Home / Devices / Ransomware

Ransomware Data Recovery Bracknell

Monday morning and nothing will open. Every filename has picked up a suffix nobody recognises, a text file has appeared in each folder setting out the price, and the entire presentation is staged to leave you believing that one route exists. Usually there are others. Locked PCs, servers and NAS boxes come in from firms and households across Bracknell, Wokingham, Slough and the wider Thames Valley, and what gets looked for here is strictly what can be reached lawfully. Whoever did this gets nothing out of us.

Anything sent in for ransomware recovery is diagnosed free. The written figure that follows is settled before a screwdriver leaves the drawer: £300 + VAT for a single drive and from £500 + VAT for an array.

No fix, no fee covers logical recoveries. Outside it sit electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and physical work is 50% up front. Every band is published on the data recovery cost page.

// thirty faults, in rough order of frequency

Thirty ways it goes wrong, and what sits behind each

Reading a symptom back to the failure underneath it is where the work genuinely starts, and this set of thirty accounts for all but a handful of the parcels that reach the Guildford bench. If yours is not on the list, it will still be recognised — describe it on the phone and you will get a straight answer about the odds before you post anything.

Every folder on one PC locked overnight

The machine was working at teatime and useless by bedtime, with a note dropped into each folder the run passed through. One encrypted desktop or laptop is the shape this arrives in more often than any other, and it is priced the way any other single drive is priced: £300 + VAT, with a free diagnostic before that figure is set.

Encryption is not a hardware fault

Nothing mechanical has happened to the disk. It reads perfectly, spins perfectly and will pass every test you point at it. What has changed is the contents, which means the recovery is not a repair job but a search for everything the attacker failed to reach. That is a different discipline and it is worth understanding before the first decision gets made.

Restore points deleted before the encryption started

Wiping shadow copies is standard practice for every family worth the name, and it happens minutes before anything gets enciphered. Deleted shadow copies can still be carved back out of free space, which is precisely why nothing should be written to that disk in the meantime — including a fresh Windows installation.

Big files only partly encrypted

An attacker is working against the clock, so most families take the first few megabytes of anything large, mark it as done and carry on. Mail stores, databases, video projects and disk images therefore arrive with long readable stretches intact inside them. Rebuilding around what the cipher never reached returns far more than the extension on the file would lead anybody to expect.

The original deleted, the copy encrypted

Some families write an enciphered copy and then delete the original instead of overwriting it in place. That leaves the plain original lying in free space where it can be carved straight back out. It is a design oversight and it is one this bench is extremely fond of.

The NAS shares gone

Anything answering on the open internet gets found automatically, and a NAS with a port forwarded to it sits at the top of that list. What frequently survives is the snapshot tree, particularly on boxes where the snapshots were kept out of reach of the share credentials, and that is the first place looked once the disks have been imaged.

A datastore encrypted in an evening

Hypervisor strains walk the datastore taking one guest disk at a time, which is why an entire estate goes dark in a single evening instead of in stages. Servers, NAS units and arrays are quoted from £500 + VAT and the figure rises with the number of disks, on exactly the same basis as a failed array.

The backup drive was plugged in at the time

From the malware point of view a USB disk left permanently connected is simply another folder. Even so it is worth imaging, because earlier file versions, deleted originals and the fragments around them survive on it far more often than people assume, provided it is read properly rather than plugged back in and browsed.

Copied first, encrypted second

Double extortion means the data left the building before anything was locked, and the threat is publication rather than deletion. Establishing what actually went is a separate exercise from recovering what stayed, and it matters to the insurer and, where personal data is involved, to the notification clock that started running without anybody noticing.

A demand instead of a login prompt

Where the start-up code has been overwritten with a payment screen, the situation looks total from the keyboard. In most cases the data behind it has not been altered at all. It gets imaged and read outside the machine, where a note demanding payment carries no authority whatsoever.

Databases caught mid-write

SQL Server and Exchange files enciphered while in use finish up part encrypted and part not, with the boundary sitting inside a transaction. Salvage then proceeds page by page on the captured image, and consistency is rebuilt from what the logs still hold.

A box that is still owned by somebody else

Where every restore is enciphered again within the hour, nobody has been evicted yet. The order is isolate, then image, then recover on copies, and nothing goes back onto the network until the images have been examined for the accounts, scheduled tasks and tools that were left behind for exactly this purpose.

An extension nobody recognises

An unfamiliar strain is identified from the note, the extension and a handful of samples, then checked against the public catalogues to see whether a lawful decryptor has been published for that family. Most of the time none has, and that answer comes back on the first day rather than being spun out over a month.

