Gavilan Consulting Call (559) 507-2076

Data Recovery, Backup & Digital Forensics

Getting data back when it has gone, keeping copies so it never has to be got back, and examining a device carefully enough to establish what actually happened on it. On site across California's Central Valley, and remotely across the entire United States.

If You Have Just Lost Data, Stop Using The Device

The most useful thing on this page is free and takes about ten seconds to act on: stop using the device and power it down. Not after you have had one more look. Now.

Deleting a file does not scrub it off the disk. It removes the entry that says where the file lives and marks that space as available for something else. Until something else is actually written into that space, your file is still physically sitting there — which is the only reason data recovery is possible at all.

A computer that is switched on writes constantly, whether or not anyone is touching it: log files, temporary files, browser cache, software updates, search indexing, crash reports, the operating system's own housekeeping. Every one of those writes is a candidate to land in the space your missing data occupies. Very often the thing that permanently destroys the data is not the original fault at all. It is the hours of ordinary use that come after it.

Then call (559) 507-2076 or send us the details and tell us what happened, including anything that has already been tried. What has been tried matters as much as the original fault.

What To Do Right Now

  • If the drive is making an unusual noise, cut the power immediately — hold the power button in until it goes off.
  • If it is quiet and the problem is missing or deleted files, shut down normally, then leave the machine off.
  • Unplug an external drive or memory card rather than continuing to browse it.
  • Write down what happened in order, and roughly when you noticed. Small details settle arguments later.
  • Work from a different computer while you sort out what to do next.
  • If the data matters to the business, tell whoever else uses that machine to leave it alone too.

What Not To Do

  • Do not install recovery software onto the affected drive. The installer writes to the exact space you are trying to get back.
  • Do not run disk repair tools — chkdsk, Disk Utility First Aid, fsck. Their job is to make a file system consistent again, and they do that by discarding what does not fit.
  • Do not reformat, reinstall or reset the machine to see whether that clears the problem.
  • Do not keep powering a failing drive on and off hoping it comes back. Each attempt can turn a recoverable fault into a permanent one.
  • Do not put the drive in the freezer. It circulates as folk advice and it adds condensation to a precision mechanism.
  • Do not open the drive. It is a sealed environment, and ordinary household dust is larger than the gap the heads fly at.

Data Recovery

When The Data Is Already Gone

Deleted files. A drive the computer no longer recognizes. A volume that mounts but shows nothing. A RAID that will not rebuild. A phone that will not start. A folder full of files that were renamed overnight by something that then asked for money. They are different faults with one thing in common: the clock started when it happened.

Logical Failure And Physical Failure Are Two Different Problems

Almost every recovery job falls into one of two categories, and knowing which one you are in changes what you should do next.

A logical failure means the hardware is fine and the information describing where everything lives is not. The drive spins, the computer sees it, but the map is wrong or missing. That covers deleted files, a reformatted drive, a damaged partition table, an update that was interrupted halfway, a phone stuck in a restart loop, and files encrypted or scrambled by malware. The device is not sick; the index is. Work on these jobs is done by taking a complete copy of the drive and then rebuilding structure from the copy.

A physical failure means the hardware itself has broken. Heads, motor, bearings, the controller board, worn flash memory, or damage from water, heat, or being dropped. The symptoms are usually audible or obvious: clicking, grinding, beeping, spinning up and immediately down again, getting hot, or simply not being detected no matter which cable or computer you try. No amount of software fixes a mechanical fault, and software is exactly what most people reach for first.

A Clicking Or Grinding Drive Should Be Powered Off, Not Retried

That noise is a mechanical part failing while the platters are still turning underneath it. Every retry is another pass over surfaces that hold the only copy of your data, and a drive that clicks for an hour can end up in a state no one can read afterwards. Opening a drive to work on those parts belongs in a cleanroom with proper equipment, because the gap the heads fly at is smaller than a dust particle. Power it off, leave it off, and let someone tell you honestly which category it is in before another attempt is made.

What We Are Asked To Look At

Laptops And Desktops

Windows and Mac machines that will not boot, that boot to an empty desktop, or that have had an operating system reinstalled over the top of everything that mattered.

Hard Drives And SSDs

Internal and external drives, including the external drive that was itself the backup — which is how a great many people discover they only ever had one copy.

Servers And RAID Arrays

Arrays that lost a second disk during a rebuild, controllers that dropped their configuration, and virtual machine files that will no longer open. Order of operations matters enormously here.

