Home / Devices / Ransomware

Ransomware Data Recovery Coventry

Filenames ending in something nobody has seen before, and a text file in every directory explaining where to send money. The disks underneath are in perfect working order. What has changed is the content of the files, which has been put through a cipher held open by somebody else. That makes this a media job on healthy hardware, billed at £300 + VAT for a workstation disk and from £500 + VAT for an array. It is not investigation work and it never carries the investigation figure.

Looking at a drive hit by ransomware costs nothing. What comes out of that examination is one written figure, agreed between us before anybody picks up a screwdriver: £300 + VAT where one disk was caught, from £500 + VAT where an array was.

Logical work is no fix, no fee. Four things sit outside that: electronic and mechanical failures, chip-level work, DVR jobs and forensic work, and anything physical is half up front. All five bands are laid out on the data recovery cost page, while data recovery services follows a postal job from the parcel to the answer.

// thirty faults, roughly by how often they turn up

Thirty ways it fails, and what lies behind each one

Tracing a symptom back to whatever caused it is where the job genuinely starts, and these thirty cover very nearly every box opened on the Oxford bench. A fault that is not on the list is not an unfamiliar one: describe it over the telephone and you will get a straight reading of the odds before you have spent a penny on postage.

Every file renamed, and a note in each folder

What most people see first. The documents are still where they were and roughly the size they were, with a suffix appended and a text file dropped alongside them. The hardware has nothing wrong with it. What changed is that the contents went through a cipher whose key sits with somebody else.

The note itself, and why it is worth keeping

Read it, photograph it and keep a copy. Between the wording, the extension and the internal structure of one encrypted file, the strain can be identified, and the strain decides what is possible. Establishing which family this is comes first and it is part of the free examination.

Restore points deleted before the encryption began

Almost every family removes Windows shadow copies as its opening move, because that is the cheapest route back and they know it. A deleted snapshot has not been overwritten, only unlinked, and on a computer nobody has used since, what is left of it can often be carved back out of free space.

Only the first few megabytes of each file touched

Plenty of strains encrypt the head of a file and leave the rest, purely for speed. On video, archives, databases and large documents that leaves a great deal of usable material sitting behind the encrypted opening, and rebuilding those files around it is among the most productive routes on this page.

The original deleted and the copy encrypted

Some attacks do not encrypt in place at all. They read the file, write an encrypted version alongside it and delete the original, which is an entirely different situation. Where nothing has since been written over them, those originals return by perfectly ordinary means, so working out which of the two patterns occurred comes early.

A backup drive that happened to be plugged in

An external disk attached at the moment the attack ran is encrypted along with everything else, which is the whole argument against a permanently connected drive being a backup. It is recovered on the same terms as the machine, £300 + VAT for a single disk, and it is not investigation work.

Shares on the NAS sealed from a workstation

A share mapped on an infected computer is treated exactly like a folder on its own disk, and units published straight onto the internet are hit in their own right besides. Where the compromised account could not delete snapshots, those live. NAS and array work opens at £500 + VAT.

A hypervisor hit, and every guest with it

Where the attacker reached the host rather than the machines on it, whole virtual disks are encrypted as single enormous files. That sometimes works in your favour, because a partially encrypted file that size may still hold long readable stretches, and the virtual disk can be rebuilt around them.

A machine still running when somebody found it

The instinct is to leave it alone until somebody who knows about computers can look at it, and that instinct is expensive. A run in progress is still working down the folder tree while everybody waits, so the correct action is the immediate one, taken by whoever is standing nearest.

An attack that ran weeks before anyone noticed

Some strains work slowly, or wait until the backup rotation has turned over, so the discovery and the event are a long way apart. That makes the position harder, because the backups have cycled and the machine has been used since. It does not make it hopeless and it is worth assessing.

A decryptor that was bought and damages what it touches

This happens often enough to warrant its own line. What the money buys is an undertaking, not working software, and more than one family hands over a tool that wrecks whatever it is aimed at. Where one has already run, stop there and tell us, since its output changes what is still retrievable.

A family somebody has already broken

For a number of older strains the keys were published, seized or the encryption was implemented badly enough to be defeated. That gets tested before anything else on every job, since where it holds the work turns short and inexpensive. It is not the usual outcome, and ruling it in or out is free.

Databases caught mid-write

A database file is held open and written to constantly, so an attack partway through leaves something that is neither whole nor entirely sealed. Logs from the engine, and earlier whole copies of the file lying in free space, are each worth pursuing, and one or the other regularly yields something that opens.

Backup archives that lived on a mounted volume

Backup software writing to a share or an attached disk loses its archives along with everything else. Copies kept on something unplugged between runs come through the whole event untouched, which is the argument for offline media in a single sentence, generally learned the expensive way.

