Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

File Recovery for Linux Drives (ext4, ext3, ext2 from a Disk Image)

Undelete files from an image of a Linux-formatted drive or card, with names and folders.

Data Recovery No upload Works offline Free preview, no sign-upIncluded in your pass Ultimate tool Ultimate pass: ₹1,199 for 30 days

Free preview.

  • Free preview: every file found with its name, folder, size and condition, small watermarked thumbnails and the first half of each video (up to 10 seconds), marked.
  • Locked until you unlock it: download and saving to your device.
  • Unlock: Ultimate pass, ₹1,199 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Before you scan

  • Stop using the card or drive now. Deleted data is still there only until something new is written over it: every photo, file or update saved to it now can land on the space a deleted file used.
  • Save the image and the recovered files on a different drive. Writing to the card or drive you are recovering overwrites the very data you want back.
  • Is it an SSD inside a computer? Windows (7 and later) and Macs with Apple SSDs send a TRIM command as soon as a file is deleted, and the SSD then erases those blocks, so files deleted from an internal SSD are almost always gone. Over USB, TRIM support is newer and patchier, so an external SSD has a fair chance. R-Studio: data recovery from SSDs · DiskDigger: TRIM over USB
  • Was it a full format? A full format (for example Windows format /P, or a “zeroing” or secure erase) writes over every sector, so nothing is left. A quick format replaces only the file system’s tables and usually leaves the files’ data in place. Microsoft: the format command
  • Is it encrypted (BitLocker, FileVault, or a card that its device encrypted)? An encrypted volume is unreadable without its key, and this page does not decrypt volumes.
  • Is the card or drive failing (clicking, read errors, disconnecting)? Apple’s Disk Utility guide says not to make a disk image of a disk you believe to be failing. Use GNU ddrescue, which copies the good parts first and keeps a mapfile so it can resume, or a data recovery lab. Apple: create a disk image with Disk Utility
  • Nothing is uploaded. The image is read on your device, a few megabytes at a time, by code that runs in this page. No file data leaves it.
  • Use it only on cards and drives you own or may examine. Deleted files can be private: recover them only from your own cards and drives, or with their owner’s permission. This page never cracks passwords and never unlocks devices.

A web page cannot read a card, USB stick or disk directly, so you first make an image of it: a single file with every sector, made with a disk-imaging program. The Data Recovery Assistant shows how, step by step, and lists the routes worth trying before that (the Recycle Bin, cloud trash folders, backups).

What this page works on

  • Drives and cards formatted with ext4, ext3 or ext2 (how Linux formats them, also the system card of a Raspberry Pi), as a disk image. Imaging the running system disk of a computer is hard; image a drive or card you have taken out.
  • ext3 and ext4 erase where a deleted file’s data was. The page finds it in older copies of the file’s record that the file system’s journal still holds, which is often the case for files deleted shortly before the drive stopped being used. For the others, the deep scan finds photos, videos and documents by their content.
  • ext2 keeps that map, so its deleted files usually come back whole, with their names matched to them by their place in the folder.
  • The image needs room: a card of 32 GB makes an image of 32 GB, saved on another drive.

Choose the disk image

Next steps

About the File Recovery for Linux Drives (ext4, ext3, ext2 from a Disk Image)

First make a disk image of the drive or card: one file that holds every sector of it, made with a disk-imaging program and kept on another drive with room for it (the Data Recovery Assistant shows the steps for Linux, macOS and Windows). Then open the image here. The page reads the ext4, ext3 or ext2 file system the way the Linux kernel’s documentation describes it and lists the files that were deleted, with their names, folders, sizes and dates, and how likely each one is to be whole.

ext3 and ext4 erase the list of a file’s blocks from its record when the file is deleted, so the page also reads the file system’s journal: it holds older copies of recently changed records, often from before the deletion, and those still say where the file’s data was. ext2 keeps that list, so its deleted files usually come back whole. Then each photo, video, PDF, ZIP archive and Office file found is checked by its own content and marked Opens fully, Partly damaged or Can’t be opened; kinds of file the page cannot check, such as plain text, are marked Not checked. Nothing is uploaded: the image is read on your device, a few megabytes at a time.

