CHKDSK audits the catalogue rather than the warehouse, and that distinction decides whether it rescues an afternoon or ends a recovery. Here is what each switch does, why resolving a contradiction usually means deleting one side of it, what ends up inside the found.000 folder and why, the four conditions under which running it is entirely sensible, and what it costs to undo when none of them applied.
Read this before you type anything. The tool audits filing and cannot reach the hardware, so on a dying disk it destroys recoverable material while trying to be helpful. Where that has already happened, one drive is £300 + VAT and the examination that says what survived is free.
Most people reach this page holding a command that somebody on a forum told them to type. Here is what each one does, arranged by how much damage it is capable of, so the decision can be made with open eyes instead of in hindsight.
Purely read-only. It inspects the filing structures, reports what it believes is wrong, and alters not one byte in the process. This is the only version on the list that is safe on a disk holding something irreplaceable, and it answers the question most people actually have. Nobody quotes it, because it fixes nothing.
Fixing means writing. Entries that cannot be resolved get removed, records that look wrong get shortened, and structures are rebuilt so they agree with each other rather than so they match what used to be there. Perfectly sensible on sound hardware after a power cut. On a disk that is dying it is the fastest way to lose material.
Everything the fix switch does, and then a sweep of every sector on the volume with relocation of anything the tool dislikes. On a multi-terabyte disk that is hours of continuous heavy reading, and heavy continuous reading is the single most punishing thing you can ask of a drive already struggling to answer at all.
This one makes whatever is using the volume let go first, and it usually turns up alongside the fix switch out of habit rather than thought. It adds no safety of any kind. All it does is guarantee the repair happens, removing the last obstacle between an impatient decision and a permanent alteration.
Scanning runs while Windows carries on using the volume and simply queues what it finds; the second half takes the volume down briefly and works through that queue. Gentler than a full offline pass, certainly, and still a write at the end of it. The rule about failing hardware does not soften for either of them.
Where the volume is in use, Windows offers to check it during the next boot instead, and most people agree and then forget entirely. If the disk is unwell that reboot is exactly when the harm occurs, unattended, at four in the morning, behind a countdown any key will cancel. Cancel it if the drive has been odd.
Think of NTFS as a library. There is a catalogue describing every book — where it sits, how long it is, which shelf lists it, who is allowed to borrow it — and there are the books themselves. This tool audits the catalogue. It compares the entries against one another and against the record of which shelves are occupied, and it resolves the contradictions it finds: two books claiming one shelf, a shelf listing a book that is not there, a book with no catalogue entry, an occupancy record that does not match the room.
On a sound disk after an untidy shutdown that audit is quick, useful and entirely appropriate. What it cannot address is the building falling down. A head assembly that no longer positions itself, a firmware region that has become unreadable, a controller board on its way out, a coating leaving the platter — none of that is catalogue work, and confronted with any of it the tool simply keeps asking, over and over, because from where it sits the shelves are merely slow this afternoon.
This is the part that surprises people, and it is worth stating without euphemism. Internal consistency is the goal, not restoration. Where an entry points at something that cannot be verified, the resolution is to remove the entry. Where a record looks implausible, the resolution is to shorten the file it describes. Where occupied space belongs to no entry anywhere, that space is written out as numbered files with a .chk extension into a folder named found.000 — your contents, stripped of their names, their folders and their dates. On a badly damaged volume, that folder is where an enormous amount of somebody work ends up sitting.
The stage counter on screen shows how far through the audit it has travelled. Early stages examine the records and the tree that lists them. Later ones deal with permissions and with the occupancy map. With the surface switch, a long sweep of the platters follows everything else. A pass frozen at one percentage for hours, particularly deep into the sequence, is almost always waiting on a drive that cannot reply — the plainest available evidence that filing was never what went wrong.
It reads hard and it reads continuously, and that workload is what finishes disks with weakening surfaces or tired heads. It commits its conclusions to the same disk it is reading, so every judgement it gets wrong becomes permanent within seconds. And it does both while whatever working hours the drive has left drain away on an exercise that was never capable of helping in the first place.
