Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · Extract Without Executing

Reading a Machine Is Not the Same as Running It

Her enquiry asks for two things and the second is the interesting one. An old laptop running a long-unsupported system, holding photographs she wants moved to an external drive, where security software would not install and a later scan "sat at zero per cent for hours" — and she asks whether the photographs can be extracted "and ensured virus free." Both are reasonable, and they are achieved by not starting the machine at all.

MediaInternal drive of a laptop running a long-unsupported operating system — security software failing to install and scans failing to progress; photographic content required
Reported situationLaptop of considerable age running an operating system no longer receiving updates · newer machine in use for several years · security software failing to install on the older machine · alternative security software installing but failing to progress a scan · photographic content held on the older machine · external drive purchased as a destination · content required and required to be clean
Fault classPossible compromise on an unsupported system with storage otherwise readable — extraction achievable without executing the installed system; content scanned in isolation before release
Equipment usedDrive removed and read without the installed system being started · imaged write-blocked at the block level before any interpretation · photographic content extracted from the image rather than through the host · extracted content scanned in isolation before delivery · executable content excluded from the deliverable

The decode: why not starting the machine solves both problems

Why her security software behaved as it did: a scan that will not progress is characteristic of a system under strain, and an unsupported one may also lack what current software requires. It is not proof of compromise and it is not reassurance either — it simply did not complete.

Why running the machine is what she should stop doing: anything present on it only acts while the system is running. Starting the laptop is what gives installed software the opportunity to do anything at all, including to whatever is connected to it.

Why that matters for her plan specifically: she intended to copy photographs onto a new external drive from the machine itself. Connecting clean media to a possibly compromised running system is the route by which anything present would travel.

What is done instead: the drive comes out and is read on equipment that does not start it. Reading a drive executes nothing — it copies sectors, and no software on the drive is given the chance to run.

Why that distinction is the whole answer: a machine is dangerous when it is executing and inert when it is being read. Extraction and execution are entirely separate activities, and only one of them involves risk.

How the second requirement is then met: the photographs are extracted from the image and scanned in isolation before being delivered. They are examined on a controlled system rather than on hers, and anything not required is excluded.

Why photographs are a favourable deliverable in this respect: they are data rather than programs. An image file is interpreted by whatever opens it and does not run, so a set restricted to photographs is inherently the safer request.

Why the deliverable should exclude executable content deliberately: she wants photographs, and nothing else needs to travel. Restricting the output to the file types requested is a protection in itself, and it costs nothing.

Why the age of the system is otherwise not a problem: the filesystem is well understood and reads straightforwardly. The drive itself is ordinary and the operating system's obsolescence affects running it rather than reading it.

What must not happen meanwhile: no further attempts to start the machine, install software or run scans. Every one of those requires the system to execute, which is the only thing worth avoiding here.

On the bench

The drive was removed and read without the installed system being started — software present on a machine acting only while that machine executes, so reading sectors runs nothing and gives installed software no opportunity, whereas connecting clean media to a running system is the route by which anything present would travel. Photographic content was extracted from the image rather than through the host, then scanned in isolation before delivery, with executable content excluded from the deliverable.

The outcome

The drive read without the system being started, content extracted from a block-level image, and the deliverable scanned in isolation with executable content excluded. Free assessment, one fixed written figure including VAT; where a drive has to be opened, 50% of parts and labour is payable upfront with the balance only on success — otherwise no recovery, no fee. The decode: not starting the machine answers both of your questions. Reading a drive executes nothing, and photographs are data rather than programs — so restricting the deliverable to them is itself a protection.

Getting files off a machine you no longer trust

Stop starting it, and don't copy anything from it onto new media while it's running — that's precisely the route by which anything present would travel to your clean drive. The safer approach is to take the drive out and read it without ever starting the installed system, because software only acts while a machine executes, and copying sectors runs nothing. Ask for the deliverable to be restricted to the file types you actually want: photographs are data rather than programs, so a photo-only set is inherently safer, and anything else needn't travel at all.

Photographs on an old machine you would rather not run?
Don't start it — call Manchester Data Recovery on 0161 871 0788; drive read without the installed system being started, content extracted from an image, deliverable scanned in isolation with executables excluded.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.