When you create a new file, like a picture from your vacation (vacation.jpg), and save it to your hard drive (formatted with the NTFS file system), Windows does a couple things. It finds an open file record in the metadata area of the disk (called the Master File Table or MFT) and writes some information about the file, such as the file name and date. If there are no open file records, Windows will expand the MFT and create a new file record.
Windows then finds some free data blocks on the volume to write the actual file data to. Once the data blocks are identified, Windows links the new file record to the data blocks and writes the actual data to the disk. The picture below illustrates the vacation.jpg file as written to the disk.
So what happens when a file is deleted (assuming it is not going into the Recycle Bin)? Two very important things happen (from a data recovery perspective): 1. The file record is marked as deleted and available for reuse. 2. The data area is marked as free space and available for reuse.
The image above shows the areas of the disk that hold the data for the vacation.jpg file have now been marked as free space and are available for use for new files or to expand existing files. The file record has also been marked as deleted and is available for reuse by the file system. To recover deleted data, your data recovery company or software needs to be able to find deleted file records that have not been overwritten and the data blocks that relate to those files. The DR company or software should also scan the unallocated space on the disk for data blocks that were in use, but whose file records have been overwritten. An example of such a process is as follows:
The figure below illustrates a file that has been deleted, its file record overwritten by a new file, and the data is fragmented on the drive.
Our example file (vacation.jpg) has been deleted and the file record overwritten with a new file (birthday.jpg). The only recovery possible for the vacation.jpg file is to find and assemble the raw data blocks (assuming there isn’t another copy of the FR somewhere else on the volume). The success rate for this type of recovery is very high as the data blocks (Blocks 1-4) in our example have not been overwritten by new data.
If the new file (birthday.jpg) had overwritten some of the data blocks like in the example below, then the file would only be partially recoverable (blocks 2 and 3 overwritten).
If all of the data blocks had been overwritten like the example below then the file would not be recoverable (blocks 1-4 overwritten).