How to use it

  1. Stop using the drive or card, and make an image of it on a different drive (the Data Recovery Assistant gives the exact steps; on Linux, GNU ddrescue or dd). The sooner after the deletion, the more the journal still holds.
  2. Read the checklist above the scanner (SSD, full format, encryption, a failing drive): it says when there is nothing left to find.
  3. Choose the image file (.img, .dd, .bin, .raw, or an image saved in parts, .001, .002 …, chosen together). The page shows the partitions it found, with each Linux volume’s kind, name, size and block size. E01, DMG, VHDX, VMDK and other formats are turned into a raw image first by the Disk Image Converter.
  4. Press Find deleted files. Tick Also list files that were not deleted to copy files off a drive or card that Linux will not mount.
  5. Filter the list by kind or condition, look at the thumbnails, play the first seconds of the videos, and select the files you want.
  6. With an Ultimate pass, save them to a folder on another drive (Chrome or Edge on a computer) or as a ZIP; without one, the list, the checks and the watermarked previews are the free preview.

Examples

Photos deleted from a Raspberry Pi camera card
Input
pi-card.img (an image of a 32 GB card), photos in /home/pi/camera deleted with rm the day before
Result
home/pi/camera/2024-05-01_0612.jpg · 3.2 MB · Opens fully · found in an older copy of its record in the journal

The card’s ext4 erased each photo’s block list when it was deleted; the journal still held the records from before, so the photos came back with their names.

A folder deleted from an ext2 USB drive
Input
backup-stick.img, the folder Projects/2023 deleted
Result
Lost files/Folder 16321/plan.odt · Opens fully (its folder’s name could not be told apart from the other deleted folders’)

ext2 keeps a deleted file’s block list, but clears the link from each name to its record. The page matches names to records by their place in the folder where that is certain, and otherwise keeps a deleted folder’s files together under its record number.

Files emptied from the desktop Trash
Input
An external drive used with a Linux desktop, its Trash emptied
Result
.Trash-1000/files/report.pdf · Opens fully (emptied from the Trash)

Desktop Linux moves deleted files into a .Trash folder first, under their own names. Emptying it deletes them there, and the page lists them under that folder.

Common uses

  • Getting back photos, videos and documents deleted from a Linux drive, an external disk formatted with ext4, or a Raspberry Pi card.
  • Restoring files deleted with rm or emptied from the desktop Trash, under their names and folders.
  • Copying files off an ext4 drive or card that Linux will not mount, from its image (tick “Also list files that were not deleted”).
  • Checking which deleted files are still whole before deciding what to save.

Why you need an image first

A web page cannot read a disk or memory card sector by sector, and no browser setting changes that: the WebUSB standard does not let a page claim USB storage devices, and the File System Access API gives pages files and folders, never raw devices. A disk image (a file with every sector of the drive, deleted areas included) is what recovery needs, and imaging is also the safe way to work: the drive is read once and never written to, and every later step works on the copy.

On Linux, sudo ddrescue /dev/sdX drive.img drive.map (GNU ddrescue) images a drive and keeps going past read errors; sudo dd if=/dev/sdX of=drive.img bs=4M status=progress does the same on a healthy one. Unmount the drive first, and save the image on a different drive.

How deleted files are found on ext4, ext3 and ext2

Each file on an ext file system has a record (an inode) with its size, times and the list of blocks that hold its data: block numbers on ext2 and ext3, extents on ext4 (the kernel’s ext4 documentation). A folder is a list of names, each with the number of its record. Deleting a file removes its name from the folder by joining its space to the name before it, which leaves the name in place until a new name is written there, and frees the record and the blocks.

