Last updated: September 2026 — Reviewed by the RecuperaTusDatos Technical Team
Every document now ends in an extension you do not recognise, nothing opens, and there is a note on your desktop demanding payment?
By the time that note appears, the encryption has already finished. What decides whether your files come back is what happens next: reinstalling Windows, formatting the disk, running a cleanup tool or paying before anyone has looked at the machine will quietly close the routes that are still open.
At RecuperaTusDatos we identify the family and version that hit you, check whether a legitimate public decryptor exists for it, and go after every copy of your data the attacker did not reach: shadow copies, unencrypted remnants, deleted originals, damaged backups and NAS snapshots.
Free diagnosis in 4 hours. No recovery, no fee. We will never tell you to pay.
Professional ransomware data recovery for individuals and small businesses. We identify the ransomware family, check for a legitimate public decryptor, and recover what the attack did not reach: shadow copies, previous versions, deleted originals, damaged backup sets and NAS snapshots. Laboratory in Barcelona, ISO Class 5 clean room, ISO 9001 and ISO 27001 certified by AENOR. Over 12 years of experience. No recovery, no fee.
Key Facts — Ransomware Recovery
- Diagnosis: Free and without obligation in 4 hours, whether or not you accept the quote
- Quote: Fixed price, in writing, before any work begins — no surprises
- Prices: From 250 EUR + VAT for standard recoveries
- Guarantee: No recovery, no fee
- Devices: Windows and Mac computers, external drives, USB media, NAS and small servers
- Laboratory: Barcelona, ISO Class 5 clean room, ISO 9001 and ISO 27001 (AENOR) · INCIBE registered
- Track record: More than 18,000 cases, 93% success rate, 4.8/5 from 487 reviews
The First Hours: What To Do Right Now
Do this before you touch anything else
- Isolate the machine. Pull out the network cable and switch off Wi-Fi. Ransomware spreads across mapped drives, shared folders and any NAS it can see, so the first job is to stop it reaching what is still clean.
- Do not reboot and do not reinstall. A restart ends any chance of examining what is still held in memory, and a reinstall is one of the most destructive things you can do to your own data.
- Unplug external drives and USB sticks. If Windows offers to format or “repair” them, say no. A backup drive that was connected during the attack may still hold usable fragments.
- Preserve the evidence. Keep the ransom note where it is, and keep at least one encrypted file of a type you know well (a photo, a PDF, a spreadsheet). Those two things are what identify the family and version.
- Photograph the screen. Note the exact extension added to your files (.locked, .encrypted, .djvu and so on), and the time you first noticed the problem.
- Do not download “decryptors” from forums or search ads. Many are repackaged malware; others destroy file headers the first time they run, closing off the only route left.
- Do not pay, and do not negotiate, before you know what you actually have. The diagnosis is free and commits you to nothing.
If the encryption still looks like it is running — files changing in front of you, disk activity that will not stop — disconnect the network first and call us on 900 899 002 before shutting anything down. If it clearly finished hours or days ago, leave the machine switched off and contact us. Our emergency checklist covers the same steps for other kinds of data loss.
Why Reinstalling Windows Destroys Your Best Chance
This is the part almost nobody is told, and it is mechanics, not opinion. Most ransomware does not scramble your files in place. It reads the original, writes a brand-new encrypted file next to it, and deletes the original. Deleting erases nothing: it marks those sectors as free. Until something else is written over them, the untouched original content is physically still on the disk.
Reinstalling the operating system overwrites exactly the wrong areas
A clean install of Windows or macOS recreates the file system and pours gigabytes of new files into precisely the free space where your deleted originals were waiting. It also wipes System Volume Information, where Windows keeps its shadow copies. In one afternoon a reinstall can turn a recoverable case into an unrecoverable one.
Every gigabyte you write costs you data
Windows updates, browser caches, indexing, an antivirus scan writing quarantine files, even copying the encrypted files “somewhere safe” on the same disk — each one consumes free sectors. That is the whole reason we ask you to stop using the machine: not superstition, just arithmetic.
On an SSD the clock runs much faster
When a file is deleted on an SSD the operating system sends the drive a TRIM command, and the controller's garbage collection then physically erases those NAND cells in the background — while the drive is powered on, even with nobody using it. On an SSD the window for recovering deleted originals is short and closes on its own. Our SSD and NVMe recovery page explains the mechanism.
