Rescue Corrupted WD External HDD

Aug 11, 2014 49 Replies

A computer semi-literate might not feel the cold shivers down the back at that question and just reflexively agree.

--sp

Hopefully you *won't* put your hard drive in the freezer. That can be a very bad thing.

Rick

"Accessed"?

I realize much of this is probably coming to you second-hand (from her). But "hand-waving" isn't a good diagnostic tool.

First, what version of Windows is she running?

Second, did she "do" (click) anything "disk related" (for that disk) prior to removing it? E.g., Windows typically complains that a disk is "not formatted" (the Linux partition being unrecognizable to Windows) and offering to format it for you (which you would decline, in this case).

Third, how long between the insertion event and unplugging? I.e., was Windows just performing its initial probe of the device? Or, was it dicking with the disk for some other reason? (e.g., because she told it to format the drive!)

It won't show up under Windows until it has been "registered" (signed) as such and formatted. You could look under "disk management" to see that the drive is visible there (as a "disk" without a letter) and see what partitions are visible on the drive (even if they aren't named by Windows).

First step is to look at the boot record and partition table. I.e., that's where every OS *starts* its examination of a drive.

On a UN*X box, you could examine the *raw* device (not a slice or partition) to see what the disk looks like, logically. If the boot record appears intact, then, chances are, nothing beyond there was actually altered.

Note, however, that this doesn't mean the *enclosure* supporting the drive hasn't been altered in some way. Or, that the drive's internal configuration hasn't been "tweeked". (E.g., I have an external IDE enclosure that will promptly and irreversibly reconfigure any > 127GiB drives to have 127GiB limits ENFORCED BY THE DRIVE'S CONTROLLER... even after the drive is removed from the enclosure and placed in a "more tolerant" enclosure!)

Be wary of attempts to image the drive as anything that relies on an interpretation of the partition table can be fooled if the partition table is nonsense! Ideally, you want to image the

*raw* device -- which could lead to a pretty sizeable image if the drive's contents (even "empty" sectors) aren't readily compressible.

Don't dick with things you don't understand. :-/ Your errors take mere ohnoseconds to become permanent!

Maybe the Master Partition table is toast. There is a backup, usually ;)

Anyway I'd try something like Spin Right to recover what is on there.

Cheers

SystemRescueCD comes to mind. You are in a lot better shape if you know what the partitioning was before (even approximately), then you can guide the rescue tools better. I have pulled of some amazing rescues with it and similar tools.

?-)

the

currently

the disc using dd or ideally gnu dd_rescue. This will work as long as the hardware is alive, regardless of whether there is an intact filesystem that the operating system can understand.

then various tools can be applied to try and restore the filesystem structure or at least pull off the most important files.

clone is a very bad idea, as this may make things much worse.

YES! Highly recommended. Make several. Just be sure the target drives are of at least the same size in blocks or larger (preferably only a little bit, but twice the size is OK).

?-)

I've from time to time felt the need for a hardware read-only option on HDDs.

"Am I really copying *from* the disc I want to read, *to* the disc I want to write, and not the other way around?"

So far, I've not got that wrong, but one day...

Sylvia.

This is possible on (older) SCSI disks.

On UN*X boxen you can, of course, mount a drive/partition R/O

GUARANTEED to 10^6 percent trash the drive. Even the finest dust is like tossing a huge bolder in front of a rollerskate going 100MPH. Never, ever open a hard drive unless all you want out of it is the magnet and maybe some pretty shiny platters for artwork.

Case? What case? ***DO NOT*** take the drive apart, unless what you want is some expensive and useless metal.

Check. After one verifies that the computer BIOS recognizes the drive.

"WD external HDD"

i.e., disassemble the EXTERNAL HDD ENCLOSURE so you can remove the drive contained therein and connect it directly to a SATA port.

Sounds reasonable! And, reasonably safe!

Of course, it assumes that the drive is a SATA drive (I have some "WD external HDD" enclosures with PATA drives inside). And, that the drive inside has a genuine SATA/PATA/etc. interface (instead of a more highly integrated USB interface -- as many of the small "pocket sized" WD enclosures have)

I have recovered two hard drives that otherwise were completely un-recognized by the BIOS. Cooling a hard drive some definitely changes alignment in some way that made them readable. The SHOT-TERM sitting in a freezer cooled off everything inside the case.

Yes....it dew happen, even after a check and a double check... Unfortunately there aint no sech ting.

Yes, I will never buy WD again. Short term thinking on their part.

When I plug the corrputed drive into Win 7, Explorer does not show it and then crashes.

TestDisk also hangs up, and does not proceed to detect any drives at all on my system.

I will try Jan's Linux solution tomorrow.

David King

That's fine if one wants to mount it. If one wants to use dd, or some other direct I/O mechanism, one just has to be very careful.

Sylvia.

Note that if you don't care about the data WD will replace the drive if it's still under warranty. I think that they have a 2 or 3 year warranty.

First of all, please find out the version of Windows is running on the other machine. Starting with Windows 8, Microsoft, in its zeal to Kill off Linux, started the nonsense of Secure Boot, UEFI etc., This has caused very irritating issues for dual-boot machines, as I have observed from personal experience. All the latest Linux distributions have added workarounds to deal with these issues on the dual boot machines. So, if a Linux formatted hard drive is used as an external hard drive for a Windows 8+ machine, there could be any number of guesses as to what the real problem is. Very likely, your hard drive needs a full re-formatting, and it is very likely that all existing data is lost for ever.

As I said, older SCSI drives typically had a "R/O" jumper. Of course, the OS needs to understand that a drive can't be written without "consent" for this to be meaningful -- even if mounted R/O!

I've never seen one on a PATA drive. And, suspect they aren't present on SATA drives, either.

[I'd have to check my FC drives to see what they support. And I;m not sure whether or not SAS drives would mimic their ancestors in this regard]

I would have expected that if the drive had a R/O jumper set, that it would not accept write commands even if they were sent.

Sylvia.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required