Most malware does not set out to destroy your documents — it wants credentials or resources. Where files disappear after an infection, the cleanup is usually responsible: quarantined by antivirus, deleted by a removal tool, or rolled back by a system restore. The first of those is free to undo.
$ mdr diagnose /dev/sdb → Device: SanDisk USB (64 GB) → Status: MALWARE — shortcut virus, files hidden → Client: confidential · Lancaster LA1 $ mdr engineer-working → Isolated image: taken · malware contained → Hidden files: un-hidden + recovered → Scan: data cleaned · 0 threats remaining $ mdr verify → ✓ documents — 9,840 files → ✓ photos — 12,300 files → ✓ clean data returned — recovered
Wiping and reinstalling is the standard advice and it destroys the artefacts that tell you what happened — which you may need for an insurer, for the ICO, or simply to know whether anything left the building.
An uncomfortable finding, and the reason we ask what has already been run.
Most malware does not destroy data deliberately. It steals credentials, mines currency, serves adverts or waits quietly for instructions — none of which needs your documents deleted. Where files genuinely vanish, the cause is frequently the removal rather than the infection: antivirus quarantining infected documents wholesale, a cleanup tool deleting anything it could not clean, or a system restore rolling the machine back past work that had not been backed up.
That matters because quarantined files are usually recoverable — they are moved to a protected folder rather than erased, and most antivirus products will release them. Before treating this as a recovery job, look in the quarantine. It is free and it resolves a fair number of these.
Different causes, different prospects.
Because recovering infected data onto a working system is how this happens twice.
Never boot the infected machine again to recover from it. The drive is imaged read-only on isolated equipment instead.
Everything recovered is checked against current definitions before it goes anywhere near your working systems.
Documents, images, databases and mail come back. Programs and system files do not — those get reinstalled from clean sources rather than carried across.
Once the data is safe, a clean install is exactly right. Doing it first destroys both the data and the evidence of what happened.
Assuming the quarantine folder has not already solved it.
A single infected drive is from £300 +VAT after a free 48-hour diagnostic, with most jobs no fix, no fee. Servers and arrays start from £500 +VAT.
Check the antivirus quarantine before anything else — if the files are sitting there, releasing them takes a couple of clicks. And if your files are encrypted with a ransom note rather than missing, that is ransomware and handled differently; the free assessment will tell you which you are dealing with.
Send the device over with a short account of what happened to it. The diagnostic costs nothing and commits you to nothing, and the figure that follows is fixed in writing before anything is opened.
Nothing can begin until the device is on the bench, which makes this the only step that needs anything from you. Pack it properly, put your details in with it, and send it over. What follows is a free diagnostic and a written figure, in that order.
Posting it? Use something tracked and insured — whatever is on the drive is worth considerably more than the postage. Bringing it in? Weekdays, 9am to 5:30pm, and it still wants packing as above for the journey.
Tell us what the device is, what it is doing, and anything already tried — an engineer will come back with a realistic view of the odds and a price band, before you commit to posting anything.
We’ll be in touch shortly. For anything urgent, call 0161 871 0788.
Everything people tend to ask before sending in a virus-hit or malware-hit drive.
Frequently, and the first place to look is free: antivirus quarantine. Most products move suspect files to a protected folder rather than deleting them, and they can be released from the interface. Where files were genuinely deleted, ordinary recovery applies — stop using the machine.
Not before the data is off. A reinstall writes over everything you are trying to recover and destroys the artefacts showing what happened. Recover first, rebuild after — and the rebuild is the right thing to do once the data is safe.
No. Ransomware encrypts your files and demands payment. Most other malware steals credentials or resources and rarely destroys data deliberately — where files go missing after an infection, the cleanup is usually responsible.
They are scanned against current definitions before being returned, and we return data rather than executables — documents, images, databases and mail, not programs or system files, which should be reinstalled from clean sources.
Open its quarantine or vault and restore what you need. Quarantined files are moved, not destroyed, and this resolves a good share of the enquiries we get about virus damage without anyone paying anything.
From £300 plus VAT for a single drive after a free 48-hour diagnostic, or from £500 plus VAT for servers and arrays. Check the quarantine folder first — it costs nothing and it often solves it.
A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.