Phones And Tablets

Devices that will not start, will not charge, or were never backed up. What is possible depends heavily on the model, the operating system version and whether the passcode is known.

Cards And USB Sticks

Camera cards, phone storage cards and memory sticks — usually accidental deletion, a card pulled out mid-write, or a card the device has offered to format.

After A Ransomware Event

Working out what was reached, what survived untouched, whether usable versions exist elsewhere, and how it got in — so that rebuilding does not simply restore the way back in.

Being Honest About What Cannot Be Recovered

This is the part most pages leave out, so here it is plainly: some data comes back, some does not, and nobody can tell you which before they have looked. Anyone who promises a recovery in advance is guessing with your money.

  • Overwritten is gone. Once new data has been written into the same space, it is not underneath somewhere waiting to be found. This is why the advice at the top of this page matters more than anything else here.
  • Deleted files on an SSD are frequently unrecoverable. Solid-state drives clear deleted blocks in the background, often within minutes, as part of normal housekeeping. It makes the drive fast and it makes deletion close to final. Anyone who tells you otherwise as a blanket promise is selling something.
  • Strong encryption without the key is a wall. If a drive was encrypted with BitLocker or FileVault and the key and recovery key are both gone, the data is unreadable by design. That is the feature working.
  • Ransomware is not decrypted, it is restored. Where the encryption was implemented properly there is no clever way through it. Recovery comes from backups, off-site copies, previous versions, shadow copies and machines the malware never reached — which is precisely why the backup section below exists.
  • Severe physical damage can be final. Scored platters, fire, and long-running mechanical failure can destroy the surfaces themselves. Sometimes part of the data comes back and part does not.

We would rather tell you at the first conversation that a job looks unlikely than take it on and tell you at the end. A recovery is judged by whether the files open afterwards, not by how many filenames appeared in a list.

How A Recovery Job Runs

  1. You Describe What Happened

    What the device is, what it did, when it started, and everything that has been tried since — including anything that was installed or run. Nothing here is a telling-off; it just changes the approach.

  2. Logical Or Physical Is Established First

    Because the answer decides everything else. A physical fault gets said out loud rather than quietly attacked with software until it becomes unrecoverable.

  3. The Device Is Imaged Before Anything Else

    A complete sector-level copy is taken and every later step is done against the copy. The original is never the thing being experimented on. This is the difference between careful work and hopeful work.

  4. You See What Came Back Before You Commit Further

    You should be able to look at the recovered files and open them. A list of recovered filenames proves nothing on its own.

  5. It Comes Back On Different Media

    Recovered data is never written back onto the drive it came from. We also talk about why it happened, because the second half of this page is the part that stops it happening twice.

Backup & Disaster Recovery

The Cheapest Recovery Is The One You Never Need

Encrypted copies held on site and off site, checked rather than assumed, and a written plan that says what comes back first when a bad day arrives. Everything above this line is what happens when there is no good copy. This is the half of the page that keeps you out of it.

On Site And Off Site, Both, Encrypted

An on-site copy is the one that gets you working again quickly. When a single server or a single machine fails, the restore runs at the speed of a local disk, which is the difference between being down for part of a morning and being down for days.

An off-site copy is the one that survives the event that takes the building — fire, flood, theft, or a burst pipe over the cupboard the server lives in. It is also the copy that survives a member of staff deciding to be helpful with the backup drive.

Neither is sufficient on its own. On site alone dies with the premises. Off site alone means your slowest possible restore on your worst possible day. Both copies are encrypted, so a backup drive that goes missing is an inconvenience and a replacement cost rather than a conversation with your clients about their data.

A Copy That Is Always Connected Is Not Protection From Ransomware

This is the assumption that catches most people out, and it is nobody's fault — it is genuinely counter-intuitive.

Ransomware does not run as some outside force. It runs as you, on your machine, with your permissions. Anything you can write to, it can write to. That means the external drive that stays plugged in, the mapped network drive everyone can see, and the folder that synchronizes to the cloud. A sync service does exactly what it was designed to do: it faithfully copies the newly encrypted version over the good one, everywhere, within minutes.

What actually helps is copies the infected machine cannot reach or overwrite: off-site copies held under an account the local machine does not control, retention that keeps previous versions for long enough that you can still go back past the day it started, and at least one copy that is not connected at all. Intruders are often inside a network far longer than anyone assumes before anything visible happens, so a backup that only keeps the last few days can be faithfully preserving the problem.

