Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / virus & malware
Specialist recovery · virus & malware

Virus and malware data recovery in Cambridge.

Most malware does not set out to destroy your documents — it wants credentials or resources. Where files disappear after an infection, the cleanup is usually responsible: quarantined by antivirus, deleted by a removal tool, or rolled back by a system restore. The first of those is free to undo.

£300 + VAT
Most jobs — no fix, no fee
Returned malware-free
~ malware_2026-001 — live RECOVERED
$ cdr diagnose /dev/sdb
 Device: SanDisk USB (64 GB)
 Status: MALWARE — shortcut virus, files hidden
 Client: confidential · Norwich NR1

$ cdr engineer-working
 Isolated image: taken · malware contained
 Hidden files: un-hidden + recovered
 Scan: data cleaned · 0 threats remaining

$ cdr verify
 ✓ documents — 9,840 files
 ✓ photos — 12,300 files
 ✓ clean data returned — recovered
// the malware is rarely what broke it

Four different things get called a virus.

What happenedActual causeProspect
Files encrypted, ransom noteRansomware A different problem with a different answer. Not decryptable, but a great deal is usually recoverable from what the run missed. See ransomware
Files gone after a clean-upThe antivirus quarantined them The most common cause by a distance. The security software moved infected files to quarantine and they are frequently restorable from within it. Check quarantine
Windows will not boot after removalSystem files removed with the infection The malware attached itself to system components and removing it took those too. Your data is untouched; the operating system is not. Data is fine
Files corrupted or renamedFile-infecting virus Genuinely rare now. Older infectors attached to executables and could damage them. Modern malware has little interest in corrupting your documents. Usually repairable
// check quarantine first

Before anything else, and before anyone charges you.

Antivirus software does not usually delete what it finds. It moves it to a quarantine area, and if it decided a document was infected, that document is sitting there intact. Windows Defender keeps its quarantine under Virus & threat protection, in Protection history. Third-party products all have an equivalent.

A meaningful proportion of the enquiries we take on this end here, in five minutes, at no cost. It is worth checking before assuming files are gone.

The second place to look is System Restore and Previous Versions, which frequently survive a malware clean-up intact and can return a folder to how it looked last week.

// recovering safely

The data comes off, the system does not.

Where the machine is compromised and the data still matters, the correct approach is to take the drive out of service, image it, and extract the files from the image rather than from a running infected system. That way nothing executes and nothing spreads.

Extracted files are then scanned before release, and documents are inspected for embedded macros and scripts. What comes back is data rather than a restored system — and that distinction is deliberate. A machine that has been compromised should be rebuilt from clean media rather than disinfected and trusted.

We do not return the operating system, and we would advise against anyone who offers to.

// pricing

From £300, fixed in writing.

Data extraction from a compromised machine is from £300 +VAT. Where the underlying drive has also failed, that is quoted as recovery work at the appropriate class.

If the answer turns out to be that your files are in quarantine, we will tell you that at no charge. It happens frequently enough to be worth saying.

// questions

Malware and lost files, answered.

Check the antivirus quarantine first. Security software moves suspected files rather than deleting them, and this resolves a large share of these enquiries in a few minutes for nothing.

The removal took system files the malware had attached itself to. Your documents are almost certainly untouched. Do not reinstall over the top — get the data off first, then rebuild.

We will get your data off, scanned and verified. We will not return a disinfected operating system, because a compromised machine should be rebuilt from clean media rather than trusted after a clean-up.

They are scanned before release and documents are checked for embedded macros and scripts. Extraction happens from an image rather than a running system, so nothing executes during the process.

That is ransomware rather than a virus and the approach is different. Do not reimage anything — those disks hold unencrypted originals in free space.

Three to seven working days. Imaging and extraction are quick; scanning and verifying a large document set is what adds time.

// hit by a virus?

Don’t keep running it — let us recover it clean.

A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.