How to Remove Ransomware?
Ransomware is malicious software that locks your device or encrypts your files and then demands payment to give them back. The FBI describes it as malware that “prevents you from accessing your computer files, systems, or networks and demands you pay a ransom for their return.” If you are dealing with it right now, the short answer is: disconnect the device, identify the strain, report it, clean or reinstall the system, and restore your files from a backup.
Our laptops hold family photos, business documents, and years of work, but we rarely protect them like a safe. That is why ransomware hurts so much: one moment you are working normally, the next your files will not open and a ransom note fills the screen.
Ransomware usually arrives through phishing emails, fake downloads or “updates,” compromised websites, and unpatched systems. The No More Ransom project says a ransomware attack “is typically delivered via an e-mail attachment which could be an executable file, an archive or an image.” The ransom note then demands payment, often in cryptocurrency such as Bitcoin.
This guide shows you how to spot ransomware, remove it on Windows and Mac, recover your files, and prevent the next attack.
How to tell if your device has ransomware?
Spotting ransomware early limits the damage. Watch for these signs:
- Your antivirus suddenly shows a burst of alerts or gets switched off without your action
- Files have new or strange extensions added to their names
- File names change to random letters and numbers
- Your computer slows down sharply while the disk works nonstop
- A text or HTML file appears in many folders with instructions on how to pay
- A full-screen message blocks your desktop and demands payment
According to the FBI, you usually discover ransomware “when you can no longer access your data or you see computer messages letting you know about the attack.” If you see these signs, act right away.
How to remove ransomware step by step
The right fix depends on the variant, how badly your device is affected, and whether you have backups. These steps follow the order in the CISA #StopRansomware Guide, adapted for home users and small businesses, and match what most cybersecurity experts recommend.
Step 1: Isolate the infected device
Unplug the network cable, turn off Wi-Fi and Bluetooth, and disconnect USB drives, external disks, and network shares. CISA advises you to “immediately isolate” affected systems. Only power the device down if you cannot disconnect it, because CISA notes this destroys evidence stored in memory.
Step 2: Document what you see
Photograph the ransom note. Write down any email address, website, onion link, or Bitcoin address it contains, plus the new file extension. You need these details to identify the strain and report the attack.
Step 3: Identify the ransomware strain
The strain tells you whether a free decryptor exists. Two free services help:
- No More Ransom Crypto Sheriff. On Crypto Sheriff, you can upload two encrypted files (each no larger than 1 MB) and type in any email, website URL, onion, or Bitcoin address from the ransom note, or upload the note itself. If a solution exists, it links to the decryptor.
- ID Ransomware. ID Ransomware identifies the strain from the ransom note and a sample encrypted file. As of September 2026, the site says it detects more than 1,100 ransomware variants. It only identifies the strain and does not decrypt files.
Where possible, upload files without sensitive data. ID Ransomware says it cannot guarantee uploads stay 100% confidential.
Step 4: Report the attack
In the United States, the FBI asks victims to contact their local FBI field office or file a report at ic3.gov, the FBI’s Internet Crime Complaint Center. Organizations can also report to CISA. Outside the U.S., the No More Ransom Report a Crime page lists where to report in each participating country.
Reports help police disrupt ransomware groups, which is sometimes how decryption keys become available.
Step 5: Remove the ransomware with trusted tools
Run a full scan with an up-to-date security tool: Microsoft Defender on Windows, or XProtect plus a reputable scanner on Mac (details below). A second-opinion scanner such as the free version of Malwarebytes can catch what one tool misses. These tools remove the ransomware program but usually cannot decrypt files that are already locked. Avoid deleting malware files by hand unless you are experienced. Learn more about how to fight the malware that often arrives alongside ransomware.
Step 6: Try a free decryptor
If you found a match, check the No More Ransom decryption tools page. The project was started by the Dutch National Police, Europol’s European Cybercrime Centre, Kaspersky, and McAfee, and hosts free decryptors from security companies and police agencies. Download decryptors only from No More Ransom or the vendor’s own site.
If no decryptor exists yet, keep a copy of the encrypted files. No More Ransom explains that decryption sometimes becomes possible later, when developers make mistakes or police recover the keys.
Step 7: Restore your files from a clean backup
Restore only after the device is clean. Microsoft’s OneDrive ransomware guidance warns to clean all devices first, “otherwise, your files could get encrypted again when you restore them.”
Step 8: Reset or reinstall the operating system if needed
If the scan fails or the infection returns, copy any unaffected files you need to a separate drive, then wipe and reinstall Windows or macOS (steps below). A clean install is the surest way to remove hidden malware, but it erases the drive.