A ransom note and nothing actually encrypted

Notes turn up over files that were never touched, either because the run crashed early or because it was never more than a bluff. Telling genuine damage apart from fright takes a bench check, and that happens inside the free diagnostic, which closes 2 working days after the media is booked in at Guildford.

A strain that arrived with cracked software

STOP and Djvu travel with pirated installers and keygens, which makes them a household problem far more than a corporate one. Several of the older offline-key variants have a published decryptor, and where the samples genuinely match one it gets used. Where they do not match, you are told that plainly instead of being encouraged.

In through remote desktop

Remote desktop left open to the internet is still the most common front door, and the encryption usually follows several hours behind the first successful sign-in while somebody has a look around. The event logs date that sign-in to the minute, and it is among the first things an insurer will ask you to produce.

Sync carrying the damage into the cloud

OneDrive and Dropbox did precisely what they were installed to do, uploading each enciphered file over the good copy within seconds. Both ends are worth working — version history at the cloud end, remnants at the disk end — and neither of them waits indefinitely.

Virtual machine files enciphered on the host

A single damaged VMDK or VHDX takes a whole guest with it. The same speed-tuned partial encryption that spoils large files also tends to leave enough of those guests intact to rebuild them from the images, one at a time.

Data copied and nothing locked at all

Nothing enciphered, no notes in the folders, just an email demanding payment to keep quiet. That is an investigation rather than a recovery: what left, when, and through which account. Different questions, a different method, and it is quoted as forensic work rather than as media.

Caught between backup rotations

The set that happened to be connected on the night is the set that was hit, and the copy sitting off site is a fortnight behind. Older rotations together with what can be carved out of free space usually close most of that fortnight, and an honest view of how much of it they close comes out of the assessment.

Something left behind for later

Scheduled tasks, services and stolen credentials can restart the encryption weeks afterwards, generally during a restore, which is the worst moment available. Images are swept for footholds before anything is allowed near a network again.

The backup server attacked first

Going for the backups before triggering anything is standard practice now, and the crews are well drilled at it. Even where the management console has been destroyed, repository and chain files often keep enough structure to be worth taking apart, which is the argument for imaging that server rather than rebuilding it.

A wiper dressed up as ransomware

A few families destroy rather than encrypt, and no key exists for them at any price, whatever the note promises in return. Recognising that early saves a great deal of money and false hope. From that point the work is remnants, snapshots and whatever copies the attacker could not reach.

Configuration locked, bulk data untouched

Some runs go for small files and never get near the large flat data behind them, because working through terabytes takes hours nobody has. Systems have been put back into service by rebuilding around what the run skipped, without a single file being decrypted.

Backups the attacker was not allowed to delete

Immutable and object-locked copies come through attacks that flatten everything around them, because the credentials the intruder stole do not carry permission to remove them. Whether one exists is established during the assessment, before anybody spends days carving free space that may turn out not to be needed.

A purchased decryptor that damages files

Where payment has already been made, the tool that comes back is often slow, unreliable on large files, or destructive. Files damaged by a bad decryptor become a second recovery problem sitting on top of the first, so everything should be imaged before that tool is run a second time.

Whether to pay is your decision, not ours

It is a commercial and legal judgement for the business and its insurers, taken with proper advice, and it is not a decision this laboratory makes for you. No ransom is paid from here and no message is carried to the people holding your files. What is offered is recovery from evidence and a straight account of how much of it is realistic.

Mail that went missing in the cloud

Nothing running on a desktop can encipher a hosted mailbox. What normally happened is that the attacker had the credentials and deleted mail directly. Recovery windows inside the tenant are finite and already counting down, so that thread gets pulled on day one rather than in week two.

Hosts enciphered while the guests kept running

A host can be encrypted underneath guests that are still running quite happily in memory. Powering those guests down finishes the job the attacker started. There is a correct order for handling this, it has saved entire estates, and it costs one phone call before anything is shut down.

Rebuilt by IT before anybody thought to ask

The reflex after an attack is to wipe and rebuild so the company can trade again, and the rebuild writes straight over the free space a recovery would have been carved from. If the data matters at all, take the disks out and put them on a shelf before that starts. Half a day of patience has saved whole companies.

