
The safest decryption attempt starts before the decryptor launches. Preparation protects the only copy of your encrypted data and makes later troubleshooting much easier.
1. Contain the active infection
Do not begin recovery while ransomware is still running. Remove or quarantine the malicious process and address persistence before reconnecting backup drives.
2. Create a preservation copy
Copy encrypted data to separate storage and keep one copy untouched. If a recovery tool, failing disk or manual rename damages a working set, the preserved copy remains available.
Keep filenames and ransom notes
Extensions, ransom notes and directory context can help identify the ransomware family. Avoid bulk-renaming encrypted files before you know the correct procedure.
3. Verify the decryptor source
Match the publisher, product name and download destination. A ZIP whose repository name does not match the claimed decryptor should not be presented as that decryptor.
4. Test a small copy first
When the official instructions allow it, test the workflow on copied files before processing an entire drive.
Use the download verification checklist before the final step.