Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Second Fixes & Trade Handoffs · Work From the Copy

The Difficult Part Is Already Done

His enquiry buries the most important sentence in the middle. A returning customer with "a hard drive that's not dead, it just won't mount. I can see the data in terminal and have managed to make a disk image of the data, but I thin"k something is wrong with it. He has done, unprompted, exactly what a recovery firm would do first. Once a good image exists, the failing drive stops being the constraint — there is no more wear, no time pressure and no limit on attempts. What remains is a question about the image itself, and there is one specific thing worth checking.

MediaHard drive readable at block level but not mounting — full disk image already taken by the owner; reconstruction required
Reported situationDrive readable at block level and visible from the command line · volume failing to mount · disk image successfully created by the owner · reconstruction of contents sought
Fault classFilesystem structure damage over readable media — content intact; work proceeds against the image
Equipment usedImage completeness verified against device capacity and error logging · original drive retained and set aside · structures rebuilt against the image including surviving backup copies · signature carving alongside · files validated by opening

The decode: what the image gives him, and what to verify about it

Why imaging first is the correct order: every attempt at reconstruction — mounting, repairing, rebuilding, carving — can be run against a copy as many times as needed, with a wrong hypothesis costing nothing. Run against the original, each attempt is more work for a struggling drive and some of them write. Taking a full sector image before touching anything is the first thing done professionally, and he did it himself.

What being visible from the command line tells us: that the device responds to block-level reads. Sectors can be requested and returned, which means the drive, its electronics and its connection are working. That is the layer beneath filesystems and it is functioning.

Why it will not mount despite that: mounting requires the operating system to read the volume's structures and find them coherent. Where they are damaged — an interrupted write, a partially applied change, a corrupted catalogue — the system declines rather than presenting something it does not trust. The files themselves are untouched; what is damaged is the index describing where they are.

The one thing to check about the image, and it is the reason his instinct that something is wrong may be right: completeness. Imaging tools behave differently when they meet a sector they cannot read. Some stop. Some retry indefinitely. Some skip silently and carry on, filling the gap with zeros and reporting success at the end. An image made by a tool of that last kind can look complete, be exactly the right size, and contain holes where the drive struggled — and if those holes fall in the filesystem structures, the image will refuse to mount for a reason that has nothing to do with the original damage. An image is only as good as its error record. So the questions are: does the image size match the device's true capacity, and does the tool's log report read errors, and how many?

What follows from the answer: if the image is clean, the whole job is reconstruction against the copy and the drive can go in a drawer. If it has gaps, a second pass over the missing regions specifically — with per-sector timeouts and repeated later attempts — fills them in, and the original drive is needed once more for that.

What to do meanwhile: keep the original drive and do not let anything repair or mount it read-write. And keep a second copy of the image, since it is now the only complete copy of the data.

On the bench

Image completeness was verified against device capacity and error logging before any reconstruction — since tools differ in how they handle unreadable sectors, and one that skips silently produces an image of exactly the right size containing zero-filled holes, which will refuse to mount for reasons unrelated to the original fault. The original drive was retained and set aside rather than worked on further. Structures were rebuilt against the image, including the backup copies filesystems maintain at known positions, with signature carving alongside, and files validated by opening.

The outcome

The image verified for completeness first, the original set aside and the structures rebuilt against the copy. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who has imaged their own drive: you have done the part that matters, and the failing drive is no longer the constraint — attempts against a copy cost nothing and cause no wear. Now verify the image rather than trusting it, because tools differ at unreadable sectors and some skip silently, producing a full-size image with zero-filled holes. Check the size against true capacity and read the error log.

Made your own image of a failing drive

You've done the part that matters — but verify the image before trusting it. Imaging tools behave very differently when they hit a sector they can't read: some stop, some retry forever, and some skip silently, fill the gap with zeros and report success at the end. An image from that last kind looks complete, is exactly the right size, and has holes wherever the drive struggled. If those holes fall in the filesystem structures, the image won't mount for reasons that have nothing to do with the original problem. So check two things: does the image size match the drive's true capacity, and what does the tool's log say about read errors. If it's clean, the drive can go in a drawer and everything else happens against the copy. Keep a second copy of the image — it's now the only complete copy you have.

Already imaged the drive and stuck on the rest?
Verify the image first — call Newcastle Data Recovery on 0191 406 1051; completeness checked against true capacity and error logs, structures rebuilt against the copy, files validated by opening.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.