A note demanding payment, files renamed with a strange extension, and a business or household locked out of its own data overnight — a ransomware attack is frightening, but it's rarely as total as the ransom note wants you to believe. We help homes and businesses across Staines and Surrey recover what the encryption left behind.
Free diagnostic on every ransomware job. One fixed quote in writing before any work begins.
No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the free diagnostic page.
Every ransomware job starts by matching the symptoms to the fault — these twelve cover almost everything that reaches the bench.
Documents and photos suddenly carry an odd extension (.lockbit, .phobos, .djvu) and refuse to open — the classic sign of an encryption run.
A readme.txt, .hta or on-screen note demanding cryptocurrency payment appears right across the system.
The malware ran vssadmin to wipe Volume Shadow Copies — sometimes carvable back from unallocated space.
Attached backup drives and network shares were hit in the same pass, so the 'backup' is locked too.
Everything the infected account could reach — shares, mapped drives, sync folders — was encrypted along with the local disk.
Exposed NAS boxes and servers encrypted over the network, often with the volume structure damaged as well.
ESXiArgs-style attacks encrypt VMFS datastores and VMDK files, taking whole virtual estates offline at once.
Some strains encrypt a copy and delete the source — the original files are recoverable where the freed space survives.
Speed-focused strains encrypt only the first portion of big files (databases, PSTs) — the tail is often intact and usable.
A quick reinstall on the 'clean' machine overwrote recoverable data — we work from an image taken before further writes where possible.
STOP/Djvu, some Phobos and older variants have published flaws or free decryptors that can unlock files lawfully.
Data was exfiltrated as well as encrypted — forensic logs help scope what left, for insurers and ICO reporting.
Modern ransomware doesn't scramble your files randomly — it uses strong, standard cryptography, typically a fast symmetric cipher (AES) to encrypt the data and a public-key cipher (RSA or elliptic-curve) to lock the AES keys so that only the attacker holds the means to unlock them. Well-built strains also hunt down and delete Windows shadow copies, local backups and connected NAS shares first, precisely so that restoring isn't easy. That's why the honest starting point matters: where the cryptography is implemented correctly and the keys are gone, the encrypted files themselves simply cannot be 'cracked'.
We'll always be straight with you: paying the ransom is not something we advise — it funds the attackers, breaks no technical deadlock, and frequently returns a broken or partial decryptor even when they do respond. Real-world recovery instead comes from the gaps the attack left behind: restoring from Volume Shadow Copies or backups the malware failed to reach, recovering deleted originals where it encrypted a copy and removed the source, carving unencrypted remnants and temporary files off the disk, rebuilding damaged RAID and NAS volumes so intact data underneath becomes readable again, and decrypting properly where a free, published decryptor already exists for that specific strain. We assess which of these routes your case actually has before quoting anything.
The single most useful thing you can do the moment you spot an attack is disconnect the affected machines from the network and the internet and leave them powered as they are — don't wipe, don't reinstall, and don't run cleanup tools that overwrite the very remnants recovery depends on. Preserve the ransom note and a couple of sample encrypted files (they help us identify the strain), then get in touch. We work only from forensic images, so your originals are never altered while we look for a way back.
Ransomware work is careful, isolated, evidence-aware recovery — never a gamble with the attacker. The bench is built for it:
Infected media is examined on an air-gapped bench, disconnected from any live network, so nothing can spread or re-encrypt while we work.
Every affected drive is imaged sector by sector through write-blockers first — all recovery runs on the copy, and your originals are never altered.
Volume Shadow Copies, NAS snapshots and deleted source files the malware tried to remove are carved back from unallocated space wherever they survive.
Ransom notes and sample files are matched against strain databases and reputable published decryptors (No More Ransom and vendor tools) to decrypt lawfully where a key or flaw exists.
Encrypted servers often have damaged array structures too — the volume is reconstructed so intact and remnant data underneath becomes readable again.
The strain, the entry point where evident, and exactly what was and wasn't recovered are documented — useful for insurers, ICO reporting and internal review.
Where a strain's encryption is correctly implemented and the keys are gone, the files themselves cannot be brute-forced — reputable recovery means restoring from shadow copies, backups, deleted originals and rebuildable RAID/NAS data, and decrypting only where a lawful, published decryptor exists. We don't advise paying the ransom, and we work exclusively from forensic images so nothing is made worse.
Hit by ransomware? Disconnect the affected machines from the network and the internet and leave them powered as they are — don't wipe, reinstall or run cleanup tools, as those overwrite the very remnants recovery depends on. Keep the ransom note and a couple of sample encrypted files (they help us identify the strain), then call us on 0800 689 0668 before sending anything in.
Most customers post or courier their media to us.
Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.