Call us — 0131 202 0491
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Formatted & Logical Faults · The Desktop That Wasn't His

The temporary-profile trap, decoded: why Windows gave him a stranger's empty desktop, where the files he dragged there actually went — and the both-sides hunt that brought the university work back

His enquiry arrived as a numbered list — "this is a lengthy problem so I'll try to keep it compact" — and the list describes, step by step, one of Windows's cruellest and least-understood traps. The sequence: a new driver downloaded for his laptop, "NOT compatible with the OS," failing to install; games lagging; a restart. Then: "desktop was fully empty. Went into C: drive to look for uni files and thankfully, they were there." Relieved, he "dragged important files onto desktop" — and here the list turns on its saddest line: "did not notice (my fault) the 'You are not signed in — anything placed on desktop will be lost after restart' notification." One more restart: "all the files I had dragged onto the desktop were no longer on the desktop — and could not be found in C: drive." A Windows 7 system restore afterwards muddied things further. Two corrections before the decode: the parenthetical "(my fault)" is too harsh — this trap is engineered to be missed — and the files are very likely not gone. They went where the trap always sends them, and this page maps it.

MediaWindows laptop hard drive — failed driver install, then login into a temporary profile; university files dragged onto the temporary desktop and lost on the subsequent restart; system restore since attempted
Reported situationEmpty desktop after restart; original files initially visible in C: · files moved onto the temporary profile's desktop past an unnoticed warning banner · second restart removed them from both locations · restore attempt has written to the drive since
Fault classTemporary-profile data loss — files relocated into a discarded profile's folders and/or deleted at source by the move; recoverability governed by post-incident writes; profile-folder hunt plus deleted-entry recovery indicated
Equipment usedDrive imaged write-blocked (Atola TaskForce 2) · temporary-profile folder hunt across the users area (OSForensics) — orphaned and renamed profile directories parsed · deleted-entry recovery for the moved-from originals · sets reconciled; university files verified by opening

The decode: the stranger's desktop, the move's two halves, and where everything went

What a temporary profile is — and why his desktop was empty: when Windows starts, it loads the user's profile — the personal world of desktop, documents and settings. If that load fails (and a botched driver install is a classic saboteur), Windows doesn't refuse entry; it does something far sneakier: it signs the user into a temporary profile — a blank, disposable stand-in world, complete with its own empty desktop — and posts one easily-missed banner saying so. His "fully empty desktop" was never his desktop damaged; it was a stranger's desktop, freshly built, while his real profile — desktop files and all — sat intact but unloaded on the disk. His trip into C: confirming the uni files "thankfully there" was him glimpsing his real world from inside the disposable one. Everything about the trap invites exactly what he did next.

Where the dragged files actually went: dragging the files "onto the desktop" placed them onto the temporary profile's desktop — a folder inside a disposable profile directory that Windows creates in the users area and regards as rubbish. And because a drag within the same drive is a move, the act had two halves: copies landing in the temporary desktop folder, and the originals removed from their C: locations — which is why the second restart emptied both places at once: Windows discarded or orphaned the temporary profile (its folders typically deleted, or left renamed and stranded in the users area), and the originals had already been moved away from home. So the files went two places, both recoverable in principle: the temporary profile's folders — sometimes still present, renamed and overlooked; otherwise freshly deleted and carvable — and the deleted original entries at their old C: addresses. The banner kept its word; the disk, as ever, kept more than the interface admits.

The restore attempt, and the clock: the system restore afterwards was a reasonable instinct with an unhelpful side-effect this archive must flag honestly: restores write — rolling system files across the disk — and every write since the loss has been spending the recoverable set. Not fatally: restores target system areas more than user data regions, and his files' odds remain real. But the instruction from this point is absolute and familiar: the laptop rests now, and the hunt happens on an image.

On the bench

The drive was imaged write-blocked on the Atola TaskForce 2, freezing whatever the trap and the restore had left — and the hunt ran both halves on the copy. OSForensics swept the users area for the temporary profile's remains: orphaned and renamed profile directories located and parsed, their desktop folders opened — the first and best home of the dragged files — while deleted-entry recovery worked the second half: the originals' old C: addresses, their freshly-moved-away entries recovered where post-incident writes had spared them. The two sets were reconciled — temporary-desktop copies against recovered originals, the best surviving version of each file chosen — and the university work was verified by opening and delivered. The stranger's desktop gave back what it had taken; the banner's threat, in the end, only half-kept.

The outcome

The university files recovered from the temporary profile's remains and the moved-from originals, reconciled, verified and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. The trap, mapped for every student who'll meet that banner mid-crisis: an empty desktop after a bad restart may be a temporary profile — a stranger's blank world, not your damaged one — never move files onto it, because its folders are built to be discarded and a drag is a move that empties your real home too; if it's already happened, stop using the machine — the files persist in the discarded profile's folders and as recoverable deleted entries — and let the hunt run on an image. And "(my fault)"? The banner is engineered to be missed. The fault is the trap's.

Desktop came up empty — files dragged there vanished after restart

Recognise the trap before blaming yourself: an empty desktop with your files still visible in C: means Windows signed you into a temporary profile — a disposable stand-in world with its own desktop that gets discarded on restart — and anything moved onto it goes with it, while the move simultaneously empties the originals' real locations. If it's already happened: stop using the laptop now (every write, including system restores, spends the odds), and know the two places the files persist — the discarded profile's folders, often renamed or freshly deleted in the users area, and the recoverable deleted entries at their old addresses. Both are hunted from an image. And if you ever see that "not signed in" banner again: touch nothing, restart once, and if your real desktop doesn't return, get help before moving a single file.

Files lost to an empty desktop that wasn't really yours?
The trap has two hiding places, both reachable — call Edinburgh Data Recovery on 0131 202 0491; imaged, profile remains parsed, deleted originals recovered, verified — one written figure, no recovery, no fee.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0131 202 0491