This tutorial will show you how to use the Windows File Recovery command line app to try and recover deleted files in Windows 10 and Windows 11.
If you can’t locate a lost file from your backup, then you can use Windows File Recovery from Microsoft, which is a command line app available from the Microsoft Store. Use this app to try to recover lost files that have been deleted from your local storage device (including internal drives, external drives, and USB devices) and can’t be restored from the Recycle Bin. Recovery on cloud storage and network file shares is not supported.
For photos, documents, videos and more, Windows File Recovery supports many file types to help ensure that your data is not permanently lost.
If you want to increase your chances of recovering a file, minimize or avoid using your computer. In the Windows file system, the space used by a deleted file is marked as free space, which means the file data can still exist and be recovered. But any use of your computer can create files, which may over-write this free space at any time.
Reference:
Windows File Recovery | Microsoft Support
Learn how to use Windows File Recovery app to restore or recover lost files that have been deleted and are not in the recycle bin.
You must be signed in as an administrator to install and use the Windows File Recovery command line app.
Here's How:
1 If you haven't already, install the Windows File Recovery app by Microsoft.
Download
2 Open the Windows File Recovery app.
3 If prompted by UAC, click/tap on Yes to approve.
4 Windows File Recovery will now open a maximized elevated command prompt window for you to use the winfr command in the following format to try and recovery deleted files. (see screenshot and tables below)
winfr source-drive: destination-drive: [/mode] [/switches]5 When you are prompted for confirmation to continue, enter Y to start the recovery operation. Depending on the size of your source drive, this may take a while. To stop the recovery process, press Ctrl + C.
Command Usage
Windows File Recovery | Microsoft Support
Learn how to use Windows File Recovery app to restore or recover lost files that have been deleted and are not in the recycle bin.
There are 2 basic modes you can use to recover files: Regular and Extensive.
Regular mode examples
Recover your Documents folder from your C: drive to the recovery folder on an E: drive. Don’t forget the backslash (\) at the end of the folder.
Winfr C: E: /regular /n \Users\<username>\Documents\Recover PDF and Word files from your C: drive to the recovery folder on an E: drive.
Winfr C: E: /regular /n *.pdf /n *.docxExtensive mode examples
Recover any file with the string "invoice" in the filename by using wildcard characters.
Winfr E: C: /extensive /n *invoice*Recover jpeg and png photos from your Pictures folder to the recovery folder on an E: drive.
Winfr C: E: /extensive /n \Users\<username>\Pictures\*.JPEG /n\Users\<username>\Pictures\*.PNGThe source and destination drives must be different. When recovering from the operating system drive (often C: ), use the
/n <filter> switches to specify the user files or folder.Microsoft automatically creates a recovery folder for you called,
Recovery_<date and time> on the destination drive.About modes and file systems
The following information can help you decide which file system you have and which mode to use.File systems
File system | Examples |
|---|---|
| FAT and exFAT | SD cards, flash or USB drives (< 4GB) |
| NTFS | Computers (HDD, SSD), external hard drives, flash or USB drives (> 4GB) |
There are several file systems supported by Windows that vary depending on the storage device or operating system. Recovering files from non-NTFS file systems is only supported by extensive mode. To see which file system you have, right click a drive in File Explorer and select Properties.
Deciding which mode to use
Use the following table to help you decide which mode to use. If you are not sure, start with Regular mode.
File system | Circumstances | Recommended mode |
|---|---|---|
| NTFS | Deleted recently | Regular |
| NTFS | Deleted a while ago | Extensive |
| NTFS | After formatting a disk | Extensive |
| NTFS | A corrupted disk | Extensive |
| FAT and exFAT | Any | Extensive |
Command line syntax
General syntaxThe following table summarizes what each advanced switch is used for.
Parameter / switch | Description | Supported mode(s) |
|---|---|---|
| Source-drive: | Specifies the storage device where the files were lost. Must be different from the destination-drive. | All |
| Destination-drive: | Specifies the storage device and folder on which to put the recovered files. Must be different from the source-drive. | All |
| /regular | Regular mode, the standard recovery option for non-corrupted NTFS drives | Regular |
| /extensive | Extensive mode, a thorough recovery option suitable for all file systems | Extensive |
| /n<filter> | Scans for a specific file by using a file name, file path, file type, or wildcards. For example:
| All |
| /? | Summary of syntax and switches for general users. | All |
| /! | Summary of syntax and switches for advanced users. | All |
Advanced syntax
The following table summarizes what each advanced switch is used for.
Switch | Description | Supported modes |
|---|---|---|
| /ntfs | NTFS mode, a fast recovery option for healthy NTFS drives using the master file table | NTFS |
| /segment | Segment mode, recovery option for NTFS drives using file record segments | Segment |
| /signature | Signature mode, recovery option for all file system types using file headers | Signature |
| /y:<type(s)> | Recover specific extension groups, comma separated | Signature |
| /# | Signature mode extension groups and supported file types. | Signature |
| /p:<folder> | Saves a log file of the recovery operation in a different location than the default location on the recovery drive (for example, D:\logfile). | All |
| /a | Overrides user prompts, which is useful in a script file. | All |
| /u | Recovers undeleted files, for example, from the Recycle Bin. | NTFS Segment |
| /k | Recovers system files. | NTFS Segment |
| /o:<a\|n\|b> | Specifies whether to always (a), never (n), or keep both always (b) when choosing whether to overwrite a file. The default action is to prompt to overwrite. | NTFS Segment |
| /g | Recovers files without primary data streams. | NTFS Segment |
| /e | To keep your results manageable and focus on user files, some file types are filtered by default, but this switch removes that filter. For a complete list of these file types, see the information after this table. | NTFS Segment |
| /e:<extension> | Specifies which file types are filtered. For a complete list of these file types, see the information after this table. | NTFS Segment |
| /s:<sectors> | Specifies the number of sectors on the source device. To find sector information, use fsutil. | Segment Signature |
| /b:<bytes> | Specifies the cluster size (allocation unit) on the source device. | Segment Signature |
File extension filter list
The following file types are filtered from results by default. Use the /e switch to disable this filter or the /e:<extension> filter to specify file types not to filter.
_, adm, admx, appx, appx, ascx, asm, aspx, aux, ax, bin, browser, c, cab, cat cdf-ms, catalogItem, cdxm, cmake, cmd, coffee, config, cp, cpp, cs, cshtm, css, cur, dat, dll, et, evtx, exe, fon, gpd, h, hbakedcurve, htm, htm, ico, id, ildl, ilpdb, iltoc, iltocpdb, in, inf, inf_loc, ini, js, json, lib, lnk, log, man, manifest, map, metadata, mf, mof, msc, msi, mui, mui, mum, mun, nls, npmignore, nupkg, nuspec, obj, p7s, p7x, pak, pckdep, pdb, pf, pkgdef, plist, pnf, pp, pri, props, ps1, ps1xm, psd1, psm1, py, resjson, resw, resx, rl, rs, sha512, snippet, sq, sys, t4, targets, th, tlb, tmSnippet, toc, ts, tt, ttf, vb, vbhtm, vbs, vsdir, vsix, vsixlangpack, vsixmanifest, vstdir, vstemplate, vstman, winmd, xam, xbf, xm, xrm-ms, xs, xsd, ym
That's it,
Shawn Brink
Last edited:









