Home / Devices / Ransomware

Ransomware Data Recovery Liverpool

Monday morning, and nothing opens. Every filename ends in something nobody recognises, a text file sits in each folder explaining the price, and the whole production is built to convince you there is exactly one way out. Usually there is more than one. Merseyside firms and households send in locked PCs, servers and NAS boxes, and the search here is for lawful routes only. The people who did it get nothing from us.

Every ransomware job is diagnosed free. One fixed figure follows in writing, agreed before a screwdriver comes out of the drawer.

No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Every band is listed on the data recovery cost page.

// thirty faults this bench sees most

Thirty ways they call it a day

Matching the symptom to the fault underneath is the first job on any ransomware, and after twenty-odd years these thirty account for very nearly everything that arrives.

Every folder on one PC locked overnight

Fine at six in the evening, unusable by nine, with a note dropped in each folder on the way through. A single encrypted desktop or laptop is the commonest shape this arrives in, and the price follows the hardware: one PC drive is £300 + VAT.

The NAS shares gone

Boxes reachable from the internet get hunted first, and a NAS with port forwarding switched on is a standing invitation. The snapshot tree underneath the shares survives the sweep more often than the attackers intend it to.

A datastore encrypted in an evening

Hypervisor strains work along the datastore taking one virtual disk at a time, so the estate goes down together rather than in parts. Servers, NAS boxes and arrays are quoted from £500 + VAT, rising with the disk count.

Big files only partly encrypted

Families tuned for speed encipher the opening stretch of a large file and move straight on to the next one. Databases, mail stores and archives are left with usable remainders, and those remainders are worth far more than they sound.

Restore points deleted before the attack

Wiping shadow copies is standard practice now and it happens before the encryption starts. Deleted shadow copies can still be carved out of free space, which is exactly why nothing should be written to the disk in the meantime.

The backup drive happened to be connected

If Windows could see it, so could the malware. Even so, older versions on that disk and the remnants sitting around them count for a great deal once it has been imaged properly.

Copied first, encrypted second

Double extortion takes the data out before locking anything, then threatens publication. Scoping what genuinely left the network matters to the insurer and, where personal data is in it, to the ICO and the 72-hour clock.

A ransom screen where the login used to be

Boot-lockers replace the start-up sequence and look total. The disk underneath is usually untouched. It gets imaged and read outside the machine, where the note carries no authority at all.

Databases caught mid-write

SQL Server and Exchange files encrypted while in use end up part enciphered and part not, with the boundary sitting inside a transaction. Salvage then works page by page on the captured image.

A NAS that is still owned by somebody else

If every restore is re-encrypted within the hour, the intruder still has access to the box. Isolation comes first, imaging second, and recovery only ever runs on copies.

An extension nobody recognises

Unfamiliar strains are fingerprinted against the public databases to identify the family and to establish whether a documented weakness exists that can lawfully be used.

A ransom note and nothing actually encrypted

Scareware drops notes over files it never touched, and plenty of genuine runs crash before they achieve much. A bench check separates fright from real loss, and it happens inside the free diagnostic, which takes 2 working days from arrival.

The well-known crews

The large operations run deletion passes that are thorough and still imperfect. Recovery lives in the imperfections. After enough cases you develop a reasonable idea of where those tend to be.

A strain that arrived with pirated software

STOP and Djvu come bundled with cracked downloads and keygens, which makes them the home-PC staple. Where an older offline-key variant is involved, a free public decryptor exists and gets applied if the sample genuinely matches it. If it does not match, you are told so.

The original deleted, the copy encrypted

Some families write out an encrypted copy and then delete the original rather than overwriting it. That leaves the original lying in free space, which is exactly where it gets carved back from. A design oversight, and one we are extremely fond of.

In through remote desktop

An exposed RDP port remains the commonest way in, and the encryption usually follows a few hours after the first successful login. The logs put a minute on that first login, which is one of the first things an insurer asks for.

Sync carrying the damage to the cloud

OneDrive and Dropbox did their job perfectly, uploading each enciphered file over the good copy within seconds of it being written. Both ends are worth working: version history in the cloud, remnants on the disk. Neither of them waits forever.

Virtual machine files encrypted on the host

A single enciphered VMDK or VHDX takes a whole guest with it. Partial-encryption habits frequently leave enough of those guests to rebuild them from the images.

Data copied and nothing locked

No encryption, no notes in the folders, and an email asking for money to stay quiet. That is forensic scoping rather than recovery, and the questions change completely.

Caught between backup rotations

The one disk that was connected on the night is the one that got hit, and the off-site set is a fortnight stale. Off-rotation copies plus carved remnants close most of that gap between them.

Something left behind for later

Scheduled tasks and services can restart the encryption weeks afterwards, usually during a restore, which is the worst possible moment. Images are swept for footholds before anything is allowed back on the network.

