PikoSystem IT engineering services
Security & Recovery

Ransomware recovery and infected network cleanup

Files have strange extensions and every folder has a ransom note. Don't power systems off or delete anything; unplug infected machines from the network and call us. Our job is to contain the attack, work out how far it spread, and bring services back from clean backups.

Tools & technology ransomware-recovery
  • ID Ransomware
  • No More Ransom
  • Velociraptor
  • KAPE
  • Sysinternals
  • Veeam
  • Microsoft Defender
  • Windows Event Logs
6work areas
4deliverables
4steps

What is Ransomware Recovery?

Ransomware recovery is the work of containing a ransomware attack, establishing how far it spread, cleaning the infected network and bringing services back from clean backups. It is needed when server files carry an unknown extension, the accounting database won't open, or even the backups on a NAS are encrypted. PikoSystem isolates infected systems and disables suspicious accounts, preserves evidence before anything changes, identifies the strain with ID Ransomware and checks No More Ransom for a legitimate decryptor, locates the last clean backup or Shadow Copy, resets passwords and closes the entry point, such as exposed RDP. Decryption is never promised, and you hear plainly what can and can't be recovered. You receive an incident report with timeline and likely entry point, a list of restored systems and lost data, and preserved evidence for legal or insurance follow-up.

When you need Ransomware Recovery

  • Files on our server have an unknown extension and won't open.
  • A file called something like HOW_TO_DECRYPT appeared on the desktop.
  • Our accounting software won't start and its database file is encrypted.
  • The backups on our NAS are encrypted too.

What Ransomware Recovery includes

01

Containment

Infected systems isolated, remote access cut, suspicious accounts disabled, and encryption stopped from reaching healthy servers.

02

Evidence preservation

The ransom note, sample encrypted files, Windows event logs and, where possible, memory and disk images captured before anything changes.

03

Identify the strain

The ransomware family identified from the note and file extensions using ID Ransomware, and a check for a legitimate public decryptor in sources such as No More Ransom.

04

Backup assessment

Backups and Shadow Copies checked, the last pre-infection copy located, and that copy verified clean before restoring.

05

Cleanup and rebuild

Systems cleaned or reinstalled, every password reset including service and domain admin accounts, and the initial entry point closed, such as exposed RDP or a vulnerable VPN.

06

Restore and resume

Servers and data restored in order of business priority, with monitoring for signs the attacker is coming back.

What you get from Ransomware Recovery

  • An incident report with timeline, scope of damage and likely entry point
  • A list of restored systems and any data that could not be recovered
  • Preserved evidence for legal or insurance follow-up
  • A list of security actions to prevent a repeat

Ransomware Recovery: a practical guide

What to gather before ransomware recovery starts

A few simple facts speed up the assessment when you call. Note the time the first sign appeared, which systems have encrypted files and which still look healthy, and keep a photo or copy of the ransom note, which usually names the group or a contact channel.

We also need to know where backups live and when the last good one ran, which domain and server admin accounts exist, and how the network is laid out, even as a sketch on paper. Write down everything done so far, with times. Name one person who can make fast calls, such as cutting the company off the internet.

Ransomware recovery plan: in what order do systems come back?

Restore order matters as much as the backups. Identity comes first: a compromised domain controller is either restored from a pre-intrusion backup in an isolated network or the domain is rebuilt, and the krbtgt account password is reset twice with a gap between resets. Then DNS, DHCP and the backup infrastructure, then databases and core business applications, and finally file servers and user machines.

Each restored system is powered on and scanned in a separate VLAN before it rejoins the main network. This order is best written down before any incident.

Mistakes that restart a ransomware incident

The most common is restoring before the entry point is closed. If exposed RDP or a leaked VPN account is still active, the attacker encrypts everything again the same night. Next is restoring from a backup taken while the attacker was already inside, which brings their backdoor back with the data.

Resetting passwords from a machine that is itself infected, missing service accounts and the scheduled tasks an attacker pushed out through Group Policy, and reconnecting the backup NAS before cleanup is finished all send recovery back to square one.

How does WannaCry compare with ransomware attacks today?

WannaCry spread in 2017 as a worm, using the EternalBlue exploit against SMBv1 and jumping between machines automatically. Installing the MS17-010 patch and blocking port 445 from the internet stopped most infections.

Current ransomware is mostly human-operated. Attackers log in with stolen VPN or RDP credentials, spend days or weeks moving around the network, take over a domain admin account, delete backups, copy data out, and then launch encryption on every server at once. That is why recovery today also has to cover compromised accounts, attacker persistence and possible data theft.

How Ransomware Recovery works

  1. 01

    Call and contain

    On the first call we guide you through isolating systems and arrange the access we need.

  2. 02

    Assess

    We identify the strain, the affected systems and the state of your backups, then explain your real recovery options.

  3. 03

    Clean and restore

    We close the entry point, clean or rebuild systems and restore data in priority order.

  4. 04

    Report and harden

    We deliver the incident report and implement or recommend changes to backups, access and the network.

Ransomware Recovery: frequently asked questions

Can you decrypt our files?

For most current ransomware, decryption without the attacker's key isn't possible, and we won't promise it. If a legitimate decryptor exists for your strain, we test it on copies of your files. The main recovery path is clean backups and any surviving Shadow Copies.

Should we pay the ransom?

That decision is yours, but paying doesn't guarantee a working key and may carry legal consequences. Before deciding anything, check the state of your backups and your recovery options.

Was our data stolen as well?

Many ransomware groups copy data out before encrypting. By reviewing firewall logs, outbound traffic and tools the attacker left behind, we assess whether data left the network and state it in the report.

What if the backups are encrypted too?

We then look at Shadow Copies, older backups on separate media, file versions in cloud services, and database files that were only partly encrypted. Results depend on each incident, and we tell you plainly what is and isn't recoverable.

Related searches

  • ransomware recovery
  • ransomware decryption
  • recover encrypted files
  • ransomware removal
  • ransomware attack on network
  • server infected with ransomware

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.