Discovering a ransom note on your screen, with your files renamed or refusing to open, is one of the most alarming things that can happen to a home PC. Ransomware encrypts your personal files and demands payment β€” usually in cryptocurrency β€” for the promise of a decryption key. This guide explains exactly what to do in the first few minutes, how to assess your options, and how to recover as much as possible without making the situation worse.

What ransomware actually does

Ransomware is malicious software that scrambles (encrypts) your files using an encryption key the attacker controls, then displays a message demanding payment in exchange for the decryption key needed to restore them. Modern ransomware often also threatens to leak stolen copies of your files publicly if you don't pay, adding pressure beyond simply losing access. It typically spreads through malicious email attachments, compromised software downloads, or exploited vulnerabilities in outdated software.

Warning: Ransomware spreads extremely quickly across connected drives and network shares. Every minute it continues running, more files are at risk β€” the very first thing to do is isolate the infected machine, before anything else.

Step 1: Disconnect the PC from the network immediately

  1. Unplug the Ethernet cable, or turn off Wi-Fi (via the physical switch if your laptop has one, or Settings > Network & Internet > Wi-Fi).
  2. If you have other devices on the same network β€” a NAS drive, shared folders on other PCs, or cloud sync clients β€” disconnect or pause those too, since ransomware actively seeks out and encrypts anything reachable over the network, including mapped drives and connected backup drives.
  3. Do not shut the PC down yet if you're able to safely disconnect it instead β€” in some cases, encryption keys can be recovered from memory while the machine is still running, though this requires specialist help and isn't guaranteed.

Step 2: Do not pay the ransom

It's understandable to consider paying, especially if the encrypted files are precious (family photos, irreplaceable documents), but law enforcement and cybersecurity experts consistently advise against it for several strong reasons:

  • There's no guarantee you'll actually receive a working decryption key β€” many victims pay and get nothing.
  • Paying confirms you're a viable target and may make you more likely to be attacked again.
  • It directly funds further criminal activity and the development of more ransomware.
  • In some cases, paying may inadvertently breach sanctions law depending on who operates the ransomware.

Pro tip: Report the attack. In the UK, report to Action Fraud (actionfraud.police.uk) and, for businesses or if significant data may have been affected, consider notifying the National Cyber Security Centre (ncsc.gov.uk). This helps authorities track ransomware campaigns and may occasionally connect you with a genuine decryption tool if one has since been developed.

Step 3: Identify which ransomware strain you're dealing with

Different ransomware families behave differently, and identifying the exact strain is crucial because free decryption tools exist for some older or poorly-implemented variants.

  1. Note the exact wording of the ransom note, and the file extension added to your encrypted files (e.g. .locky, .wannacry, .stop).
  2. Take a photo of the ransom note screen with your phone rather than trying to copy text from an infected machine you've disconnected from the network.
  3. Visit the No More Ransom project (nomoreransom.org), a well-established partnership between law enforcement agencies and cybersecurity companies, and use their Crypto Sheriff tool β€” upload a sample encrypted file and the ransom note, and it will attempt to identify the strain and tell you if a free decryptor exists.

Step 4: Do not delete or reformat anything yet

It's tempting to immediately wipe the infected drive, but resist this until you've explored your options, for two reasons:

  1. If a decryption tool is later released for the specific ransomware strain, you'll need the encrypted files intact to use it β€” sometimes fixes are developed weeks or months later.
  2. If you plan to involve a professional data recovery service or report the incident formally, an intact (though disconnected) drive is valuable evidence and gives specialists the best chance of helping.

Step 5: Check your backups

This is the moment that determines how bad the situation really is.

