Apps Recover Deleted Files with Windows File Recovery app in Windows 11

  • Thread starter Thread starter Brink
  • Start date Published: Start date Updated Updated:

Windows_File_Recovery_header.webp

This tutorial will show you how to use the Windows File Recovery command line app to try and recover deleted files in Windows 10 and Windows 11.

If you can’t locate a lost file from your backup, then you can use Windows File Recovery from Microsoft, which is a command line app available from the Microsoft Store. Use this app to try to recover lost files that have been deleted from your local storage device (including internal drives, external drives, and USB devices) and can’t be restored from the Recycle Bin. Recovery on cloud storage and network file shares is not supported.

For photos, documents, videos and more, Windows File Recovery supports many file types to help ensure that your data is not permanently lost.

If you want to increase your chances of recovering a file, minimize or avoid using your computer. In the Windows file system, the space used by a deleted file is marked as free space, which means the file data can still exist and be recovered. But any use of your computer can create files, which may over-write this free space at any time.


Reference:

You must be signed in as an administrator to install and use the Windows File Recovery command line app.




Here's How:

1 If you haven't already, install the Windows File Recovery app by Microsoft.


2 Open the Windows File Recovery app.

3 If prompted by UAC, click/tap on Yes to approve.

4 Windows File Recovery will now open a maximized elevated command prompt window for you to use the winfr command in the following format to try and recovery deleted files. (see screenshot and tables below)

winfr source-drive: destination-drive: [/mode] [/switches]​

5 When you are prompted for confirmation to continue, enter Y to start the recovery operation. Depending on the size of your source drive, this may take a while. To stop the recovery process, press Ctrl + C.

winfr.webp


 Command Usage


There are 2 basic modes you can use to recover files: Regular and Extensive.

Regular mode examples
Recover your Documents folder from your C: drive to the recovery folder on an E: drive. Don’t forget the backslash (\) at the end of the folder.

Winfr C: E: /regular /n \Users\<username>\Documents\

Recover PDF and Word files from your C: drive to the recovery folder on an E: drive.

Winfr C: E: /regular /n *.pdf /n *.docx

Extensive mode examples
Recover any file with the string "invoice" in the filename by using wildcard characters.

Winfr E: C: /extensive /n *invoice*

Recover jpeg and png photos from your Pictures folder to the recovery folder on an E: drive.

Winfr C: E: /extensive /n \Users\<username>\Pictures\*.JPEG /n\Users\<username>\Pictures\*.PNG

The source and destination drives must be different. When recovering from the operating system drive (often C: ), use the /n <filter> switches to specify the user files or folder.

Microsoft automatically creates a recovery folder for you called, Recovery_<date and time> on the destination drive.

About modes and file systems​

The following information can help you decide which file system you have and which mode to use.

File systems

File system​
Examples​
FAT and exFATSD cards, flash or USB drives (< 4GB)
NTFSComputers (HDD, SSD), external hard drives, flash or USB drives (> 4GB)

There are several file systems supported by Windows that vary depending on the storage device or operating system. Recovering files from non-NTFS file systems is only supported by extensive mode. To see which file system you have, right click a drive in File Explorer and select Properties.

Deciding which mode to use

Use the following table to help you decide which mode to use. If you are not sure, start with Regular mode.

File system​
Circumstances​
Recommended mode​
NTFSDeleted recentlyRegular
NTFSDeleted a while agoExtensive
NTFSAfter formatting a diskExtensive
NTFSA corrupted diskExtensive
FAT and exFATAnyExtensive

Command line syntax​

General syntax

The following table summarizes what each advanced switch is used for.

Parameter / switch​
Description​
Supported mode(s)​
Source-drive:Specifies the storage device where the files were lost. Must be different from the destination-drive.All
Destination-drive:Specifies the storage device and folder on which to put the recovered files. Must be different from the source-drive.All
/regularRegular mode, the standard recovery option for non-corrupted NTFS drivesRegular
/extensiveExtensive mode, a thorough recovery option suitable for all file systemsExtensive
/n<filter>Scans for a specific file by using a file name, file path, file type, or wildcards. For example:
  • File name: /n myfile.docx
  • File path: /n /users/<username>/Documents/
  • Wildcard: /n myfile.*
  • /n *.docx
  • /n *<string>*
All
/?Summary of syntax and switches for general users.All
/!Summary of syntax and switches for advanced users.All

Advanced syntax

The following table summarizes what each advanced switch is used for.

Switch​
Description​
Supported modes​
/ntfsNTFS mode, a fast recovery option for healthy NTFS drives using the master file tableNTFS
/segmentSegment mode, recovery option for NTFS drives using file record segmentsSegment
/signatureSignature mode, recovery option for all file system types using file headersSignature
/y:<type(s)>Recover specific extension groups, comma separatedSignature
/#Signature mode extension groups and supported file types.Signature
/p:<folder>Saves a log file of the recovery operation in a different location than the default location on the recovery drive (for example, D:\logfile).All
/aOverrides user prompts, which is useful in a script file.All
/uRecovers undeleted files, for example, from the Recycle Bin.NTFS
Segment
/kRecovers system files.NTFS
Segment
/o:<a\|n\|b>Specifies whether to always (a), never (n), or keep both always (b) when choosing whether to overwrite a file. The default action is to prompt to overwrite.NTFS
Segment
/gRecovers files without primary data streams.NTFS
Segment
/eTo keep your results manageable and focus on user files, some file types are filtered by default, but this switch removes that filter. For a complete list of these file types, see the information after this table.NTFS
Segment
/e:<extension>Specifies which file types are filtered. For a complete list of these file types, see the information after this table.NTFS
Segment
/s:<sectors>Specifies the number of sectors on the source device. To find sector information, use fsutil.Segment
Signature
/b:<bytes>Specifies the cluster size (allocation unit) on the source device.Segment
Signature

File extension filter list

The following file types are filtered from results by default. Use the /e switch to disable this filter or the /e:<extension> filter to specify file types not to filter.

_, adm, admx, appx, appx, ascx, asm, aspx, aux, ax, bin, browser, c, cab, cat cdf-ms, catalogItem, cdxm, cmake, cmd, coffee, config, cp, cpp, cs, cshtm, css, cur, dat, dll, et, evtx, exe, fon, gpd, h, hbakedcurve, htm, htm, ico, id, ildl, ilpdb, iltoc, iltocpdb, in, inf, inf_loc, ini, js, json, lib, lnk, log, man, manifest, map, metadata, mf, mof, msc, msi, mui, mui, mum, mun, nls, npmignore, nupkg, nuspec, obj, p7s, p7x, pak, pckdep, pdb, pf, pkgdef, plist, pnf, pp, pri, props, ps1, ps1xm, psd1, psm1, py, resjson, resw, resx, rl, rs, sha512, snippet, sq, sys, t4, targets, th, tlb, tmSnippet, toc, ts, tt, ttf, vb, vbhtm, vbs, vsdir, vsix, vsixlangpack, vsixmanifest, vstdir, vstemplate, vstman, winmd, xam, xbf, xm, xrm-ms, xs, xsd, ym


That's it,
Shawn Brink
 
Last edited:

Latest Support Threads

Back
Top Bottom