The sequence repeats itself with dispiriting regularity. A drive begins stalling. Somebody runs the full version with the surface sweep. It labours through the night, finishes or gives up around breakfast, and the volume now shows a fraction of what it held, with most of the remainder sitting in found.000 as anonymous numbered fragments. That job was straightforward at bedtime and is not straightforward now.
Four things need to be true together. The disk sounds and behaves normally, with no clicking, no stalling, no disconnections, no long pauses on ordinary files. Its health counters show nothing climbing week on week. Something everyday caused the problem, such as a power cut, a battery dying mid-write, or a stick pulled out during a copy. And a second copy exists of anything you would mind losing. With all four true, the fix switch is fine and generally resolves the matter in a few minutes, which is precisely what it was written for.
Where the drive has been misbehaving and there is no second copy, run nothing whatever. Not this, not a rival utility, not a defragment, not a format, not a manufacturer diagnostic. Power it down and have an image taken. Every idea can be tried safely against a copy, and no idea can be untried against the original.
RAW file system, tool not available. Windows cannot work out which file system it is looking at, which normally means the boot sector or the master table has been damaged — and both are frequently recoverable. It is emphatically not a reason to format. Formatting the volume so the tool will consent to run would be writing over precisely the material that needs reading first.
An unspecified error occurred. Vague by design, and on a struggling disk it generally means the drive stopped replying part way through something. Where the hardware has been unwell, read that as a message about the hardware rather than about the filing.
The volume is write protected. Occasionally a physical switch on a card or a stick. More often a controller that has locked itself read-only because it has detected its own decline. In that second case the lock is protecting whatever survives, and defeating it with a utility works directly against you.
Cannot lock the current drive. Entirely normal on the disk Windows is running from, which is why the boot-time option exists at all. Where the disk has been behaving oddly, decline that offer rather than accepting it and going to bed.
Stop using the drive, and treat that as more important than everything else on the list. Then look in the root of the volume for a folder called found.000, and expect there to be several numbered upwards if the damage was widespread. Inside are files named in sequence with a .chk extension. Those are your contents with the labels taken off, and a great many of them can be identified from what is inside and given sensible names again — routine on a bench, and a very long wet afternoon by hand.
Do not run the audit a second time on the theory that it might tidy up after itself; it has no memory of what it removed. Do not defragment, which rearranges exactly the space you want left alone. Do not delete found.000 to reclaim room. Where the drive is stable enough to allow it, copy anything still visible onto different storage before doing anything else at all, and where it is not stable, power it down and send it in. If the files disappeared before the repair pass rather than because of it, deleted file recovery is the page that applies.
One hard drive or SSD, £300 + VAT. Cards, sticks and pen drives, £250 + VAT. Recorder disks out of CCTV systems, and encrypted volumes where the key can be produced, £400 + VAT. Anything holding several disks — RAID, NAS, SAN, a server — from £500 + VAT, climbing with the member count. Forensic casework reported in full, £800 + VAT, or £400 + VAT for the verified image with deletions extracted and no report attached.
Looking is free and closes on the second working day after the drive is logged in, and the figure is fixed in writing before a thing is started. A disk that suffered nothing worse than a bad repair pass is a logical job, so no fix, no fee applies to it. Chip-level work, DVR jobs, forensic jobs and mechanical or electronic failure fall outside that guarantee, and invasive work takes half upfront.
Very often it is not, and that ought to come from the people who would otherwise take the money. Where the drive is healthy, the volume mounts and a few files are missing, restore them from wherever the second copy lives. Where found.000 holds a dozen documents you can identify by opening them, spend the afternoon doing exactly that. Send it in when the volume will not mount at all, when what disappeared cannot be replaced from any other source, or when the disk is behaving as though it is failing — those are the situations where a laboratory changes the ending rather than merely charging for it.
Every idea can be tried safely against a copy and no idea can be untried against the original, which is this entire page compressed into one sentence.
Something rigid, some padding and a tracked label treat an ailing device far better than a week of being carried about in a bag while its owner decides what to do next. Handed in at a Coventry counter during the afternoon, it generally reaches the Oxford bench the following working morning, which beats what most people manage by clearing a day for the M40.
As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.
↓ Print the shipping & booking-in form (PDF)
Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.
Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.