Windows Wants to Scan and Repair Your Drive. Here's What That Does to Your Files.
You plug the drive in and Windows has an opinion about it. A notification slides in offering to scan and repair the drive. Or you open the drive's properties, and there's a Check button on the Tools tab looking helpful. Or you restart and the machine spends four minutes on a blue screen announcing that it's scanning and repairing drive E:.
If everything on that drive exists somewhere else too, let it run. If it doesn't — if this is the drive with the only copy of the photos — then the order matters, and the repair is not step one.
Short version: Windows repairs the file system, not your files. On a damaged volume that means rewriting the exact structure a recovery scan would have read, and anything it can't place comes back as nameless
.CHKfiles in aFOUND.000folder. Copy the drive first, then let it repair the copy's original if you still want to.
"Repair" means the file system, not your files
The tool behind all three of those prompts is chkdsk. Microsoft's own reference describes it plainly: it "checks the file system and file system metadata of a volume for logical and physical errors," and without parameters it "displays only the status of the volume and doesn't fix any errors." Only /f, /r, /x or /b actually change anything.
That's worth reading twice. The job is to return the volume to a consistent state — a directory tree that adds up, an allocation table with no contradictions. A consistent volume is not the same thing as a volume containing your files. If the fastest route to consistency is to declare a confusing region unallocated, that is a successful repair by the tool's definition and a loss by yours.
Windows decides the volume needs looking at based on a flag called the dirty bit. The documentation lists three reasons it gets set: the volume is online with outstanding changes, changes were made and the computer shut down before they were committed, or corruption was detected. Note that the first two have nothing to do with damage. And once it's set, "if the dirty bit is set when the computer restarts, chkdsk runs to verify the file system integrity and to attempt to fix any issues with the volume" — automatically, without asking you again.
You can check the flag yourself before deciding anything. Open Command Prompt and run:
fsutil dirty query e:
It answers either Volume E: is dirty or Volume E: is not dirty. If it comes back dirty, a check is queued for your next restart whether or not you clicked anything.
Where FOUND.000 and those .CHK files come from
This is the part people meet after the fact, usually while searching for why a folder full of holiday photos turned into a folder full of files named FILE0001.CHK.
When chkdsk repairs a FAT-family volume — FAT32 and exFAT, which is what most USB sticks and memory cards use — it finds clusters holding data that no directory entry claims. Microsoft's reference shows the prompt it raises:
10 lost allocation units found in 3 chains.
Convert lost chains to files?
Press Y and "Windows saves each lost chain in the root directory as a file with a name in the format File<nnnn>.chk." Press N and "Windows fixes the disk, but it doesn't save the contents of the lost allocation units." Microsoft's older reference page for that same message is more specific about where they land: the chains "will appear as FILExxxx.CHK in FOUND.xxx, or they can be released to free space."
So a FOUND.000 folder on a drive is a receipt. It says chkdsk found data it couldn't attach to any filename and parked it rather than discarding it. Each .CHK file is one run of clusters with no name, no folder, no timestamp and no file type — just bytes.
There's also a switch that skips the parking step entirely. /freeorphanedchains "frees any orphaned cluster chains instead of recovering their contents." Nobody types that by accident, but it's a clean illustration of what the tool considers optional: the contents.
And there's a wrinkle in how you meet all this. Run chkdsk yourself from a command prompt and it stops and asks. Let the check happen at a restart instead and the documentation describes something else entirely: chkdsk "checks the drive and corrects errors automatically when you restart the computer." No pause, no question in between. Which fits the Microsoft Q&A threads from people who clicked a scan-and-fix popup and went looking afterwards for where their folders went.
The part that costs you: the map gets rewritten
Here's the reason this matters more than a bit of tidy-up.
Recovering deleted or lost files works in two ways. The better one reads the file system's own records — the allocation table or the NTFS master file table — and reconstructs files with their real names, folders and fragment order intact. The fallback, when those records are gone, is to scan raw sectors for the byte patterns that start known file types and read forward, which produces files with generic names and no folder structure, and which struggles whenever a file was split into pieces.
Repair works on exactly those records. Microsoft says so directly: "repairs on FAT file systems usually change a disk's file allocation table and sometimes cause a loss of data." The table is both the thing being repaired and the thing the good recovery method depends on. Run the repair first and you may finish with a mountable drive whose remaining chance of a clean recovery just got downgraded to pattern-scanning — and a FOUND.000 folder full of the fragments, stripped of the names that made them findable.
None of this makes chkdsk a bad tool. It's the right tool for a drive whose contents are already backed up and which you need working again by lunchtime. It's the wrong first move on a drive whose contents are the whole point.
The order that keeps your options open
- Stop writing to the drive. Close anything reading from it. Don't move files onto it, don't let backup software sync to it.
- Decline the repair for now. Dismissing the notification doesn't break anything. If a check is already queued for restart, simply don't restart yet.
