Most malware does not set out to destroy your documents — it wants credentials or resources. Where files disappear after an infection, the cleanup is usually responsible: quarantined by antivirus, deleted by a removal tool, or rolled back by a system restore. The first of those is free to undo.
$ cdr diagnose /dev/sdb → Device: SanDisk USB (64 GB) → Status: MALWARE — shortcut virus, files hidden → Client: confidential · Norwich NR1 $ cdr engineer-working → Isolated image: taken · malware contained → Hidden files: un-hidden + recovered → Scan: data cleaned · 0 threats remaining $ cdr verify → ✓ documents — 9,840 files → ✓ photos — 12,300 files → ✓ clean data returned — recovered
Antivirus software does not usually delete what it finds. It moves it to a quarantine area, and if it decided a document was infected, that document is sitting there intact. Windows Defender keeps its quarantine under Virus & threat protection, in Protection history. Third-party products all have an equivalent.
A meaningful proportion of the enquiries we take on this end here, in five minutes, at no cost. It is worth checking before assuming files are gone.
The second place to look is System Restore and Previous Versions, which frequently survive a malware clean-up intact and can return a folder to how it looked last week.
Where the machine is compromised and the data still matters, the correct approach is to take the drive out of service, image it, and extract the files from the image rather than from a running infected system. That way nothing executes and nothing spreads.
Extracted files are then scanned before release, and documents are inspected for embedded macros and scripts. What comes back is data rather than a restored system — and that distinction is deliberate. A machine that has been compromised should be rebuilt from clean media rather than disinfected and trusted.
We do not return the operating system, and we would advise against anyone who offers to.
Data extraction from a compromised machine is from £300 +VAT. Where the underlying drive has also failed, that is quoted as recovery work at the appropriate class.
If the answer turns out to be that your files are in quarantine, we will tell you that at no charge. It happens frequently enough to be worth saying.
Check the antivirus quarantine first. Security software moves suspected files rather than deleting them, and this resolves a large share of these enquiries in a few minutes for nothing.
The removal took system files the malware had attached itself to. Your documents are almost certainly untouched. Do not reinstall over the top — get the data off first, then rebuild.
We will get your data off, scanned and verified. We will not return a disinfected operating system, because a compromised machine should be rebuilt from clean media rather than trusted after a clean-up.
They are scanned before release and documents are checked for embedded macros and scripts. Extraction happens from an image rather than a running system, so nothing executes during the process.
That is ransomware rather than a virus and the approach is different. Do not reimage anything — those disks hold unencrypted originals in free space.
Three to seven working days. Imaging and extraction are quick; scanning and verifying a large document set is what adds time.
A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.