Firms that quietly pay and call it recovery

Some outfits advertising decryption negotiate and pay, then present the attacker's own tool as their expertise. We recover from evidence, we tell you what is realistic, and we carry no messages to criminals for anybody.

The backup server attacked first

Modern crews go for the safety net before they trigger anything, and they are practised at it. Repository files usually retain enough structure to be worth recovering, even after the console itself has been wrecked.

A wiper dressed as ransomware

Some strains simply destroy, and no decryption route exists for them at all, whatever the note offers in return for payment. That gets identified early and said plainly, and the work then moves to remnants, copies and snapshots.

Configuration locked, bulk data untouched

Some runs encipher small configuration files and never reach the large flat data sitting behind them. Rebuilding around what they skipped has brought entire systems back into service.

Backups the attacker could not alter

Immutable and object-locked copies come through attacks that take everything around them, because the credentials the attacker stole are not permitted to delete them. Whether such a copy exists is settled during the assessment, before anybody starts carving free space.

A purchased decryptor that damages files

Some organisations pay before they ring anyone, and the tool that comes back is slow, falls over on large files, or damages what it writes. Files ruined by a faulty decryptor become a separate recovery problem, so image everything before it is run a second time.

Mailboxes in a hosted tenant

Encryption on the desktop does not reach Microsoft 365. An attacker holding the credentials can delete mail at will, and that is normally what happened. Recovery windows inside the tenant are finite and already running, so that thread gets pulled on day one.

Hosts encrypted while the guests kept running

A virtualisation host can be enciphered while the guests on top of it carry on running in memory, apparently untouched. Switch those guests off and you finish the job on the attacker's behalf. There is a correct order for this and it has saved whole estates. Ring before anything gets shut down.

Rebuilt by IT before anybody thought to ask

The instinct after an attack is to flatten everything and start trading again, and the rebuild lands directly on top of the material a recovery would have used. If the data has any value at all, pull the disks and put them on a shelf before the rebuild starts. An afternoon of delay has saved entire businesses.

What actually ran through your files

Nothing exotic happens during the run. The program opens each file in turn, encrypts the contents with AES, then wraps that per-file key using a public key whose partner never leaves the crew who built the strain. Renaming everything to one odd extension is how a family signs its work, and the note gets written last, after the sweep is over. Better-built strains do more than encrypt. They purge shadow copies, hunt down any backup the compromised account could see, and follow every mapped share to the end. That thoroughness is why the note reads so confidently. What no note ever lists is the ground the sweep missed, and there is usually some.

Routes that exist without the attacker

Sound encryption does not yield to equipment, and anyone implying otherwise is selling a story. A fair share of what this trade markets as decryption is really negotiation with the crew, marked up and passed on. Genuine work is duller and far more useful, because it hunts for what the run got wrong. A snapshot that survived the purge. A backup that happened to be unplugged, or living on a machine the account could not reach. Original copies left behind as deleted blocks because the strain encrypted duplicates and binned the source. Working files and fragments carved out of unallocated space. A NAS or array whose layout the attack wrecked, put back together until readable volumes appear underneath. And for the small number of families with published mistakes in their code, a free decryptor used properly. The assessment names which of these you have, and says so when the honest answer is none of them.

On the question of paying

This bench sends no money and carries no messages, and no client has ever been steered towards settling. Three reasons, all practical. A payment funds the next round of attacks on somebody else. A receipt buys no obligation, because there is nobody to complain to afterwards. And criminal decryptors are badly written, so files come back mangled about as often as whole. In place of all that you get every technical route worked to its end plus a written record of what returned and what did not. Where an insurer or a legal adviser later steers a business into talks, that call belongs to them. Our job was making sure the technical answer arrived before the decision did.

// what the bench runs on

Proper engineering kit, not a downloaded scanner

Every ransomware job runs as an incident: isolated first, imaged second, documented throughout, and recovered last:

An air-gapped bench

Incident media never goes near the network. It stays on an isolated rig for the whole job, so nothing can spread, call home, or carry on encrypting from the point it stopped.

Physical write-blocking

Attacked disks are captured behind hardware write-blockers before anyone examines them properly. Everything afterwards happens on copies while the originals sit sealed on a shelf.

Shadow copy and snapshot carving

Free space is swept for the shadow copies and snapshot fragments the deletion pass missed, then those are rebuilt into restore points that genuinely restore.

Strain identification

The note, the extension and a few samples give the family a name. That name is then put to the databases worth trusting, in case a lawful decryptor exists for it. Usually none does, and you hear that on day one rather than in week three.

Free-space and remnant carving

Unencrypted originals, temporary files and half-written copies pulled back out of free space. Every hurried encryption run leaves a mess behind it, and the mess is the raw material.