- Copy the whole drive to an image file. A sector-by-sector copy onto a healthy drive. Everything after this happens on the copy.
- Scan the image, not the drive. Recovery is rarely one pass — you adjust and run it again — and a flaky drive doesn't enjoy being read five times.
- Save recovered files to a third location. Never back onto the source.
- Then, if you still want the drive usable, let Windows repair it. At that point a repair that rewrites the allocation table costs you nothing you haven't already copied.
Steps 3 and 4 are why DiskRescue has a Recover safely (two steps) path beside the normal one: Step 1 · Full disk backup writes the whole drive into a single .img file, and Step 2 · Recover from backup scans that file instead of the drive. The original gets read once. You need free space on another drive equal to the size of the one you're copying, which is the main planning constraint. Scans are read-only either way — nothing is written back to the source — and an overnight scan that gets interrupted resumes where it stopped.
Finding out what chkdsk already did
If a check ran and you want to know what it changed, the log is sitting in Event Viewer. Press Win+R, run eventvwr.msc, expand Windows Logs, right-click Application, choose Filter Current Log, and pick Chkdsk and Wininit from the event-sources dropdown. Wininit is where the boot-time runs land, so it's usually the one you want.
Same thing from PowerShell, if you'd rather read it as text:
get-winevent -FilterHashTable @{logname="Application"} | ?{$_.providername -match "wininit"} | fl timecreated, message
The report tells you how many index entries were processed, what was recovered, and whether orphaned files were dealt with. It's the difference between guessing and knowing whether your folders were unlinked or were never touched.
If you already have a FOUND folder
It doesn't mean you're finished. It means chkdsk saved fragments in the plainest form it has.
Leave that folder alone and image the drive anyway. The .CHK files are one interpretation of the leftovers; a raw scan of the same drive reads the sectors directly and often reconstructs complete files with recognisable types that the fragments alone don't show. Renaming .CHK files by guessing extensions is worth a try on a handful of them, but it only works when a fragment happens to be a whole file, and it tells you nothing about the ones it isn't.
Two habits pay off here. Recover to an empty folder on a different drive so results don't mix with earlier attempts. And if you run a second pass with different settings, give it its own output folder.
Trying it on your own drive first
Install DiskRescue on your computer — not on the affected drive — and pick that drive in the list. For a drive that's making noises or stalling, take Recover safely (two steps) and image it first; otherwise Recover now scans it directly. Either way the scan only reads.
While it runs you get live counts of photos, videos and documents found, which tells you within a few minutes whether there's anything there worth paying for. Unreadable areas get retried in smaller chunks rather than skipped.
The trial then restores 20 files at any size, with no sign-up and no social share asked of you. Spend them on the files you'd be most upset to lose, save them to another drive, and open them. If they open cleanly, the rest of the scan is likely in similar shape.
One note on scope: the mode that restores files with their original names and folder paths reads NTFS records, so it applies to NTFS drives. Memory cards and most USB sticks are FAT32 or exFAT, and there DiskRescue scans by file signature — you get the files, but with generic names, which is the same trade-off every signature scan makes.
When software is the wrong tool
If the drive doesn't appear in Disk Management at all, if it clicks or grinds or spins up and stops, or if it was dropped or got wet, none of the above applies. That's a hardware problem, software has no path to the data, and each retry costs you a little more. A professional recovery lab is the route, and the fewer things you've tried first, the more they have to work with.
Take a note of what happened and when — when it was last working, whether you clicked repair, what you've already run and how many times. It saves them from repeating your steps, and it saves you the bill for the hours that would take.
How DiskRescue Compares
On a lifetime license, DiskRescue costs about 1/5 what the big-name recovery suites below charge — paid once and used for life, with no auto-renewal.
| DiskRescue | EaseUS Data Recovery Wizard Pro | Disk Drill PRO | |
|---|---|---|---|
| Price | $29.99 lifetime — launch price | $149.95 lifetime, or $99.95/year | $149 lifetime, or $89/year |
| Billing | One-time, lifetime — no auto-renewal | Monthly / yearly, or lifetime | Yearly, or lifetime |
| What you get free | Preview, then restore 20 free (any size, no share, no sign-up) | Preview, then recover 500 MB (2 GB after a social-media share) | Preview, then recover 100 MB |
| Damaged-disk recovery | ✓ | ✓ | ✓ |
| Deleted-file recovery | ✓ | ✓ | ✓ |
| Secure erase | ✓ | — (not listed) | ✓ |
Prices, features, and free-tier limits checked on each official site (Windows editions) on July 14, 2026 — they may change with sales or updates. The price comparison uses DiskRescue's launch price ($29.99). EaseUS free recovery is 500 MB by default, expanding to 2 GB after a social-media share (kb.easeus.com); Disk Drill's official free limit is 100 MB (cleverfiles.com).