Data Recovery Case File · Formatted & Logical Faults · Reconstructing the Sequence
A Nearly Full Drive Showing One File Has Lost Its Directory, Not Its Contents
His enquiry sets out a sequence and ends with a fair question. A drive "only showing an autorun file when I can see it is nearly full when I look at properties", following a replaced internal drive, a machine that would not start with a second external attached, and a reformat that did not help. The occupancy figure and the file listing disagree, and that disagreement is the finding — everything else is context.
| Media | External hard drive reporting substantial occupancy while listing a single startup file — following replacement of the machine's internal drive and reformatting of a second external drive |
| Reported situation | External drive listing only a startup file · drive properties reporting it as nearly full · machine's internal drive having failed and been replaced · machine not starting with a second external drive attached · second drive copied and reformatted without resolving that · first drive subsequently recognised afresh on each start · first drive now not accessible |
| Fault class | Directory structures unreadable with allocation retained — occupancy confirming content present and undescribed; unrelated host events forming context rather than cause |
| Equipment used | Occupancy figure reconciled against directory listing to confirm content presence · unrelated host events separated from the drive's own fault · imaged write-blocked before any interpretation · primary and duplicate directory structures compared · files validated by opening |
The decode: which observation matters, and what the rest of the sequence was
Why the two figures cannot both be right: properties reports the drive as nearly full while the listing shows one small file. Occupancy is read from the filesystem's record of allocated space, and the listing from its record of files — two separate structures, and only one of them is being read successfully.
What that establishes immediately: the content is there. Space marked as allocated with nothing described as occupying it means the directory has been lost, not the data — which is the most useful thing in his account.
Why the single file showing is characteristic: a startup file of that kind sits at the very beginning of the drive. The first region is frequently the one that still reads when later structures do not, so a lone early file appearing is consistent with directory damage rather than with an almost-empty drive.
Why the rest of his sequence is context rather than cause: the internal drive failing, the machine not starting with a second external attached, and the reformat are separate events. None of them writes to this drive, and the temptation to connect them into one story is worth resisting.
What the machine not starting with an external attached actually was: the machine attempting to start from it. Computers examine attached devices for something to start from, and an external drive carrying startup structures can be selected ahead of the internal one — which explains that symptom entirely and has nothing to do with a fault.
Why that explains the autorun file's significance differently: the presence of startup-related files on an external drive is exactly what caused the machine's confusion. It is a clue to the earlier symptom rather than to the current one.
What "recognised afresh each time" suggests: the machine treating a known device as new. That follows an operating system reinstall, which discards its record of previously seen devices — again context, and again not a fault.
Why the reformat of the second drive is the one thing worth flagging: it was carried out to solve the startup problem and did not. It also erased that drive's directory, and if its content was copied first, that copy is now the only version — worth confirming rather than assuming.
What is done with the drive that matters: imaged, then the directory rebuilt from the duplicate structures filesystems maintain elsewhere on the volume. The allocation record already tells us how much should be there, which gives a check on whether the reconstruction is complete.
What must not happen: no formatting this drive, and no repair utility run against it. The allocation figure proving the content exists is exactly what a format would clear.
On the bench
The occupancy figure was reconciled against the directory listing to confirm content presence — allocation and file records being separate structures, so substantial reported occupancy alongside a near-empty listing indicates directory loss rather than absent content, with a lone startup file at the drive's beginning consistent with early regions still reading. Unrelated host events were separated from the drive's own fault, a machine failing to start with an external attached indicating startup selection rather than a defect.
The outcome
The occupancy figure reconciled against the listing, host events separated from the drive's fault, and the directory rebuilt from duplicate structures. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: the two figures disagreeing is the finding. Space allocated with nothing described as occupying it means your directory is lost and your content is not — and most of the sequence around it was the machine trying to start from an external drive.
A drive that says it is full and shows almost nothing
Don't format it or run a repair — the occupancy figure proving your content exists is exactly what a format clears. That disagreement is the useful finding: allocation and file listings are separate records, so a drive reporting nearly full while showing one file has lost its directory rather than its contents. A lone file at the very start is consistent with early regions still reading. Separately, if a machine wouldn't start while an external drive was attached, that's the computer trying to start from it rather than a fault — worth knowing so you don't fold it into the same story.
Don't format it — call Easy Data Recovery on 028 9002 0144; occupancy reconciled against the listing, host events separated from the drive's own fault, directory rebuilt from duplicate structures.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.