Ransomware: your PC is encrypted – what to do now

Every file locked and a ransom note on screen? Disconnect the machine right now – and do not pay. Here is how to work through it, step by step.

If the screen is demanding a ransom right now
  1. Disconnect the machine immediately: Wi-Fi off, Ethernet cable out – so the encryption cannot spread further.
  2. Disconnect other devices and external drives on the same network or plugged into the PC.
  3. Do not pay and do not delete anything in a hurry.
  4. Photograph the ransom note as evidence – with your phone, not on the PC.

First, size it up: what is ransomware?

Ransomware is malware that encrypts your files and then demands payment for the key – usually in cryptocurrency and with a short deadline. The critical fact: it spreads across networks. The faster you isolate the machine, the less damage reaches other PCs, network drives and cloud folders.

These questions take you through the first decisions:

1Is the device still connected to the network or to external drives?

Yes
  • Isolate it now: disconnect Wi-Fi and Ethernet, unplug external drives
  • Check other computers in the household and take them off the network too
No
  • Good, keep it isolated. Photograph the ransom note and the file extensions

2Do you have a clean, disconnected backup?

Yes
  • Do NOT plug the backup into the infected computer
  • Rebuild the system clean first, then restore from the backup
No
  • Keep the encrypted files - a decryption key may appear later
  • Check No More Ransom for a free decryption tool

3Are you considering paying the ransom?

Yes
  • Do not pay - there is no guarantee, and you fund the next attack
  • Consider professional help and report the case to the FBI at IC3.gov
No
  • Right call. Reinstall the system and restore from a verified backup

Step by step

What to do now

  • Isolate: take the infected machine off Wi-Fi and Ethernet, unplug external storage.
  • Stop the spread: check other computers in the household and disconnect them too.
  • Preserve evidence: photograph the ransom note and the changed file extensions.
  • Identify the variant: check No More Ransom for a free decryption tool.
  • Keep the encrypted files – a key may be released later.
  • Rebuild the system: reinstall Windows clean, then restore from a verified backup.

What not to do

  • Do not pay – no guarantee of decryption, and you finance the people who did this.
  • Do not connect the backup drive to the infected PC, or it gets encrypted too.
  • Do not delete files in a hurry – a future tool might still recover them.
  • Do not just keep working and hope it goes away.

Who to contact

  • The FBI at IC3.gov – ransomware is a federal crime and reports feed real investigations. File a local police report as well.
  • CISA at cisa.gov, which publishes guidance and, for some variants, recovery help.
  • An IT professional or the manufacturer’s support if you do not want to do the cleanup yourself.
  • If business or client data is involved: check your reporting obligations. Most states require notification when personal data is exposed.

Recovering your data

The safest source is a clean backup that was never connected to the PC. For many ransomware families there are also free decryption tools – the international No More Ransom project collects them. Identify the variant first (the ransom note or the file extension helps) before you try anything.

Protecting yourself from now on

The best defense against ransomware is preparation:

  • Test your backup : regular backups, at least one of them offline.
  • Spot phishing : most infections arrive through a manipulated attachment or link.
  • Keep Windows and your apps updated – that closes most of the entry points.
  • Install nothing from dubious sources or “cracks.”
Rule of thumb A backup is only a real backup if it is kept separate from the PC. A drive that stays plugged in gets encrypted right along with everything else.

Frequently asked questions

Should I pay the ransom to get my files back?

Law enforcement advises clearly against it. There is no guarantee you receive a working key, and you fund the next attack. Rely on backups instead, and check whether a free decryption tool exists for your variant.

Can I recover my files without paying?

Often yes. The safest source is a clean backup that was not connected to the PC. For many ransomware families there are also free decryption tools, collected by the No More Ransom project. Keep the encrypted files in case a tool appears later.

Do I have to reinstall Windows completely?

In most cases a full reinstall is the cleanest way to be sure nothing is left behind. Restore your data from a verified backup afterwards – never before.

Topics: Emergency