopped working: "I was getting a pop-up telling me there was a problem with the drive and to do a scan, so I did, and it told me there were some problems and to do the recovery, so I did. But then this" made things worse. He was not careless — he followed his computer's own advice at every step, and the reason it ended badly is that the advice was written to achieve something other than what he wanted.
| Media | External hard drive — host reporting volume problems and prompting a scan, then a repair; both accepted; condition deteriorating afterwards |
| Reported situation | Drive ceasing to work normally · host prompting that a problem existed and advising a scan · scan performed on the host's advice · host reporting problems and advising a repair · repair performed on the host's advice · condition worse afterwards · contents required |
| Fault class | Filesystem damage compounded by host repair operations — unverifiable entries discarded; content present beneath |
| Equipment used | Drive removed from use and no further host operations permitted · imaged write-blocked before any reconstruction · pre-repair structures located from surviving backup copies · signature carving alongside · files validated by opening |
The decode: what those prompts are for, and why they cost him
What the operating system was trying to do: restore a volume to a usable state. That is a legitimate goal, it is what those tools exist for, and for the overwhelming majority of users — whose drives hold reinstallable software and files that also live elsewhere — it is the right outcome. A working drive is what the flow is designed to produce.
Why that is not the same as saving his files: the way a repair achieves a usable volume is by making the filing structures internally consistent. Where entries cannot be reconciled, it discards them — because a consistent volume missing some files is usable, and an inconsistent one is not. Consistency is achieved at the expense of whatever could not be verified, and what cannot be verified is disproportionately the material that was in use most recently.
So the sequence he followed: the first prompt reported a problem, which was accurate. The scan confirmed it, which was also accurate. The repair then did exactly what it is for. Every step was correct and the outcome was wrong for him, because at no point did anything ask whether the drive held something irreplaceable.
Why nobody warned him: the prompts cannot know. From the system's position there is a volume with problems and a remedy available, and offering it is helpful. The distinction between a drive I need working and a drive I need the contents of exists only in the owner's head, and nothing in the interface asks.
The rule that follows, and it is the whole lesson: when a drive holds something that exists nowhere else, the answer to every prompt is decline and disconnect. Not scan, not repair, not fix, not check. Those are all writes, offered in the language of help, and they are the correct choice only when the data is replaceable.
Why the position is still recoverable: a repair discards entries rather than overwriting content. The files are physically present, unreferenced, and filesystems keep backup copies of key structures away from the primary set — which a repair frequently rewrites while leaving the duplicates alone. Working from an image, those copies are what returns files with folders and names.
What must not happen now: no further prompts accepted, and the drive should stay disconnected between now and any assessment.
On the bench
The drive was removed from use and no further host operations were permitted, each prompt being a write offered in the language of assistance. It was imaged write-blocked before any reconstruction, and pre-repair structures located from their surviving backup copies — a repair achieving consistency by discarding entries it cannot reconcile while typically rewriting only the primary set, so duplicates elsewhere on the volume survive. Signature carving ran alongside and files were validated by opening.
The outcome
The drive taken out of use, imaged before any reconstruction and pre-repair structures recovered from their surviving copies. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: you followed correct advice to a different destination. Those prompts exist to restore a usable volume, and a repair achieves that by discarding entries it cannot reconcile — consistency at the expense of what could not be verified. Nothing asked whether the drive held something irreplaceable, because nothing can.
Doing what the computer told you and ending up worse off
You followed correct advice — it was just written for a different goal. Those prompts exist to restore a volume to a usable state, which is the right outcome for most people, whose drives hold reinstallable software and files that live elsewhere too. A repair achieves it by making the filing structures internally consistent, and where entries can't be reconciled it discards them, because a consistent volume missing some files is usable and an inconsistent one isn't. Nothing in that flow asks whether your drive holds something irreplaceable, because nothing can know. So the rule is simple: when a drive holds the only copy of something, decline every prompt and disconnect it. Scan, repair, fix and check are all writes.
Disconnect it now — call Guildford Data Recovery on 01483 901310; imaged write-blocked before any reconstruction, pre-repair structures recovered from their surviving copies, files checked by opening.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.