Data Recovery Case File · Interventions · Stop the Scan
Reading a scan's agony as diagnostics: the 24-hour crawl decoded, the two absent folders explained — and the drive imaged properly once the grinding stopped
This enquiry arrived live, mid-process, which made the first reply an intervention rather than a quote. The setup: an overnight copy "which would have taken it to full capacity, possibly over if I miscalculated" — and by morning, file-copy errors and a disconnected drive that would no longer mount, though Disk Utility could see it. His response was a well-known photo-recovery application, and his narration of its progress is the page's evidence: phase 1 stuck at 13% for a couple of hours, then creeping; 24 hours to reach phase 3; now at 3% of that phase, having found 39,829 entries — with all folders listed in the preview "except the two folders I was writing to at the time of failure." The reply that went back within the hour: stop the scan. Here is why that was the whole case — and how everything, including the two missing folders, came home once it stopped.
| Device | External hard drive — filled to near or full capacity by an unattended overnight copy; failed mid-transfer with errors and self-disconnection |
| State at contact | Won't mount; visible in Disk Utility; consumer recovery scan running into its second day — prolonged stalls, slow phase progression, 39,829 entries previewed, the two actively-written folders absent from the listing |
| Fault class | Media degradation surfaced by the sustained transfer — with the scan's own behaviour mapping the failing regions in real time |
| Equipment used | DeepSpar USB Stabilizer 10Gb · ACE Lab PC-3000 Express + Data Extractor (managed imaging; journal and structure reconciliation for the mid-write folders) |
The decode: what the scan's stalls were telling him, and why the two folders were the ghosts
Read the scan as an instrument and his narration becomes a diagnosis. Recovery software progresses by reading the drive, sector after sector — so its speed is a live map of the drive's health: brisk progress is healthy territory; a bar stuck at 13% for hours is the application grinding against a region the drive can barely serve, retrying unmanaged, over and over, against failing media. The 24-hour crawl wasn't the app being thorough; it was the app spending a full day working the drive's worst territory at maximum effort — precisely the treatment a degrading drive can least afford, and the reason the intervention's first word was stop: every additional hour of scanning was a stress test administered to the patient by its own rescue. (The trigger, for the record, was the classic pair this archive keeps filing: a near-capacity fill — allocators churning through the drive's last, least-used territory — under an overnight sustained load, the marathon that finds the wear.) The two missing folders, decoded: their absence from a 39,829-entry preview wasn't their destruction — it was their circumstance. Folders being actively written at the moment of failure have their metadata mid-update: entries half-written, structures caught between states — exactly the records a filesystem-walking scan can't parse into its tidy tree, so it lists everything whose paperwork was at rest and skips the two whose paperwork was in motion. The data of those folders lay where the copy had put it; the listing of them lay in the journal and the interrupted structures — recoverable, but by reconciliation, not by a preview pane. And the quiet third decode his numbers deserve: entries found is not files recovered — a preview's count is candidates sighted, with extraction, reassembly and verification all still ahead; the figure impresses precisely because it's the cheapest stage.
The recovery — after the grinding stopped
With the scan halted, the drive got what the second day of crawling had been costing it: managed reading. On the PC-3000 through the USB Stabilizer, the imaging ran the professional order — the healthy majority (the scan's brisk stretches, essentially) banked quickly; the failing regions (its stalls, now mapped twice over) negotiated in bounded passes that take an answer or a boundary, never an hour at 13%. Coverage closed in the high ninety-nines. On the image, the volume's structures were reconciled — and the two ghost folders resolved exactly as the decode predicted: their interrupted metadata completed from the journal, their trees re-linked, their contents present where the overnight copy had written them — with the honest residue confined to the very last files in flight at the moment of failure, itemised by name as the transfer's true casualties. Verification opened files across the whole estate, the two recovered folders deliberately first; delivery went out on roomier media than the drive he'd nearly overfilled, with the capacity arithmetic gently annotated: drives dislike living at 100%, and the new one has headroom by design.
Outcome
Everything home, including the two ghosts — and the intervention doctrine filed for everyone currently watching a progress bar crawl. A stuck scan is a message, not a queue: hours at one percentage means the software is grinding failing media unmanaged — stop it; the stall has already told you what you needed to know (the drive is degrading there), and continuing converts diagnosis into damage. Missing-from-preview means mid-flight paperwork more often than lost data — the folders being written at failure are the likeliest ghosts and the most recoverable ones, by journal reconciliation rather than deeper scanning. And found-entries is a candidate count, not a result — judge recoveries by verified files, never preview totals. He wrote in at hour 25 instead of hour 50. That email was the recovery's first successful operation.
Recovery scans that stall for hours
Stop the scan — a bar stuck at one figure means unmanaged retries against failing media, and every hour is stress, not progress. Don't restart it, don't try a different app on the same drive, and don't write the preview's findings back to it. Note where it stalled (that's a map of the bad regions) and which folders it couldn't list (usually the mid-write ones — the most reconcilable losses, not the worst). Near-full drives failing during big overnight copies are a pattern; leave headroom, and split marathons into supervised legs.
Stop it now, then call Belfast Data Recovery on 028 9002 0144 — the stalls already drew us the map.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.