A machine rebuilt to get the business moving

Wiping and reinstalling to get somebody working again is understandable, and it removes a large share of the recoverable material at the same time. If the old disk is still in a drawer, leave it there and do not press it back into service. If it has already gone back to work, what survives depends on how long and how heavily.

Antivirus that removed the payload and left the files

Removing the malware unlocks nothing, and occasionally it takes with it the very component that was holding key material in memory. Where a scanner has been through the machine or quarantined anything, mention it, because it alters where there is any point looking.

Remote desktop left open to the internet

Exposed remote access is the usual way in for the strains that target small firms, and knowing it was the route matters for putting things back safely. Establishing that properly is a separate forensic engagement at £800 + VAT with a report, and it is not part of the recovery.

Every machine in the building sealed at once

One compromised account with wide rights reaches every server and every desk in the place, and that is what an overnight domain attack looks like the next morning. The hardware still sets the price: £300 + VAT per single disk, £500 + VAT and upwards per array, whatever the machine count comes to.

A sync folder that carried it upstream

Files encrypted locally are synchronised to the service and overwrite the good copies held there. Most services keep version history for a period, and restoring from it is usually faster and cheaper than anything done on a bench. That gets checked before anybody is asked to pay for a recovery.

An attack on a disk that was already failing

Two problems stacked. A copy is taken first, on the same terms any dying disk would get, and the sealed files are dealt with on that copy. The mechanical half is billed as physical work with half the figure up front, because mechanical failure is one of the four exclusions. Attack recovery on its own is not one of them.

Data copied out as well as locked

Current groups copy first and encrypt second, which is why there are two threats rather than one: publish, and withhold. Pinning down what actually went out of the door is investigation work at £800 + VAT with a report, and it is a separate instruction from putting the files back.

An insurer asking what happened before they pay

An independent account of what happened is a standard requirement on a claim, and it is quoted as an investigation on its own terms. Retrieving the files is recovery, priced by the hardware. Two services, and they should not turn up on one invoice dressed as a single one.

A home machine with twenty years of photographs

The same problem at a domestic scale and it gets the same answer. One drive is £300 + VAT, the examination is free, and what comes back depends on the strain and on what has happened since. There is no cheaper category for households and no dearer one either.

A disk formatted after the attack

A format wipes the index and leaves the contents lying where they were, sealed or not. Where the attack had deleted originals rather than encrypting in place, formatting over the top raises the difficulty without closing the door. Stop using that disk from now on.

Firms that quietly pay and call it technical work

There is a trade in companies who take a fee, pay the ransom on the customer's behalf without saying so, and present the result as their own engineering. It is worth knowing about in advance rather than discovering afterwards. Where a strain cannot be beaten, that is said here plainly and at no charge.

An attack interrupted before it finished

Where the machine lost power or was switched off partway through, a proportion of the files were never reached. Working out which ones is quick, and it regularly returns a substantial part of the data before any harder work is begun at all.

Autosaves, caches and spool files the attack missed

Working copies, autosave folders, print spools, thumbnail databases and application caches often sit in places the attack never visited. They rarely add up to everything. On a document-heavy machine they add up to a great deal more than most people would guess.

A backup that is old but real

An offline copy that is three months stale still does most of the work, and the sensible instruction is then to go after what has changed since rather than the whole disk. That is a smaller job, and it is quoted as a smaller job rather than inflated into something nobody needs.

A demand where nothing was ever encrypted

Some of what arrives is theatre: a note dropped on the desktop, a locked screen, files renamed and otherwise untouched. It is checked before anything else, because where that is what happened the files are simply there and the answer is short, cheap and rather satisfying.

A strain that did its job properly, and an honest no

When a current family has built its encryption properly, the key stays with the people who wrote it and no bench anywhere gets past that. Where that is the finding, it arrives during the free examination and costs nothing, rather than a fortnight and an invoice later.

Pull the plug, then leave the scene alone

The first decision is whether the process is still running, and the safe assumption is that it is. Cutting power stops it mid-file, which loses one document and saves the rest, whereas a clean shutdown gives it time to finish the job. After that, resist the urge to tidy up. Three habits do real damage in the hours afterwards. Reinstalling Windows to get a usable machine writes over the free space where the survivors are hiding. Antivirus and cleanup tools quarantine the encrypted files along with the malware, and quarantine is a folder people then empty. Decryptors downloaded from search results are, more often than not, either a second piece of malware or a program that mangles what it touches. Keep the note, photograph the screen, and set aside one encrypted file together with an untouched copy of the same document if such a thing exists anywhere — an old email attachment will do. That pair identifies the family faster than anything else, and the family determines whether there is a route back at all. Anything connected at the time comes too: the external drive on the desk, the members out of the array, the network box.

