Data Recovery Case File · Desktop Externals & Aging Drives · The Log Knew First
Event Viewer Recorded the Fault Before He Noticed
His enquiry did something almost nobody thinks to do, and it turned an unexplained failure into a documented one. A 2TB hard drive: "stopped working today. It's not being detected in Disk Management, and I've checked in the event viewer — three hours before the failure there was a critical error stating that Windows Disk Diagnostic detected a hardware self-monitoring fault on the disk." He then asked, reasonably, how likely recovery is and what it might cost. The technical answer follows. But the finding itself deserves the page, because it describes something that happens constantly and is almost never noticed: the machine knew three hours before he did, and told nobody.
| Media | 2TB hard drive — no longer detected by the operating system's disk management; system event log recording a self-monitoring fault approximately three hours before failure |
| Reported situation | Drive failed without warning from the owner's perspective · absent from disk management · critical event logged three hours prior · owner having located the log entry himself |
| Fault class | Self-reported drive fault progressing to loss of identification — deterioration documented in the host log before presentation failed |
| Equipment used | Atola Insight Forensic identification and surface diagnostics · PC-3000 Express technological-mode access with service-area assessment · Data Extractor imaging under strict timeouts; losses reported per file |
The decode: what the log recorded, where those warnings go, and what it means now
What the entry actually means: hard drives monitor themselves continuously, tracking things like reallocated sectors, read error rates and the health of their own reserved regions. When one of those crosses a threshold the manufacturer considers serious, the drive reports a fault, and Windows records it as a critical event. So the message he found is the drive saying, in its own words, that it had detected something it considered terminal — three hours before it stopped presenting itself at all.
Where those warnings go, and why nobody sees them: the genuinely useful part. That event was recorded in a system log that is not shown to the user in any prominent way. There is no notification, no banner, and nothing that interrupts what you are doing. Unless someone happens to open the event viewer — which is what he did, after the fact — the warning sits there unread. So the common experience of a drive failing "without warning" is frequently untrue: the warning existed and was filed somewhere nobody looks. That is worth knowing because it can be changed. Drive health can be checked deliberately, and it takes minutes: the event log can be reviewed for disk-related critical entries, and self-monitoring status can be read directly with freely available tools. A drive that reports a fault is telling you to copy your data off today, and three hours is a real window if anyone is listening.
What it means for his recovery: honestly. The combination — a self-reported fault, followed by the drive no longer being detected — describes deterioration that has progressed past the point of presenting itself. That usually means either the reserved firmware regions the drive needs before it can identify itself have become unreadable, or the surface degradation has reached the point where start-up cannot complete. Both are worked at bench level through the manufacturer's own technological modes rather than by anything a computer can do, and both are recoverable often enough to be well worth attempting. What cannot be promised in advance is completeness, because a drive that reported its own failure has genuine damage somewhere — so the deliverable should be a per-file account rather than a percentage.
What to do now: stop connecting it. There is nothing further to learn, and each attempt asks a drive that has already reported its own failure to try again.
On the bench
The Atola Insight Forensic established what the drive was reporting during identification and assessed its surface directly, which turned his log entry into a measured picture — whether the failure to present was a firmware-region problem or general surface deterioration. Access followed through the PC-3000 Express in the drive's technological modes, with the service area read directly and its damaged modules assessed and repaired until the drive would identify itself and address its media. Imaging then ran under Data Extractor with strict timeouts, the healthy expanse captured first and the weak regions revisited afterwards, with every unreadable area resolved to the files it affected.
The outcome
The self-reported fault verified by measurement, access restored at firmware level and the contents imaged with losses named per file. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode, for anyone whose drive failed without warning: it very often did warn, and the warning was filed in a system log with no notification attached — so "no warning" usually means nobody was looking; drives monitor themselves and report faults they consider terminal, and that report is worth checking deliberately rather than after the fact; a self-reported fault followed by loss of detection means deterioration has passed the point of self-identification, which is bench work through the manufacturer's own modes; and the right deliverable is a per-file account rather than a percentage.
Checking whether your drive is warning you
Do it now rather than after a failure. Drives monitor themselves continuously and report faults they consider serious, and your computer records those reports — but it files them in a system log with no notification, no banner and nothing that interrupts you, which is why so many failures feel like they came from nowhere. Open your system's event log and look for critical entries mentioning disks or disk diagnostics, and read your drives' self-monitoring status directly with any of the freely available tools that do it. If anything reports a fault, treat it as an instruction to copy your data off today rather than as something to monitor — a drive that has declared its own failure may have hours rather than weeks. And if a drive has already failed and you find such an entry afterwards, stop connecting it: it has told you what it thinks, and further attempts only spend what's left.
Stop connecting it — call Glasgow Data Recovery on 0141 404 0294; identification and surface measured, service area repaired in technological mode, imaged under strict timeouts with losses named.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.