Data Recovery Case File · Formatted & Logical Faults · Not a Device Fault at All
A Version That Was Never a Separate File Cannot Be Found as One
Her enquiry describes a loss with no hardware in it. A document worked on and saved as usual, which the next morning "had reverted to a version from two weeks ago that I had sent to a friend" — with recovery software unable to locate the newer work. Nothing is wrong with the storage, and the reason the software finds nothing is that the version she wants may never have existed as a separate file on the disk.
| Media | Working storage holding a document reverted to an earlier state — hardware unaffected; superseded content sought |
| Reported situation | Document worked on across a session and saved · document found the following morning in a state matching a copy from two weeks previously · that earlier copy having been sent to a third party · advice received attributing the loss to accidental overwriting · consumer recovery software unable to locate the newer version · recovery sought |
| Fault class | File superseded in place or replaced by an older copy — no device fault present; recoverability governed by whether prior content persists in unallocated space or application-managed copies |
| Equipment used | Absence of any device fault established before assessment · overwriting in place distinguished from replacement by a separate file · device removed from use before imaging · imaged write-blocked before any scanning · application recovery copies, temporary files and unallocated regions examined for prior content |
The decode: what probably happened, and where the newer version might still be
Why this is not a storage problem: the drive is working normally and the file is present. What changed is its contents, which is an application and filesystem question rather than a hardware one — and it means nothing needs repairing.
What "accidentally overwritten" most likely describes: the older copy being saved over the newer one. If the version sent to her friend came back — reopened from an email, a download folder, or a synced location — and was then saved to the original name, it would replace the newer work exactly as described.
Why the software finds nothing, and this is the crux: recovery tools search for files that were deleted, looking for content that still sits in space marked as available. A file saved over is frequently not deleted at all — the same file is updated in place, so there is no deleted version anywhere to find.
Why that distinction decides the whole case: deletion leaves content behind until it is overwritten, which is what makes ordinary recovery possible. Overwriting in place replaces content directly, and where an application writes new content over old within the same file, the previous state is simply gone from that location.
Why some applications behave differently and this matters: many write a new temporary file and then replace the original, which does leave the previous version in unallocated space. Which behaviour applies depends on the application, so it is worth establishing rather than assuming — and it is the difference between a recoverable case and one that is not.
Where else the newer version may exist, and these are worth checking first: the application's own recovery or autosave copies, which are frequently retained separately; temporary files from the editing session; and any cloud or account-based version history, which keeps prior states independently of the file itself.
Why version history is the most promising of those: where documents are stored in an account that retains versions, the state before the overwrite is held as a separate record. That is unaffected by anything that happened to the file, and it is checked in minutes.
Why continued use of the machine is the risk: if a previous version does exist in unallocated space, it is being displaced. An operational computer writes constantly into space marked available, so the window for that route narrows every hour the machine runs.
What the honest position is: if the application saved in place and no autosave or version history exists, the newer work is very likely gone. That is worth establishing quickly rather than pursued at length, and the checks that would find it cost nothing.
On the bench
Absence of any device fault was established before assessment — functioning storage with the file present indicating an application and filesystem matter rather than hardware. Overwriting in place was distinguished from replacement by a separate file, recovery tools locating content in space marked available following deletion, whereas a file updated in place is not deleted and leaves no prior version to find, while applications writing a temporary file and replacing the original do leave the previous state in unallocated regions. Application recovery copies, temporary files and unallocated regions were examined.
The outcome
No device fault established, overwriting in place distinguished from replacement, and application copies and unallocated regions examined. Free assessment, one fixed written figure including VAT. The decode: your storage is fine, and the software finds nothing because a file saved over is usually not deleted at all — it is updated in place, so there is no deleted version to locate. Where an application writes a temporary file and replaces the original, the previous state does survive.
A document that reverted to an older version
Check three places before anything else, and stop using the computer meanwhile. Look for the application's own autosave or recovery copies, which are often kept separately; temporary files from the editing session; and any account-based version history, which retains prior states independently of the file and is checked in minutes. Understand why recovery software found nothing: it searches for deleted content sitting in space marked available, and a file saved over is usually updated in place rather than deleted, so no earlier version exists to find. If a version does survive in unallocated space, a running computer is displacing it.
Stop using the machine — call Easy Data Recovery on 028 9002 0144; overwriting in place distinguished from replacement, imaged before any scanning, application copies and unallocated regions examined.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.