Home / Devices / Ransomware

Ransomware Data Recovery York

You arrive to find every document wearing a strange extension and a demand note in every folder, insisting the criminals' decryptor is the only way home. The drives usually know better. Encrypted PCs, servers and NAS units from York businesses and households are examined here for every lawful route back — and handing money to attackers has never once been on the list.

Every ransomware job is diagnosed free. The quote turns up fixed, in writing, before a screwdriver is lifted.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// top 25 faults on this bench

The twenty-five ways they let go

First job on any ransomware is putting the symptoms against the fault — after twenty-odd years, these twenty-five account for nearly everything that comes through the door.

One machine, everything locked

Every user folder ciphered in a single overnight run: the classic single-PC attack, and the shape most cases arrive in.

Shares on the NAS ciphered

Internet-facing boxes are preferred prey. The snapshot trees beneath the shares dodge the purge more often than attackers intend.

An ESXi datastore, gone in an evening

Hypervisor-focused strains work through the datastore VMDK by VMDK, felling the whole virtual estate at once.

Large files only partly ciphered

Speed-tuned families encrypt an opening stretch of each big file and move along. Databases and archives keep usable remainders.

Restore points swept first

vssadmin runs before the encryption does. Even so, deleted shadow copies can sometimes be carved back out of free space.

The backup drive was attached

Plugged in meant reachable, and reachable meant encrypted. Its older versions and remnants still count for plenty.

Stolen first, locked second

Double extortion pairs theft with encryption and threatens publication. What left the network gets scoped for insurers and the ICO.

A demand where the login should be

Boot-locked machines give up their drives, which get imaged and examined beneath the lock — where the files actually are.

Databases torn mid-transaction

SQL and Exchange files caught writing end up half-ciphered. Salvage runs page by page against the capture.

Still infected, still busy

A NAS that re-encrypts each restore attempt remains owned. Isolate first; recover strictly from images thereafter.

An extension nobody's met

Unknown strains get fingerprinted against the databases in search of family and any published weakness worth exploiting lawfully.

All note, no cipher

Scareware plants ransom notes over untouched files, and some genuine runs crash early. A rig check separates fright from loss.

The corporate heavyweights

The big-name crews run deletion passes both thorough and imperfect. Recovery lives in the imperfections, and we know where they tend to be.

STOP/Djvu off a cracked download

The home-PC staple. Older offline-key variants carry a free public decryptor, applied lawfully whenever it fits.

Original deleted, duplicate ciphered

Certain families encrypt a copy and delete your original — abandoning that original in free space, carvable. A design oversight we cherish.

Walked in through RDP

Exposed remote desktop remains an open door, with encryption following hours after entry. The logs date the walk-in to the minute.

Sync pushed the damage upstream

OneDrive loyally replaced good files with ciphered ones. We check version history and remnants at both ends of the pipe.

Hyper-V hosts held hostage

Ciphered VHDX files drop every guest together. Partial-encryption quirks frequently leave those guests rebuildable.

Exfiltration without encryption

Nothing locked, everything copied, leak threatened. The job turns from recovery to forensic scoping, and the questions change.

Caught between rotations

The one disk connected on attack night took the hit. Off-rotation sets plus carved remnants bridge the gap it left.

A foothold left for later

Scheduled tasks and services can re-fire the malware weeks on, mid-restore. Images get swept for footholds before any rebuild goes live.

Middlemen who simply pay

Some 'recovery specialists' quietly pay the ransom and re-badge it as expertise. We recover from evidence, say what's possible, and carry no messages to criminals.

Backup servers hunted first

Modern crews disable the safety net before pulling the trigger. Repository files often keep recoverable structure all the same.

A wiper in ransomware's clothing

Some strains destroy with no decryption path in existence. Identified fast and said plainly; recovery then works from remnants and copies.

Config ciphered, data skipped

ESXiArgs-style runs encrypt small config files and miss the flat data behind them. Rebuilding from the skipped material restores entire machines.

What the attack actually did

The malware walked the storage encrypting file after file with entirely conventional cryptography — AES across the contents, those keys sealed in turn under an asymmetric key whose private half never leaves the attacker. The strange extension is the strain's signature; the note prints once the run finishes. Capable families also purge shadow copies, chase down reachable backups and sweep every share the compromised account could see, which is why the demand sounds so certain of itself. It never mentions what the run failed to reach, though — and a careful look nearly always finds something it didn't.

