Taking work now — the first look is freeNAS drives posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
NDRNAS Data Recovery 0800 6890668 Price my job
NDR / Ransomware data recovery

Ransomware · NAS · server · snapshots · deleted originals · partly encrypted · no decryptor · what to do first

Ransomware data recovery. The encryption cannot be broken; what the ransomware did not reach, or did not finish, often can be recovered.

Ransomware does two things: it encrypts your files with a key you do not have, and it tries to destroy every other copy. The first part cannot be undone by a lab, and anyone who says otherwise is selling something; modern ransomware uses the same encryption as banking, and without the key it stays shut. The second part is where recovery lives, because ransomware is rarely as thorough as it claims. It often encrypts a copy and deletes the original, which leaves the original on the disk until something overwrites it. It often encrypts only the first part of each large file. It frequently fails to delete the snapshots a NAS or server keeps, or runs out of time, or never reaches a drive that was offline. We recover from all of that: the deleted originals, the untouched snapshots, the partly encrypted files, the unencrypted remnants, imaged from the drives before anything else is done to them. The first look is free and tells you honestly what exists before you decide anything about the ransom. A single drive is £300 + VAT; a NAS or server set is quoted on its members.

Free first lookOne fixed figure in writingNo data, no bill on most jobsReturn postage paid

Rather talk it through? An engineer answers the bench line
0800 6890668

Power the NAS or server down and disconnect it from the network, then stop. Do not wipe it, reinstall it, restore it from the ransomware's own instructions, or let an IT provider reinitialise the volume to get the business back up on the same drives. Every write reduces what survives, and the deleted originals and snapshots that make recovery possible are the first things lost. Report the attack to Action Fraud; the NCSC's guidance is not to pay, and the free first look will tell you what can be recovered before you decide.

Where recoverable data hides after an attack.

The deleted originalsMuch ransomware reads a file, writes an encrypted copy, then deletes the original. Deletion removes the entry, not the data, so the originals remain on the disk until overwritten. Imaged early, a large share of them come back whole, especially on hard drives, less so on SSDs with TRIM.
Snapshots and shadow copiesSynology and QNAP Btrfs snapshots, ZFS snapshots and Windows shadow copies hold earlier versions of everything. Ransomware tries to delete them and often fails, is interrupted, or lacks the rights. Where they survive, recovery is clean and complete to the snapshot's date.
Partly encrypted filesTo be fast, many families encrypt only the first few hundred kilobytes or megabytes of each large file. Databases, video, archives and large documents can be substantially intact beyond that point, and are rebuilt with the encrypted head accounted for.
What it never reachedA drive that was offline, a second NAS, an external backup, a laptop that was off, a cloud copy with versioning, mail on a server. The first look includes an inventory of what the ransomware did not touch, which is often more than the ransom note suggests.

What you see, and what it means.

Describe yours to us →
What you see The usual reason Where that leaves you
Every file renamed with a new extension and a ransom noteEncryption complete on that volumeDeleted originals and snapshots are the route; the encrypted files are not
Some files open, others do notInterrupted, or large files only partly encryptedThe intact and the partly encrypted recovered from the image
NAS shows snapshots, but the attacker claims to have deleted themDeletion often fails or is incompleteSnapshots recovered from the image; clean copies to their date
The volume was reinitialised to get back upThe recovery routes have been written overHarder and partial; stop any further use
A decryptor exists for this familySome older families have published keys or flawsChecked at the first look; applied to copies, never originals

How a ransomware recovery runs here.

Every drive imaged first. The NAS or server drives are imaged sector by sector before any examination, so the deleted originals and snapshots are preserved exactly as the attack left them, and so there is a forensic copy if you need one for insurers or the police. Nothing is written to the drives, and the volume is never reinitialised.

The volume and its snapshots reassembled on the images. A multi-drive NAS or RAID set is rebuilt in software from the images; the file system, Btrfs, ext4, ZFS, NTFS or ReFS, is read on the copy; and every surviving snapshot is mounted and its contents catalogued. Where a snapshot predates the attack, recovery from it is complete to that date.

Deleted originals and partial files recovered. The space freed by the ransomware's deletions is searched for the originals, and partly encrypted files are rebuilt with the encrypted head identified. A known decryptor, where one exists for the family, is run on copies. What was recovered is listed, by folder and by date, before any figure exists.

The honest limit. A file fully encrypted by a modern family, with no snapshot, no deleted original and no decryptor, cannot be recovered without the key. The first look tells you how much falls into that category and how much does not, so the decision about the ransom is made on facts. A single drive is £300 + VAT; a NAS or server set is quoted on its members, with no bill on most jobs if no data comes back.

Questions answered before you commit.

Can you decrypt ransomware-encrypted files?

Not without the key, and no lab can; modern ransomware uses encryption that cannot be broken. What we recover is what the ransomware did not reach or did not finish: snapshots, the originals it deleted, partly encrypted files and unencrypted copies. That is often a great deal, and the first look tells you how much.

The ransom note says our snapshots and backups were deleted. Are they?

Often not, or not completely. Ransomware frequently fails to delete NAS snapshots, lacks the rights to, or is interrupted. We image the drives and check; where snapshots survive, recovery is clean to their date.

Our IT provider wants to reinitialise the NAS and restore from backup. Should we?

Not on the same drives until they have been imaged. Reinitialising writes over the deleted originals and snapshots that make recovery possible. Image first, or swap in new drives for the rebuild and keep the originals untouched.

Do you deal with Deadbolt, Qlocker and eCh0raix on QNAP and Synology?

Yes; the NAS families are the commonest we see, and the NAS ransomware page and the Deadbolt and Qlocker page cover what comes back from each.

What does it cost?

A single drive is £300 + VAT; a NAS or server set is quoted on the number of members, with the first look free and no bill on most jobs if no data comes back. Where you need a preserved forensic copy for insurers or the police, our forensic service can provide it.

Power it down, and find out what survives before you decide anything.

Disconnect the NAS or server, leave it off, and tell us what the note says and what the box is. The first look is free, and it tells you honestly what can come back without the key.

0800 6890668