  • ext2 marks the record deleted and leaves its block list, so the data is found exactly. It does clear the record number beside the deleted name, so the page matches names to records by their place in the folder (Linux gives a new file the first unused record of its folder’s group), only where the match is one to one; other records are listed under Lost files, deleted folders’ files together.
  • ext3 and ext4 keep the record number beside the name but erase the block list from the record. Their journal writes every changed block of records and folders to a ring of its own before writing it in place, so it often still holds a copy of a record from before the deletion. The page reads the whole journal, also its parts already written in place, and takes the newest copy from when the file still existed, checked by the record’s generation number (which changes when a record is used for another file) and by the copies of the folder that show when the name was deleted.
  • The volume’s block bitmaps say which blocks are in use today. A deleted file’s blocks that a file in use holds now, that a file deleted later used (seen in the journal’s copies too), or that now hold the file system’s own structures are marked as written over.

When the start of a volume is damaged (Linux then says it cannot find the file system), the page reads one of the backup copies of the superblock and the group descriptors that every ext volume keeps further on.

What the conditions mean

  • Opens fully: the file’s own structure checks out from its first byte to its last (a JPEG to its end marker, every PNG chunk checksum, a video’s index and data, every file inside a DOCX or ZIP).
  • Partly damaged: it starts correctly, but part of it is missing or was written over; or some of its blocks now belong to other files.
  • Can’t be opened: its first block now belongs to another file, or the file system no longer says where its data was (an ext3 or ext4 file whose record the journal no longer holds). Its name is still listed.
  • Not checked: a kind of file whose content the page cannot check (text files, for example). The note says whether another file uses its blocks now.

When a file made after a deleted one was deleted too and its own record is gone, nothing on the volume says which blocks it used. Such files are marked: their data may be that later file’s.

Measured on test images

NIST’s CFReDS deleted-file-recovery test images include 22 images made with Linux, each with an ext2, an ext3 and an ext4 partition, with NIST’s record of every file deleted from them and the sectors it used (NIST tags each 512-byte block with its file and position). The page’s results on all of them:

  • ext2: 717 deleted files listed. 668 came back with every block in place (names in Devanagari, Arabic, Korean, Japanese, Chinese, Cyrillic and Hebrew characters among them, and 260 files deleted from one folder); 34 were marked as written over by later files, which they were; 14 names could not be matched to their records one to one and were listed by name, their records among the Lost files; and one small file was the desktop Trash’s note of a file it had emptied, read exactly.
  • ext3: 882 deleted files listed, all but one by name. The journal still held records from before the deletion for 33 of them: 27 came back whole and 6 were marked as written over, which they were.
  • ext4: 926 deleted files listed, 923 of them by name. The journal still held records for 221 of them: 218 came back whole, 2 were marked as written over, and 1 was marked as possibly holding another file’s data, which it did (a file made and deleted after it had used its blocks).
  • No file was said to be whole that was not.

The other ext3 and ext4 files had lost their block lists, as these file systems do on deletion, and the journal no longer held their records: their names are listed, and the deep scan searches for them by content. With “Also list files that were not deleted” ticked, the page lists every file on the 66 partitions, also 1,022 files in nine folders. Eight of these images (24 partitions) are part of the page’s automated tests, as small extracts, with their checks, together with a modern ext4 volume (64-bit, with metadata and journal checksums).

Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries. Raspberry Pi is a trademark of Raspberry Pi Ltd. MySmartCoPilot is not affiliated with either.

