Home / Devices / Ransomware

Ransomware Data Recovery Norwich

You arrive to find every document wearing an extension you have never seen and a demand note repeated in folder after folder, insisting the attackers' own decryptor is the only road home. The disks frequently disagree. PCs, servers and NAS units belonging to Norfolk firms and households are gone through here for every lawful way home, and paying the people responsible has never once been on that list.

Every ransomware job is diagnosed free. The quote follows in writing, fixed, before a screwdriver is picked up.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// thirty faults this bench knows well

The thirty ways they give up

The first job on any ransomware is matching the symptom to the fault — and after twenty-odd years, these thirty account for very nearly everything that comes through the door.

One machine, everything locked

Every user folder encrypted in one overnight run. It is the classic attack on a single machine, and the shape most cases arrive in.

The shares on the NAS encrypted

Boxes reachable from the internet are the preferred target. The snapshot trees beneath the shares escape the purge rather more often than the attackers intend.

A datastore gone in an evening

Hypervisor-focused strains work through the datastore one virtual disk at a time and bring down the whole virtual estate together.

Large files only partly encrypted

Families tuned for speed encrypt the opening stretch of each large file and move straight on. Databases and archives are left with usable remainders, which matters more than it sounds.

Restore points swept first

The shadow copies are deleted before the encryption starts, as a matter of routine. Even then, deleted shadow copies can often be carved back out of the free space.

The backup drive was plugged in

Plugged in meant reachable; reachable meant encrypted. Older versions on it, and remnants, still count for a great deal.

Stolen first, locked second

Double extortion pairs the theft with the encryption and threatens publication. Whatever left the network is scoped for the insurers and, where it applies, for the ICO.

A ransom demand where the login should be

Boot-locked machines still give up their drives, which are imaged and examined underneath the lock, where the files have been all along.

Databases torn mid-transaction

SQL and Exchange files caught while writing end up half encrypted and half not. Salvage runs page by page against the captured image.

Still infected and still busy

A NAS that re-encrypts every restore attempt is still owned by somebody else. Isolate first, then recover strictly from images.

An extension nobody recognises

Unknown strains are fingerprinted against the databases in search of a family and any published weakness that can lawfully be used.

All note and no encryption

Scareware plants ransom notes over files it never touched, and some genuine runs crash early. A bench check separates fright from actual loss inside the free diagnostic.

The well-known crews

The big names run deletion passes that are thorough and imperfect at the same time. Recovery lives in the imperfect parts, and we have a decent idea of where those tend to be.

A strain off a cracked download

The home-PC staple, arriving with pirated software. Older offline-key variants have a free public decryptor, which is applied lawfully whenever it fits the sample.

Original deleted, copy encrypted

Some families encrypt a copy and delete the original, which abandons that original in free space where it can be carved. It is a design oversight we are very fond of.

In through remote desktop

Exposed remote desktop is still an open door, and encryption tends to follow some hours after entry. The logs date that entry to the minute.

Sync pushing the damage upstream

Cloud sync loyally replaced good files with encrypted ones as fast as they appeared. Version history and remnants are checked at both ends of that pipe.

Virtual machine hosts held hostage

Encrypted virtual disk files bring down every guest at once. Partial-encryption habits frequently leave those guests rebuildable.

Exfiltration without any encryption

Nothing locked, everything copied, and a leak threatened. The job turns from recovery into forensic scoping and the questions change accordingly.

Caught between rotations

The one disk that happened to be connected on the night took the hit. Off-rotation sets and carved remnants bridge the gap it leaves.

A foothold left for later

Scheduled tasks and services can refire the malware weeks afterwards, generally in the middle of a restore. Images are swept for footholds before any rebuild is allowed to go live.

Middlemen who simply pay

Some firms advertising recovery quietly pay the ransom and present the result as expertise. We recover from evidence, we say what is possible, and we carry no messages to criminals on anybody's behalf.

Backup servers hunted first

Modern crews take out the safety net before they pull the trigger, and they are good at it. Repository files often keep recoverable structure regardless.

A wiper wearing ransomware's clothes

Some strains destroy with no decryption route in existence, whatever the note promises. It is identified quickly and said plainly, and recovery then works from remnants and copies.

Configuration encrypted, data skipped

Some runs encrypt small configuration files and never touch the large flat data behind them. Rebuilding from the material they skipped restores entire machines.

Backups that could not be altered

Object-locked and immutable copies survive attacks that take everything else, because the attacker's own credentials could not delete them. Where one exists it changes the whole job, and part of our assessment is establishing whether one does before anybody starts carving.

A purchased decryptor that does not work

Some organisations pay before ringing anybody, and the tool that arrives is slow, crashes on large files, or corrupts what it touches. Files damaged by a faulty decryptor are their own recovery problem, and it is worth capturing everything before running it a second time.

Mailboxes in a cloud tenant

Encryption on the desktop does not reach a hosted mailbox, but deletion by an attacker who took the credentials certainly does. Retention and recovery windows in the tenant are finite and they are ticking, so that thread gets pulled early.

Hosts encrypted while the guests kept running

Virtualisation hosts are sometimes encrypted underneath machines that are still running happily in memory. Powering those guests off completes the attacker's work for them. There is an order in which to do this, and getting it right can save the estate.

Reimaged by IT before anyone asked

The instinct after an attack is to rebuild and get trading again, and the rebuild lands on top of everything that could have been recovered. If there is any chance the data matters, take the disks out and set them aside first. It costs an afternoon and it has saved entire businesses.

What the attack actually did

The malware walked the storage encrypting one file after another with entirely conventional cryptography: AES over the contents, and those keys then sealed under an asymmetric one, the private half of which stays with the people who sent it. That unfamiliar extension is the strain's signature, and the note prints once the run is finished. Capable families also remove shadow copies, chase down whatever backups they can reach, and sweep every share the compromised account had rights over, which is why the demand reads with such confidence. It says nothing at all about what the run failed to reach, and a careful look almost always finds something.

