Data recovery
Recover files from a failing disk.
MBI Clone starts with a health check of the disk, without reading its data. It then makes a rescue image of it on a disk or network share in your workshop. Files are recovered from this image, including deleted files, without reading the failing disk’s data again.
From health check to recovered files.
- Before connecting: a few questions about the disk’s condition, while it is still powered off.
- Health check: within seconds, a light and a sentence saying what to do, then the SMART details.
- Rescue image: the whole disk, sector by sector, copied into a file in your workshop.
- Files: the image can be browsed, and the selected files are extracted with a list to hand to the customer.
A light, and what to do next
- Green light
- The disk reports no sign of failure; its SMART attributes, or its NVMe health log, were read and compared with their thresholds. This is not a guarantee: the check does not read the surface.
- Amber light
- The disk is degrading or wearing out: reallocated or pending sectors, uncorrectable errors, a failed self-test, wear at its threshold, SSDs included. Copy the data without delay.
- Red light
- The disk predicts its own failure, shows mechanical signs, reports a fault or stops responding, or a physical sign was noted before connecting it. Depending on the case: copy the data with no further attempts, or send the disk to a data recovery lab.
- Undetermined
- The check cannot conclude: SMART unreadable (a USB enclosure that does not pass it through, RAID, a memory card), unstable responses or link errors. Connect the disk directly if possible and run the check again. MBI Clone never gives a green light without SMART data.
Rescue image
Copy the disk before it fails completely.
The customer’s disk is copied in full into a file, on an NTFS volume or a network share in your workshop. After that, its data is not read again: the disk only stays connected while you browse the image and extract files from it, so that MBI Clone can check that the image is not on that disk.
- Before the first read, the disk is taken offline and made read-only for Windows. On this computer, it stays that way after the rescue, until you choose “Bring back online…”.
- Before copying, a quick surface analysis assesses the disk: depending on what it finds, MBI Clone suggests continuing, stopping or sending the disk to a data recovery lab. On a red light, the analysis only runs if you force it.
- What matters most first: the partition tables, the start and end of each partition, then the rest, damaged areas last.
- Read profiles for a hard disk, an SSD, a dead head or slow firmware.
- A surface map shows what has been read; skipped areas can be retried at the end.
- Resumes after a stop or a power cut, except when the disk’s identity cannot be read (some USB enclosures, card readers).
- Emergency stop on every screen, effective once the current read ends.
Files
The files, retrieved from the image.
MBI Clone reads the volumes in the image and shows their files by folder, with filters by type and status, a search and a preview. You tick what should be returned to the customer.
NTFS, FAT32 and exFAT
Windows disks, USB sticks and memory cards. If the partition table has been erased or damaged, or a partition has been deleted, the volume is located through its boot sector.
Deleted files
Listed with their original name and folder when these are still known, emptied Recycle Bin included, on NTFS, exFAT and FAT32. The old folders of a quick-formatted USB stick are found too. A file whose space has been reused is flagged as overwritten.
Found by their content
When nothing is left to show where a file was, the deep search recognises it by its content: photos, PDFs, Office documents, Outlook messages, audio files, SQLite databases… A photo is named after the date it was taken, a document after its title.
The status of each file
Intact, partial, unreadable, uncertain or overwritten: each file is labelled with its status. A file found without its original address is verified according to its format on extraction, and ticked files can be verified on request: a photo is decoded, a document or an archive is decompressed and its checksums compared.
A list for the customer
Files are extracted to a disk or network share in your workshop, with the list of recovered files to hand to the customer: for each one, whether it was recovered in full, in part or not at all, and what its format says about it when it has been verified. A log explains why a file could not be returned in full.
During the copy
The file list can be viewed while the image is being made. Files can be extracted once the rescue has been stopped or has finished.
The customer’s disk, protected from the health check through to the end of the rescue.
A health check that reads no data
The check queries the disk through a fixed list of read commands: identification, SMART over SATA, and over USB when the enclosure passes it through, error and self-test logs, health log on NVMe. Over SATA and USB, each command has a 10-second timeout; a check that runs for more than a minute is abandoned.
Registered as “under recovery”
Before the check sends its first command, the disk is registered as “under recovery”: cloning, transfer and DiskPart leave it alone, even after a restart, until you release it.
Recognised across enclosures
When the enclosure passes the identification through, its serial number, and its WWN for a SATA disk, are read from the disk itself, not from the enclosure: it stays recognised if it moves to another USB enclosure or to a direct SATA port.
Intake form
Printed, or saved as an HTML page: the disk handed in, its condition before power-on, the result of the check, the risks explained to the customer, and their consent.
A lab when needed
Unusual noise, a drop, a burning smell, liquid damage, a disk that does not spin up: MBI Clone recommends a data recovery lab. The check then only runs if you force it, and that choice is logged.
The data stays in your workshop
The image and the recovered files stay on your disks or your network share. Only the diagnostic report, if you send it, goes to MB Informatique, without the contents of files or sectors.
Good to know
What recovery does not do.
- BitLocker volumesRecognised in the image, but not read yet.
- ReFS, Mac and Linux disksReFS volumes are recognised but not read; HFS+, APFS and Linux file systems are not supported.
- Repairing a diskMBI Clone does not repair the disk: a mechanical or electronic failure is a job for a lab.
- Guaranteeing a resultA failing disk may not be readable in full, and an overwritten file cannot be recovered. MBI Clone shows the status of each file; it does not guarantee their recovery.
See also
Cloning
Clone Windows to a new SSD
A faithful copy of the Windows installation to a new disk. MBI Clone does not duplicate the manufacturer’s layout: it rebuilds it, then checks the partitions, file system, boot and recovery before handing the disk back to you.
- Checks before the first write
- To a larger or smaller disk
- UEFI or BIOS boot verified
Profile transfer
Transfer profiles to a new PC
Files, AppData, registry and saved passwords: MBI Clone creates the local account and transfers the profile into it, from the old disk or over the local network.
- From the old disk or over the local network
- Accounts, files, AppData and saved passwords
- A report of what is left to do
Equip your workshop.
A one-month pass at €30 excl. VAT without renewal, a monthly subscription at €30 excl. VAT or an annual subscription at €300 excl. VAT: one licence per company, with unlimited technicians, computers and migrations, and updates included.