Other Repairing badly corrupted NTFS disk

I have dual boot windows and a 4TB NTFS HDD partition was corrupted, showing in windows as RAW, cant see volume size, and windows chkdsk fails. In FreeBSD fsck too fails, ntfs-3g utilities i found dont help either. I used dd
Code:
dd if=/dev/ada1 of=/mnt/windows/windiskold
to clone the filesystem into windiskold file in freebsd zfs disk so i could salvage the data if possible. The disk also has ada1p1 and ada1p2 sub partitions (shown at 4TB too) as shown by lsblk.
By the way while the NTFS disk is 4TB dd seems to continue over 4,5TB of data, thats strange (dd hasnt finished yet).
How can i continue with restoration of disk and/or salvaging the files? Is the disk failing (so it would be a risk reformatting it again)? It isnt a very old disk, its 6 years old with no huge use load. Thanks.
 
I have dual boot windows and a 4TB NTFS partition was corrupted, showing in windows as RAW, cant see volume size, and windows chkdsk fails. In FreeBSD fsck too fails, ntfs-3g utilities i found dont help either. I used dd
Code:
dd if=/dev/ada1 of=/mnt/windows/windiskold
to clone the filesystem into windiskold file in freebsd zfs disk so i could salvage the data if possible. The disk also has ada1p1 and ada1p2 sub partitions (shown at 4TB too) as shown by lsblk.
By the way while the NTFS disk is 4TB dd seems to continue over 4,5TB of data, thats strange (dd hasnt finished yet).
How can i continue with restoration of disk and/or salvaging the files? Is the disk failing (so it would be a risk reformatting it again)? It isnt a very old disk, its 6 years old with no huge use load. Thanks.
When disk goes RAW like that, its usually game over. If you value you data, i would not attempt to do anything with it because you can make it worse. Specialist data recovery company is your best bet at this point. Your data may still be salvageable if the disk electronic or heads are the only thing that has gone bad. Keep in mind that this sort of data recovery is expensive. So you make a decision if its worth paying for it. Also. Its 2026. Learn to backup your data.
 
When disk goes RAW like that, its usually game over. If you value you data, i would not attempt to do anything with it because you can make it worse. Specialist data recovery company is your best bet at this point. Your data may still be salvageable if the disk electronic or heads are the only thing that has gone bad. Keep in mind that this sort of data recovery is expensive. So you make a decision if its worth paying for it. Also. Its 2026. Learn to backup your data.
You are correct about the backup advice. I tend to forget about stuff and save it two and three times (through subfolders) and end up with unneeded data. Is there an utility in FreeBSD that checks for duplicate filenames, sizes, and especially content like this windows program?:
 
when you dd a disk use as bs=64k otherwise you will wait forever
also you dd the entire disk not a partitition so maybe that is why is larger than the partition
if only the partition table is broken that is not that hard to fix without special tools

can you post file -s /dev/ada1 and gpart show ada1 ?
 
when you dd a disk use as bs=64k otherwise you will wait forever
also you dd the entire disk not a partitition so maybe that is why is larger than the partition
if only the partition table is broken that is not that hard to fix without special tools

can you post file -s /dev/ada1 and gpart show ada1 ?
Code:
file -s /dev/ada1
/dev/ada1: DOS/MBR boot sector MS-MBR Windows 7 english at offset 0x163 "Invalid partition table" at offset 0x17b
 "Error loading operating system" at offset 0x19a "Missing operating system"; partition 1 : ID=0xee, start-CHS (0
x0,0,2), end-CHS (0x3ff,255,63), startsector 1, 4294967295 sectors

Code:
gpart show ada1
=>        34  7814037101  ada1  GPT  (3.6T)
          34      262144     1  ms-reserved  (128M)
      262178        2014        - free -  (1.0M)
      264192  7813771264     2  ms-basic-data  (3.6T)
  7814035456        1679        - free -  (840K)
 
That file command is misleading:

"Error loading operating system" at offset 0x19a "Missing operating system"; partition 1 : ID=0xee, start-CHS (0

It's catching the pmbr fake partition with id 0xee ; i.e. useless information.
The gpart output is what you are after, it's the actual layout of the GPT partitions. As gpart is not complaining about its consistency it's safe to assume it's correct - primary GPT header agrees with its backup.

