04 · Scenarios
Patterns we see again and again
Educational composites, not paid reviews. They mirror common forum threads so you can calibrate expectations.
“After a bad eject the SD looked empty. Deep scan took ages but brought most photos back.”
“Shift-deleted a folder. Junk ‘free’ tools everywhere. A clean installer + recover to another disk worked.”
“Laptop SSD: almost nothing. TRIM had cleaned blocks. Backups matter more than undelete.”
“USB wanted a format. Cloned sectors first, then scanned. Names were gone but files opened.”
“Emptied Recycle Bin on Friday. Monday panic. Quick scan still saw paths; recovered to a spare SSD before reinstalling anything big.”
“Dual-boot Linux resize went wrong. Windows saw RAW. Deep scan pulled docs but the partition table needed a pro—Recuva was only half the story.”
These are composites for learning, not testimonials. Use them to ask: Is metadata still there? Is TRIM or encryption in play? Am I still writing to the sick volume? When two of those stack against you, adjust expectations before you spend a weekend on scans.
Quick read
Accidental delete, disk still healthy
Try quick scan first, recover out to another drive, verify a few files, then consider deep scan only if paths never appeared.
Quick read
Card or USB misbehaving
Stabilize power and ports, clone if you can, then deep scan the image or device. Expect generic names if the filesystem is damaged.
Quick read
Internal SSD, days since delete
Hope for backups and cloud versions; treat undelete as a long shot once TRIM and idle time have passed.
“Outlook PST vanished after a bad shutdown. Deep scan found a huge file with a junk name—renamed to .pst and Outlook opened it. Not pretty, but mail came back.”
“Crypto note on the desktop, weird extensions everywhere. Recuva wasn’t the answer—we restored from offline backup. Undelete can’t reverse encryption.”
When to escalate past undelete
- Physical noise or SMART red flags
- Image or power down; software scans rarely fix motor or head problems.
- Full-disk encryption you cannot unlock
- No key means no plaintext blocks for a consumer tool to read.
- Suspected ransomware
- Isolate the machine, preserve logs, and lean on backups or incident response—not mass undelete on the encrypted volume.