Suspected copying reduces to a few narrow questions. Which device. Attached when. Carrying what. Windows answers most of them unprompted, and we read those answers off a verified image and set them out in order — for employers throughout Merseyside, from the plants at Speke and Halewood to the transport offices behind the docks.
◇ Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.
Sticks, cards and portable drives sit at the centre of more disputes than anything else that reaches this bench.
Windows takes a note of every removable device it meets. USBSTOR receives the manufacturer, the model and the serial number of each stick, card reader and portable drive. setupapi.dev.log fixes to the second the day any of them first appeared. Additional registry entries associate a device with the profile that mounted it and preserve the last time it was seen. Pulled from a verified image, the result is a register spanning the machine's entire working life, including hardware nobody mentions until it appears on the schedule.
Attachment shows presence; a case usually needs movement. LNK files and jump lists capture company documents being opened from whichever letter the volume was assigned, with paths and times attached. Shellbags retain the folder structure somebody browsed on it long after the device itself has disappeared. The change journal orders the surrounding activity minute by minute. If the stick is produced as well, its own image completes the account: what it holds now, when each item landed, and what has been taken off since.
Timestamps reward careful reading, because copying leaves a signature. When a file is copied to another volume, its creation time records the moment of the copy while its modification time travels unchanged with the contents. A document apparently created at 23:41 but last modified two years earlier is therefore reporting when it was copied, not when it was written. Read with the device register and the journal, that signature dates each transfer, and a cluster of them outside working hours is seldom innocent.
The same discipline covers far more than sticks. SD and microSD cards from cameras, dashcams and survey drones, CF cards out of older equipment, portable SSDs: each is imaged and analysed identically. Card work runs in both directions — documents traced onto a card, deleted photographs and video recovered off one. Where a card is the case, it is examined together with whichever machine wrote to it, so that neither account goes unchecked.
Method and custody are set out at the forensic recovery hub. Dating a deletion continues at deleted-file forensics, and the employer casework this feeds into sits at employee data theft. Both fees are listed on the prices page.
Every finding arrives with a date, the account it belongs to, and the artefact behind it.
Every stick, card and drive the machine has seen, by manufacturer, model and serial.
The second at which each device first appeared, and when it was last present.
Documents opened from the device's letter, with paths and hours recorded.
The directory structure explored on the device, preserved in shellbags.
Timestamp patterns that date each copy onto the device.
The card or drive captured in its own right, with its deleted contents restored.
Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.
Removable-media work runs on company machines and on media the company issued, or on a solicitor's written instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.
A stick and the machine that wrote to it are best examined as a pair. Ring 0800 689 0668 and we will agree the set. Each item goes by tracked, insured post to the Manchester laboratory, since nothing is collected, and enters the custody record at booking-in.
Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.
↓ Print the shipping & booking-in form (PDF)
Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.
Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.
Leave the machine untouched, keep hold of the stick, and ring the freephone.