Malware usually hides, scrambles or unlinks what you had rather than genuinely erasing it, so in most cases it’s all still sitting on the disk. We copy the affected SSD, hard drive, card or USB stick in isolation, lift the files off that copy, and give them back clean — the infection is never once set running.
$ bdr diagnose /dev/sdb → Device: SanDisk USB (64 GB) → Status: MALWARE — shortcut virus, files hidden → Client: confidential · Cranleigh GU2 8XH $ bdr engineer-working → Isolated image: taken · malware contained → Hidden files: un-hidden + recovered → Scan: data cleaned · 0 threats remaining $ bdr verify → ✓ documents — 9,840 files → ✓ photos — 12,300 files → ✓ clean data returned — recovered
Every hour an infected drive keeps running gives the malware more time to damage or wipe your files, and more chance to jump to whatever else you plug in. Repeated antivirus sweeps are just as risky — they can quarantine or bin the very files you’re trying to save. Power the device down, keep it clear of your other machines, and get in touch: we lift your data off an isolated copy without the infection ever executing.
A drive that won’t open its files is nearly always damaged structures, missing pointers or flipped attributes — not files that have genuinely gone. Show us it’s yours, and here’s the sort of trouble we untangle most weeks.
Whatever it’s stored on and whoever made it, a virus or malware job is one we can almost always take on — if your files are on it, we can help.
The disks inside laptops, PCs and Macs; standalone SSDs and hard drives; external and portable units; and flash of every kind — USB sticks, SD, microSD and CF.
One rule governs the whole job: the infection never runs. We copy your device in isolation, recover from that copy, then clean and hand back — in that order, every time.
Talk us through what happened; we establish what the malware actually did to your data — corrupted, hidden, deleted — and put a written quote to you, usually within 48 hours.
Onto a write-blocked, air-gapped rig goes a read-only image, so at no point can the infection execute, reach the network or spread to anything else.
With the malware frozen, hidden and system flags come off, directory entries are rebuilt, and anything deleted is carved back out of the unallocated space.
A mangled $MFT, cross-linked clusters, a lost partition table — we repair those, or reconstruct them from the volume’s own spare copies, until the data is reachable again.
Everything recovered is checked against current signatures and cleared, then opened and checksum-matched, so nothing infected or broken rides back with your files.
Back it comes on fresh media, tidied and ready to go.
Onto an external drive and posted back, or via our free download service for up to 75GB — your choice.
Infected disks of every sort — the drives in laptops and PCs, SSDs and hard drives, external units, USB sticks and memory cards — recovered from a sealed-off copy and handed back clean, with the infection never once set running.
Tell us what happened and we will get back to you, usually within one working day.
We’ll be in touch shortly. Anything urgent, call 01483 901310.
No surprises and no hard sell — a free diagnostic and a written quote land before any work is done.
A few recent virus and malware jobs across different devices. Names withheld, outcomes verified.
Classic hidden-attribute infection. Imaged in isolation, the real files un-hidden, the whole set recovered and returned scanned clean.
Its Windows files were shot; the data wasn’t. We read everything straight off the disk and gave it back with no infection attached.
Antivirus had swept up files that mattered. We retrieved them from a forensic image while the free space still held them.
Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.
Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.
Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.
Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.
We’ll be in touch shortly. For anything urgent, call 01483 901310.
Everything people tend to ask before sending in a virus-hit or malware-hit drive.
Nearly always. The damage a virus does is mostly to the plumbing, not the water: it corrupts file-system structures — the $MFT on NTFS, the FAT tables on flash — or rewrites headers, while the file contents underneath stay put. Working on an isolated copy, we mend or rebuild that plumbing, pull deleted items back out of free space, and return everything with the infection stripped out.
Not at all. That particular pest — the one you catch off USB sticks and memory cards — simply flags your files hidden and system and litters .lnk shortcuts (plus an autorun.inf) over the top. It deletes nothing. Reset the attributes, clear away the shortcuts, and your files are exactly where they always were.
They won’t. The recovery happens in a sealed-off environment and the results are scanned before they leave us, so plugging the returned data back in won’t reintroduce anything to your machines.
Rarely. A wrecked boot chain — MBR, boot configuration, the registry and system files Windows leans on — stops the machine starting without laying a finger on your documents. We sidestep the operating system entirely, image the disk, and read your files off it on their own.
Frequently. A quarantined file is really an encoded copy tucked into the antivirus vault with the original unlinked; a straight deletion just leaves the blocks in place until something overwrites them. Either way there’s a good chance of recovery — from the vault or from unallocated space — so long as the drive stays idle. Stop using it and call us.
What we do is get your data out and hand it back clean. The infected system is never booted — your files come off an image and are scanned in isolation — so the copy you receive carries no malware. Cleaning up and rebuilding the machine itself, though, is a job in its own right.
A logical recovery is priced from £300 + VAT. The diagnostic beforehand is free, most jobs run on a no fix, no fee basis, and if the hardware turns out to be failing as well we’ll put any higher figure to you in writing first.
Just about anything that stores files — the drives inside laptops, PCs and Macs, standalone hard drives and SSDs, external and portable units, and flash of every kind, from USB sticks to SD, microSD and CF cards.
One to three working days covers most infections, often less, with the free diagnostic usually wrapped up inside 48 hours. If it’s urgent, say so and we’ll try to jump it up the queue.
Two options: bring it to our Guildford premises on a weekday between 9am and 5:30pm, or send it in fully insured. Seal it up well and tuck your contact details — name, address, phone, email — inside so we can log it. The free diagnostic and a written quote follow before we touch anything.
A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.