Antivirus cleanup is good security and bad evidence
Removing the malicious binary is right for safety, but automated cleanup often deletes the ransom note and the dropper, and sometimes quarantines encrypted files as “suspicious”. Those are the artefacts we use to pin down the exact variant. Clean the machine after the diagnosis, not before it.
Never rebuild, re-initialise or factory-reset a NAS
On a NAS or RAID volume, a factory reset or a rebuild rewrites metadata across every member disk and discards snapshots that were, until that moment, perfectly restorable. Take the unit off the network, leave the disks in their bays and label them. See RAID and NAS recovery.
What Can Realistically Be Recovered — And What Cannot
We will be straight with you: ransomware that implements AES and RSA correctly cannot be broken, and anyone who tells you otherwise is selling something. Real recovery comes from four other routes, and the free diagnosis exists to tell you which of them apply to your case.
1. Families with a public decryptor
Some families were built with flaws: reused offline keys, predictable key generation, or master keys published after a law-enforcement takedown or an internal leak. Older STOP/Djvu, Dharma and Crysis builds and certain REvil versions fall into this group, as does WannaCry on a machine that has not been rebooted since the attack. Identifying your variant is the first thing we do, and we check it against every decryptor released by the security industry and by the Europol-backed No More Ransom project. If a legitimate free tool exists for your case, we tell you so — that answer is part of the free diagnosis and costs you nothing.
2. Shadow copies and previous versions
Windows keeps block-level snapshots in the Volume Shadow Copy Service. Most ransomware tries to delete them first, but again, deleting only releases those blocks; it does not erase them. Working on a forensic image, we can locate the shadow copy catalogue and difference-area blocks in unallocated space and rebuild earlier versions of your documents from them. This route survives the attack far more often than people expect — provided the machine has not been used since.
3. Unencrypted remnants and deleted originals
Because the attacker's software copies, encrypts and deletes, the originals can frequently be carved back out of free space by file signature. Many families also encrypt only the first portion of each large file, or a few slices of it, so that the attack finishes quickly — which leaves the rest of a video, a database, a mailbox or a disk image untouched and often rebuildable. Office temporary files, autosave copies, mail stores, thumbnail caches and previously synced cloud folders add to what can be recovered.
4. Damaged backups and NAS snapshots
Your backup is often not lost, merely broken. Jobs interrupted halfway, archives only partially encrypted before the drive was unplugged, containers the backup software now refuses to open, Btrfs and ZFS snapshots deleted on a Synology or QNAP unit, volumes re-initialised in a panic — we work on all of these regularly. A backup set that the vendor's own restore wizard calls unusable is often still readable in the laboratory.
And the honest limit: if the family is a current, well-implemented one, the shadow copies were genuinely overwritten, the originals wiped and there is no backup of any kind, the encrypted files stay encrypted. We tell you that plainly at the diagnosis stage, before you have spent a euro — and we never charge for a recovery that did not happen.
Should You Pay the Ransom?
We are a data recovery laboratory, not your lawyer and not a negotiation service. We do not handle payments, we do not act as intermediaries, and we will never tell you to pay. What we can do is give you the technical facts before you make an irreversible decision.
A ransom payment buys nothing but a promise from the person who attacked you. Keys are sometimes not sent at all, and sometimes arrive broken; attacker-supplied decryptors are frequently poor software that damages large files while “decrypting” them. Paying also marks you as a victim who pays.
There is a legal side too, and it belongs with a professional adviser: some ransomware groups are subject to international sanctions, which can make a payment to them a serious problem for you or your company. Ask your lawyer and your insurer, not us. If you hold cyber-insurance, check the policy first — many policies require you to report the incident before anything else happens. In Spain you can report it to INCIBE and to the police, and doing so does not prevent recovery work.
How We Handle a Ransomware Case
Step 1: Collection and forensic imaging
We arrange courier collection of the disk, computer or NAS. In the laboratory we always start by taking a read-only, sector-by-sector image, and every attempt after that is made on copies. We never modify your original media, which also keeps the evidence intact for an insurance claim or a police report.
Step 2: Identification — free, in 4 hours
We pin down the family and version from the extension, the ransom note and the structure of encrypted samples, and establish whether a legitimate public decryptor exists. At the same time we survey what survived: shadow copies, remnants, deleted originals, snapshots, backup sets. You then receive a fixed written quote before anything else is done, and the diagnosis is free whether you accept it or not.
