Security6 min readAdvancedUpdated July 2026

Ransomware on Your PC — What to Do in the First Hour

If a machine is showing a ransom note, the next 30 minutes matter. Here is the calm, correct order of operations — and what NOT to do.

Symptoms

  • A full-screen ransom note demanding payment in cryptocurrency
  • Files renamed with unusual extensions (.locked, .crypt, .encrypted)
  • Documents that open as unreadable garbage

Likely causes

  • A malicious email attachment or link was opened by someone with local admin rights
  • An exposed RDP or SMB port was brute-forced
  • A compromised remote-support tool (unpatched RMM) was used against you

Step-by-step fix

  1. 1

    Disconnect the network immediately

    Unplug the Ethernet cable. Turn off Wi-Fi (physical switch if there is one, or airplane mode). Do NOT shut the machine down — some ransomware writes recovery-relevant data to disk during shutdown that a specialist may need.

  2. 2

    Photograph the ransom note

    Take a phone photo of the exact wording and any file extensions. Note the time. This tells a responder which family it is (LockBit, Akira, BlackCat, etc.) in about 30 seconds.

Full guided fix

Unlock the remaining 4 steps + engineer follow-up

Detailed instructions, screenshots where it matters, and a real UK engineer on standby if a step doesn't behave.

Payments aren't wired up in this build — the button takes you to the expert form and an engineer follows up.

Free unlock

Prefer not to pay? Get the full fix free with your email.

We'll send occasional plain-English fixes and warnings. No spam, one-click unsubscribe.

Watch out for

  • Never plug an external backup drive into the infected machine to 'check the backup' — it will encrypt the backup too.
  • Do not run 'ransomware removal tools' from unfamiliar sites. Most are themselves malware.

Frequently asked

Can decryption tools actually recover my files?

Sometimes. The 'No More Ransom' project (nomoreransom.org, backed by Europol and the NCA) has free decryptors for many older families. It's worth checking before you wipe — but only after the machine is isolated.

Should I ever pay the ransom?

No. Payment is typically a 30–40% chance of any working decryptor, funds further attacks, and can put UK payers in breach of sanctions. The correct answer is always: isolate, report, restore from backup.

How do I stop this happening again?

MFA on every important account, offline backups (a drive that only plugs in during the backup), patched software, and — most importantly — day-to-day accounts that don't have local admin rights. That combination stops almost all opportunistic ransomware.

Still stuck? A UK engineer can jump on remotely.

Fixed fee, secure one-time session, usually within the hour.