Data Recovery Case File · Formatted & Logical Faults · The Reinstall That Wrote Over the Evidence
Recover Files After a Windows Reinstall: What the Install Wrote Over
His account described a fix that worked perfectly and cost him everything it was meant to save. A hard drive failed and "stopped my PC from starting up." His remedy was resourceful: "I then got Windows off of an external hard drive and downloaded it back onto the failed hard drive, which then begun to work again and acted as usual — but all of the old files before the failure are gone." His question: can they be recovered? He asked for email contact, which was honoured throughout. Two decodes below, and the first is genuinely encouraging: the fact that the drive "acted as usual" afterwards tells us the original failure was almost certainly software, not hardware — a healthy disk with a broken system on it. The second is the arithmetic that decides his odds: what a Windows installation actually writes, and what it leaves alone.
| Media | Internal PC hard drive — original boot failure; Windows subsequently reinstalled onto the same drive; drive now healthy and functioning; pre-failure user files absent |
| Reported situation | Boot failure resolved by reinstalling Windows to the same disk · machine working normally since · all previous files missing · email contact requested and honoured |
| Fault class | Overwrite of filesystem structures by OS installation — user data partially surviving in unallocated regions; recoverability governed by writes since |
| Equipment used | Drive imaged write-blocked (Atola TaskForce 2) · previous filesystem structures located and reconstructed on the image · OSForensics signature carving and deleted-entry recovery · recovered set validated by opening and delivered on separate media |
The decode: what an install writes, and what it never touches
Why the drive was probably always healthy: the most useful thing in his message is what happened after the reinstall — the machine ran normally. A drive with failing heads or dying media does not quietly accept a fresh operating system and behave itself; it stumbles, stalls and fails again. So the original "failure" was almost certainly the system's own structures — a corrupted boot configuration, a damaged registry, a botched update — sitting on a perfectly sound disk. That matters twice over: it means the physical odds are good, and it means the files were never destroyed by the failure at all. They were abandoned by the fix.
What the installation actually did: installing Windows onto an existing disk writes a new filesystem at the front of the partition and lays the operating system down across it. Two things follow. First, the catalogue that named and located all his old files was replaced — which is why they vanished instantly and completely, and why nothing in the interface can find them. Second, and far more hopefully, an installation only physically occupies a fraction of a modern disk: the system files land where the fresh filesystem chooses to put them, and the great bulk of the platters — where years of photographs and documents were written — is simply marked as free space and left untouched.
The arithmetic that decides the outcome: so his files exist as content without a catalogue, in regions the new install has declared available but not yet used. From that point everything depends on one variable: how much has been written since. A machine reinstalled and then used normally for months — updates, downloads, new documents, a browser cache filling daily — steadily consumes exactly that free space, and each write may land on top of an old photograph. Which is why the only instruction that matters here is the uncomfortable one: stop using the machine now. Every hour of ordinary use is spending the recoverable set, and unlike the original fault, this loss is genuinely irreversible.
What recovery looks like: the disk is imaged write-blocked, and the work happens on the copy — the previous filesystem's own structures hunted at their old positions and rebuilt where they survive, which returns files with their real names and folders; and the whole surface carved by content signature alongside, which recovers documents, photographs and video by their internal structure regardless of any catalogue. The two results are reconciled, validated by opening, and delivered onto separate media — never back onto the drive being recovered.
On the bench
The drive was imaged write-blocked on the Atola TaskForce 2 at once, freezing the disk as of the day he stopped using it — the single most valuable thing he did. On the image, the previous volume's surviving structures were located and reconstructed, returning a substantial part of the old tree with its original names and folders intact; OSForensics carved the free-space regions in parallel, recovering photographs and documents by signature from areas the new install had claimed but never filled, each validated by opening. The two sets were reconciled and de-duplicated, the losses honestly identified where the install had landed on top of old data, and everything recoverable was delivered on separate media with a written account of what had and had not survived.
The outcome
A substantial part of the pre-reinstall archive recovered by structure reconstruction and content carving, verified and delivered with the gaps documented rather than glossed. Free assessment, one fixed written figure including VAT, no recovery, no fee. The lesson, posted for everyone whose fix worked: reinstalling an operating system onto the drive that holds your only copy replaces the catalogue and turns your files into unnamed content in "free" space — recoverable, but only until ordinary use writes over them. If it has already happened, the machine goes off now; and if you are about to do it, install to a different disk and let the old one be read first.
Reinstalled Windows and your old files have gone
Stop using the computer immediately — this is the one instruction that changes the outcome. Your files weren't destroyed by the reinstall; their catalogue was replaced, and the data itself sits in space the new system has marked free but not yet occupied. Every subsequent update, download or new document risks landing on top of it, and that loss is permanent. So: shut the machine down, don't install recovery software onto that drive (it writes to the very space you're trying to save), and don't run disk cleanup or defragmentation. Have the disk imaged write-blocked and worked on the copy — the old filesystem structures often rebuild with real filenames, and content carving recovers the rest. And note the good news in your own story: a drive that ran normally after a reinstall was probably never physically failing.
Turn the machine off and call Leeds Data Recovery on 0113 322 3083; imaged write-blocked, old structures rebuilt, free space carved and validated — one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.