Call us — 0191 406 1051
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · There Is a Second Copy

The Table Went, Not the Partitions

His enquiry describes a loss with a clear trigger and one detail that needs pinning down. A disk carrying three partitions where, "after my system hanging and forcing me to reboot, they now appear to have disappeared. I have tried a number of partition managers, but none of them see my attached disk, let alone work with the partitions." A forced reboot during a hang is a classic way to lose a partition table — and modern disks keep a second copy of it in a place most tools never look, which is why this is frequently straightforward.

MediaHard disk formerly carrying three partitions — partitions no longer presented following a forced restart during a system hang
Reported situationSystem hanging during use · machine restarted by force · three partitions no longer present afterwards · several partition management tools tried · tools reported as not seeing the attached disk · partitions not workable
Fault classPartition table damage from an interrupted write — secondary table copy typically intact; enumeration to be confirmed separately
Equipment usedNo partition table write, repair or rebuild permitted · enumeration confirmed before any table work · imaged write-blocked before any reconstruction · secondary partition table located at the end of the disk · volumes reconstructed on the image and validated by opening

The decode: what a forced reboot interrupts, and where the backup lives

Why a hang plus a forced restart does this: the partition table is small and it is written rarely — but it is written, whenever a volume is created, resized, mounted with changes, or when certain utilities touch it. If the system was in the middle of such an operation when it hung, and power was removed by force, the table can be left half-written. It occupies a tiny region at the very start of the disk, so damage to it removes the description of every partition at once while touching none of their contents. Three partitions do not disappear; one small structure describing all three does.

Where the second copy is, and this is the useful part: modern partitioning schemes keep a backup copy of the partition table at the opposite end of the disk, in the last sectors. It exists for precisely this situation. A damaged primary table with an intact secondary is one of the more routine recoveries there is — the layout is read from the backup, the volumes reappear exactly as they were, and files come back with folders and names entirely intact.

The detail that needs pinning down first: he says the tools cannot see his disk, not just his partitions. Those are very different statements. If the tools genuinely cannot see the device at all, then the fault is at enumeration — the disk is not presenting itself — and no amount of partition work applies, because there is nothing to work on. If they see the disk and show it as empty or unallocated, that is the partition table case and the outlook is good. Establishing which is true costs nothing and decides everything, and it is worth being precise about before anybody starts.

What must not happen, and this is the real risk here: partition tools do not merely inspect. Faced with a disk showing no partitions, they offer to create a new table, write a fresh one, or rebuild what they think should be there. Writing a new partition table overwrites the damaged primary — and some tools write the secondary at the same time, which removes the backup copy that would have solved this. Every additional tool tried is another opportunity for one to write something.

Why the work happens on an image: a reconstruction hypothesis can be tested against a copy repeatedly at no cost, and a wrong guess costs nothing. Applied to the disk itself, a wrong guess is permanent.

On the bench

No partition table write, repair or rebuild was permitted — partition tools offer to create or rebuild a table when they find none, and writing one overwrites the damaged primary while some tools write the secondary at the same time, removing the backup that resolves the case. Enumeration was confirmed before any table work, since a device not presenting itself is a different fault entirely. The disk was imaged write-blocked, the secondary partition table located at the end of the disk, and volumes reconstructed on the image and validated by opening.

The outcome

Enumeration confirmed first, the disk imaged before any reconstruction and the layout recovered from the secondary table. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose partitions vanished after a forced reboot: the partitions did not disappear, the small structure describing all of them did — and modern disks keep a backup copy of that structure in the last sectors, precisely for this. Do not let any tool write or rebuild a partition table, because some write the backup too.

Partitions that disappeared after a forced restart

Don't let any tool create, write or rebuild a partition table — that's the one thing that turns this from routine into serious. Your partitions haven't disappeared; the small structure at the start of the disk that describes all of them has been damaged, most likely half-written when you forced the restart. Modern disks keep a backup copy of that structure in the very last sectors, which exists for exactly this situation, so recovering the layout from it usually brings every volume back with folders and filenames intact. The danger is that partition tools offer to write a fresh table when they find none, which overwrites the damaged original — and some write the backup at the same time. Also worth checking whether your tools can see the disk itself or just not the partitions.

Partitions gone after a crash or forced reboot?
Don't let anything write a new table — call Newcastle Data Recovery on 0191 406 1051; enumeration confirmed first, imaged write-blocked, layout recovered from the secondary table at the end of the disk.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.