Where the survivors hide

Nobody here attacks the cipher, because properly written encryption does not give way to effort or equipment. The work is finding what the attack skipped and repairing what it half-finished, and speed is the attacker's weakness. Encrypting terabytes properly takes longer than an intruder can afford, so many families process only the opening megabytes of each file, which leaves databases, video, archives and long documents readable behind a spoilt header and rebuildable. Others work by copying a file, encrypting the copy and deleting the original, and a deleted original on a spinning disk is exactly the job this trade has done for thirty years. Shadow copies are usually the first casualty, but deletion is not erasure and the remains turn up in free space on a machine that has been left switched off. Then there are the corners nothing reached: autosave folders, temporary directories, print spools, mail caches, the copy of the spreadsheet somebody had open on a laptop at home. And for a handful of older families the keys were published after arrests or after a flaw was found in the implementation, which turns a bad week into an afternoon. That check is free and it goes first.

The figure, and the second job people are sometimes sold

Media pricing applies because the media is the problem. One workstation disk is £300 + VAT. A server, a NAS or any other array is from £500 + VAT and rises with how many members there are, since the volume has to be put back together before a single file can be examined. Examination is free, closes two working days after the equipment is logged in, and answers three questions: which family, whether snapshots or deleted originals survived, and whether there is a genuine route back. No fix, no fee applies here in the ordinary way — the exclusion list runs to electronic and mechanical failure, chip-level work, DVR jobs and forensic instructions, and none of those describes an encrypted file on a working disk. The second job is separate and legitimate: an organisation that has to tell a regulator, an insurer or a board how the intruder got in and what left the building beforehand needs an investigation with a written report, and that is £800 + VAT. It belongs on its own line. Recovery quoted at the investigation rate is a billing decision rather than a technical one.

// the tools it takes

What stands on the bench, and why any of it matters

Nothing on this bench attacks the cipher, because a correctly built one does not give way to effort or to money. What it does instead is find the material the attack never reached, rebuild the files it only half touched, recover the originals it deleted, and identify the strains where a genuine route back exists.

Identifying the strain before anything else

Wording, appended extension and the internal shape of one sealed sample are enough between them to name the family, and the family fixes the ceiling on the whole job. Published keys and weak implementations are found in the first hours rather than after a hopeful week.

Carving snapshots and shadow copies out of free space

Volume shadow copies the attack unlinked, snapshots on a NAS, snapshots the file system took for itself — all carved back out of free ground, provided nobody has used the machine since. Unlinking is not overwriting, and this route alone finishes a fair share of these jobs.

Rebuilding files the attack only half touched

Where a strain sealed the first portion of each file and moved on, large documents, archives, databases and video are reconstructed around the encrypted opening. On a media-heavy machine that alone recovers a substantial share of what was lost.

Recovering the originals the attack deleted

Where the sealed version was written alongside and the original merely unlinked, standard file recovery gets the originals back. It is among the more rewarding routes on this bench, and it is the reason a machine should be stopped rather than left to run.

Putting the array back together first

There is nothing useful to examine on a set that is still in pieces, so a sealed NAS or array goes back together from copies of its members before any of the routes above are tried at all. Multi-disk work runs from £500 + VAT upwards by member count.

An isolated bench, and copies rather than originals

Every device is imaged on write-blocked ports and all the work happens on the copies, on equipment kept off the network. That protects whatever survived, and it keeps the original intact in case a decryptor for that family is published later, which for some of them eventually happens.

// badges that turn up in the post

What arrives after an attack

One office PC or laptopA server, Windows or LinuxAn array, or a SAN volumeA NAS reached across the networkA host, and the guests on itA backup appliance and its archivesAn external drive plugged in at the timeA Mac, which happens less oftenA sync folder that carried it upstreamA home machine full of photographs

What actually gets files back

The hardware sets this price, exactly as it does on any other media job. A single sealed disk out of a desk machine is £300 + VAT. A server, a NAS or an array opens at £500 + VAT and rises with the member count, because every disk is copied before the volume can be put back. It is not forensic work, it is never quoted at the investigation figure, and a firm that presents it as forensic should be asked why. Ransomware is not on the no fix, no fee exclusion list either; that list runs to electronic and mechanical failures, chip-level work, DVR jobs and forensic jobs, and encrypted files sitting on healthy hardware are none of the four. Two working days after the device is logged in, the free examination closes, having named the strain, said whether snapshots or deleted originals came through, and said whether a genuine route back exists. Where there is none, that costs you nothing to find out. An organisation that also wants the route in traced, and an account of what was carried out, is asking for a second instruction: an investigation at £800 + VAT ending in a written report.

