Virus & Malware Removal · 8 min read

How to Remove Ransomware and What to Do About Your Files

Removing ransomware and recovering files are two separate problems. Removal is usually straightforward; decryption without a backup usually is not.

Nothing on this page guarantees file recovery. Anyone whose business or regulated data is affected should involve a qualified incident-response professional immediately.

Published 2026-08-09 · Last updated 2026-08-09

First hour: isolate before anything else

Disconnect network and Wi-Fi, unplug external drives and stop cloud sync clients so encrypted versions do not overwrite good copies in the cloud. Leave the machine powered on unless you are told otherwise — shutting down can lose recoverable material.

Photograph the ransom note and identify the strain

Keep the note and a sample encrypted file. The note text and the new file extension are what identify the family, and identification determines whether a free decryptor exists.

Remove the payload

Boot into safe mode and run a full scan plus an offline scan to remove the executable and its persistence. Removing the payload stops further encryption; it does not decrypt anything already encrypted.

Look for a legitimate free decryptor

For a number of older or broken families, free decryption tools published by security vendors and law-enforcement-backed initiatives genuinely work. Only use tools obtained directly from a recognised vendor or the No More Ransom project — 'decryptors' offered in search advertisements are themselves malware.

Restore from backup — carefully

Restore only after the machine is confirmed clean, or better, onto a freshly installed system. Restoring onto a still-infected machine simply re-encrypts the restored files.

About paying

Payment funds the operation, marks you as a paying target, and frequently produces a decryptor that only partly works. Law enforcement advises against it. If you are considering it because a business depends on the data, take professional advice first — and check your obligations, since some payments carry legal exposure.

Afterwards: close the door

Reset passwords from a clean device, patch everything, disable unnecessary remote access, and set up backups with at least one offline or immutable copy. Ransomware overwhelmingly enters through remote access, phishing and unpatched services.

Frequently asked questions

Can antivirus decrypt my files?
No. Antivirus removes the malware. Decryption depends on having a key or a flaw in that specific family, which is why backups matter more than any security product here.
Will a factory reset get my files back?
No — it deletes them along with the ransomware. Copy the encrypted files to external storage first in case a decryptor is released later.