Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
/ home / services / virus & malware
Malware & virus damage · recovery

Struck by malware? What you lost is usually still there.

Malware usually hides, scrambles or unlinks what you had rather than genuinely erasing it, so in most cases it’s all still sitting on the disk. We copy the affected SSD, hard drive, card or USB stick in isolation, lift the files off that copy, and give them back clean — the infection is never once set running.

£300 + VAT
Most jobs — no fix, no fee
Returned malware-free
~ malware_2026-001 — live RECOVERED
$ bdr diagnose /dev/sdb
 Device: SanDisk USB (64 GB)
 Status: MALWARE — shortcut virus, files hidden
 Client: confidential · Cranleigh GU2 8XH

$ bdr engineer-working
 Isolated image: taken · malware contained
 Hidden files: un-hidden + recovered
 Scan: data cleaned · 0 threats remaining

$ bdr verify
 ✓ documents — 9,840 files
 ✓ photos — 12,300 files
 ✓ clean data returned — recovered
!

Stop using the infected device — right now.

Every hour an infected drive keeps running gives the malware more time to damage or wipe your files, and more chance to jump to whatever else you plug in. Repeated antivirus sweeps are just as risky — they can quarantine or bin the very files you’re trying to save. Power the device down, keep it clear of your other machines, and get in touch: we lift your data off an isolated copy without the infection ever executing.

// what malware does to data

The shapes malware damage takes.

A drive that won’t open its files is nearly always damaged structures, missing pointers or flipped attributes — not files that have genuinely gone. Show us it’s yours, and here’s the sort of trouble we untangle most weeks.

// devices we recover

Every device. Every brand.

Whatever it’s stored on and whoever made it, a virus or malware job is one we can almost always take on — if your files are on it, we can help.

SamsungSanDiskKingstonWestern DigitalSeagateLexarCrucialSonyToshibaTranscendPNYVerbatimIntegralADATACorsairKioxiaSilicon PowerHitachiMaxtorTeam Group

The disks inside laptops, PCs and Macs; standalone SSDs and hard drives; external and portable units; and flash of every kind — USB sticks, SD, microSD and CF.

// our recovery process

Inside a malware recovery.

One rule governs the whole job: the infection never runs. We copy your device in isolation, recover from that copy, then clean and hand back — in that order, every time.

01

Free diagnostic

Talk us through what happened; we establish what the malware actually did to your data — corrupted, hidden, deleted — and put a written quote to you, usually within 48 hours.

02

Copy it, sealed off

Onto a write-blocked, air-gapped rig goes a read-only image, so at no point can the infection execute, reach the network or spread to anything else.

03

Recover from the copy

With the malware frozen, hidden and system flags come off, directory entries are rebuilt, and anything deleted is carved back out of the unallocated space.

04

Rebuild what’s broken

A mangled $MFT, cross-linked clusters, a lost partition table — we repair those, or reconstruct them from the volume’s own spare copies, until the data is reachable again.

05

Scan, then verify

Everything recovered is checked against current signatures and cleared, then opened and checksum-matched, so nothing infected or broken rides back with your files.

06

Return it usable

Back it comes on fresh media, tidied and ready to go.

07

Backup Drive or Download

Onto an external drive and posted back, or via our free download service for up to 75GB — your choice.

// what we recover from

Any device. Your files back, clean.

Infected disks of every sort — the drives in laptops and PCs, SSDs and hard drives, external units, USB sticks and memory cards — recovered from a sealed-off copy and handed back clean, with the infection never once set running.

All media
HDD, SSD, USB, cards
Isolated
malware never runs
Clean return
data scanned safe
48 hr
Diagnostic SLA
1–3
Working days typical
25 yrs
Recovering data
// get a custom quote

Get a custom quote

Tell us what happened and we will get back to you, usually within one working day.

Prefer to call? 01483 901310 · Mon–Fri 9am–5:30pm

// pricing

Clear, fixed pricing.

No surprises and no hard sell — a free diagnostic and a written quote land before any work is done.