A Backup Nobody Has Ever Restored From Is Not A Backup

It is an assumption with a green tick next to it. The ways it goes wrong are boringly consistent:

  • The job has been failing for months and the alert emails go to somebody who left.
  • It runs perfectly and excludes the one folder that mattered, because that folder was created after the job was set up.
  • The database was copied while it was open, so the file exists and restores into something the software will not load.
  • The backup media filled up, and the oldest good copy was rotated away to make room.
  • Everything is backed up except the thing nobody thinks of as data — the license keys, the line-of-business configuration, the account that controls the domain name.
  • Nobody has ever measured how long a full restore actually takes, so the plan assumes an afternoon and reality is a week.

The fix is unglamorous and it works: restore something on purpose, on a normal day, and open it. Then do a full restore of a whole machine occasionally, and write down how long it really took. A backup you have restored from is the only kind you are entitled to have confidence in.

What A Written Disaster Recovery Plan Contains

A plan is not a product you buy; it is a short document that answers questions you will not want to be answering for the first time at seven in the morning:

  • What the business needs back first, in order, and who gets to decide when the list is wrong.
  • How long each of those can realistically be down before it costs real money — and how much data you can afford to lose. Last night's work, or the last hour's?
  • Where every copy lives, what is actually on it, and who has the ability to get to it.
  • The hardware, software, license keys and account access needed to rebuild from nothing.
  • Who to phone, in order: staff, us, the internet provider, the software vendor, the insurer.
  • How people keep working while the systems are down, including the paper fallback for the jobs that cannot wait.
  • When the plan was last tested, what broke during the test, and what changed as a result.
  • Where the printed copy is kept — because a plan stored only on the server is a plan you cannot read on the day you need it.

Microsoft 365 And Cloud Files Still Need Their Own Copy

Keeping your email and files available is not the same thing as keeping the version you had before somebody deleted it, before a compromised account emptied a mailbox, or before a departing employee tidied up. Retention windows in cloud services are limited and they run out quietly. If the business lives in Microsoft 365, treat it as a system that needs backing up like any other — it is one of the first things we look at when we take on networks, servers and cloud services for a customer.

Five Questions Worth Asking Today

  • When did a backup last complete successfully, and who saw that?
  • Who receives the failure alerts, and do they still work here?
  • Is there a copy that is not reachable from an infected PC?
  • How far back can you go — days, or months?
  • When did anyone last restore something and open it?

If any answer is a shrug, that is worth a phone call before it becomes a recovery job.

Or Stop Thinking About It Entirely

Under a managed IT agreement, the backups are monitored, the failures are chased by us rather than reported to you, restores are tested, and the disaster recovery plan is kept current as the business changes. It is a flat monthly fee, quoted after we have looked at what you actually run.

Digital Forensics

Establishing What Happened, And When

Sometimes the question is not whether the data can come back. It is what was done on this machine, by whom, and in what order — and whether the answer will still stand up when somebody disputes it.

When Businesses Ask For This

  • A departing employee is suspected of taking client lists, drawings or pricing.
  • Files appear to have been copied to a memory stick or a personal cloud account before a resignation.
  • An internal investigation where accusations are being made in both directions.
  • An employment matter where what was on the machine is part of the story.
  • An insurance claim that needs the state of a system documented properly.
  • Suspected unauthorized access to email, files or accounts.
  • A device that needs examining before it is wiped and reissued.

The Handling Is The Point

Anybody can open a laptop and look through it. That is not the service, and it is not what makes the answer worth anything. The value is in being able to say afterwards exactly what was done, by whom, in what order, and to show that the examination did not change the thing being examined.

In practice that means the work is done against a complete copy rather than the device itself; the copy is checked against the original with a cryptographic fingerprint so that both can be shown to be identical; the original is set aside and not worked on; who had the device and when is written down as it happens; and what was observed is kept separate from what it is thought to mean. A finding with no record of how it was obtained is just an opinion with a computer attached.

Letting IT Have A Quick Look Is Often What Destroys The Evidence

This is the natural first move and we understand entirely why it happens. Somebody trusted is already there, the machine is already on the desk, and it feels like the fast option. It is also the single most common way the answer gets destroyed before anyone starts looking for it.

