Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Contact

Contact Us

Intake runs 24/7. In an emergency call first and follow the containment instructions; when reaching out by email or WeChat, include the ransom note and the appended extension.

Emergency contacts

24/7 emergency hotline

+86 15639272850

365 days a year, straight through to an engineer

Availability
24/7, including public holidays
Office
Room B2006-7, Building 20, Xicheng Technology Building, No. 41 Jinsuo Road, Zhengzhou High-tech Industrial Development Zone, Zhengzhou, Henan, China
SheMo Noransom WeChat QR code

WeChat

Scan to chat and send ransom note screenshots directly

In an emergency

If encryption is in progress, still spreading, or a ransom note has just appeared, call the hotline directly rather than waiting on an email reply.

Have three things ready for the call:

  1. When it was discovered and how — who noticed it, and what symptom gave it away;
  2. The affected scope: how many hosts and business systems, and whether virtualization platforms, databases, NAS units or backup servers are involved;
  3. What has already been done: any reboot, reinstall, antivirus or recovery software run, and whether anyone has contacted the attacker.

While waiting to be connected, do the following — these actions directly determine how much can be recovered:

  • Disconnect the network but keep the power on. Unplug or switch-isolate; do not shut down or reboot.
  • Do not reinstall, do not format, do not run disk check or repair utilities.
  • Keep the original ransom note. Do not delete it, and do not rush into virus cleanup.
  • Pause automated backup and sync jobs so usable backups are not overwritten.
  • Disconnect external drives, backup media and mapped shares to stop further spread.

What to include when you contact us

For non-urgent enquiries, assessment requests or hardening work, reach us by email or WeChat. The more complete the information, the more specific our first read can be.

Worth including

  • organization name, contact person and a phone number for urgent callbacks;
  • when the incident was discovered and its current state — still spreading, operations already down;
  • the appended file extension, for example ".locked" or a random-suffix pattern;
  • the ransom note filename and its text content — copy and paste is fine, no need to upload the file itself;
  • the affected system inventory: server count, OS versions, database types and versions, any virtualization platform or NAS;
  • backup status: last successful run, whether backups were also encrypted, any offline or off-site copy;
  • recovery priorities and the acceptable downtime window;
  • whether a forensic report is needed for a police filing or compliance.

We reply with a first read and the material needed next. For anything urgent, please call as well as writing in.

Remote and on-site coverage

Remote service — the primary mode

Intake runs 24/7 and we respond quickly. Work proceeds through remote sessions and a controlled access channel, covering clients anywhere in China, and usually reaches substantive response faster than waiting for an engineer to travel. Remote work is logged, and your operations staff can supervise throughout if you prefer.

On-site service

We dispatch engineers on site — nationwide — in these cases:

  • damaged physical media or inconsistent RAID structures requiring hands-on hardware and imaging work;
  • fully air-gapped or classified environments where external remote access is not permitted;
  • evidence that must be preserved locally, internal procedures that need someone present, or a briefing to be delivered in person;
  • an explicit client request for on-site presence.

Whether an on-site visit is needed, and how it combines with remote work, is settled during assessment.

Sending samples safely

Family identification needs very little material. Please follow these rules so no data leaves your environment unnecessarily.

Please send

  • the ransom note: filename plus its text content, pasted or as a screenshot;
  • two or three encrypted sample files — small, ordinary files such as a throwaway test document, a sample image or an explanatory text file;
  • if possible, the pre-encryption original of one of those files, which helps considerably for some families;
  • your antivirus quarantine record or alert screenshot, if the payload was already handled.

Please do not send

  • any file containing sensitive data: customer records, employee or patient personal information, financial and contract data, source code, classified material;
  • database backup files or full database exports;
  • the malicious executable itself, unless we specifically ask and agree a secure transfer method;
  • production credentials — when remote access is needed we agree a secure method separately; never put passwords in email or chat.

Also worth knowing

  • samples are used only for family identification and the recoverability judgement, handled under the confidentiality terms, and deleted within the agreed period after assessment;
  • if you are unsure whether a file is safe to send, do not send it — describe it on the phone instead;
  • we never ask for your full production dataset, and we never withhold the family identification behind a payment.