Data Recovery Case File · Desktop Externals & Aging Drives · Two Problems, One Not Real
The Slowness Was the Warning, and the Locked Folders Are Not Damage
His enquiry is honest about what he did and contains a second problem that is not a problem at all. A laptop drive that "probably suffered damage when I thumped it for being so slow. The drive was making a noise as if it was stuck trying to read something. I took it out and attached it to an external cable and could see the folder structure and access program files, but it wouldn't let me into documents and settings." Two separate things are happening here — a genuine physical fault he made worse, and an access refusal that is ordinary security behaviour and can be resolved in a minute.
| Media | 2.5-inch laptop hard drive — slow access preceding physical impact; attached externally with folder structure readable and user profile directories access-denied |
| Reported situation | Drive running progressively slowly · audible repeated read attempts · drive struck by the owner · removed and attached through an external cable · folder structure visible and program directories accessible · user profile directories refusing access |
| Fault class | Physical read degradation compounded by impact — user directory refusal being access control rather than damage |
| Equipment used | Further host access discontinued · access-control refusal distinguished from read failure before assessment · Atola Insight Forensic error-rate assessment · imaged write-blocked under per-sector timeouts · ownership resolved against the image rather than the drive |
The decode: the folders first, because that part is easy
Why he cannot open the user folders, and it is not damage: when a drive is attached to a different computer, the user profile directories on it are protected by access control — a record of which account owns them, tied to the original installation. A different machine, with different accounts, is not on that list, so it refuses. The folder is intact, readable, and simply not being handed over.
How that is resolved: by taking ownership of the directory from the attached machine, which is an ordinary administrative action and takes moments. The fact that he can browse the structure and open program directories — which carry no such protection — while being refused on user folders is the exact signature of this, and it is one of the commonest false alarms in the whole subject. People conclude their data is destroyed when it is merely private.
Now the real problem, and it came first. The drive was slow and making repeated noises as it tried to read. That is a drive retrying sectors internally — the mechanism attempting a region, failing its checksum, and trying again, with each retry costing time. Slowness of that kind is the commonest early symptom of physical read failure, and the noise was the drive telling him what was wrong.
What the impact did, said plainly and without lecturing: striking a drive that is powered and spinning is the worst mechanical thing that can be done to it, because the heads are flying microscopically above surfaces turning at speed, and a shock can bring them into contact. Frustration with a slow computer is universal and the response is understandable. But the drive was already failing when he hit it, and the blow will have added surface damage to a mechanism that was struggling.
Why the outlook is still reasonable: he can read the structure, which means the drive spins, identifies itself and returns data. That is a working starting position. The task is to capture it before it degrades further — which is why further browsing should stop, since every exploratory session is more reading of a compromised surface.
Why ownership is resolved against the image: taking ownership of directories writes to the filesystem. Doing that on a failing drive means writing to a device that should only be read. Captured first, the permissions are then adjusted on the copy at no risk.
On the bench
Further host access was discontinued, each exploratory session being more reading of a compromised surface. The access-control refusal was distinguished from read failure before assessment — user profile directories carrying ownership records tied to the original installation and refusing a different machine, which produces an identical symptom to damage and is not damage. The Atola Insight Forensic assessed error rates, imaging ran write-blocked under per-sector timeouts, and ownership was resolved against the image rather than the drive, since taking ownership writes to the filesystem.
The outcome
The permissions question separated from the physical one, error rates measured and the drive imaged under timeout control before ownership was resolved on the copy. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: those two symptoms are unrelated. Being refused on user folders while program folders open is access control, not damage — the directories carry ownership tied to the original installation and a different machine is not on the list. The slowness beforehand was the real fault, and it was the drive retrying reads.
Drive readable except for the user folders
That refusal almost certainly isn't damage. User profile directories carry ownership records tied to the installation they came from, so attaching the drive to a different computer means a machine that isn't on the list — and it refuses. Your files are intact and simply not being handed over. Being able to browse the structure and open program folders, which carry no such protection, while being blocked on documents is the exact signature of it. Taking ownership from the attached machine resolves it in moments, though on a drive that's physically failing it's safer to capture first, because taking ownership writes to the filesystem. And if the drive was slow before any of this, that was the real warning — slowness means it's retrying reads internally.
That's usually permissions — call Guildford Data Recovery on 01483 901310; access refusal distinguished from read failure first, imaged under per-sector timeouts, ownership resolved against the copy.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.