A ransomware warning can make you feel pressured to act immediately. That urgency is exactly why the first response matters: isolate the affected Windows computer before the malware reaches another device, shared folder, or backup.
This guide explains how to contain ransomware, preserve useful evidence, remove the malicious software, and evaluate recovery options. It applies to Windows 11 and supported Windows environments, but businesses and shared networks should involve their IT or incident-response team immediately.
To remove ransomware from Windows, disconnect the infected PC from Wi-Fi, Ethernet, Bluetooth, shared drives, and external storage. Do not pay or delete evidence in panic. Report the incident, identify the ransomware, run Microsoft Defender Offline or another trusted recovery scan, and restore files only from a verified clean backup or legitimate decryptor. A malware scan may remove the infection, but it usually cannot decrypt files.
Table of Contents
ToggleDo These Things Immediately
- Disconnect the network. Unplug Ethernet and turn off Wi-Fi and Bluetooth. Disconnect the PC from VPNs and network shares.
- Disconnect external storage. Remove backup drives, USB drives, and memory cards so ransomware cannot encrypt them.
- Isolate other affected devices. If another computer shows the same ransom note, filename extension, or unusual file activity, disconnect it too.
- Contact IT immediately. On a work, school, or managed computer, stop and follow the organization’s incident-response process.
- Photograph the warning. Record the ransom note, extension added to files, attacker contact details, wallet address, and approximate time the incident began.
If you cannot disconnect an actively encrypting computer from the network, CISA advises powering it down to prevent further spread. Otherwise, leave it isolated and seek qualified help before wiping it, because memory and disk evidence may help an investigation.
Do not reconnect a backup drive merely to check whether it works. Keep every backup disconnected until the infected computer has been cleaned or rebuilt and the backup has been checked from a trusted system.

Preserve Evidence and Report the Attack
Before resetting or reinstalling Windows, keep a copy of the ransom note and record what happened. Note suspicious emails or downloads, newly installed software, affected usernames, the first damaged file, and any accounts used on the computer.
Home users in the United States can report ransomware to the FBI Internet Crime Complaint Center and CISA. People elsewhere should use their national cybercrime-reporting service or local police guidance. Businesses may also have legal, contractual, insurance, or data-breach notification duties.
Should You Pay the Ransom?
The FBI does not encourage paying a ransom. Payment does not guarantee a working decryptor, does not prove stolen data was deleted, and may fund more crime. It can also identify the victim as willing to pay.
If an organization is considering payment, the decision should involve leadership, legal counsel, law enforcement, the cyber-insurance provider, and a qualified incident-response specialist. Home users should not negotiate through random recovery services or send cryptocurrency based only on the ransom note.
Identify the Ransomware Safely
Identification can reveal whether a reputable free decryptor exists. From a separate clean device, use the No More Ransom Crypto Sheriff. It can analyze the ransom note and a small encrypted sample. Upload only files you are comfortable sharing; do not submit confidential, medical, financial, or client information.
You can also search the exact ransom-note filename, the extension added to encrypted files, or a short non-sensitive sentence from the note. Treat search results cautiously and use decryptors only from No More Ransom, a recognized security vendor, or law enforcement.
Do not download a “universal ransomware decryptor.” No single tool decrypts every ransomware family. An unknown recovery program can be malware, destroy evidence, or damage files further.
How to Remove Ransomware from Windows
Removal stops the malicious program from running again; it does not automatically restore encrypted files. Keep the computer isolated throughout the cleaning process.
Option 1: Run Microsoft Defender Offline
- Save your evidence and close open work.
- Open Windows Security.
- Select Virus & threat protection.
- Under the scan options, choose Microsoft Defender Offline scan.
- Select Scan now. Windows will restart and scan outside the normal Windows environment.
- After Windows starts again, open Windows Security > Virus & threat protection > Protection history and review the result.
Microsoft Defender Offline is useful because persistent malware has less opportunity to hide while Windows is not fully running. If the option is unavailable or Windows cannot start safely, use a trusted recovery environment or professional assistance.

Option 2: Rebuild Windows When Trust Is Lost
For a confirmed ransomware infection—especially one involving administrator access, credential theft, a business network, or unknown persistence—the safest recovery may be to erase and reinstall Windows from trusted installation media. A reset that keeps personal files offers less assurance than a clean rebuild.
Before erasing the drive, preserve evidence and copies of encrypted files if recovery might become possible later. Use a clean device to change passwords for email, banking, cloud storage, password managers, and work accounts. Enable multifactor authentication, revoke active sessions when available, and assume passwords entered on the infected PC may be exposed.
Do not sign in to sensitive accounts from the infected computer, even after one scan reports no threats. Use a different, trusted device until the PC has been rebuilt or a qualified responder confirms it is safe.