What the program actually did to your files

There is nothing clever in the mechanism, which is worth knowing because the mystery does half the intimidating. Each file gets opened in turn and its contents scrambled with AES. The key used on that one file is then sealed with a public key, and the matching private half never leaves the people who wrote the strain. That odd extension bolted onto every filename is a signature and nothing more, a way of telling one crew apart from the next. The note goes down last, once the sweep has finished. What separates a well-built strain from a lazy one is everything it does besides encrypting: deleting volume shadow copies, walking the network for any backup target the compromised account could reach, and following mapped shares to the far end of them. That completeness is why the note sounds so sure of itself. It never mentions the places the sweep failed to get to, and on most jobs there are some.

The routes that do not involve the attacker

Encryption done competently cannot be undone by equipment, and any firm hinting otherwise is telling you a story. A large part of what gets advertised in this trade as decryption turns out to be a conversation with the crew, held on your behalf and invoiced with a margin on top. The real work is duller and considerably more productive, because it looks for the gaps in the run instead of at the mathematics. Snapshots the purge never found. A backup drive that happened to be unplugged that week, or one sitting on a machine the compromised account had no rights to. Original files still present as deleted blocks, since a good many strains encrypt a copy and delete the source rather than overwriting in place. Fragments and working files carved out of unallocated space. Arrays and NAS volumes whose structures the attack damaged, reassembled until something readable appears underneath. And for the handful of families where researchers have found and published a flaw, a free decryptor applied properly. The assessment tells you which of those you have, and tells you when the answer is none of them.

Why nothing here goes to the attacker

No money leaves this building and no messages are carried, and nobody has ever been advised here that settling is the sensible move. The reasoning is practical rather than moral. Whatever is paid this month finances the campaign that hits somebody else next month. There is no contract behind the promise and no authority to complain to when it is broken. And the decryptors handed back are poorly written, so a proportion of what they touch comes back damaged. In its place you get every technical avenue pursued to the end, plus a written record setting out what came back and what did not. If an insurer or a solicitor later takes a business down the negotiation road, that decision belongs to them. The point of this work is that the technical answer exists before anyone has to make it.

// the equipment behind the bench

The kit that does the work, and why it matters

Every ransomware job is run as an incident: isolated first, imaged second, documented all the way through, and recovered last:

An air-gapped bench

Incident media is worked on a rig with no network attached to it at all. Nothing can spread from it, nothing can call out, and nothing can quietly resume from where it was interrupted while the job is under way.

Hardware write blocking

Nothing is examined until it has been copied behind a write blocker. The originals go into sealed bags and stay there for the length of the job, which also keeps them usable as evidence should the incident turn into a claim.

Shadow copy and snapshot carving

The deletion pass that runs ahead of the encryption is thorough without being complete. Free space is swept for what it left behind, and the fragments that come back are reassembled into restore points that will actually mount.

Strain identification

The note, the extension and two or three samples are enough to put a name to the family in most cases. That name goes to the catalogues worth trusting, in case a lawful decryptor has been released for it, and the answer arrives inside the first day either way.

Free-space and remnant carving

Plain originals, temporary working files, half-written output and abandoned fragments pulled back out of unallocated space. An encryption run in a hurry leaves a considerable amount of litter behind it, and that litter is the raw material the recovery is built from.

Incident logging

What the strain was, how far it spread, when each stage happened and what came back, written down as the work proceeds. Insurers ask for it, regulators sometimes ask for it, and your own review afterwards will certainly want it.

// the makes that turn up here

Strains and behaviours seen here

LockBit, in each of its versionsAkira, against Windows and ESXiPhobos and the family around itDharma, sometimes labelled CrySiSMakop and its relativesSTOP and Djvu, offline and online keysBlackCat, also known as ALPHVMedusa, which is not MedusaLockerBlack Basta, Royal and the other Conti descendantsESXiArgs and the hypervisor strains

Where recovered data actually comes from

Two things are promised in writing before any work starts. Where a family has no published weakness, nobody is going to break it, here or at any firm advertising that they can. And no ransom is paid from this laboratory and no message is carried to the people holding your files; whether to pay at all is a decision for you and your insurers to take with proper advice. What does come back comes back from snapshots the deletion pass missed, from remnants in free space, from large files the run only partly enciphered, from guests it never reached, and from copies it had no permission to delete. On price, a ransomware job is quoted from the hardware in front of us in exactly the way any other media is quoted, and it is never billed as forensic work. One encrypted PC drive is £300 + VAT. A server, a NAS or an array opens at £500 + VAT and climbs with the number of disks in it. The assessment costs nothing and closes 2 working days after the media is booked in. The figure is agreed and paid before the work starts, since the result rests on what the attacker failed to destroy rather than on any repair we carry out. The calls come from manufacturing and distribution units off the A329(M), from professional firms in the town centre and out towards Wokingham, and from IT providers across Berkshire and north Surrey.