Incident logging and reporting

Strain, spread, timeline and outcome recorded as the work proceeds. That is the paperwork the insurer wants, the regulator may want, and your own post-mortem will certainly want.

// makes and models we see

Strains and behaviours we see

LockBit and its rebuildsAkira, on Windows and ESXiPhobos and its clonesDharma, also called CrySiSThe Makop familySTOP and Djvu variantsBlackCat, otherwise ALPHVMedusa, distinct from MedusaLockerEverything out of the Conti lineageESXiArgs on hypervisors

Where recovered data actually comes from

Two undertakings, both given in writing before any work starts. Where a strain has no published weakness, nobody is going to brute-force it, here or anywhere that advertises otherwise. And no ransom is paid from this lab, nor any message carried to the people holding your files. What comes back comes back from snapshots, remnants, partially encrypted large files, unencrypted guests and shadow copies. On price, ransomware follows the hardware rather than the forensic bench: £300 + VAT for one encrypted PC drive, from £500 + VAT for a server, NAS or array, rising with the number of disks. The assessment is free and takes 2 working days from arrival. Payment is settled before the work rather than under no fix, no fee. The calls come from studios and digital firms in the Baltic Triangle, from the manufacturing units at Speke and Halewood, and from offices right across Merseyside.

// before it goes in the post

Before it goes in the post — work the drive loose if you can

Unplug the network leads first and then leave the affected machines alone, exactly as they stand. Nothing else. No antivirus sweep, no reinstall, no format, because each of those passes wears away the very remnants a recovery is built from. Hang on to the ransom note, and to two or three enciphered files as samples, so the family can be named. Then telephone 0800 689 0668 between 9:00am and 5:30pm, Monday to Friday, and what needs to travel gets decided on that call. Media goes tracked and insured, or by a courier you have booked, to Manchester Data Recovery, Peter House, Oxford Street, Manchester M1 5AN, roughly 35 miles along the M62. Nobody is sent out to collect it, and there is no Liverpool counter to walk into, though the lab reception in Manchester will take a parcel by hand. Everything is captured on the air-gapped bench, and the recovery itself runs on copies.

// posting your device in

Sending it in — a padded box and a label

Almost every job on this bench came in by tracked, insured post. It is the calmest way to move a drive that is already struggling, and a parcel handed in anywhere on Merseyside usually reaches the bench the following working day.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// ransomware recovery questions

Common questions

Sometimes, but only where the strain left a door open, meaning a decryptor published by researchers or a coding mistake somebody documented. That list stays short, mostly older STOP/Djvu builds and a handful of copycats who got the maths wrong. Where the implementation is sound, no key means no plaintext, and no laboratory alters that. So the effort turns elsewhere: surviving snapshots, backups the sweep could not touch, originals sitting in unallocated space as deleted blocks, carved fragments, and arrays rebuilt from wrecked structures. Which of those applies to you is what the free assessment settles.
No, and not in any indirect form either. We do not pay, we do not act as go-between, and we never put settling forward as the sensible option. Money sent now buys the attack somebody else gets next month, the promise behind it cannot be enforced anywhere, and the tools handed back tend to corrupt a share of whatever they open. Should a business decide to go that way regardless, the decision sits with its owners, its insurer and its lawyers. Our part finishes when the last technical route has been tried.
Assessing the disks costs nothing, with an answer inside 2 working days of them reaching the bench, and one fixed figure follows in writing. Pricing follows the hardware rather than the drama: £300 + VAT where a single PC drive is involved, and from £500 + VAT where the encrypted data sits on a server, a NAS or an array. Because handling is forensic in class, that figure is agreed before recovery begins rather than settled afterwards, and the scope gets spelled out plainly first.
Pull the network off anything affected, then stop touching it. No reinstalling, no formatting, no clean-up tools swept across the volumes, because every one of those chews up the leftovers a recovery depends on. Keep the ransom note and two or three encrypted files, since that pair is what identifies the strain. Then ring 0800 689 0668, number the disks as they come out of the chassis, and post them to the Manchester lab. Everything after that runs on forensic copies, and the originals you sent stay sealed.
Fewer outfits than the search results suggest, because a good share of what is marketed as decryption is a negotiation desk with a technical name over the door. Liverpool Data Recovery keeps the work in-house. Encrypted PCs, NAS boxes, servers and whole virtual estates arrive by tracked, insured post at Manchester Data Recovery, Peter House, Oxford Street, Manchester M1 5AN, open Monday to Friday, 9:00am to 5:30pm, and they come from every part of the country. The assessment costs nothing, names the strain and sets out what is realistically available. Handling is forensic in class, so the figure is agreed before work starts, and no money goes to an attacker on a client's behalf.
// related services

Other work this bench takes on

Whenever you're ready, the bench is.

Diagnosis free, one figure written down, and £300 + VAT covers a single drive or SSD. Start online or ring.