Data Recovery Case File · Formatted & Logical Faults · Found Is Not Recovered
A Scan Result Is a List of What Was Located, Not a Copy of Any of It
Her enquiry describes a very specific place to get stuck. A system update that left an error she cannot get past, where she "used a data recovery program which has allowed me to see that my original files are still on my hard drive" — and now she is "unsure how to fully recover them." Seeing them is genuine progress and it is not the same as having them, and the step she is missing has one requirement that catches almost everyone.
| Media | Internal hard drive following an operating system update — original content located by a scan; recovery not completed; host reporting an error preventing normal start-up |
| Reported situation | System update applied · host reporting an error afterwards · normal access not restored · consumer recovery software run by the owner · original files located and listed by that software · recovery not completed · guidance sought on completing it |
| Fault class | Content located but unreferenced following an update — recovery requiring a separate destination; writing to the source risking the located content |
| Equipment used | Scan listing distinguished from recovered content before any further step · machine removed from use · drive imaged write-blocked at the block level before any interpretation · located content written to separate media rather than to the source · recovered files validated by opening |
The decode: what the list is, and the requirement people run into
What her scan actually produced: a set of locations. The software read the drive, recognised structures and file openings, and recorded where each item begins — it did not copy anything.
Why the display is so convincing: it can show previews. Thumbnails and file names are generated by reading a small part of each item, which is enough to display and not enough to save.
Why that is nonetheless valuable information: it establishes the content exists. A scan that lists her original files has demonstrated that they are physically present and locatable.
Now the requirement that stops people: a destination. Recovery software will not write recovered files to the drive it recovered them from, and it is right to refuse.
Why it refuses: writing would overwrite. The located content sits in space the system considers free, so saving anything there lands on top of what is being rescued.
Why that is the commonest place to get stuck: a second drive is needed and not obvious. Nothing in the process announces that another device of sufficient capacity has to be attached first.
What is genuinely risky about proceeding alone: not the scanning but the saving. A recovery directed at the wrong destination destroys precisely what the scan found.
Why the machine should be out of use meanwhile: ordinary operation writes. A system that starts, even into an error, writes logs and temporary data into the same free space.
Why the update is likely the cause rather than a coincidence: updates rewrite structures. An interrupted or failed update can leave a volume whose directory no longer describes what is on it, while the content remains.
What that means for the outlook: favourable. Her own scan has already shown the content is there, which is the question most enquiries cannot answer at all.
On the bench
The scan listing was distinguished from recovered content before any further step — recovery software recording where each item begins rather than copying it, with previews generated from a small portion of each file, enough to display and not to save. Recovery then requires a separate destination, because located content occupies space the system considers free and writing there overwrites it. Located content was written to separate media rather than to the source.
The outcome
The scan listing distinguished from recovered content, the machine removed from use, and content written to separate media. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your scan found the files and did not copy them. The step you are missing needs a second drive attached — and saving to the original is what would destroy what you found.
When a scan has found your files
Attach a second drive before going any further, and stop using the machine meanwhile. A scan produces a list of locations rather than copies — previews are generated from a small part of each file, enough to display and not enough to save. Recovery software refuses to write results to the drive it scanned, and it's right to: the located content sits in space the system treats as free, so saving there lands on top of what you're rescuing. Your scan finding them is genuinely good news.
You need a second drive — call Cambridge Data Recovery on 01223 655015; the listing distinguished from recovered content, imaged write-blocked, results written to separate media rather than the source.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.