Data Recovery Case File · Portable Drives · What Ejecting Is For
Pulled Out, and Now It Will Not Connect
His enquiry names the moment it went wrong and blames it, reasonably. An external drive used with a laptop: "it was working until I withdrew it physically before ejecting the drive. When plugged in again I have a white light and can hear whirring, but it won't connect. I have tried the disk utility and its repair function, and no connection to the drive." Removing a drive without ejecting is a genuine risk and worth explaining properly. But it does not usually produce a drive that will not connect at all — so there is a second thing going on, and the repair attempts are the part to worry about.
| Media | External hard drive used with a laptop — removed without ejecting; powering and spinning on reconnection without presenting a volume; repair utility attempted |
| Reported situation | Drive removed physically without being ejected · powering on reconnection with indicator lit and drive audibly spinning · no volume presented · disk utility and its repair function attempted without connection |
| Fault class | Failure to present a volume beyond the scope of an unclean removal — readiness or structure failure to be established separately |
| Equipment used | No further repair attempts permitted · drive removed from the enclosure and assessed on a native connection · readiness sequence read directly under strict timeouts · imaged write-blocked · structures rebuilt on the image |
The decode: what ejecting protects, and why this is more than that
What ejecting actually does: not a formality. Operating systems buffer writes in memory to make things fast, so a file that appears saved may still be waiting to be written. Ejecting tells the system to flush everything outstanding to the device and confirm it landed, then marks the volume cleanly closed. Pulling a drive before that can leave writes unfinished and the filesystem marked as still in use — which is the risk, and it is real.
What that risk actually produces: a volume that is inconsistent — structures half-updated, a file that saved partially, or a filesystem flagged as not cleanly unmounted. On a Mac such a drive usually still appears: it shows in the disk utility, often greyed out, sometimes mounting read-only, sometimes prompting a repair. The drive is present and the volume is questionable.
Why his symptom is different: he reports no connection at all, with the drive lit and spinning. That is a stage earlier than a damaged filesystem — it means the device is not presenting itself in a usable way, which an unclean removal does not normally cause. So the eject is unlikely to be the whole story, and something about the drive's own readiness needs establishing. Drives also fail for their own reasons at moments that happen to coincide with something memorable, and the memorable thing gets the blame.
Why that distinction matters practically: because it changes the expected work. A filesystem left inconsistent is rebuilt from an image and usually returns everything with folders and names. A drive that cannot present itself needs its readiness sequence examined first, and the two are not the same job.
The repair attempts, and this is the real concern: he has run the disk utility's repair function. Those tools do not inspect and advise — they form a conclusion about what the structure should be and write it back. On a volume that is merely inconsistent that is often fine, and on one where the underlying device is struggling it is not, because the conclusion is drawn from reads that may be failing. A repair that fails leaves things largely alone; a repair that succeeds on bad information can overwrite the structures a rebuild would have used. It should not be run again.
What the light and the whirring establish: power reaching the drive and platters turning, which eliminates a dead enclosure and a seized mechanism. That is a reasonable starting position.
The habit worth keeping, briefly: eject properly, and if a drive will not eject because something is using it, close applications rather than pulling it. It matters most on the drives people are most casual with.
On the bench
No further repair attempts were permitted, since those tools write their conclusions back and a conclusion drawn from failing reads overwrites the structures a rebuild depends on. The drive was removed from the enclosure and assessed on a native connection, with the readiness sequence read directly under strict timeouts — establishing whether the failure to present was a device-level matter rather than the filesystem damage an unclean removal explains. It was imaged write-blocked and structures rebuilt on the image.
The outcome
The repair stopped, the drive assessed natively under strict timeouts and the structures rebuilt from the image. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone who pulled a drive without ejecting: that is a real risk and it usually produces a volume that still appears while refusing to mount cleanly — not a drive that will not connect at all. So a drive lit, spinning and entirely absent has probably done something else as well. Stop running the repair function, which writes its conclusions back.
Drive pulled out without ejecting that now won't connect
Stop running the repair utility — that's the thing most likely to make this worse. Those tools don't inspect and advise; they decide what the structure ought to be and write that conclusion back, and where the underlying reads are failing the conclusion comes from bad information. A repair that fails is much better than one that succeeds. As for the eject, it's a genuine risk but it explains a different symptom: systems buffer writes in memory, so pulling a drive early can leave writes unfinished and the filesystem flagged as still in use. That normally leaves a drive that still appears, greyed out or prompting a repair. A drive that's lit and spinning and won't connect at all is a stage earlier than that, so something else is likely involved too.
Don't run the repair again — call Newcastle Data Recovery on 0191 406 1051; assessed on a native connection under strict timeouts, imaged write-blocked, structures rebuilt from the copy.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.