How to Recover Files After Ransomware
Restore a Verified Clean Backup
A backup is the most dependable recovery path when it predates the infection and was not connected while ransomware was active. Restore it only after Windows has been rebuilt or confirmed clean. Scan the backup before opening files and restore a small test set first.
Check cloud services for version history or ransomware-recovery features. For example, OneDrive may let eligible users restore an earlier state, but retention and recovery options depend on the account and timing. Do not overwrite the only copy of encrypted data while testing recovery.
Use a Legitimate Decryptor When Available
If Crypto Sheriff identifies the ransomware and links to a recognized decryptor, read the instructions carefully and work on copies of encrypted files first. Keep the originals unchanged. Some decryptors require a matching encrypted and unencrypted file or work only with specific ransomware variants.
If no decryptor exists, archive the encrypted files and ransom note on offline storage. Security researchers sometimes release tools later, but there is no guarantee. File-recovery utilities generally cannot reverse strong encryption, although a specialist may recover deleted originals in limited cases.
Use this guide to improve your backup routine after the incident is resolved.
What Businesses and Shared Networks Should Do
Do not treat a business ransomware incident as a single-PC repair. Isolate affected network segments, protect identity systems and backups, preserve logs, and activate the organization’s incident-response plan. Determine whether attackers accessed or removed data before encryption.
Contact the incident-response provider, cyber insurer, legal counsel, and appropriate authorities. Resetting one endpoint too early can destroy evidence or leave the original access path open. Credentials, remote-management tools, servers, cloud services, and backup consoles may all require investigation.
Add a second sign-in factor to important accounts so a stolen password is less useful.
How to Prevent Another Ransomware Infection
- Keep Windows, browsers, Microsoft 365, security software, and third-party apps updated.
- Use supported Windows versions and remove software that no longer receives security fixes.
- Maintain at least one offline or otherwise isolated backup and test restoration regularly.
- Use multifactor authentication for email, cloud storage, remote access, and administrator accounts.
- Avoid daily work from an administrator account.
- Download software only from Microsoft, the device maker, or the official vendor.
- Disable or restrict unnecessary remote-access services and protect required access with MFA.
- Be cautious with unexpected attachments, shared documents, QR codes, and urgent payment requests.
- Keep Microsoft Defender or another reputable security product active and tamper-protected.
Review the Windows security settings that reduce the risk of reinfection.
Frequently Asked Questions
Can Windows Defender remove ransomware?
Microsoft Defender can detect and remove many ransomware infections, and Defender Offline can scan outside the normal Windows environment. Removal does not usually decrypt files that ransomware already encrypted.
Does resetting Windows remove ransomware?
A clean erase and reinstall from trusted media offers stronger assurance than a reset that keeps personal files. Preserve evidence and encrypted files first, and do not restore data until the system is clean.
Can encrypted ransomware files be recovered?
They may be recoverable from a clean backup, cloud version history, or a legitimate decryptor for the exact ransomware family. Recovery is not guaranteed, so preserve the encrypted originals.
Can ransomware spread through Wi-Fi?
Ransomware does not infect devices merely because they use the same Wi-Fi, but an attacker or malware can use reachable network shares, weak credentials, or vulnerable services to move between connected systems.
Should I pay a ransomware demand?
The FBI does not encourage payment because it does not guarantee recovery or deletion of stolen data and supports criminal activity. Organizations should involve law enforcement, legal counsel, insurers, and incident-response specialists.
Final Recovery Checklist
- The infected device and every affected system are isolated.
- The ransom note, timeline, indicators, and important logs are preserved.
- The incident has been reported to the appropriate organization or authority.
- Ransomware identification was attempted using a reputable service.
- The malware was removed or Windows was rebuilt from trusted media.
- Passwords were changed from a clean device and MFA was enabled.
- Backups were checked before restoration and kept isolated from the infection.
- Windows, apps, remote access, and the original entry point were secured.
Ransomware recovery is not just deleting a malicious file. A safe response contains the incident first, preserves evidence, restores trust in the computer, and only then brings back verified data.




One Response