The Problem
Your files have new extensions you do not recognise, none of them open, and there is a text file or full-screen note demanding payment in cryptocurrency for a decryption key.
The next hour matters. Ransomware often continues encrypting while you read the note, and it actively hunts attached backup drives and mapped network shares. The first job is not recovery — it is stopping the spread.
Not sure it's ransomware? Fake "your PC is infected, call this number" pop-ups are far more common and encrypt nothing. See remove fake antivirus and scareware and avoid tech support scam calls.
Step 1: Disconnect Immediately
Do this before anything else, including reading the ransom note properly.
- Unplug the Ethernet cable and turn off Wi-Fi — use the physical switch or
Win + A→ Wi-Fi tile. - Unplug every external drive and USB stick. Backup drives connected during an attack get encrypted too.
- Disconnect mapped network drives and NAS shares.
- If several PCs share the network, disconnect all of them until you know how far it spread.
- Do not shut down. Some strains hold keys in memory, and a running system also preserves evidence. Leave it on but isolated.
Step 2: Photograph the Evidence
- Take a phone photo of the ransom note and any on-screen message.
- Note the file extension appended to your files —
.lockbit,.phobos,.mallox, or similar. - Note the ransom note's filename, often
README.txt,HOW_TO_DECRYPT.hta, orRESTORE-FILES.txt. - Record the date and time you first noticed it, and what you were doing beforehand.
- Keep one encrypted sample file and the note — free decryptors need both to confirm the strain.
Step 3: Do Not Pay
- Payment is a gamble: a substantial share of victims who pay never receive a working key, and paying marks you as a target for repeat attacks.
- Depending on the group behind the attack, payment may also be illegal under sanctions rules in your country.
- There is usually a better route — Steps 4 to 7 — and it costs nothing to check first.
Step 4: Identify the Strain
- Visit ID Ransomware (id-ransomware.malwarehunterteam.com) from a clean device, such as your phone.
- Upload the ransom note and one encrypted file. It identifies most known families.
- Then check No More Ransom (nomoreransom.org), a project run by Europol and major security vendors.
- If a free decryptor exists for your strain, it is listed there with instructions. This works more often than people expect.
Step 5: Check for Recoverable Copies
Some strains do a sloppy job of removing recovery points.
- Right-click an affected folder → Properties → Previous Versions. If entries appear, restore from there.
- Check whether File History or Windows Backup was running: back up your PC with Windows Backup and File History.
- Check OneDrive on the web — it keeps version history for 30 days and has a Files Restore feature that rolls your whole drive back to a point before the encryption.
- Check cloud folders from Google Drive or Dropbox the same way. Both keep prior versions.
- Do not run recovery tools that write to the affected drive — see how to recover deleted files for the safe method.
Step 6: Image the Drive Before Cleaning
Even with no decryptor today, one may be released later — several families have been broken months or years after the fact.
- Remove the drive, or connect it to a clean PC through a USB enclosure as a secondary drive — never boot from it.
- Copy the encrypted files onto a separate external drive and store it offline.
- Label it clearly with the strain name and date.
Step 7: Wipe and Rebuild the PC
Assume the machine is fully compromised. "Removing" ransomware does not restore files and does not guarantee the attacker's access is gone.
- Perform a clean install, deleting the existing partitions: how to clean install Windows 11.
- Do not restore a full system image made after the infection date — it may contain the payload.
- Restore data files only, from a backup you are confident predates the attack.
- Scan restored files before opening them: remove viruses and malware.
Step 8: Change Your Passwords from a Clean Device
Most ransomware groups steal credentials before encrypting anything.
- Using a phone or another clean PC, change the passwords for email, banking, and any account saved in your browser.
- Start with email — it is the reset route for everything else: recover a hacked email account.
- Turn on two-factor authentication everywhere it is offered: set up two-factor authentication.
- Move to a proper vault so browser-stored passwords are not a single point of failure: use a password manager safely.
Step 9: Report It
- In the UK, report to Action Fraud; in the US, to the FBI's IC3; elsewhere, to your national cybercrime unit.
- If personal data about other people was on the machine, you may have a legal duty to notify them or a regulator — particularly for a business.
- Notify your bank if financial details were stored on the PC.
- Reporting also feeds the intelligence that produces future free decryptors.
Step 10: Close the Door Behind You
- Set up backups that ransomware cannot reach — the rule is three copies, two media types, one offline or immutable: set up automatic backups.
- Keep one backup drive physically disconnected except while backing up.
- Turn on Controlled folder access: Windows Security → Virus & threat protection → Ransomware protection.
- Patch promptly: keep your devices updated safely.
- Most infections arrive by email or a fake download: spot and avoid phishing emails and avoid malware and fake downloads.
- Harden the network too: secure your home Wi-Fi router.
What Not to Do
- Don't pay before checking No More Ransom. A free decryptor may already exist.
- Don't reconnect backup drives to the infected PC to "check if they're okay". That is how the last clean copy gets encrypted.
- Don't rename or "repair" encrypted files. It breaks decryptors that could otherwise work.
- Don't install random "ransomware removal" tools found by searching the extension name. That search result page is itself targeted by attackers.
- Don't trust the attacker's countdown timer. Pressure is the product; take the time to check your options.
Still Not Working?
If no decryptor exists and no backup predates the attack, keep the imaged drive offline and check No More Ransom every few months — families do get broken. Meanwhile rebuild and restore what you can from cloud version history and email attachments.
Related: enable BitLocker drive encryption, organize and back up important documents, and fix Windows Defender not working.
Related guides
How to Secure Your Home Wi-Fi Router
Lock down your home Wi-Fi in an evening: change default logins, switch to WPA3, disable WPS and remote admin, and keep neighbours and attackers off your network.
How to Set Up Two-Factor Authentication (2FA)
Stop hackers even when they have your password. A plain-English guide to turning on two-factor authentication for email, banking, and social accounts.
How to Stay Safe on Public Wi-Fi
Cafés, airports, and hotels offer free Wi-Fi—but it isn't always safe. Simple steps to protect your passwords and data on public networks.
How to Recover a Hacked Email Account
Locked out or seeing strange activity in your inbox? Step-by-step actions to recover a hacked email account and lock attackers out for good.
How to Back Up Your PC with Windows Backup & File History
Set up File History and Windows Backup on Windows 11 so a deleted file or dead drive can't wipe out your photos, documents, and settings. Step-by-step.