Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Service

Ransomware Decryption

  • Identify the family first, then commit to a recoverable scope — without paying a ransom.

For organizations whose servers, databases or virtualization platforms have been encrypted: family identification, recoverability assessment and multi-path data extraction, with no ransom payment.

What this service covers

This service is for organizations that are already encrypted and whose operations have stopped. The goal is to recover as much core production data as possible without paying the attacker, and to shorten downtime.

What we do

  • Family and version identification, based on the appended extension, the ransom note text, contact patterns inside the note, file header and footer structure, and the distribution of encrypted blocks. This step determines every path that follows, and it cannot be skipped.
  • Recoverability assessment, performed on read-only images or copies: encryption algorithm and key handling, whether intermittent encryption was used, whether shadow copies or storage snapshots survive, and whether backups are usable. The output is an explicit recoverable scope.
  • Decryption and repair. Where an official or vendor-published decryptor exists for the specific variant, we use it first. For databases and virtual disks we combine structure repair, page- and block-level repair, log replay, and extraction of unencrypted regions.
  • Verification and handover: file integrity checks, database consistency checks and business sampling, delivered together with a verification checklist before anything goes back into production.

The limits, stated honestly

Whether data can be decrypted depends on the family and version, not on how much is paid or how hard anyone works. For mainstream strong-encryption families there is no feasible brute-force path unless keys have leaked, so any claim of "guaranteed decryption" or "100% recovery" is false.

When direct decryption is not viable we move to other paths — backup and snapshot restoration, file-level database repair, extraction of unencrypted remnants and fragments, and reassembly of valid data from intermittently encrypted files — and we state the expected outcome, cost and risk of each. If the assessment concludes the data is unrecoverable, we say so and advise on rebuilding instead of spending the client's time window on an uncertain approach.

Deliverables

  • Family and variant identification, with the evidence and sample analysis behind it
  • Recoverability assessment report: recoverable scope, available paths, expected outcome and risks
  • Decryption and repair plan, with recovery priorities and downtime windows
  • Post-recovery verification checklist: file integrity, database consistency, business sampling
  • Operation log of the engagement plus a follow-up hardening checklist

How it works

  1. Intake and containment guidance

    We respond quickly after intake, establish the affected scope by phone or remote session, and immediately issue containment steps: isolate affected hosts from the network, do not reboot, do not reformat, do not reinstall, preserve the original ransom note, and pause automated jobs or backup runs that could overwrite data.

  2. Sample collection and family identification

    The client provides the ransom note and two or three encrypted samples — ordinary files with no sensitive content are enough. From these we determine family and version, and state whether a public decryptor exists for that build, whether intermittent encryption was used, and whether shadow copies are typically destroyed.

  3. Recoverability assessment and sign-off

    On read-only copies we assess the current state: how much of the data is encrypted, whether database files are repairable, what backups or snapshots survive, and which directories were untouched. The output is a recoverability assessment with tiered options, a quote and a time estimate — work starts only after the client signs off.

  4. Decryption and data extraction

    All work happens on copies while the original disks stay read-only, so nothing is damaged twice. Execution follows business priority: the databases and key files needed by core production systems first, archives and historical data after. Progress and the actually achieved ratio are reported at regular checkpoints.

  5. Verification, handover and review

    Before handover we complete integrity and consistency checks; databases must mount cleanly and pass sampled queries. We deliver the verification checklist and the operation log, and advise on the intrusion entry point — with optional handover to our forensics and hardening services.

When to use it

  • File servers and shared drives encrypted; office and production documents will not open
  • SQL Server, Oracle or MySQL data files encrypted and the application cannot start
  • ESXi or Hyper-V virtual disks encrypted, taking several business systems down at once
  • Backups deleted, or the backup server encrypted along with everything else
  • A ransom note has arrived and you need an independent recoverability opinion before deciding
  • A self-service decryptor from the internet was already tried and failed

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related ransomware families

Related questions

FAQ

Frequently asked questions

  • Can you guarantee successful decryption?

    No — and neither can anyone else. Whether decryption is possible is decided by the family and version: a small number of families have usable public decryptors because keys leaked or the implementation was flawed, while most mainstream families offer no feasible path unless keys are exposed.

    Our approach is to run the recoverability assessment first and state plainly what can be recovered, to what degree, and by which path, so you can decide whether to proceed. Treat any vendor promising "100% decryption" as a red flag.

  • How long does the whole process take?

    Family identification and a first read are usually a matter of hours. A full recoverability assessment depends on data volume and environment complexity, and normally concludes within one to several business days.

    Execution varies far more: a single file server may take a day or two, while multiple virtual machines, large databases or file-by-file repair take considerably longer. The assessment report gives a staged time range, and we update it against real progress during execution.

  • Do we have to ship servers or disks to you?

    Usually not. We work remotely on a 24/7 basis through remote sessions and controlled access channels, which covers clients anywhere in China.

    On-site engineers are arranged when physical media are damaged, RAID structures are inconsistent, the environment does not permit remote access, or the client wants forensics performed in person. Whether an on-site visit is needed is settled during assessment.

  • Why do you advise against paying the ransom?

    First, receiving a decryptor is not the same as getting data back: decryptors are often incomplete, extremely slow, or corrupt large files such as databases — and sometimes never arrive. Second, paying marks the organization as a payer, and repeat extortion is common. Third, moving such funds carries its own compliance exposure.

    We do not pay ransoms, do not negotiate on a client's behalf, and do not handle ransom transfers. Spending the same budget on assessment, recovery and hardening is the better long-term trade.

  • The system was reinstalled or cleaned by antivirus — is there still a chance?

    The odds drop, but they are not necessarily zero. Reinstalling overwrites the original data regions, and antivirus cleanup may remove key files, the ransom note and important logs along with the payload — all of which affect identification and some recovery paths.

    Stop writing to that disk immediately, do not repartition, format or run disk checks, and keep the quarantined samples and quarantine records. We assess what remains in read-only mode first.

Updated