  1. Do you have a recent backup on an external drive that was disconnected at the time of the attack? If so, this is your fastest and most reliable path to recovery.
  2. Check any cloud backup service you use (OneDrive, Google Drive, Dropbox, iCloud, or a dedicated backup service) β€” many offer file version history that can restore files to a point before encryption, even if the synced local copies were also encrypted. Look for a "Version history" or "Previous versions" feature within the service's web interface.
  3. Check Windows' own File History feature if you had it enabled (Settings > Update & Security > Backup, or search "Restore files with File History").
  4. Check System Restore (search "Create a restore point" > System Protection tab > System Restore) β€” this won't recover encrypted files directly but can sometimes help remove the malware itself and restore system stability.

Warning: Never restore a backup onto the still-infected PC. Wipe and reinstall Windows on the infected machine first (see Step 7), and only then restore your backup onto the clean system β€” otherwise the ransomware may simply re-encrypt the restored files.

Step 6: Try free decryption tools if available

If Crypto Sheriff or your own research identifies the ransomware strain and a free decryptor exists (No More Ransom hosts a large library of these, built by cybersecurity vendors and law enforcement), download it only from the official No More Ransom site or the named vendor's official site, never from a third-party link.

  1. Follow the tool's specific instructions carefully β€” most require you to point it at a sample of both an encrypted file and, if you have one, an unencrypted original version of the same file for comparison.
  2. Run it against a copy of your encrypted files first, never the only copy, in case something goes wrong.
  3. Be aware that decryptors don't exist for all ransomware strains, particularly newer or well-implemented ones β€” this is far from guaranteed.

Step 7: Fully wipe and reinstall Windows on the infected PC

Regardless of whether decryption succeeds, the PC itself must be treated as fully compromised and should not simply be "cleaned" with an antivirus scan.

  1. If possible, remove the hard drive/SSD and use another (clean) PC with security software to copy off any encrypted files you want to keep or attempt decryption on later, without booting the infected drive's operating system.
  2. On the infected PC, boot from Windows installation media (a USB drive created using the Microsoft Media Creation Tool on another PC) and perform a clean install, choosing to fully format the drive rather than an in-place upgrade.
  3. Do not simply use "Reset this PC" from within the infected Windows installation alone for a serious ransomware case β€” a full clean install from external media gives a genuinely fresh start, since some ransomware can survive an in-Windows reset.
  4. Reinstall all software from official sources only, and apply all Windows updates before reconnecting any personal files.

Step 8: Restore your files from a clean backup

Once Windows is freshly installed and fully updated, restore your personal files from the backup or cloud version history you identified in Step 5. Scan the restored files with Windows Defender or Malwarebytes before opening them, as an extra precaution.

Step 9: Change your passwords

From a separate, known-clean device, change the passwords for your email, banking, and any other important accounts, particularly if you're unsure how long the ransomware had access before you noticed it, since some strains also steal credentials before encrypting files. Enable two-factor authentication on every account that offers it.

How to prevent a repeat attack

  • Keep regular backups using the 3-2-1 rule: three copies of important data, on two different types of media, with one copy kept offline or disconnected (a cloud backup with version history counts as a strong second copy).
  • Keep Windows and all software fully updated, since many ransomware attacks exploit known, patched vulnerabilities on outdated systems.
  • Be extremely cautious with email attachments, especially unexpected invoices, delivery notifications, or documents asking you to "enable macros."
  • Use a reputable antivirus with real-time protection permanently enabled, and don't disable it to install unofficial software.
  • Consider enabling Controlled Folder Access in Windows Security (Virus & threat protection > Ransomware protection), which blocks unauthorised programs from modifying files in your protected folders like Documents and Pictures.

Closing thoughts

A ransomware attack is frightening, but the outcome depends heavily on decisions made in the first hour: disconnect immediately, don't pay, don't panic-delete anything, and check every backup option before assuming files are lost for good. A clean Windows reinstall on the infected machine is non-negotiable regardless of whether decryption succeeds, since the malware's presence can't be trusted to be fully gone through scanning alone. Going forward, a proper offline or version-history backup is genuinely the single best protection against ever facing this situation again.


Was this guide helpful? Explore more Malware Removal guides, or browse all Security & Performance articles.