The ways back that are actually lawful

No laboratory anywhere brute-forces properly implemented encryption, and a firm hinting that it might is selling a story rather than a service. Much of what gets advertised as decryption turns out on inspection to be negotiation with the attackers, resold at a markup. The honest version goes mining for the mistakes the attack made. Snapshots and shadow copies the purge missed. Backups that were offline, or simply out of reach. Files that were deleted rather than encrypted, because the strain worked on duplicates. Temporary artefacts and fragments carved from slack and unallocated space. NAS and RAID structures broken by the attack and rebuilt until readable data appears underneath. For the handful of families whose implementation flaws are public, a free decryptor applied properly. Which of those doors exists in your case is what the free assessment establishes, and it says so plainly when the answer is none of them.

Where we stand on paying

Nothing is ever paid from this bench, no message is carried to an attacker for a client, and nobody is nudged toward settling. It finances the next campaign, guarantees nothing whatever, and criminal decryptors are notorious for wrecking the files they are meant to release. What you get instead is every technical avenue followed to its end, and a written account of what returned and what did not. Should insurers and advisers later take a company down the negotiating road, that decision is theirs to own; our part was to see that the technical answer got there first.

// what sits on the bench

Engineering kit, not download-and-hope software

Ransomware cases run as forensic incidents from the first minute: isolated, imaged, documented, and only then recovered:

Air-gapped imaging bench

Incident media stays off the network entirely and is worked on an isolated rig where nothing can spread, call home, or resume encrypting where it left off.

Hardware write-blockers

Attacked drives are captured behind physical write-blocking before anyone examines them. Recovery then touches copies while the originals sit sealed.

Shadow copy carving

Free space swept for shadow copies and snapshot remains that the purge overlooked, then rebuilt into restore points that genuinely restore.

Strain identification

The note plus a handful of samples identify the family, and that family gets checked against the public sources worth trusting for any lawful decryptor that exists.

Remnant and free-space carving

Unencrypted originals, temporary copies and half-finished files pulled out of free space: the debris that every rushed encryption run leaves behind.

Forensic logging and reporting

Strain, spread and outcome documented as the work proceeds, which is the paperwork that insurers, regulators and your own post-mortem all end up wanting.

// makes & models we see

Families and patterns handled

LockBitAkiraPhobosDharmaMakopSTOP / DjvuBlackCat / ALPHVMedusaConti lineageESXiArgs

The honest sources of recovery

Two undertakings, given in writing before any work begins. A strain with no published weakness will not be brute-forced — not by this lab and not by any other. No ransom is paid from here either, nor any message carried to the people who are holding them. Ransomware sits in the forensic class — free assessment first, one fixed quote, payment before the work rather than no fix, no fee.

// before you post it

Before you post it — get the drive loose if you can

Before anybody reaches for the parcel tape: pull the network leads out and leave the affected machines precisely as they stand. No antivirus sweeps, no reinstalling and no formatting, because every one of those passes grinds away the remnants recovery feeds on. Hold on to the ransom note and two or three encrypted samples so the strain can be named, then ring 0800 689 0668 and we will agree between us what should travel. Media travels tracked and insured, by your own courier, or in person to reception at our Cambridge location. Capture happens on the air-gapped bench and recovery only ever touches copies.

// getting your device to us

Getting it here — no great performance

Most of what reaches this bench arrived by tracked, insured post. It is the steadiest way to move a poorly drive, and a parcel posted in Norfolk is usually on the bench the next working day.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// ransomware recovery questions

Common questions

Only where the strain permits it, meaning a published free decryptor or a documented implementation flaw, and that list is short — mostly older STOP/Djvu variants and a few careless imitators. Encryption done properly opens for nobody at all. So the effort goes where it can achieve something: snapshots, backups, originals that were deleted instead of encrypted, fragments carved out of unallocated space, and volumes rebuilt from broken structures. The free assessment tells you which of those you have.
No, in any form. Nothing is paid, nothing is brokered, and settling is never recommended — the money finances the next attack, the promise cannot be enforced, and the tools handed back frequently damage what they unlock. Should that decision ever get made, it rests with you, with your insurer and with your advisers; our involvement ends once every technical avenue has been followed to its end.
Assessment of the disks costs nothing, with a verdict inside 2 working days of them arriving, and a single fixed quote follows in writing. This work sits in the forensic class, so that quote is settled before recovery starts rather than on a no fix, no fee basis, and it sets out a realistic scope before you part with anything at all.
Take the network off everything affected, and then leave it alone. Nothing reinstalled, nothing formatted, no clean-up utilities run over it, because each of those grinds away the leftovers a recovery leans on. Hold on to the note and a couple of the encrypted files, which is what identifies the strain, then ring 0800 689 0668 and get the numbered disks posted to our Cambridge location. All of the work happens on forensic copies and your originals stay sealed.
Fewer firms than the advertising implies, given how much of what is sold as decryption is negotiation wearing a different coat. Norwich Data Recovery does the work in-house. Locked PCs, NAS boxes, servers and whole virtual estates reach us by tracked, insured post at our Cambridge location — Cambridge Data Recovery, Compass House, Vision Park, Chivers Way, Cambridge CB24 9AD, Monday to Friday 9am to 5:30pm — from every corner of the country. Assessment is free and identifies the strain along with the realistic options; as forensic-class work the quote is settled up front, and nothing is ever paid to an attacker or brokered for a client.
// related services

More work we take on

Whenever you’re ready, the bench is.

Diagnosis free, one figure written down, most work under no fix no fee. Start online, or ring us.