Step 9: Change passwords and turn on MFA
Many ransomware groups steal data before encrypting it. From a clean device, change the passwords for email, banking, cloud storage, and work accounts, and turn on multi-factor authentication (MFA). CISA recommends phishing-resistant MFA, such as FIDO security keys or passkeys, particularly for email.
Step 10: Get professional help for serious cases
If the attack reached a business network, servers, or customer data, bring in an incident response team. CISA notes that attackers often leave “dropper” malware behind, which must be found before you rebuild from backups.
How to remove ransomware on Windows
Windows has free built-in tools for cleanup and recovery.
- Run a Microsoft Defender Offline scan. Open Windows Security, go to Virus & threat protection, select Scan options, choose Microsoft Defender Offline scan, and select Scan now. Microsoft explains that this scan runs after a restart “without loading Windows, so any persistent malware has a more difficult time hiding or defending itself.” See Microsoft Support.
- Use Safe Mode if a screen locker blocks you. Safe Mode loads only essential drivers and services, so a screen locker may not start. Hold Shift while selecting Restart, then choose Troubleshoot, Advanced options, Startup Settings, Restart, and press 4 or F4 (Microsoft guide). Then run your scan.
- Restore OneDrive files. If your files sync to OneDrive, Microsoft 365 subscribers can restore their OneDrive to an earlier point within the last 30 days. Microsoft says non-subscribers get their first ransomware notification and recovery free.
- Restore from File History. Once the PC is clean, connect your backup drive, right-click a folder, and select Restore previous versions (File History guide).
- Reset the PC as a last resort. Go to Settings, System, Recovery, Reset this PC, and choose Remove everything. Have your BitLocker recovery key ready if your drive is encrypted (Reset your PC).
How to remove ransomware on a Mac
Macs can be hit by ransomware too, including through encrypted files synced from shared drives or cloud storage.
- Let built-in protection work. Apple’s platform security guide explains that XProtect is “built-in antivirus technology” that detects and removes known malware, with signatures Apple updates automatically. Gatekeeper helps block malicious apps from launching. Keep macOS updated.
- Start up in safe mode. Safe mode stops login items and non-essential extensions from loading. On Apple silicon, hold the power button until startup options appear, select your startup disk, then hold Shift and click Continue in Safe Mode. On Intel, hold Shift at startup (Apple guide). Then run a reputable Mac scanner.
- Remove suspicious apps and login items. Check System Settings, General, Login Items, and delete apps you did not install on purpose.
- Erase and reinstall macOS if needed. Start up in macOS Recovery, erase the startup disk with Disk Utility, and reinstall (Apple guide).
- Restore from Time Machine. After a clean install, use Migration Assistant to restore files from a Time Machine backup made before the infection (Apple guide).
What not to do after a ransomware attack
Panic leads to mistakes. Avoid these:
- Do not connect your backup drive to the infected device. CISA warns that “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups.”
- Do not restore files before the device is clean. Restored files can be encrypted again.
- Do not delete the encrypted files. A free decryptor may be released later.
- Do not wipe the system before you document the attack.
- Do not download “decryptors” from ads or unknown websites. Fake recovery tools can install more malware.
- Do not log in to your accounts from the infected device.
Should you pay the ransom?
No. The FBI and the No More Ransom project, run by Europol, the Dutch National Police, and security companies, both advise against paying. No More Ransom puts it simply: “you should never pay!” The FBI states that it “does not support paying a ransom in response to a ransomware attack.”
The reasons:
- No guarantee. The FBI says paying “doesn’t guarantee you or your organization will get any data back.”
- It funds more attacks. According to the FBI, paying “encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity.”
- Your data may still leak. CISA explains that many groups steal data and threaten to publish it, a tactic called “double extortion.” Paying does not prove the stolen copy is deleted.
If your business is under pressure to pay, talk to law enforcement and legal counsel first.
What are the types of ransomware?
Knowing the type helps you pick the right response.
- Crypto ransomware encrypts your files and demands payment for the key. Files stay locked even after the malware is removed.
- Locker ransomware locks your screen or device without encrypting files. Safe mode and a malware scan often fix it.
- Master Boot Record ransomware interferes with the startup process so the operating system cannot load.
- Leakware or doxware threatens to publish your stolen files. It is often combined with encryption.
- Mobile ransomware targets phones, mainly Android devices according to No More Ransom.
- Scareware is a related scam that shows fake virus warnings and demands payment for a “fix.”
What is Ransomware-as-a-Service?
Ransomware-as-a-Service (RaaS) is a criminal business model where one group builds the ransomware and others rent it. Microsoft explains that the RaaS operator “develops and maintains the tools to power the ransomware operations,” including payment portals. Affiliates break into victims’ networks and deploy the ransomware, and the two sides split the profit. Separate “access brokers” often sell network access to affiliates. The result is that attackers with little technical skill can rent working ransomware.