// packing it for the post

Before the parcel is made up — free the drive if it will come

Take the network leads out, then leave the affected machines exactly as they are and touch nothing else. No antivirus sweep, no reinstall, no format, no disk clean-up, because each of those wears away the remnants a recovery is built from. Keep the note itself, and put aside a couple of locked files to travel with it, because samples are what allow the family to be identified. Where a server or a host is involved, do not power the guests down until you have spoken to somebody, since the order that happens in matters more than most people expect. Then ring 0800 689 0668 on a weekday between 9:00am and 5:30pm and what needs to travel gets worked out on that call rather than guessed at. Media goes insured and signed for, or by a courier you book yourself, to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH, which is around 40 minutes from Bracknell on the A322 and the A3. Nothing is collected and there is no counter in Bracknell, although the Guildford reception will take a parcel by hand during office hours. Once it arrives, the imaging is done on the isolated rig and every stage of the recovery after that runs against copies.

// getting the media to the bench

Booking a device in — what actually has to happen

Nearly every job here arrived as a parcel. Tracked, insured post is the calmest way to move a drive that is already struggling, and something handed over in Berkshire, Surrey or London is normally on the Guildford bench the next working day.

Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.

  • Pick packaging that holds its shape — a rigid carton or a heavy padded mailer — and pack round the unit so it cannot shift in transit. Leave the caddy, the mains adaptor and the leads at home; none of them are wanted at this end.
  • Print the shipping and booking-in form (PDF), put your name and mobile on it along with a sentence describing how the fault started, and slip it in alongside the media.
  • Send it Special Delivery through the Post Office and it travels tracked and covered. A courier account of your own works just as well. The only thing that matters is that somebody signs for it at this end.
  • If you would sooner deliver it by hand, the Guildford reception on the address card takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Bracknell shopfront nor a pickup van exists — those are the two things we cannot offer.
// write this on the label

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the shipping & booking-in form (PDF)

The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.

Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.

// ransomware recovery questions

Common questions

Occasionally, and only where the strain itself left a way in: a decryptor released by researchers, or an implementation error somebody has documented publicly. The list of families that qualify is short and largely historic, older STOP/Djvu builds and a few imitators who mishandled their key generation. Where the encryption was done properly, no key means no plaintext, and no equipment anywhere on earth changes that. So the effort goes into the gaps instead: snapshots that survived, backups the account could never reach, source files still lying in unallocated space as deleted blocks, carved fragments, and volumes rebuilt out of the structures the attack broke. The free assessment tells you which of those exist on your hardware.
No, and not through an intermediary either. We send nothing, relay nothing, and never present settlement as the reasonable option. The money funds the next campaign, the promise attached to it is unenforceable, and the tool that comes back damages a share of what it opens. If a business chooses that road anyway, the choice belongs to its directors, its insurer and its solicitors. Our part ends when the last technical avenue has been followed.
The disks are assessed free, with an answer within 2 working days of them reaching the lab, and one fixed figure follows in writing. The price comes off the hardware rather than off the drama: £300 + VAT where the encrypted data sits on a single PC drive, and from £500 + VAT where it sits on a server, a NAS or an array. The figure is agreed before recovery starts rather than settled at the end, and the scope is written down first. It is not forensic casework and is never charged as such.
Disconnect anything affected from the network and then leave it completely alone. No reinstalling, no formatting, no running a clean-up tool across the volumes, because each of those consumes exactly the leftovers a recovery depends on. Keep the ransom note itself along with two or three of the encrypted files, because that pairing is how the strain gets identified. After that, ring 0800 689 0668, mark each disk with its bay as it comes out of the chassis, and post them to Guildford. Everything from there runs on forensic copies and the originals you sent stay sealed.
Fewer firms than the search results imply, since a good deal of what is sold as decryption is a negotiation desk wearing a technical name. Bracknell Data Recovery does the work itself. Locked PCs, NAS boxes, servers and entire virtual estates come in by tracked, insured post to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH, open Monday to Friday, 9:00am to 5:30pm, and they arrive from every corner of the country. The assessment is free, it names the strain, and it sets out what is genuinely available. The figure is fixed before the work starts, and not a penny goes to an attacker on anybody's behalf.
// other work on the same bench

What else comes through here

When you're ready, so is the bench.

Nothing to pay for the diagnosis, one written figure before any work begins, and the band on this page is £300 + VAT for a single drive and from £500 + VAT for an array.