Limitations

  • Works on disk images only, not on drives directly (browsers do not allow it). Raw images (.img, .dd, .bin, .raw, .iso), raw images saved in parts (.001, .002 …) and fixed-size VHD files open directly; E01, DMG, VHDX, dynamic VHD, VMDK, QCOW2 and VDI images are turned into raw images first by the Disk Image Converter.
  • ext2, ext3 and ext4 only. Memory cards and USB sticks formatted with FAT or exFAT are undeleted by SD Card & USB Drive Recovery, Windows drives by NTFS Deleted File Recovery; Btrfs, XFS, ZFS and F2FS are not read, and the deep scan finds photos, videos and documents on any of them by their content.
  • ext3 and ext4 erase where a deleted file’s data was. The page finds it only while the journal still holds an older copy of the file’s record; the journal is a ring that a busy file system fills within minutes or days, so the chances fall with every change made after the deletion. Files whose records it no longer holds are listed by name only.
  • A file written and deleted after another one may have used its blocks; when that file’s record is gone too, nothing on the volume records it. The page marks such files, and the content check catches this for photos, videos and documents, not for plain text.
  • Data that has been written over cannot be recovered by any software. A full format, a secure erase, or TRIM on an SSD (many Linux distributions run fstrim every week, and the discard mount option erases at once) leave nothing to find.
  • Encrypted volumes (LUKS, or folders encrypted with fscrypt) cannot be read without their key, and this page does not decrypt them. Unlock the volume on Linux and image the unlocked device (under /dev/mapper). LVM and software RAID volumes are read the same way: activate them on Linux and image the logical volume or the assembled array.
  • Files kept inside their record (ext4 inline data) and files with holes are listed but cannot be saved whole. Symbolic links are listed by name, as they hold no data of their own. Very large ext4 files whose extent tree was erased lose the parts the journal does not hold.
  • A web page cannot set a file’s date: files saved to a folder carry the day they were saved. The ZIP keeps the original dates, shown in this computer’s time zone.

Privacy

The image is read by your browser on your device, a few megabytes at a time, in background workers; no part of it or of the files in it is sent anywhere.

Frequently asked questions

What do I get without a pass?

Without a pass, File Recovery for Linux Drives (ext4, ext3, ext2 from a Disk Image) shows every file found with its name, folder, size and condition, small watermarked thumbnails and the first half of each video (up to 10 seconds), marked. Until you unlock it, the result can’t be downloaded or saved to your device. An Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

Can this page scan my Linux drive or Raspberry Pi card directly?

No. Browsers do not let web pages read storage devices sector by sector, so you make an image of the drive first and open that. On Linux, GNU ddrescue or dd makes one; the Data Recovery Assistant shows how on Linux, macOS and Windows, with the commands to copy.

Why are some deleted files listed with their names but no data?

ext3 and ext4 erase a file’s block list from its record when it is deleted. The page then looks for an older copy of the record in the journal; when the journal has been written over since (it is a ring of a fixed size), nothing on the volume says where the data was. The deep scan can still find photos, videos and documents among them by their content, without their names.

How is this different from extundelete or ext4magic?

Those are command-line programs that read the journal of an unmounted ext3 or ext4 volume in much the same way. This page does it on an image in the browser, without installing anything, and checks each file’s condition before you save it: which blocks other files have used since, and whether the file’s own content opens.

What does “Lost files” mean?

Deleted records whose names could not be found or matched to them: on ext2, a deleted name loses the number of its record, and the page only matches names and records where the match is certain. A deleted folder whose name could not be told apart from the others is listed as Lost files/Folder and its record number, with its files inside under their own names.

Does it work on the system card of a Raspberry Pi?

Yes: a Raspberry Pi OS card has a small FAT boot partition and an ext4 partition with the system and your files; the page reads the ext4 one. Take the card out of the Pi, image it on another computer, and open the image here. Turn the Pi off as soon as you notice the deletion: the system writes to the card all the time.

Should I mount the drive to check it first?

Not with write access. Mounting an ext3 or ext4 volume read-write replays and then reuses its journal, which is where the older copies of deleted files’ records are. Image the drive first; if you mount it at all, use mount -o ro,noload, which neither writes nor replays the journal.

Where should I save the recovered files?

On a different drive from the one you are recovering: saving onto the same drive could overwrite the deleted data you are trying to get back.

Is anything uploaded?

No. The image never leaves your device: the page reads it in pieces with your browser and processes it in background workers. It works offline once the page has loaded.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.