Don't Panic — But Do Act Now
Seeing .locked or .crypt on every document you own is gut-wrenching. I've been there — a client's entire photo library got hit once. The first hour matters. Stop using the PC for anything that creates new files. Every new write can overwrite the remnants of your originals. Breathe. We'll try the cheap fixes first.
Fix 1: Shadow Copy Restore (30 Seconds — Works More Than You'd Think)
Windows often keeps hidden snapshots of your files called Volume Shadow Copies. Ransomware doesn't always delete them before encrypting. This is the single fastest way back.
- Right-click the folder that has encrypted files.
- Pick Properties, then the Previous Versions tab.
- If you see any older version listed, select it and click Restore. Watch for the folder to revert to pre-ransomware state.
No luck? Open File Explorer, right-click the drive (like C:), go to Properties → Previous Versions. Sometimes the whole drive has a snapshot even when a subfolder doesn't.
If that worked, jump below to Clean Up the Infection — because recovery without removing the malware means round two.
Fix 2: Remove the Ransomware (5 Minutes, Do This Even If You Recovered Files)
Seriously, don't skip this. The ransomware is still running in the background. It'll re-encrypt your recovered files the moment you open them.
- Boot into Safe Mode with Networking. On Windows 10/11: hold Shift while clicking Restart, then Troubleshoot → Advanced Options → Startup Settings → Restart → press 5.
- Download and run Malwarebytes (free version is fine). It catches most ransomware families that traditional antivirus misses.
- Run a full scan, not just a quick one. Quarantine everything it flags.
- Still worried? Grab HitmanPro (trial is enough) and let it do a second pass. Two engines disagreeing is a good sign.
After the scan, check your startup programs (Task Manager → Startup tab) and disable anything you don't recognize. Ransomware loves to set itself to launch on boot.
Fix 3: Try Decryption Tools (15+ Minutes, Your Last Free Hope)
Not all ransomware is new. Old strains have known flaws, and security researchers release free decryptors. The No More Ransom project (nomoreransom.org) hosts official tools from police agencies and antivirus vendors.
- Visit nomoreransom.org on a clean device (your phone works).
- Click Decryptor and search by ransomware name. If you don't know it, upload a sample encrypted file to their Crypto Sheriff — it fingerprints the strain.
- Download the matching tool to a USB drive. Run it on the infected PC — it may take a while.
If Crypto Sheriff comes back with no match, you're out of luck for free decryption. That brings me to the hard truth: paying the ransom is not recommended. Even after paying, you often get nothing. The FBI says don't pay. I say the same, but I also get that your thesis might be irreplaceable.
If You Must Consider Paying
Before you do anything stupid, check ID Ransomware. It identifies the strain and tells you if a decryptor exists. If not, and the files are truly critical, some decryptors have been reverse-engineered by researchers who publish the keys on BleepingComputer. Search your ransomware name there. Those forums have saved more than one of my clients.
Clean Up the Infection — The Right Way
You can't just delete the encrypted files and move on. If you restored from shadow copies, the original infection vector is still on your machine. Here's the sequence I use:
- After Malwarebytes and HitmanPro come back clean, run Windows Defender Offline Scan. Settings → Update & Security → Windows Security → Virus & threat protection → Scan options → Windows Defender Offline scan. It boots into a pre-OS environment and catches nasty rootkits.
- Change every password you have — email, banking, social. Ransomware often steals credentials before it locks files. Do this on a different device if you can.
- Update your software. Outdated Java, Flash, or PDF readers are how most ransomware sneaks in. Uninstall anything you don't use.
Restore From Backup (The Real Fix)
Here's the truth: the only bulletproof fix for ransomware is a backup you made before the attack. Shadow copies are a temporary patch, not a strategy. Look into the Windows Backup feature that stores to an external drive, or a service like Backblaze. Store that drive disconnected when not backing up — connected drives get encrypted too.
If you have no backup and no decryptor, I'm sorry. That's a hard lesson. But you've at least stopped the bleeding — the ransomware isn't spreading to your network or your photos on the cloud. Some cloud services like Google Drive and Dropbox keep file version history. Check those too; I've seen more than one dropbox rescue a client's work.
Prevention — The 10-Minute Habit
Once you're breathing again, spend ten minutes on these:
- Enable Controlled Folder Access in Windows Security. It blocks unknown apps from modifying your Documents, Pictures, and Videos folders.
- Set up ransomware protection in your antivirus. Most decent ones have it.
- Be suspicious of attachments that ask you to enable macros. That's the #1 delivery method right now.
- Keep your OS updated. Ransomware exploits known holes; patches close them.
You'll be fine. The first time is terrifying, but now you know the playbook: shadow copies first, then malware sweep, then decryptor hunt, and finally a real backup. Go get your files back.