Disconnect the infected computer from Wi‑Fi or Ethernet first. Then preserve the ransom note, clean a Windows PC with a current full Windows Security scan, and only afterward attempt file recovery. Removing ransomware stops further encryption; it does not automatically decrypt files. Recovery usually means restoring a verified clean backup or using a trusted decryptor that specifically matches the ransomware family.
1. Isolate the computer immediately
Turn off Wi‑Fi and unplug the Ethernet cable. Isolation limits access to shared folders, mapped drives, and other devices. If the computer is owned or managed by an employer, school, or organization, contact its IT or security team before changing more systems.
- If you cannot disconnect the network, powering down may limit spread, but it can destroy volatile evidence. For managed incidents, follow the responder’s instructions; Microsoft’s enterprise guidance favors isolating compromised devices without shutting them off where feasible.
- Do not reconnect the computer to “see whether it is fixed.” Keep it isolated until cleanup is complete.
2. Preserve the ransom note and evidence
Photograph or screenshot the ransom note before deleting anything. Record the unusual file extension, the approximate time the problem began, and which folders or devices are affected. Keep encrypted files and the note; they may help identify the ransomware family. Do not rename, edit, or overwrite encrypted files.
On a business or shared network, avoid wiping devices or deleting logs unless your incident-response team directs you to do so. Evidence can help determine how the infection entered, whether credentials were stolen, and whether other systems were affected.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
3. Clean a Windows PC before trying to recover files
For a personal Windows computer, use the built-in Windows Security application and run a full scan. Interface names vary by Windows release, but the usual route is:
- Open Windows Security.
- Select Virus & threat protection.
- Choose Scan options, select Full scan, and start the scan.
- Allow Windows Security to quarantine or remove anything it detects, then restart if it requests one.
- Run another current scan if suspicious activity continues.
Cleaning must come before recovery. If the malware remains active, it can encrypt restored files or attack a backup as soon as you reconnect it.
Rank #2
- SuperSpeed: A super-fast 64GB USB3.0 USB drive with read speed up to 150MB/S and write speed up to 80MB/S. It has super speed but DOESN'T overheat. Also available in a 128GB capacity. See the A+ comparison chart for details.
- Safety: It comes with A physical write-protect switch and can safely connect to any computer while the switch set to “Read-Only”. In the Protected mode, your data is safe from viruses, malware, data tampering and accidental deletion.
- High Endurance: This flash drive has higher performance and endurance/durability as it adopts A+ MLC memory chip compared with other USB flash drives which use TLC or QLC chips.
- Capacity: This listing is for the 64GB version. A 128GB option is also available. See the A+ comparison chart for details.
- Plug and Play: Simply plug the thumb drive into any USB port and then start data transfer and storage. It is compatible with USB 3.0/3.1 and USB 2.0 ports and works on Windows2000/XP/Vista/7/8/10/11/Server, Mac OS, and Linux. The default format is exFAT file system which allows individual files larger than 4 GB, but you can always re-format to FAT32.
A single scan is not proof that an organizational incident is contained. If multiple computers, synchronized folders, or mapped-drive targets are involved, every suspected device must be assessed. Enterprise ransomware can also involve stolen credentials, persistence, lateral movement, or data theft; use professional incident responders rather than attempting a network-wide cleanup alone.
4. Identify the ransomware and check for a decryptor
Malware removal and decryption are different tasks. Removing the ransomware prevents new encryption, but it does not turn already encrypted files back into readable files.
Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
After cleanup, use No More Ransom’s Crypto Sheriff to submit a small encrypted sample and information from the ransom note. The page accepts encrypted samples up to 1 MB and may identify the family or indicate whether a known solution exists. Its decryptor catalogue contains tools for particular ransomware families.
- Use a decryptor only when the family and supported variant are a strong match.
- Obtain it from the trusted publisher listed by No More Ransom or another authoritative source.
- Follow that tool’s instructions exactly, and do not run it until the malware has been removed.
- No decryptor is guaranteed to exist, and a tool for one family or variant may fail on another.
5. Recover files from a clean source
Once the computer is clean, choose the recovery method that fits the evidence. Neither route guarantees that every file can be restored.
Rank #4
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
| Recovery route | Use it when | Checks and limitations |
|---|---|---|
| Clean backup or Windows recovery | You have a backup or file-history snapshot that predates the infection. | Verify the backup is clean and disconnected from the infected computer until needed. Windows File History or System Protection may help on supported versions only if enabled before the attack. |
| Family-specific decryptor | The ransomware family is positively identified and a trusted tool explicitly supports that family or variant. | Availability changes, results vary, and encrypted files may remain unrecoverable. Remove the malware first. |
Restore from backup or File History
Prefer an offline or otherwise isolated backup known to predate the incident. Ransomware can encrypt backups that remain continuously accessible. Scan the restored data before putting it back into normal use.
If files were synchronized to cloud storage, pause synchronization until the computer is clean. Check the provider’s version history or restore features from a clean device; otherwise, infected changes may propagate back to the cloud.
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
When no recovery method works
Keep the ransom note and encrypted files rather than paying immediately or deleting them. A future decryptor may depend on the exact family and variant. For widespread or high-value incidents, involve qualified incident responders and law enforcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.6. Do not treat ransom payment as a fix
Payment does not guarantee access to the computer or files, and it can encourage further criminal activity. If you have already paid, contact your bank and local authorities promptly; reporting channels depend on your country. Organizations should also contact the appropriate cyber-incident authorities and coordinate with their response team.
7. Prevent a repeat infection
- Maintain offline, encrypted backups and test that files can actually be restored.
- Keep at least one backup disconnected when it is not being updated.
- Use Windows Security and keep its detections current; the cited guidance does not establish that a paid antivirus product is required.
- Protect accounts with strong, unique passwords and multifactor authentication where available, especially after a business incident in which credentials may have been exposed.
- Document which devices, shares, and cloud services were affected before reconnecting anything.
What “removed” really means
A successful cleanup means the ransomware is no longer running or encrypting additional data. It does not certify that encrypted files are recoverable, that no data was stolen, or that every device on a network is safe. Treat decryption, backup restoration, and broader incident investigation as separate steps.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

