Data Recovery Case File · Formatted & Logical Faults · Read Without Writing
Installing an Operating System to Reach Data Writes to the Disk You Are Trying to Read
Her enquiry lists a sequence of increasingly determined attempts. A laptop that died overnight and would not boot, where changing the boot order failed, a recovery environment failed, and then, "to access my data at least," she installed a second operating system onto it — after which the drive showed as unallocated with nothing visible. Installing is the one step in that sequence that writes, and the distinction between running a system and installing one decides a great deal.
| Media | Laptop hard drive not booting — partition structures reported as unallocated following recovery attempts including an operating system installation |
| Reported situation | Laptop functioning normally then failing to boot overnight · boot order altered without effect · recovery environment attempted from removable media without success · alternative operating system used in an attempt to reach the content · drive presenting as unallocated with no content visible · machine being brought in for assessment |
| Fault class | Partition structures absent following prior failure and subsequent write activity — original loss cause and installation impact to be separated; content regions likely retained |
| Equipment used | Write activity from prior attempts assessed separately from the original failure · imaged write-blocked at the block level before any interpretation · installation footprint located and excluded from the reconstruction · original partition boundaries recovered from residual volume structures · content carved by signature within each reconstructed partition |
The decode: what each attempt did, and what unallocated means
Why changing the boot order was harmless: it changes where the machine looks. Nothing is written and nothing on the drive is altered, which makes it a reasonable first step.
Why the recovery environment was mostly harmless: it reads and offers repairs. Provided no repair was accepted, it examines rather than alters — though repairs offered there do write.
Why the last step is different in kind: installing an operating system writes deliberately and extensively. It creates partitions, writes filesystem structures and copies system files, all onto the disk being investigated.
Why the distinction is not obvious: the intention was to read. Using another system to reach files is sound reasoning, and only the method matters — running a system from removable media does exactly that without writing.
What running from removable media would have done instead: everything she wanted. A system started from a stick can mount and copy from the internal drive without installing anything, which is the standard approach and costs nothing.
What unallocated actually reports: no partition definitions found. The system read the partition table and found nothing describing a volume, which is a statement about a small structure at the start of the disk.
Why that does not mean the content is gone: partitions are descriptions. Files occupy the same regions whether or not anything describes the boundaries around them.
Why the two causes must now be separated: the partition table may have been lost in the original failure, or replaced during the installation. Which happened determines how much the installation cost.
Why that is establishable: an installation leaves a recognisable footprint. Its structures sit in known positions and can be located and excluded, leaving the original layout to be reconstructed around them.
Why the outlook is reasonable despite everything: an installation occupies a small fraction of a drive. It writes at the beginning and consumes a few gigabytes, so content further in is very likely untouched.
On the bench
Write activity from prior attempts was assessed separately from the original failure — boot order changes altering nothing on the drive and recovery environments reading unless a repair is accepted, whereas installing an operating system creates partitions, writes filesystem structures and copies system files onto the disk under investigation. An unallocated report indicates no partition definitions found, a statement about a small structure rather than about content. The installation footprint was located and excluded from the reconstruction.
The outcome
Prior write activity assessed separately from the original failure, the installation footprint located and excluded, and original boundaries recovered from residual structures. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: your reasoning was right and the method wrote. A system run from a stick reads the internal drive without installing anything — and unallocated describes a missing partition table, not missing files.
Using another operating system to reach your files
Run it from the stick rather than installing it — most alternative systems offer a live session that starts from removable media, mounts your internal drive and copies files off, without writing anything to the disk you're trying to read. Installing does the opposite: it creates partitions, writes filesystem structures and copies system files onto that same drive. Your other steps were fine, since changing boot order alters nothing and a recovery environment only writes if you accept a repair. Unallocated means the partition table is missing, not your files.
Stop there — call Cambridge Data Recovery on 01223 655015; write activity separated from the original failure, installation footprint excluded, original boundaries recovered from residual structures.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.