Virus & malware data recovery
£300 + VAT
From price for a logical recovery of infected data.
  • Free diagnostic and a written quote up front
  • No fix, no fee on most jobs
  • Clean, recovered files back on fresh media
// recent recoveries

Infected drives. Real recoveries.

A few recent virus and malware jobs across different devices. Names withheld, outcomes verified.

// CASE 2026-041recovered
SanDisk 64 GBUSB stickShortcut virus

A USB stick whose files a virus had swapped for shortcuts.

Classic hidden-attribute infection. Imaged in isolation, the real files un-hidden, the whole set recovered and returned scanned clean.

// CASE 2026-035recovered
Toshiba laptop drive2.5" HDD · laptopMalware

A laptop malware had corrupted until it wouldn’t boot.

Its Windows files were shot; the data wasn’t. We read everything straight off the disk and gave it back with no infection attached.

// CASE 2026-028recovered
WD Elements 1 TBExternal driveAV quarantine

An external drive with needed files locked in quarantine.

Antivirus had swept up files that mattered. We retrieved them from a forensic image while the free space still held them.

// sending your device in

Two simple steps.

Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toGuildford Data Recovery
Building 2, Ground Floor, Guildford Business Park
Guildford GU2 8XH
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01483 901310.

Thanks — your message is in.

We’ll be in touch shortly. For anything urgent, call 01483 901310.

// frequently asked questions

Malware recovery — common questions.

Everything people tend to ask before sending in a virus-hit or malware-hit drive.

Nearly always. The damage a virus does is mostly to the plumbing, not the water: it corrupts file-system structures — the $MFT on NTFS, the FAT tables on flash — or rewrites headers, while the file contents underneath stay put. Working on an isolated copy, we mend or rebuild that plumbing, pull deleted items back out of free space, and return everything with the infection stripped out.

Not at all. That particular pest — the one you catch off USB sticks and memory cards — simply flags your files hidden and system and litters .lnk shortcuts (plus an autorun.inf) over the top. It deletes nothing. Reset the attributes, clear away the shortcuts, and your files are exactly where they always were.

They won’t. The recovery happens in a sealed-off environment and the results are scanned before they leave us, so plugging the returned data back in won’t reintroduce anything to your machines.

Rarely. A wrecked boot chain — MBR, boot configuration, the registry and system files Windows leans on — stops the machine starting without laying a finger on your documents. We sidestep the operating system entirely, image the disk, and read your files off it on their own.

Frequently. A quarantined file is really an encoded copy tucked into the antivirus vault with the original unlinked; a straight deletion just leaves the blocks in place until something overwrites them. Either way there’s a good chance of recovery — from the vault or from unallocated space — so long as the drive stays idle. Stop using it and call us.

What we do is get your data out and hand it back clean. The infected system is never booted — your files come off an image and are scanned in isolation — so the copy you receive carries no malware. Cleaning up and rebuilding the machine itself, though, is a job in its own right.

A logical recovery is priced from £300 + VAT. The diagnostic beforehand is free, most jobs run on a no fix, no fee basis, and if the hardware turns out to be failing as well we’ll put any higher figure to you in writing first.

Just about anything that stores files — the drives inside laptops, PCs and Macs, standalone hard drives and SSDs, external and portable units, and flash of every kind, from USB sticks to SD, microSD and CF cards.

One to three working days covers most infections, often less, with the free diagnostic usually wrapped up inside 48 hours. If it’s urgent, say so and we’ll try to jump it up the queue.

Two options: bring it to our Guildford premises on a weekday between 9am and 5:30pm, or send it in fully insured. Seal it up well and tuck your contact details — name, address, phone, email — inside so we can log it. The free diagnostic and a written quote follow before we touch anything.

// hit by a virus?

Don’t keep running it — let us recover it clean.

A free diagnostic, no fix no fee on most jobs, and your files pulled clean off any drive, stick or card that a virus has hit. Get your recovery moving today.