Step 3: Recovery along every viable route
Depending on the case: applying a verified decryptor, carving shadow copy blocks and deleted originals out of the image, reconstructing partially encrypted large files, or repairing broken backup containers and NAS snapshots. We combine routes, because the best result usually comes from several at once.
Step 4: File list, verification and delivery
You receive a list of what has actually been recovered, and you check it before paying anything. Data is delivered on new, clean media, never back onto a machine that may still be compromised. If nothing is recovered, you pay nothing for the recovery.
Did the attack reach more than one machine? If it spread to a domain, a hypervisor, a file server or a company NAS, the approach and the priorities are different — see ransomware recovery on servers and NAS and our enterprise data recovery service.
Frequently Asked Questions — Ransomware Recovery
Can you decrypt my files without the attacker's key?
Only when the family itself has a known weakness or a published key, which is the case for some older variants. Encryption that is correctly implemented cannot be broken, and we will not pretend otherwise. In every other case recovery comes from shadow copies, unencrypted remnants, deleted originals, partially encrypted large files, backups or NAS snapshots. The free diagnosis tells you which of those routes exist in your case before you commit to anything.
How do you know whether a free decryptor exists for my ransomware?
We identify the family and version from three things: the extension added to your files, the file name and wording of the ransom note, and the byte-level structure of an encrypted sample. That fingerprint is then matched against the decryptors published by security vendors and by the Europol-backed No More Ransom project. This is exactly why we ask you to keep the note and one encrypted sample file instead of deleting them.
Should I pay the ransom?
We never recommend paying and we cannot give you legal advice on it. A payment buys only a promise from the person who attacked you: keys are sometimes not sent, sometimes broken, and attacker-supplied tools often damage large files. There is also a legal side, because some groups are subject to international sanctions, so that question belongs to your lawyer and your insurer. What we can do is show you, free of charge and in 4 hours, what can be recovered without any payment.
I already reinstalled Windows. Is it too late?
It is worse, but not always hopeless. A reinstall wipes the shadow copies and overwrites part of the free space where deleted originals were sitting, yet a fresh installation does not fill an entire disk, so material often survives in the areas it did not touch. Stop using the computer now, do not install anything else, and let us image the disk. What matters from this point is that nothing further gets written.
The attack deleted my shadow copies. Is there still a chance?
Frequently, yes. Deleting a shadow copy releases its blocks rather than erasing them, so as long as the machine has barely been used since the attack, the shadow copy catalogue and its difference-area blocks can often be located in unallocated space on a forensic image and earlier versions of your documents rebuilt from them. Every hour the computer stays in use reduces that chance, which is why we ask you to leave it switched off.
My files are on an SSD. Does that change anything?
Yes, and it makes speed more important. When files are deleted on an SSD the drive receives a TRIM command and its controller then erases those cells in the background, simply because the drive is powered on. Recovering deleted originals from an SSD therefore has a much shorter window than on a mechanical hard drive. Shut the machine down once you have isolated it and contact us the same day.
The attack also encrypted my backup drive and my NAS. Can anything be saved?
Often, yes. Backup sets are regularly caught mid-job or only partially encrypted, and a container the backup software now refuses to open can still be repairable in the laboratory. On a Synology or QNAP unit, deleted Btrfs or ZFS snapshots are also a realistic route. Take the NAS off the network, leave the disks in their bays, label them by bay number and do not run a rebuild, a repair or a factory reset, because those rewrite the metadata we need.
How much does ransomware data recovery cost, and what if you recover nothing?
Diagnosis is free and takes 4 hours, whether or not you accept the quote, and you always receive a fixed written quote before any work begins. Prices start from 250 EUR + VAT for standard recoveries, and the final figure depends on the device, the variant and which recovery routes are available. If we do not recover your data you do not pay for the recovery.
Files Encrypted? Stop, Don't Reinstall, Talk To Us First.
Free diagnosis in 4 hours. Closed written quote before any work. No recovery, no fee. Free pickup* across Spain.
* Free pickup when the case is accepted and your data is recovered. If the case is rejected or turns out to be unrecoverable and you want the device sent back, the return shipping is charged.