Data Recovery Case File · Portable Drives · Triage by Fragility
The Most Fragile One Goes First and Gets Touched Least
His enquiry describes three drives and, without meaning to, an ordering problem. Two "seem corrupted — I can see the files and folders using a recovery program, but it would take a while to copy them"; the third "when connected restarts or shuts down my laptop, but I have managed to view the files on the odd occasion that it's not restarted." Those are three different states with three different urgencies, and the order matters more than the method.
| Media | Three external hard drives — two presenting content to third-party recovery software; one causing host shutdown on connection with intermittent access |
| Reported situation | Three external drives requiring extraction · two presenting files and folders to recovery software · copying from those described as slow · third drive causing the host to restart or shut down on connection · occasional successful access to that drive's contents · all three required |
| Fault class | Two stable logical faults and one progressive fault with intermittent access — capture order determined by fragility rather than convenience |
| Equipment used | Unstable drive addressed first and removed from host connection · Atola Insight Forensic error-rate assessment on that member · imaged write-blocked under strict per-sector timeouts with retries capped · stable drives imaged subsequently with structures rebuilt from surviving copies |
The decode: why the crashing one goes first
What the two readable drives tell us: that they are stable. A recovery program can enumerate their files and folders, which means the devices respond reliably and the structures are damaged rather than the hardware. Those two are not deteriorating while he decides — they will present the same content next month as they do today.
What the third one tells us: something quite different. A drive that restarts or shuts down a computer is not answering reads — requests are issued and never completed, holding system resources until the machine gives up. That is severe read failure, and the fact that access is occasionally possible means the drive is intermittently capable and mostly not.
Why that makes it the priority: intermittent access is a diminishing resource. Each successful window is one of an unknown and shrinking number, and the drive is being asked to fail repeatedly in between. The stable drives can wait; the unstable one cannot, and doing the easy ones first because they are easier is the wrong order.
Why it must also stop being connected, and this is the part in tension with the above: every connection attempt is more sustained work on a failing mechanism, and it brings down his machine as a side effect. The good windows should be spent on a controlled capture, not on checking whether this is one of the good windows. That means no more test connections at all.
On the two he can read, and why copying through the tool is not ideal: it works, and it is slow because the software reads through the operating system, file by file, with all the overhead that involves. It also generally produces output without folder structure or original dates. Imaging the device once and rebuilding the structures against the copy is faster and returns the organisation — which for two drives' worth of content is a meaningful difference.
What is worth establishing across all three: whether they shared anything — a power source, a hub, a shelf, a machine. Three drives in trouble at once invites the question, even where the faults differ.
What to do today: disconnect the third one and leave the other two alone. Neither instruction costs anything and both preserve the position.
On the bench
The unstable drive was addressed first and removed from host connection — intermittent access being a diminishing resource, where the two stable drives present the same content indefinitely and are not deteriorating. The Atola Insight Forensic assessed error rates on that member, and imaging ran write-blocked under strict per-sector timeouts with retries capped, unanswered reads being what holds host resources and forces the shutdown. The stable drives were imaged subsequently with structures rebuilt from surviving copies.
The outcome
The unstable drive captured first under capped timeouts, the stable pair imaged afterwards with their structures rebuilt. Free assessment, one fixed written figure including VAT per drive; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: the drive that crashes your laptop is the one to do first and touch least. Its intermittent access is a shrinking resource, while the two your software can read are stable and will present the same content next month.
Several drives to recover, in different states
Do the most fragile one first and stop connecting it in the meantime — those aren't contradictory. A drive that restarts or shuts down your computer isn't answering reads, and the occasional successful access means it's intermittently capable and mostly not, which makes each working window one of an unknown and shrinking number. Those windows should be spent on a controlled capture rather than on checking whether this is a good one. The drives your recovery software can already enumerate are stable by comparison and will show the same content next month. Copying through the tool works but is slow and usually loses folder structure, so imaging them is worth it.
Disconnect the unstable one — call Guildford Data Recovery on 01483 901310; most fragile addressed first under capped per-sector timeouts, stable drives imaged afterwards with structures rebuilt.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.