Suddenly encrypted files call for calm and immediate isolation
I explain how to contain the incident without destroying evidence or exposing clean backups.
Computer Technician in Dordogne – Fast On-Site Support
Tera24 supports homeowners, small businesses, associations, and tourist accommodations with all their IT needs across Dordogne. From Windows and Mac computer repairs to virus removal, printer installation, system optimization, data backup, Wi-Fi network troubleshooting, and on-site IT support, we provide reliable and responsive assistance tailored to your needs.
Preserve evidence and copies before rebuilding Windows
Each step should protect recovery options without promising decryption that cannot be guaranteed.
Disconnect networks and storage without destroying evidence
Ransomware can block access to a device or encrypt its files before demanding payment. If documents suddenly acquire unfamiliar extensions, become unreadable or appear beside a ransom message, I treat the situation as an active incident. I do not begin by downloading a miracle utility or reinstalling Windows. The immediate objective is to stop the computer communicating with other devices and storage locations.
Unplug the Ethernet cable and disable Wi-Fi on the affected PC. Disconnect external drives and USB devices that are not needed for the initial record, without deleting, formatting or changing them. This isolation limits spread while leaving the computer in a more useful state for analysis. If several machines show the same symptoms, isolate each one and do not transfer files among them.
Immediate shutdown is not always the best first action. CISA notes that powering a system off can remove volatile evidence useful to an investigation. Power down only when network isolation is impossible. Do not, however, leave the device communicating merely to preserve that information.
Record when you noticed the problem and when you isolated the device. Do not briefly reconnect Wi-Fi to browse for help or send a screenshot from the affected PC. Use another device believed to be clean for communications. That separation is inconvenient, but it avoids turning an ordinary action into another uncontrolled network exchange.
Assess scope without opening more files
After isolation, the aim is not to open every folder and count damaged documents. Begin with what is already visible: file names, unfamiliar extensions, the displayed message, attached storage and any other computers showing similar behaviour. Keep the system isolated during this limited record.
Make a short list of the locations apparently involved without opening more files: user folders, network shares, storage that was connected or synchronised space. The actual scope should be assessed from a trusted environment, not from the computer that remains suspect.
- Do not double-click a series of files to discover which ones open.
- Do not rename extensions or reorganise affected folders.
- Do not run an executable, decryptor or cleaner downloaded at random.
- Do not connect a clean backup for an immediate comparison.
If you need to photograph the display, use a phone without connecting it to the computer. Keep an overview and a few useful details, but do not publish personal file names. I prefer a limited, clean record to an improvised exploration that makes the incident harder to understand later.
Protect unaffected backups
Backup storage that remains connected can also be reached by malicious software. Do not attach the drive containing your latest copy merely to see whether it works. Keep it offline, label it clearly and record approximately when it was last used. External backup storage should remain disconnected whenever it is not actively being used.
Copies on a NAS, network share or synchronised service may also have been exposed when they remained accessible to the system. Do not assume they are clean before checking: CISA says offline backups should be protected and their integrity verified before any restoration from a clean environment.
A resilient plan uses several copies on different media or in different locations. My guide to the 3-2-1 backup rule for photographs and documents explains that separation. If you are choosing storage, the comparison between a NAS and an external hard drive clarifies their different roles.
Before restoring anything, verify the integrity of the offline backup from a clean environment. The existence of a copy does not prove that it is healthy, complete or restorable. Keep the original backup isolated while the checking method is planned.
Record the message, extension and timeline
The ransom message, any new extension and the timeline can help characterise the incident. Photograph the complete message, then capture useful visible details without following its links. Record the exact extension on a few files already identified, the time of the first symptom and known unusual events immediately beforehand, such as an opened attachment, download, security warning or inaccessible account.
Preserve malicious messages, available logs, affected physical media and a few samples of encrypted files. This does not mean copying everything or sending your information to an unknown party. Keep each item from being altered and record its origin. Personal documents should remain confidential and go only to a legitimate recipient as part of analysis or official reporting.
Those items provide the four complementary forms of evidence named in the public guidance: the visible malicious message, available logs, affected physical storage and samples of files that are already encrypted. Preserve them before reinstalling, because a reset may remove the evidence that the process is intended to retain.
French government guidance recommends making a police report before reinstalling because reinstalling may erase evidence. Prepare a readable chronology first: discovery, isolation, affected devices, connected storage and actions already attempted. Reporting does not repair the PC, but it can preserve information useful to an investigation or to understanding how the incident developed.
Do not pay the ransom. French government guidance discourages payment and states that it does not guarantee data recovery.
Arrange analysis from a trusted environment
Analysis should not depend on the utilities installed in the suspect Windows environment. Use another computer known to be clean to find official contact details, prepare reports and arrange assistance. Keep the affected PC isolated while deciding which evidence to preserve, which storage to examine and in what order. Planning prevents urgency from becoming haste.
The assessment should answer several questions before service resumes: which devices and locations were exposed, which backups remained separate, which accounts need securing from a clean device, and which data matters first. CISA recommends prioritising systems and data before restoration and performing recovery on a clean network.
I can help establish an initial diagnosis and organise the next steps, but some cases require specialist expertise. If essential data exists only on affected storage, recovery may be considered without any guarantee. My guide to data recovery in Dordogne explains what may be attempted locally and when laboratory work is more appropriate.
Analysis from this trusted environment should come before restoration. It is used to prioritise systems and data, then organise recovery on a clean network. Until that step is complete, keep the affected computer isolated and the offline backups protected.
Explain restoration, reporting and limits without promising decryption
Decryptors exist for some ransomware cases only. Their possible availability depends on the exact incident and never supports a promise of complete recovery. Do not run a utility simply because its name appears relevant. Verify its provenance and have its suitability confirmed before allowing it to process a working copy.
When the integrity of the system cannot be established, reinstalling Windows may be necessary. That step follows evidence preservation and reporting; it is not the first reflex. Restoration is then organised from a backup believed to be clean, inside a clean environment, beginning with the highest-priority data and functions.
Before restoration, have the integrity of the offline backup checked from a clean environment. That verification does not make recovery certain: it may remain partial depending on the case, and complete decryption cannot be promised.
After service is restored, rebuild the plan so that one mistake cannot reach every copy. Keep several copies on different media or in different locations, and disconnect external backup storage when it is not in use. Finally, record what was restored and what remains uncertain. A responsible conclusion does not declare the incident erased; it states what was checked, what was recovered and which limits remain.
That separation remains useful after the incident: several copies on different media or in different locations reduce the risk of simultaneous loss. External backup storage should therefore return offline as soon as its backup use is complete.