Doing dd backup of a whole disk is a good start. If you have an option I'd do a 2nd copy of it so you can work with the first copy and attempt to recover. If you screw things up it's easy to restore from the 2nd backup and start again. Physical disk is there as last resort if you need something.
I would not recommend doing NTFS data recovery under FreeBSD. The best option is to stick with native Windows tools, or 3rd party tools available for other OS (example: disk drill under osx).

For the sake of an attempt to do anything under FreeBSD you could try sysutils/testdisk. In your case:
Code:
mdconfig -a -t vnode -f /mnt/windows/windiskold
testdisk /dev/md0
Get familiar with the interface and let the testdisk do some heuristics on the filesystem.
 
those look legit.
now to file -s /dev/ada1p2
Code:
file -s /dev/ada1p2
/dev/ada1p2: DOS/MBR boot sector, code offset 0x52+2, OEM-ID "NTFS    ", sectors/cluster 8, Media descriptor 0xf8
, sectors/track 63, heads 255, hidden sectors 264192, dos < 4.0 BootSector (0x80), FAT (1Y bit by descriptor); NT
FS, sectors/track 63, sectors 7813771263, $MFT start cluster 786432, $MFTMirror start cluster 2, bytes/RecordSegm
ent 2^(-1*246), clusters/index block 1, serial number 044583ed6583ec688; contains bootstrap BOOTMGR
 
The fsck tools for NTFS available on Linux and FreeBSD only repair a subset of possible damage.

Almost certainly you have to connect the disk to an actual Winblows installation to run Microsoft's chkdsk.
 
The fsck tools for NTFS available on Linux and FreeBSD only repair a subset of possible damage.

Almost certainly you have to connect the disk to an actual Winblows installation to run Microsoft's chkdsk.
Have already done so but chkdsk fails.
 
Also. Its 2026. Learn to backup your data.
100%.
A disk with an NTFS partition can fail at any moment. If the data is critical, you should use a professional data recovery service. If you want to repair the drive—accepting the risk of potential data loss—use a low-level utility like Victoria or HDD Regenerator.
 
100%.
A disk with an NTFS partition can fail at any moment. If the data is critical, you should use a professional data recovery service. If you want to repair the drive—accepting the risk of potential data loss—use a low-level utility like Victoria or HDD Regenerator.
Is there a reason NTFS can fail as such more compared to other filesystems?
 
Someone
Every file system has its pros and cons.
NTFS is robust within Windows, but its weak point is the MFT (Master File Table).
You are currently trying to repair an NTFS file system outside of Windows; I believe (without being a specialist) that you are less likely to succeed.
 
NTFS on windows uses cluster sizes of 4k
This means all files under this size are intact on the disk even when the directory tories are lost or corrupt.

Files greater than 4k are likely fragmented and therefore lost.

I do this sort of data recovery regularly in the windows platform so no experience with FBSD. I wrote my own Win32 tools to wade through chunks returned by the data recovery apps. This is a laborious and time consuming process.

If data is valuable pony up the $$$ and send the disk to OnTrack Data Recovery
 
Is there a reason NTFS can fail as such more compared to other filesystems?
I don't think so. Every file system has its pitfalls. Your goal shouldn't be learning how to recover data, but rather how to store it separately on a drive kept in a dry closet, safe from mechanical damage. The key is to connect the drive to power only when performing a backup; for 99% of the time, it should remain inactive and well-protected. I don't trust any redundancy systems. There are plenty of documented cases where data was lost—even within the depths of ZFS—following mechanical or electrical failures. There are certain defects (such as micro-wear, micro-cracks, or thermal degradation) that no file system can account for.
 
Most NTFS fails I see are mechanical in root cause.

Windows 10 and newer too frequently bugger the UEFI system but NTFS is intact.

I shun UEFI for this reason.
I have zero need for UEFI and BIOS works correctly and is far more stable for my needs.
 
I have dual boot windows and a 4TB NTFS HDD partition was corrupted, showing in windows as RAW, cant see volume size, and windows chkdsk fails.
Iirc I formatted a whole 10TB disk as NTFS on FreeBSD, but it was created in a way that made it look like 1 single partition on FreeBSD but 2 on Windows (Windows couldn't mount/see the NTFS partition); didn't figure out what that was about (maybe a flag with mkntfs), but maybe there's different ways to mount/recover depending on what OS the partition was formatted on.

Thinking about it after typing that though it was likely MBR and 4TB max limit
 
Back
Top