What this ransomware help tool can — and cannot — do
This is a first-aid decision aid, not a ransomware detector, removal tool or universal decryptor. It sorts broad observations into practical next steps. It cannot inspect your device, identify the attacker, confirm stolen data or authorize recovery.
Can I recover encrypted files?
Sometimes protected backups, file versions or a matching decryptor help. Availability depends on the incident and variant. Preserve originals and have a qualified responder assess the options. Paying does not guarantee recovery.
Should I turn the computer off?
Network isolation and shutdown have different consequences. Shutdown can destroy volatile evidence. If safe isolation is impossible and damage is continuing, an authorized responder may need to power down after weighing the risks. Never apply that rule blindly to safety-critical systems.
Does a threat prove I was hacked?
No. A message may contain leaked passwords without proving current access, but real data theft can occur without encrypting files. Independent evidence matters. The tool never labels a threat “definitely harmless”.
Where does my information go?
Choices and optional generic reminders stay in this tab’s memory. No application storage, uploads or third-party scripts. Download and print are explicit actions creating copies under your control. Ordinary page requests still reach our host; see the privacy notice.
Coordinating a team? Continue with the Incident Response Checklist for roles, the first hour, recovery and closure. Your first-aid answers are not transferred.
Sources and limits
- CISA: ransomware response guide
- FBI: ransomware guidance and reporting
- No More Ransom: decryption tools
- Microsoft: find your BitLocker recovery key
- FTC: Bitcoin blackmail email scams
US-oriented references; local reporting duties differ. Guidance version: . Developed with AI assistance; no independent human incident-response expert review or endorsement by the cited organizations is claimed. Methodology.