You should really be employing some decent tools for backup and containment when testing malwares.
Here I run malware in a sandbox and or virtual machine with the real system in virtual mode through Returnil as well.
I've ran/tested heaps of malware in the above setups without a breach as yet but I still have ghost images and clones on spare hard drives as backups, just in case.