Hacking Drive Status says "Unknown" in Ustealth

  • Thread starter Thread starter Cross2031
  • Start date Start date
  • Views Views 6,846
  • Replies Replies 35
@Cross2031 Ok, if you get the READ ERROR the MBR is corrupted. And there is atm no simple way to recover it without losing the data.

Did you closed the Active drive editor before? Its for sure locks the drive. Close it and replug the drive.
 
@Cross2031 Ok, if you get the READ ERROR the MBR is corrupted. And there is atm no simple way to recover it without losing the data.

Did you closed the Active drive editor before? Its for sure locks the drive. Close it and replug the drive.
I tried what you said, and it’s the same as before, got a READ ERROR
Post automatically merged:

think it's right click.
Tried this too, but the option to make a volume is grayed out/not available
 
What kind of drive is this exactly? Cause this starts to sound like flash based (or at least hybrid). Either that or a head crash or something happened.
 
It's very funny how a guy (Cross2031) ask for help, you give him the info, and he does something else and has a complaints on errors......Try what I told you! In that case, use low level format tool I told you.
If it doesn't work....THEN you can put you drive in the garbage!
 
@mrmagicm Step by step, now if the issue persist you can go deeper and use such mentioned tools and also including reading smart values. You are not running direkt everytime a drive high level check with such tools, when a drive cannot be recognized. When the normal way dont work then you can think there is something other wrong with the drive.
 
@Sypherone @mrmagicm
In case you’re wondering, I am currently scanning the drive as we speak, only problem is that the scan is going incredibly slow, and it’s estimated to be finished by monday, though seeing as how this may fix the issue, I will let it scan til it’s done.
Post automatically merged:

What kind of drive is this exactly? Cause this starts to sound like flash based (or at least hybrid). Either that or a head crash or something happened.
The drive I got is this thing I bought a while back:
863BD060-42B6-4A4F-ACAE-CB0AF47BE2CB.png


It’s the 500GB model; and before all this it worked quite well; Hopefully this clears up some things
 
I am currently scanning the drive as we speak
Scanning with what? Told you to use "WD Dlg 1.37" (free tool) just type it in google...and format fill with zeros....Not time loosing in a scan.
 
Isn't this about saving/restoring the data, not completely deleting it? So no, do not overwrite the drive with zeros. Reading out SMART values might reveal something through.

//EDIT: Also overwriting the drive with zeros is not a low-level format.
 
Isn't this about saving/restoring the data
Not really since he said he didn't really care about data on it. trying to recover this would take hours for nothing at 99.8%
 
@V10lator The data on the drive is not important to him told us. Primary is getting his drive again ready to use.

But i will still check for solutions to recover the drive with its data, it will not be last time a error happens by hidding the drive and the MBR gets corrupted.

@Cross2031 Yes, thats why we recommend using Western Digital drives for specific reasons. Even the refurbished in the WD Store are worth to be used.
//EDIT: For S.M.A.R.T values, inside Aomei Partition Assistans check under properties or get Chrystal disk info.
 
Last edited by Sypherone,
Ah, okay. Still I would suggest looking at SMART values (no need to interrupt the test/scan for this, one should be able to do both in parallel).

//EDIT: BTW, I guess the scan is a surface scan? If so really no need to do that, SMART also contains self-tests defined by the manufacturer. These self-tests are most likely better and faster than a surface scan.
 
@V10lator I`ve tested a bit around and Testdisk uses Backup Bootsektor and Superblocks to restore the partition table in the boot sektor. And it work fine for restore a corrupted MBR. For testing (tested multiple times) i`ve changed the MBR Signature to hide the drive and removed the partition table information be writing zeros into it with a ghex. Then i run Testdisk without log and searched for lost partitions but didnt show some. Then i wrote the Testdisk MBR to drive and searched for the partitions and all appeared. The MBR was restored!

So yes, there must exist somewhere a FAT32-Backup-Bootsektor.
NTFS is using Backup-Boot-Superblock, if iam correct its located in the beginning / first sector of a partition.

On Linux ext2/ext3-Backup-Superblock are stored at specific blocks which can be located by dumpe2fs.
The location of the backup superblocks are dependent on the filesystem's block size. This size is stored in the superblock, so it isn't known while searching for the backup superblock. To search for them, run TestDisk and in the Advanced menu, select the partition and choose Superblock.
Source: Advanced find Superblock
 

Site & Scene News

Popular threads in this forum