Home / Case Studies / Formatted & Logical Faults
Formatted & Logical Faults · case file

Windows Says It's Unallocated

A series of unexpected shutdowns, and afterwards the drive will not mount under Linux. Checked on a Windows machine, where it appears in Disk Management as unallocated. It still spins and it is still detected. Two separate things are going on and only one of them is a fault. The genuine fault is the partition table or the filesystem: unexpected shutdowns during writes damage the structures describing where everything lives, so the drive is seen but nothing can be mounted from it. The red herring is Windows. Windows cannot read ext4 at all, and a drive it does not understand is reported as unallocated as a matter of course. That report would look identical on a perfectly healthy Linux disk, so it is not evidence of anything. What matters is that the hardware is fine and the data is sitting behind a broken map.

Hard DriveCorruption / Filesystem
// case at a glance
MediaLinux hard drive that stopped mounting after repeated unexpected shutdowns. Shows as unallocated in Windows Disk Management. Still spins and is detected.
Reported situationLinux drive · a series of unexpected shutdowns · will not mount under Linux · shows as unallocated in Windows Disk Management · still spins and is detected · recovery sought.
Fault classPartition table or filesystem damage caused by unexpected shutdowns. The structure describing the layout is inconsistent, so the drive is detected but cannot be mounted. Windows reporting it as unallocated is expected and not diagnostic. The data is normally intact and is reached by taking a read-only image and rebuilding the structure from it.
Equipment usedRead through a hardware write-blocker, so nothing at all could be written, health confirmed on PC-3000 UDMA · imaged read-only on DeepSpar · partition table and the Linux filesystem reconstructed from the image using R-Studio and UFS Explorer, files carved by content where structure had gone · everything validated before it was written to fresh media.
// the decode

The decode

Start with the good news, which is in the description already. It spins and it is detected. That eliminates the expensive fault classes at a stroke: no head fault, no seized motor, no dead board, no firmware failure. The mechanism is doing its job and the electronics are doing theirs. What is broken is bookkeeping.

Unexpected shutdowns are hard on journalling filesystems in a specific way. A write in progress leaves the journal and the on-disk structures temporarily out of step, and the journal is designed to sort that out on the next mount. Do it repeatedly, though, and the damage can outrun the journal — particularly if the shutdowns happened during metadata operations, or if the partition table itself was being rewritten.

Then the Windows part, which needs firmly setting aside. Windows has no native support for ext4 or the other Linux filesystems. Presented with one, it sees a partition it cannot interpret and offers to initialise the disk. That offer is genuinely dangerous — accepting it writes a new partition table over the old one and destroys the very structure a recovery would rebuild from. Say no.

The work itself is logical and among the more satisfying categories on the bench. The drive gets imaged read-only, then the partition table and filesystem are reconstructed from what survives in the image, with superblock backups, journal contents and directory records all pulled into the reconstruction. Where structure is gone entirely, files are carved by content. Logical work, so it runs under no fix, no fee, with a free assessment finished within 2 working days of arrival.

// on the bench

On the bench

It was read through a hardware write-blocker, so that nothing at all could be written to it, and its health was confirmed on PC-3000 UDMA — spinning and detected proved to be an accurate description. It was imaged read-only on DeepSpar and every subsequent operation ran against the image. The partition table was reconstructed and the Linux filesystem reconstructed using R-Studio and UFS Explorer, using backup superblocks and surviving directory records to re-establish the layout. Where structure had been destroyed outright, files were carved by content signature. Everything was validated by opening it before it went to fresh media.

// the outcome

The outcome

The drive imaged read-only, the partition structure and filesystem rebuilt, and the data brought back onto fresh media. Assessment free, and one fixed written figure with VAT in it beforehand. This was logical work with no parts consumed and no clean-air stage, so it ran under no fix, no fee — nothing recoverable would have meant no invoice at all. The specific thing that made it straightforward was what had not been done to it: nobody had accepted the Windows offer to initialise, and nobody had run a filesystem check in write mode against a damaged structure. Both are common, and both make this job considerably harder.

A drive that spins, is detected, and shows as unallocated

Refuse every offer to initialise, and be firm about it — Windows will ask more than once and it means what it says. Do not run fsck in repair mode against a Linux filesystem you care about until it has been imaged, because a repair that goes wrong writes over the structures a recovery reads and there is no undo. Do not create a new partition table to make it visible. If you want to look yourself, mount strictly read-only or work from an image taken with something like ddrescue, and never write anything back to the original disk. Unallocated in Windows means nothing on a Linux disk and never did. Send the bare drive, say what filesystem it was and roughly what caused the shutdowns.

Got one of these on your desk right now? Everything here follows the same route: an assessment you are not charged for, completed inside 2 working days of the box reaching the bench, after which you get one written figure that never climbs afterwards. Logical faults are handled on no fix, no fee. Should the casing need opening, or the electronics rebuilding after a drop, a surge, a soaking or a fire, half of that figure falls due first and the rest only once your data is in hand. Ransomware, camera and DVR recorders, BitLocker volumes and anything else classed as forensic get settled in advance, in full. Where the files live inside a machine — laptop, desktop, Mac, server — pull the drive or the SSD and post that by itself. Computers are not dismantled here, and flash fixed permanently onto a logic board (the newer Apple laptops among them) is the one category refused outright. Unscrews or unplugs and we will take it. Send it tracked and insured to Edinburgh Data Recovery, 4 Redheughs Rigg, Westpoint, South Gyle, Edinburgh EH12 9DQ, arrange and pay for a courier of your own, or bring it to the counter there. No device is ever fetched from a customer. Packing notes and the shipping form sit here.
Start a free diagnostic

Each file below comes from a genuine enquiry taken from households and firms across Aberdeen, Aberdeenshire and the wider north-east, anonymised so nobody can be identified. Each one sets out how the fault was reasoned through, what was done about it, and which equipment did the work.

// related case files

Nearby files worth a look

Browse all case studies →

Recognise your own drive in this one?

Assessment is free and takes 2 working days at most once it lands, the figure is fixed in writing, and logical work carries no fix no fee. Begin online, or lift the phone.