Antivirus software exists to remove threats, not to preserve documents — so a great deal of what people lose after an infection is deleted by the cleanup rather than the malware. Unlike ransomware there is no encryption standing in the way here, which makes the outlook considerably better if the machine stops being used.
$ bdr diagnose /dev/sdb → Device: SanDisk USB (64 GB) → Status: MALWARE — shortcut virus, files hidden → Client: confidential · Witney OX28 $ bdr engineer-working → Isolated image: taken · malware contained → Hidden files: un-hidden + recovered → Scan: data cleaned · 0 threats remaining $ bdr verify → ✓ documents — 9,840 files → ✓ photos — 12,300 files → ✓ clean data returned — recovered
Antivirus tools are built to remove threats, and they routinely delete or quarantine infected files rather than repair them. If those files matter, recover them before letting a cleaner loose — or at minimum check the quarantine before emptying it.
Most data loss after an infection is not caused by the malware directly.
Worth separating, because the two are often confused and the outlook differs sharply.
Ransomware encrypts deliberately and holds the key. Ordinary malware damages, deletes or hides — and none of that involves cryptography you cannot get past. That makes conventional recovery techniques effective: deleted entries can be recovered from the file system, hidden files simply revealed, boot structures rebuilt.
If your files have been encrypted and there is a ransom note, that is a different service and a different conversation — see our ransomware page. If files have vanished, will not open, or the machine will not boot after an infection, this is the right page and the prospects are considerably better.
The order protects both the data and the machine.
Before any cleaning, so the pre-cleaning state is preserved. Quarantined and deleted files are frequently still recoverable from that image.
Deleted entries restored from the file system, hidden files revealed, boot structures rebuilt — all against the image, never the original.
Antivirus quarantine folders hold the original files in an encoded form, and legitimate documents that merely carried an infected macro can often be extracted intact.
Recovered files are checked before return, so nothing goes back onto a clean machine carrying the same problem.
Data comes back on clean media rather than the original drive, which we would recommend replacing or fully reinstalling.
Standard recovery rates — this is not a specialist premium.
A single drive is from £300 +VAT, and a server, NAS or RAID system from £500 +VAT, confirmed in writing after a free 48-hour diagnostic. Most jobs are no fix, no fee.
We recover data; we do not sell antivirus or ongoing IT support. Once your files are back, cleaning or rebuilding the machine is a job for your usual IT provider, and we will say plainly what we found so they can act on it.
Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. For anything urgent, call 01865 593000.
Everything people tend to ask before sending in a virus-hit or malware-hit drive.
Usually, in the same way as any deletion — the entry is removed and the data stays until overwritten. Stop using the machine as soon as you notice, because continued use is what actually costs you the files.
Often, and this is more common than damage by the malware itself. Check the quarantine folder before emptying it, since it holds originals in encoded form. Beyond that, deleted files are recoverable from an image of the drive.
No, and the prospects are much better. Ransomware encrypts deliberately and holds the key; ordinary malware deletes, damages or hides, none of which involves cryptography you cannot get past. If there is a ransom note, that is a different service.
Usually not. Some malware alters boot structures so the machine will not start while leaving the data entirely intact. The drive can be read on separate equipment and the files recovered regardless of whether the machine boots.
Recover first. Antivirus tools remove threats rather than preserve files, and they routinely delete or quarantine documents that merely carried an infected macro. Image the drive before letting a cleaner run.
From £300 plus VAT for a single drive and from £500 plus VAT for a server, NAS or RAID system, fixed in a written quote after a free 48-hour diagnostic, with most jobs no fix, no fee.
A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.