Ransomware · NAS · server · snapshots · deleted originals · partly encrypted · no decryptor · what to do first
Ransomware data recovery. The encryption cannot be broken; what the ransomware did not reach, or did not finish, often can be recovered.
Ransomware does two things: it encrypts your files with a key you do not have, and it tries to destroy every other copy. The first part cannot be undone by a lab, and anyone who says otherwise is selling something; modern ransomware uses the same encryption as banking, and without the key it stays shut. The second part is where recovery lives, because ransomware is rarely as thorough as it claims. It often encrypts a copy and deletes the original, which leaves the original on the disk until something overwrites it. It often encrypts only the first part of each large file. It frequently fails to delete the snapshots a NAS or server keeps, or runs out of time, or never reaches a drive that was offline. We recover from all of that: the deleted originals, the untouched snapshots, the partly encrypted files, the unencrypted remnants, imaged from the drives before anything else is done to them. The first look is free and tells you honestly what exists before you decide anything about the ransom. A single drive is £300 + VAT; a NAS or server set is quoted on its members.
Rather talk it through? An engineer answers the bench line
0800 6890668
Where recoverable data hides after an attack.
What you see, and what it means.
Describe yours to us →| What you see | The usual reason | Where that leaves you |
|---|---|---|
| Every file renamed with a new extension and a ransom note | Encryption complete on that volume | Deleted originals and snapshots are the route; the encrypted files are not |
| Some files open, others do not | Interrupted, or large files only partly encrypted | The intact and the partly encrypted recovered from the image |
| NAS shows snapshots, but the attacker claims to have deleted them | Deletion often fails or is incomplete | Snapshots recovered from the image; clean copies to their date |
| The volume was reinitialised to get back up | The recovery routes have been written over | Harder and partial; stop any further use |
| A decryptor exists for this family | Some older families have published keys or flaws | Checked at the first look; applied to copies, never originals |
How a ransomware recovery runs here.
Every drive imaged first. The NAS or server drives are imaged sector by sector before any examination, so the deleted originals and snapshots are preserved exactly as the attack left them, and so there is a forensic copy if you need one for insurers or the police. Nothing is written to the drives, and the volume is never reinitialised.
The volume and its snapshots reassembled on the images. A multi-drive NAS or RAID set is rebuilt in software from the images; the file system, Btrfs, ext4, ZFS, NTFS or ReFS, is read on the copy; and every surviving snapshot is mounted and its contents catalogued. Where a snapshot predates the attack, recovery from it is complete to that date.
Deleted originals and partial files recovered. The space freed by the ransomware's deletions is searched for the originals, and partly encrypted files are rebuilt with the encrypted head identified. A known decryptor, where one exists for the family, is run on copies. What was recovered is listed, by folder and by date, before any figure exists.
The honest limit. A file fully encrypted by a modern family, with no snapshot, no deleted original and no decryptor, cannot be recovered without the key. The first look tells you how much falls into that category and how much does not, so the decision about the ransom is made on facts. A single drive is £300 + VAT; a NAS or server set is quoted on its members, with no bill on most jobs if no data comes back.
Questions answered before you commit.
Can you decrypt ransomware-encrypted files?
Not without the key, and no lab can; modern ransomware uses encryption that cannot be broken. What we recover is what the ransomware did not reach or did not finish: snapshots, the originals it deleted, partly encrypted files and unencrypted copies. That is often a great deal, and the first look tells you how much.
The ransom note says our snapshots and backups were deleted. Are they?
Often not, or not completely. Ransomware frequently fails to delete NAS snapshots, lacks the rights to, or is interrupted. We image the drives and check; where snapshots survive, recovery is clean to their date.
Our IT provider wants to reinitialise the NAS and restore from backup. Should we?
Not on the same drives until they have been imaged. Reinitialising writes over the deleted originals and snapshots that make recovery possible. Image first, or swap in new drives for the rebuild and keep the originals untouched.
Do you deal with Deadbolt, Qlocker and eCh0raix on QNAP and Synology?
Yes; the NAS families are the commonest we see, and the NAS ransomware page and the Deadbolt and Qlocker page cover what comes back from each.
What does it cost?
A single drive is £300 + VAT; a NAS or server set is quoted on the number of members, with the first look free and no bill on most jobs if no data comes back. Where you need a preserved forensic copy for insurers or the police, our forensic service can provide it.
Power it down, and find out what survives before you decide anything.
Disconnect the NAS or server, leave it off, and tell us what the note says and what the box is. The first look is free, and it tells you honestly what can come back without the key.