The lawful ways back

No lab anywhere brute-forces properly built encryption, and a firm implying it can is selling a story. Search for a ransomware decryption service UK-wide and much of what comes back is resold negotiation dressed as engineering; the honest version mines the attack's mistakes instead. Snapshots and shadow copies the purge overlooked. Backups out of the malware's reach. Originals that were deleted rather than encrypted, where the strain worked on a copy. Temp files and fragments carved from slack and free space. Broken NAS and RAID structures rebuilt until clean data shows through. And, for the minority of families with published flaws, a free decryptor applied lawfully. The free assessment maps which of those exits exist in your particular case.

Where we stand on paying

No ransom gets paid from this bench, no message gets carried to an attacker, and no client gets steered toward paying — it bankrolls the next campaign, guarantees nothing, and criminal decryptors are famous for mangling the very files they claim to free. What you get instead: each technical route exhausted, and a written record of what came home and what stayed lost. If insurers and advisers later walk a company toward negotiating, that decision is theirs to own — ours was making certain the technical answer arrived first.

// the kit on the bench

Engineering tools, not download-and-hope software

Ransomware cases run as forensic incidents from minute one: isolated, imaged, documented, then recovered:

Air-gapped imaging bench

Incident media stays off the network entirely, worked on an isolated rig where nothing spreads, calls home, or picks up encrypting where it left off.

Hardware write-blockers

Attacked drives get captured behind physical write-blocking before examination; recovery touches the copies while originals sit sealed.

VSS / shadow-copy carving

Free space swept for shadow copies and NAS snapshot remains the purge overlooked, rebuilt into restore points that actually restore.

Strain ID & decryptor lookup

Note plus samples identify the family; the family gets checked against reputable public sources — No More Ransom, vendor releases — for any lawful decryptor.

Remnant & free-space carving

Unencrypted originals, temp files and half-copies pulled from free space: the debris every rushed encryption run scatters.

Forensic logging & reporting

Strain, spread and outcome documented as we go — the paperwork insurers, regulators and your own post-mortem will all ask for.

// makes & models we see

Families and patterns handled

LockBitAkiraPhobosDharmaMakopSTOP / DjvuBlackCat / ALPHVMedusaConti-lineageESXiArgs

The honest sources of recovery

Two undertakings, given in writing before work starts: strains without a published weakness cannot be brute-forced by us or anybody, and we neither pay ransoms nor carry messages to the people holding your files. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.

// before you post it

Before it goes in the post — free the drive if you can

First, before any parcel tape: unplug network leads and let affected machines stand exactly as they are — no antivirus sweeps, no reinstalling, no formatting, since every pass grinds away the remnants recovery feeds on. Keep the ransom note and a couple of ciphered samples so the strain can be identified, then ring 0800 689 0668 and we'll agree what should make the journey. Capture happens on the air-gapped rig; recovery only ever touches copies.

// getting your device to us

Sending it in — easier than you'd think

Nearly every job on our bench arrived by tracked, insured post — it's the quickest, safest route in. There's no collection service, so the parcel is yours to send or hand in.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// ransomware recovery questions

Common questions

Only where the strain permits — a published free decryptor or a documented flaw, and that's a small club: some elderly STOP/Djvu variants, a few botched imitators. Properly built encryption opens for nobody. So the real work goes at snapshots, backups, deleted originals, carved fragments and rebuilt volumes — and the free assessment says which of those routes you've actually got.
Never, under any framing. We won't pay, won't broker, and won't recommend paying — the money funds crime, the promise is worthless, and the criminals' own tools break what they unlock often enough to make the exercise pointless. If that call ever gets made, it's made by you, your insurer and your advisers; our part is done when every technical route has been run to the end.
The drives are assessed free, with the verdict inside 2 working days of arrival, and one fixed quote follows in writing. Ransomware belongs to the forensic class of work, so the quoted figure is settled before recovery begins rather than no fix, no fee — and that quote spells out the realistic scope before you part with anything.
Unplug the network from everything touched and then stop — no reinstalling, no formatting, no cleanup tools, since every pass of those grinds away the leftovers recovery depends on. Set the note aside with two or three encrypted samples for strain identification, ring 0800 689 0668, and send the numbered drives to our Leeds location. All work happens on forensic images; the originals stay sealed.
Fewer firms than the adverts suggest — a good deal of what's sold as decryption is negotiation with the attackers, resold. York Data Recovery runs the work in-house: encrypted PCs, NAS units, servers and virtual estates arrive by tracked, insured post at our Leeds location, Mon–Fri 9am–5:30pm, from every part of the country. The free assessment names your strain and the realistic routes; as forensic-classed work the quote is paid up front, and no ransom is ever paid or brokered by us.
// related services

More work we take on

When you’re ready, so is the bench.

Free diagnosis, a fixed written figure, no fix no fee on most work — start online or ring the freephone.