Call us — 0131 202 0491
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · The Empty Files Recovery Gave Back

Names without substance: why recovery software hands back zero-byte JPGs — the entry-versus-data anatomy of a "successful" recovery that wasn't, and the reconstruction that reunited her pictures with their names

Her enquiry was the candid report of a capable attempt, taken exactly as far as home tools go. An IDE hard drive, read through a USB adapter; a drive letter assigned in Disk Management; then "the file or directory is corrupted or unreadable" on opening. Recovery programs, tried with some apparent success: "it's all still there — but when the .jpg files are recovered they're at 0 bytes, and when opened it says it appears we don't support this file format." Her sign-off: "I somewhat have an idea of what I'm doing, but at this point I'm at a loss." She should be at no loss about her competence — every step was reasonable and her observations are diagnostically excellent. What she'd hit is one of consumer recovery's classic false summits, and this page decodes it properly: why software can list every file by name and still deliver empty shells, why that outcome means the pictures are still on the drive, and what a real reconstruction does differently.

MediaIDE hard drive read via USB adapter — volume mounts but reports "corrupted or unreadable"; consumer recovery attempts return complete file listings whose JPGs are zero bytes
Reported situationDrive letter assigns; access errors on opening · multiple recovery programs tried · files listed by correct names but recovered at 0 bytes; unopenable · owner seeking professional help
Fault classFilesystem damage severing entries from their data runs — software recovering the catalogue's names without the map beneath them; picture data intact on the platters
Equipment usedDrive imaged write-blocked (DeepSpar USB Stabilizer 10Gb, native IDE-era handling) · filesystem reconstruction on the image re-linking entries to data · OSForensics signature carving with per-file content validation · every recovered image verified by opening

The decode: names without substance, and the false summit

What a zero-byte "recovery" actually recovered: the anatomy this archive keeps returning to explains her result exactly. Every file on the volume is two joined things: the directory entry — the name, dates and size she can see — and the allocation map pointing to where the file's actual data lives on the disk. Her corruption tore the join: the entries survive legibly (which is why the software could list everything, "all still there" by name), but the map beneath them is damaged — so when the software "recovers" a file, it faithfully copies out a name attached to nothing, and writes a zero-byte shell. The viewer's complaint — we don't support this file format — is its honest reaction to being handed a file with no bytes in it: not a format problem, an emptiness problem. The software didn't fail to find her pictures; it never looked for them. It harvested the catalogue and called it the library.

Why this outcome is actually good news: here's the reframe her loss of heart deserves: zero-byte results mean the damage is in the bookkeeping layer — and her photographs' actual data, the megabytes of picture behind each severed name, was never what the corruption destroyed. It sits on the platters still, unmapped but present. A recovery that returned garbage-filled files would worry more; empty shells are the signature of intact data behind broken links, which is among the more recoverable situations on the shelf.

What professional reconstruction does differently — two roads, both taken: the difference isn't effort, it's approach. Road one: repair the join — analyse the damaged filesystem on a write-blocked image and re-link entries to their data by reconstructing the allocation structures, returning files with their real names and folders. Road two, for whatever the structures truly lost: carve by content — ignore the broken catalogue entirely and find the photographs by their own internal signatures, each candidate validated as a genuine, opening image before it's counted. Consumer tools stall at the broken join; reconstruction goes around it from both sides — and the verification standard is the one her zero-byte experience makes non-negotiable: every recovered picture opened, none merely listed.

On the bench

The drive was imaged write-blocked behind the DeepSpar USB Stabilizer 10Gb — one complete read, ending the era of repeated software passes over fragile structures — and both roads ran on the copy. The filesystem's allocation structures were reconstructed, re-linking her named entries to their data wherever the join could be repaired; OSForensics carved by JPEG signature across the image for the remainder, validating each candidate by content. And the delivery standard answered her exact wound: every photograph verified by opening — real pictures behind real names, not one zero-byte shell in the set.

The outcome

Her photographs recovered with substance restored to their names, verified image by image, and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. The false summit, mapped for everyone who's stood on it: software that lists everything and delivers zero bytes has recovered the catalogue without the library — bookkeeping damage, not data loss — the pictures remain on the drive behind the severed names, and the fix is reconstruction and validated carving on an image, with success measured the only way that counts: files that open.

Recovery software returned your files at zero bytes

Stop running further passes — each one re-reads a damaged drive to harvest the same broken catalogue — but take real heart from the result: zero-byte files mean the software recovered names whose links to their data are severed, and the data itself is typically still on the drive, intact and unmapped. Don't delete the drive's contents, don't reformat, and don't judge recoverability by tools that only read the catalogue. The professional route re-links entries to their data on a write-blocked image and carves by content for the rest, validating every file by opening it. Your instinct that "it's all still there" was right — it just needs equipment that looks below the names.

Files coming back empty from every recovery tool?
The pictures are still under the names — call Edinburgh Data Recovery on 0131 202 0491; imaged once, re-linked and carved with validation, every file verified open — one written figure, no recovery, no fee.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0131 202 0491