Data Recovery Case File · Linux-Literate · The Half-Rescue
Self-service done right, then stopped right: a live-USB rescue graded, a lost partition entry decoded — and the 2TB completed at the bench
His enquiry described the most competent self-rescue in this tranche. The machine: dual-boot Windows and Linux; the failure: shutdown one evening, "sent to the emergency boot screen upon multiple attempts" the next. His response: boot a live USB system — and from it, access the 256GB system SSD and copy its data out to an external drive himself. Textbook. Then the wall: the 2TB storage hard drive "is not accessible," and the live system's disk utility showed the reason in miniature — the drive listing only a 17MB reserved partition, with the two terabytes beside it showing as nothing at all. He stopped there and wrote in. Both halves of that sequence — the rescue and the stop — get graded below, along with the decode of a partition map that remembers the sliver and forgets the estate.
| Devices | Dual-boot machine: 256GB system SSD (self-rescued via live USB, data secured) · 2TB storage hard drive — inaccessible, partition map showing a 17MB reserved entry and an unrecognised 2.0TB remainder |
| Owner's conduct | Live-USB triage · SSD estate copied out safely · storage drive examined read-only, its state reported precisely · no repair tools, no table rewrites; enquiry sent at the wall |
| Fault class | Damaged partition metadata — the main volume's entry lost while its small system neighbour survives; contents intact behind the broken map |
| Equipment used | Write-blocked imaging · partition and NTFS structural reconstruction on the image · per-folder verification |
The decode: what the surviving sliver proves — and where the self-service line correctly sits
The 17MB survivor, read as evidence: that small reserved partition is a bookkeeping companion the operating system creates beside a main data volume — and its survival is quietly excellent news: it proves the drive's partition table is still being read, the hardware still serving, the map's paper still legible — with one entry, the big one, damaged or lost from it. A drive showing "sliver present, estate absent" is almost never a drive whose two terabytes went anywhere; it's a table missing a line, the classic map-not-territory state this archive rebuilds constantly — and the emergency boot screens that started everything were the same wound viewed from the doomed side: a system stumbling over storage metadata it could no longer parse. The self-service grade, given honestly: his live-USB rescue of the SSD was exactly right — a healthy, readable volume copied out through a read-only-minded environment is self-service at its best, and the securing of one estate before touching the harder problem is professional instinct. And the stop was equally right, at exactly the correct line: the tools a live system offers next — partition scanners with write-back options, filesystem repairs — are the one-way doors this archive documents, and a table rebuilt on a guess over the original converts missing-entry into genuinely-gone. The line, stated for every capable home user: copy freely from what mounts; touch nothing on what doesn't. He walked it precisely.
The recovery — the missing line rewritten, on the copy
The 2TB was imaged write-blocked end to end — the hardware confirmed healthy in the process, the map's damage its only injury — and the reconstruction ran where reconstructions belong: on the image, the main volume's boundaries re-derived from its own surviving internal structures, the lost table entry rewritten on the copy, and the NTFS estate mounting whole: two terabytes of storage exactly where the sliver had implied it must be. Verification ran across the folder tree; delivery went out on new media in duplicate — joining the SSD estate he'd already banked himself, the machine's whole world now secured in two rescues, one his, one the bench's. The report graded the sequence formally: self-rescue of the mounting volume — correct and complete; halt at the unmounting volume — correct and preserving; partition-entry loss rebuilt image-side; hardware sound throughout.
Outcome
The half-rescue completed — his terabytes joining his gigabytes — and the filings his sequence earns. Copy what mounts, immediately: a live system is the right tool for securing readable volumes from an unbootable machine, and doing it first is the professional order. Stop at what doesn't: a partition map showing slivers-without-estates is a missing line, not a missing archive — and every scanner's "write/fix/rebuild" offer is a one-way door best opened on an image. And read small survivors as good news: the reserved partition's presence proved the table readable and the hardware willing — evidence, not debris. He rescued half the machine and diagnosed the other half by knowing when to stop. The bench only had to finish the sentence.
Live-USB triage on a broken machine
Use it for copying: mount what mounts, secure the irreplaceable first, and work read-only throughout. When a drive shows partial or empty partition maps, stop — no table writes, no repair flags, no "fix" prompts; note exactly what the disk utility displays (small surviving partitions are diagnostic gold) and bring the drive in as-is. The missing entry rebuilds on a copy in hours; a guessed rewrite over the original can cost the estate. Capable self-service ends at the first unmountable volume — that's not a failure of skill, it's the definition of the line.
Perfect place to stop — call Belfast Data Recovery on 028 9002 0144; the missing partition line rebuilds on the copy.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.