// getting it ready for the post

Before the box is taped shut — take the drive out if it comes out

Power the machine down before anything else, at the socket if that is faster, and leave it down. Anything still encrypting is still eating files by the minute. After that: no reinstalling, no formatting, no decryptor bought from anyone, and nothing described as a cleaner pointed at the disk. Every one of those takes away material that would otherwise have come home. Take a photograph of the note and set aside one sealed file, with its original name if you can remember it. Those two together name the strain. Then send the storage: the bare drive out of a workstation, a laptop or a Mac rather than the machine itself; from a server or an array, a photograph of the chassis front and then the member disks alone with bay numbers written on them; a NAS travels whole with its drives still in it. Post it tracked and insured to Oxford Data Recovery, John Eccles House, Oxford Science Park, Robert Robinson Avenue, Littlemore, Oxford, OX4 4GP, or bring it in, since Coventry to the door is about fifty-five miles down the M40 and takes roughly an hour. Drop-offs are taken Monday to Friday, 9:00am to 5:30pm. There is no counter in Coventry and nothing is collected. Ring 0800 689 0668 and say if the business has stopped, because that moves the job up the list.

// getting your media to Oxford

Posting a device in — what goes in the box

Almost everything worked on here arrived in the post. A drive that is already in trouble has an easier time boxed, padded and insured than it does being carried round in a bag for an afternoon, and a parcel handed over in Coventry today is normally booked in at Oxford tomorrow morning.

As a rule the storage comes out and the machine stays where it is. That applies to a laptop, a tower, an iMac and to the recorder sitting under a counter. Taking equipment apart is not something this bench does, and a repair shop will free a drive in a few minutes. Two things go the other way: an external drive stays sealed inside its own case, and a NAS travels as a complete unit with its disks still in their bays. A Fusion Mac is a third case — both of its drives come out and travel together, each one labelled. The single situation nobody can work around is memory soldered flat onto a mainboard, which is how Apple Silicon Macs and a good many slim laptops are built: if the storage will not unbolt, there is no parcel to send.

  • Use a box or padded mailer with some rigidity to it, and pack around the drive until nothing shifts when the parcel is tilted. Mains adaptors, docks and leads are not wanted at this end.
  • Sending a RAID or a server? Only the member disks travel — not the chassis, not the controller — and each one wants its bay number written on it. Take a photograph of the front of the unit before anything is pulled; it costs nothing and now and again it saves a day.
  • Print the shipping and booking-in form (PDF), add a name, a number you will answer and a sentence on how the trouble began, and drop it in beside the media.
  • Most people use Special Delivery, which is tracked and covered; a courier of your own does the same job. You can also bring it: the Oxford reception takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Coventry counter nor a collection round exists.
// write this on the label

Oxford Data Recovery

John Eccles House
Oxford Science Park
Robert Robinson Avenue
Littlemore, Oxford, OX4 4GP

↓ Print the shipping & booking-in form (PDF)

Put Oxford Data Recovery on the label. From Coventry it is roughly fifty-five miles straight down the M40, about an hour if you would rather drive it in than post it. Either way you are told the moment it is logged, and the free diagnostic finishes two working days later.

Unsure what ought to go in the box? Ring 0800 689 0668 before you seal it, or work through the free online diagnostic and let it do the asking.

// ransomware recovery questions

Common questions

£300 + VAT per workstation disk, and from £500 + VAT for a server, a NAS or any other array, climbing with the member count. The hardware is healthy, so it is billed like any other media job and never at the £800 + VAT investigation rate. Nothing is charged for the examination, which closes two working days after the equipment is booked in. This work is not on the no fix, no fee exclusion list.
That decision belongs to you, though two facts should sit alongside it. What money buys is an undertaking rather than a tool, and some families distribute decryptors that damage the files they process. There is also a small industry of firms who quietly pay and then present the returned data as their own technical achievement. Let the free examination establish what can be recovered without any of that first.
Send them together. Anything mounted or plugged in when the attack ran was in scope, which is the plain reason a permanently attached drive is not a backup. Network shares are reached over the wire from an infected workstation in exactly the same way. Array pricing starts at £500 + VAT, and snapshots occasionally survive on a NAS because the account the attacker used lacked the rights to remove them.
Only if somebody outside the business has to be satisfied. Getting the files back is recovery. Establishing the entry point, the dwell time and what was taken out before the encryption started is an investigation with a written report at £800 + VAT, and insurers and regulators frequently want it. The two are separate pieces of work and a quote should show them as two.
Say so when you ring and the job is flagged the moment it arrives. What does not move is the arithmetic: two working days for the free examination from the day it lands, then the work itself. Anyone offering a rebuilt server by tomorrow morning is guessing with your money. Meanwhile get everything powered down, because a process still running is still working through your files.
// the rest of the week's work

What else reaches this bench

// where to read next

Pages that go further than this one

The bench is ready whenever you are.

Looking at it costs nothing, one written figure follows, and the band governing this page is £300 + VAT where one disk was caught, from £500 + VAT where an array was.