Call us — 0113 322 3083
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Service · virus & malware

After the infection: finding what survived.

Not every attack comes with some kind of demand for money. But most malware infections simply hide or corrupt your files. Cleaning up after an infection may cause even greater problems than the infection itself, including anti-virus programs isolating your documents, users frantically resetting their computers and wiping out their hard drives, and ‘repairs’ that effectively deleted your data. The purpose of this service is to recover from those types of infections and their aftermath.

two decades’ experience
In-house, never outsourced
Only pay if we recover your data, on most jobs
// damage patterns

What malware does to data.

Beyond encryption (which has its own page), infections harm files through four channels of attack. First, hiding, which involves turning an entire folder into a “hidden and system” file, the most common example being when you plug a thumb drive into your computer and suddenly all of the files are no longer visible even though they have been neither deleted nor moved. Second, corruption: an injector or wiper damages whatever it comes in contact with. For example, a macro in a Microsoft Office file could be damaged by a virus; or, worse yet, a virus can damage the structure of your operating system’s boot mechanism. Third, deletion: many viruses are designed as destructive agents, either directly deleting files, or simply clearing out their own digital footprints. Lastly, collateral damage: this is often the largest category, because your antivirus will frequently place one or more of your files within a special type of folder called a “quarantine”, a system restore can roll your documents back to a previous state, or a factory reset gets applied in a panic. The rule for today is to stop trying to clean up if you think you’ve got infected and you need to save your data. Stop cleaning and start saving: create an image of your hard disk before you attempt to remove anything. Do not attempt to clean up the only copy; that is where recoverable files become lost.

// safe handling

Recovery without reinfection.

Infected media is to be considered contaminated: the image of the infected media will be created in isolation, and it is never booted; each recovery step will run on a copy of the data while the original remains in quarantine. The recovered files are then verified prior to being returned to you: you’ll receive your documents back (not the “passenger” that came along with the documents), and we can identify what the actual contaminant was if possible, which will likely answer your ‘how did this occur’ question. If the machine continues to function and you’re in full-blown panic mode: flip the switch off and do nothing else. Once you’ve done so, everything will go much smoother on the workbench.

// questions

Asked often, answered straight.

In most cases, yes. Quarantine represents a form of containment (moving and encoding) as opposed to destruction. Recovery is used to extract the data, verify that the extracted data belongs to you and not an attacker or dropper, and restore those files with all malicious code removed from them. Do not perform any “housecleaning” (“purge quarantine”) operations before you take the drive out and bring it to us for analysis.

Classic example: a worm has set your document folders to hidden status. However, these worms typically leave behind decoy shortcuts. All of your original documents are still intact. Recovery will unhide your original documents and remove any malicious coding from them. Resist the temptation to click on the shortcut decoy links that the worm left behind. If you do so, you may end up infecting your computer too by loading the same malware into memory.

This response is dependent upon the actual actions taken during the reset process. For many “wipe clean” type resets, this means performing a simple disk format followed by an operating system reinstallation. In some cases, depending upon the quality of the wipe, it is possible to recover remnants of data under the new file structure. Immediately stop using the affected computer: every time you connect to the internet via this device, every time you run an application or open a program, you are putting your files at risk. Then have our engineers assess what data remains and develop a plan to attempt to retrieve as much as possible.

0113 322 3083