How to protect against ransomware in future?
These habits protect your network security and devices from ransomware and most other attacks.
- Keep everything updated. The FBI advises keeping “operating systems, software, and applications current and up to date.”
- Use security software that updates itself. Microsoft Defender on Windows, or XProtect and Gatekeeper on macOS. The FBI recommends anti-malware tools that update automatically and run regular scans. If Windows crashes with a blue screen after an infection, see how to fix Kernel Security Check Failure.
- Turn on Controlled folder access on Windows. This Defender feature lets only trusted apps change files in protected folders (Microsoft overview). Find it in Windows Security under Virus & threat protection, Ransomware protection.
- Back up with the 3-2-1 rule and keep one copy offline. CISA recommends “offline, encrypted backups” that you test regularly. The FBI adds that backups should not stay connected to the computers they back up.
- Use MFA on important accounts. CISA recommends phishing-resistant MFA, such as passkeys or security keys.
- Use long, unique passwords. A password manager helps. NIST’s current guidelines require single-factor passwords of at least 15 characters and say services should not force periodic password changes, so length and uniqueness matter more than monthly resets.
- Learn to spot phishing. Do not open unexpected attachments, even from people you know, and hover over links before clicking. See our guides to types of phishing attacks and what to do if you click a phishing link.
- Keep Office macros off. CISA recommends disabling macros in Office files sent by email.
- Do not expose Remote Desktop to the internet. CISA advises: “Do not expose services, such as remote desktop protocol, on the web.”
- Secure your home network. Harden your home router: change the default admin password, keep its firmware updated, and use WPA3 Wi-Fi encryption, or WPA2 if WPA3 is not available.
- Encrypt your drives. BitLocker or Device Encryption on Windows and FileVault on Mac protect a stolen device, though they do not stop ransomware.
- Ignore pop-ups that demand payment for repairs. Treat them as scams.
What is the 3-2-1 backup rule?
The 3-2-1 rule makes sure you can always recover your data. CISA’s Data Backup Options paper describes it this way:
- 3: Keep three copies of any important file: one primary and two backups.
- 2: Keep the files on two different media types, such as an external drive and cloud storage.
- 1: Store one copy offsite, outside your home or business.
For ransomware, keep at least one backup disconnected when you are not using it, since ransomware cannot encrypt a drive it cannot reach. Test a restore now and then so you know your backups work.
Can a VPN protect you from ransomware?
No, not directly. A VPN does not scan files, block malware, or remove ransomware. If you open an infected attachment, a VPN will not stop ransomware from encrypting your files. That job belongs to updates, security software, and backups. Read more in our guide on whether a VPN protects you from viruses.
What a VPN does is protect your connection. EonVPN hides your IP address and encrypts your traffic with AES-256-GCM over OpenVPN, which helps keep your browsing private on public or untrusted Wi-Fi. On Windows, EonVPN also includes DNS leak protection, so your DNS requests stay inside the encrypted tunnel. Treat it as a privacy layer, not a ransomware defense.
Conclusion
If ransomware hits, disconnect the device, document the ransom note, identify the strain, report the attack, clean or reinstall the system, and restore from a clean backup. Do not pay, because the FBI and No More Ransom both warn there is no guarantee you will get your files back.
The best defense is preparation: updates, MFA, phishing awareness, and 3-2-1 backups with one offline copy. With a good backup, ransomware becomes an inconvenience instead of a disaster.
FAQs
Is it possible to remove ransomware?
Yes. Tools such as Microsoft Defender can usually remove the ransomware program, and a full reset or reinstall wipes it from the drive. Getting files back is harder: you need a clean backup or a free decryptor for your strain, which you can check on No More Ransom.
Does resetting a PC remove ransomware?
Yes, a reset with the Remove everything option, or a clean reinstall, removes ransomware from the drive. It also erases your files, so you need a backup. Keep a copy of the encrypted files in case a decryptor is released later.
What is the first step in removing ransomware?
Disconnect the infected device from the network, Wi-Fi, and external drives so the ransomware cannot spread or reach your backups. Only power it off if you cannot disconnect it.
Can you decrypt ransomware files for free?
Sometimes. No More Ransom offers free decryptors for many known strains, and Crypto Sheriff tells you if one exists for yours. Many strains have no public decryptor, so backups remain the most reliable way to recover.
Should I report a ransomware attack?
Yes. In the U.S., report it to the FBI at ic3.gov or your local FBI field office. In other countries, the No More Ransom Report a Crime page lists the right agency.
Can antivirus detect ransomware?
Yes. Microsoft Defender and macOS XProtect detect and remove many known strains, and Controlled folder access blocks untrusted apps from changing protected files. No tool catches everything, so pair security software with updates and offline backups.