Simply powering the machine on changes thousands of timestamps and begins writing into exactly the free space that deleted material would still be sitting in. Opening a document to check what is in it changes when it was last accessed, and can change the file itself. Logs roll over. The records of which memory sticks were plugged in, which files were opened recently, and which accounts signed in are all finite, and ordinary use pushes the interesting entries out of them. And copying the files off to keep them safe keeps the contents while discarding the metadata around them — which is usually the part that answers when and by whom.

If you think you may one day need to establish what happened, the instruction to give is the same one at the top of this page: stop using it, power it down, and put it somewhere it will not be reissued, wiped or tidied up while a decision is being made. That costs nothing and it keeps every option open.

What We Claim, And What We Do Not

We will describe the work plainly: we examine the device, we document what we did, and we tell you what the evidence supports and, just as importantly, what it does not support. Where a question cannot be answered from what is on the device, we say that instead of stretching.

We are not going to list certifications, court qualifications, expert-witness credentials or licenses on a web page, and we are not going to tell you that findings will be admissible. Whether evidence is admitted is decided by a court on the facts of your particular matter, and no examiner can promise that in a brochure. If your matter needs a credentialed examiner who will testify, say so in the first conversation and we will tell you honestly whether that is us.

If lawyers are involved, or look likely to be, get them involved early and let them direct the work. Tell us and we will take their direction on what is examined and how it is reported. That first conversation is free, and it is worth having before the device is touched again.

Coverage

On Site Across The Valley, Remote Across The Country

On-site work runs the length of the valley: Sacramento and Stockton in the north, Modesto, Merced and Madera through the middle, Fresno and Clovis at the center, Hanford, Visalia and Tulare to the south of them, and Bakersfield at the far end. Full details are on our Central Valley service areas page.

It is worth being straight about which half of this page is remote work and which is not. Designing a backup, checking that it is running, testing restores, writing and rehearsing a disaster recovery plan, and advising on what to do in the first hour of a data-loss event are all things we do remotely for customers anywhere in the entire United States. Recovering a drive with a mechanical fault, or taking a forensic image of a computer, means the device and the person working on it have to be in the same place — which is what the on-site visits across the valley are for. If you are outside the area and holding a failed drive, call anyway and we will tell you plainly what your options look like.

Our office hours are Monday – Friday, 9:00 AM – 5:00 PM Pacific. Around-the-clock telephone support is part of what managed IT clients get under their agreement.

Straight Answers

Questions People Ask Before They Call

My drive is clicking. Should I keep trying it?

No. That noise is a mechanical part failing while the disks are still turning, and every retry risks damaging the surfaces that hold your only copy. Power it off and leave it off. This is the one situation where doing nothing is actively the most useful thing you can do.

I already ran a recovery program. Have I made it worse?

Possibly, and possibly not — it depends on what it was and where you installed it. Installing anything onto the affected drive is the part that causes harm. Either way, tell us exactly what was run and where. Nobody is going to tell you off, and knowing changes how the job is approached.

Can you recover deleted files from an SSD?

Often not, and you deserve the real answer rather than a hopeful one. Solid-state drives clear deleted blocks in the background as part of normal operation, frequently within minutes. Other kinds of SSD failure — a drive that is no longer detected, a damaged file system, an interrupted update — are a different question and are often worth looking at.

Do you have to take my computer away?

Not always. A lot of logical recovery work and forensic imaging can be started where the machine sits, on an on-site visit. A drive with a physical fault is different: opening one needs specialist facilities that cannot be improvised in an office, and sometimes the honest recommendation is that the drive belongs with a cleanroom laboratory rather than with anybody working on your desk. We will tell you which situation you are in, and what your options are, before anything moves.

Can you get our files back after ransomware?

Where the encryption was done properly there is no clever way through it, so the honest answer is that recovery comes from elsewhere: backups, off-site copies, previous versions, shadow copies, and machines the malware never reached. There is often more left than people expect. The other half of the job is finding how it got in, so that rebuilding does not restore the way back in along with the files.

Who sees my data while you are working on it?

Only what the job requires, and we agree up front what happens to the working copies once you have your data back — then we do that. If the material is sensitive, say so at the start and we will put the handling in writing before anything is copied.

Can you make sure this never happens again?

Nobody can remove the risk entirely — hardware fails and people click things. What a tested backup does is change the category of the event, from a disaster into an inconvenience with a known length. That, plus keeping machines patched and monitored, is most of what managed IT services actually buy you.

Tell Us What Happened, Before Anything Else Gets Written

Describe the device and what it did. The first conversation costs nothing, and if the honest answer is that your job belongs with someone else, we will say so rather than take it on.