Ransomware on Your PC — What to Do in the First Hour
If a machine is showing a ransom note, the next 30 minutes matter. Here is the calm, correct order of operations — and what NOT to do.
Symptoms
- A full-screen ransom note demanding payment in cryptocurrency
- Files renamed with unusual extensions (.locked, .crypt, .encrypted)
- Documents that open as unreadable garbage
Likely causes
- A malicious email attachment or link was opened by someone with local admin rights
- An exposed RDP or SMB port was brute-forced
- A compromised remote-support tool (unpatched RMM) was used against you
Step-by-step fix
- 1
Disconnect the network immediately
Unplug the Ethernet cable. Turn off Wi-Fi (physical switch if there is one, or airplane mode). Do NOT shut the machine down — some ransomware writes recovery-relevant data to disk during shutdown that a specialist may need.
- 2
Photograph the ransom note
Take a phone photo of the exact wording and any file extensions. Note the time. This tells a responder which family it is (LockBit, Akira, BlackCat, etc.) in about 30 seconds.
Unlock the remaining 4 steps + engineer follow-up
Detailed instructions, screenshots where it matters, and a real UK engineer on standby if a step doesn't behave.
Payments aren't wired up in this build — the button takes you to the expert form and an engineer follows up.
Watch out for
- Never plug an external backup drive into the infected machine to 'check the backup' — it will encrypt the backup too.
- Do not run 'ransomware removal tools' from unfamiliar sites. Most are themselves malware.
Frequently asked
Can decryption tools actually recover my files?▾
Sometimes. The 'No More Ransom' project (nomoreransom.org, backed by Europol and the NCA) has free decryptors for many older families. It's worth checking before you wipe — but only after the machine is isolated.
Should I ever pay the ransom?▾
No. Payment is typically a 30–40% chance of any working decryptor, funds further attacks, and can put UK payers in breach of sanctions. The correct answer is always: isolate, report, restore from backup.
How do I stop this happening again?▾
MFA on every important account, offline backups (a drive that only plugs in during the backup), patched software, and — most importantly — day-to-day accounts that don't have local admin rights. That combination stops almost all opportunistic ransomware.
Still stuck? A UK engineer can jump on remotely.
Fixed fee, secure one-time session, usually within the hour.