Skip to content
DataForensics Book an AppointmentBook Now

Ransomware & Crypto Virus Recovery

Files encrypted. Your data may still be recoverable.

WannaCry, Ryuk, LockBit and every other crypto-locker variant — recovered and reconstructed in our own Belfast laboratory. Do not pay the ransom and do not reboot before you talk to an engineer.

I.

Before anything else

What to do in the first hour.

Ransomware incidents are made worse by rushed decisions. A few minutes of care now protects what is still recoverable.

  • Isolate the machine. Disconnect it from the network immediately — shared drives and connected backups can be encrypted next.
  • Do not pay the ransom. There is no guarantee of a working decryption key, and payment funds the next attack.
  • Do not reformat or reinstall. This destroys evidence and any chance of a clean recovery.
  • Do not run "decryptor" tools you find online on the original drive — test them on a clone, never the source.
  • Do preserve the ransom note, encrypted file samples, and any logs — they help identify the variant and the fastest path back to your data.

Then call us. An engineer can tell you within minutes whether your case fits a known decryption route or needs full forensic recovery.

II.

Capability

Every variant. Every kind of storage.

i

Known Ransomware Families

WannaCry, Petya/NotPetya, Ryuk, LockBit and many other variants — identified and matched against known decryption routes where they exist.

ii

Encrypted Servers & RAID

Business servers and arrays hit through compromised remote access, with volumes and databases reconstructed in the lab.

Learn more →
iii

Encrypted External & Backup Drives

Attached backup drives are a common ransomware target — recovered alongside the primary system where possible.

iv

Deleted & Corrupted Files

Where a variant cannot be decrypted, we recover shadow copies, fragments and residual data left behind by the attack.

v

NAS & Shared Storage

Synology, QNAP and other network storage encrypted via compromised shared folders.

Learn more →
vi

Forensic Attack Analysis

Evidence of how the attack entered your network — RDP, TeamViewer, phishing — documented for your IT team or insurer.

Learn more →
24/7
Critical response line
01
In-house lab · no outsourcing
10+
Years in practice
5.0
Google rating · 75 reviews
IV.

Attack routes

How ransomware gets in.

Understanding the entry point matters as much as the recovery — it stops a repeat attack.

The majority of the incidents we see start with compromised remote access — Windows Remote Desktop (RDP) or TeamViewer credentials obtained through a breached email account or weak password. Once inside, attackers disable security software before releasing the crypto virus, and anything reachable over a shared folder is encrypted along with it.

Firewalls, VPNs and IP blocking reduce risk but do not eliminate it. If you do not already have a tested, offline backup strategy, it is worth a conversation with us regardless of whether you have an active incident.

V.

Process

From infection to restored data.

  1. 01

    Emergency triage

    An engineer assesses the variant and scope with you by phone. Critical business cases move straight to the 24/7 line.

  2. 02

    Variant diagnosis & fixed quote

    Drives are imaged and the ransomware variant identified in the lab. You receive an honest recoverability assessment and a fixed quote before any work begins.

  3. 03

    Recovery on clones

    Decryption and reconstruction happen on verified images — your original drives are never put at further risk.

  4. 04

    Verification & return

    Recovered files are checked and returned to you on encrypted media, with a summary of what was recoverable.

VI.

Questions

Asked by every business we speak to.

Should we pay the ransom?

We advise against it. There is no guarantee of a working key even after payment, and it does not remove the vulnerability that let the attack in. Talk to us first — decryption or recovery may be possible without paying.

Can every ransomware variant be decrypted?

No single answer covers every case. Some variants have known weaknesses that allow decryption; others do not. Our diagnosis identifies the variant and tells you honestly what routes are available for your specific files.

Our backup drives were encrypted too — is anything left?

Often, yes. Attached backups are a common target, but shadow copies, prior snapshots or residual data can sometimes be recovered even when the live backup is encrypted.

How fast can you start?

Critical cases start immediately — the emergency line (07938 182 909) reaches an engineer 24/7, with same-day collection or drop-off across the UK and Ireland.

What will it cost?

Diagnosis first, then a fixed quote based on exactly what the recovery requires — agreed with you before any work begins, so there are no open-ended bills.

Critical response · 24/7
Mid-incident right now?

Isolate the affected machine and speak directly to an engineer. We will tell you what to do next — and what to avoid — before anyone else touches it.