Recovery Guide

How to Prepare Encrypted Files Before Running a Decryptor

The safest decryption attempt starts before the decryptor launches. Preparation protects the only copy of your encrypted data and makes later troubleshooting much easier.

How to Prepare Encrypted Files Before Running a Decryptor

The safest decryption attempt starts before the decryptor launches. Preparation protects the only copy of your encrypted data and makes later troubleshooting much easier.

1. Contain the active infection

Do not begin recovery while ransomware is still running. Remove or quarantine the malicious process and address persistence before reconnecting backup drives.

2. Create a preservation copy

Copy encrypted data to separate storage and keep one copy untouched. If a recovery tool, failing disk or manual rename damages a working set, the preserved copy remains available.

Keep filenames and ransom notes

Extensions, ransom notes and directory context can help identify the ransomware family. Avoid bulk-renaming encrypted files before you know the correct procedure.

3. Verify the decryptor source

Match the publisher, product name and download destination. A ZIP whose repository name does not match the claimed decryptor should not be presented as that decryptor.

4. Test a small copy first

When the official instructions allow it, test the workflow on copied files before processing an entire drive.

Use the download verification checklist before the final step.

Related guides