Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
// case file · PC · HP Omen · LockBit ransomware

LockBit hit an HP Omen with no backup.

Every file locked, the boot record overwritten, the shadow copies gone, a ransom note waiting. This is the case file where we lay out exactly what we recovered — because the thing most firms promise in this situation can’t actually be delivered.

← All case files · £300 + VAT, flat

Device

HP Omen laptop

Failure

LockBit ransomware

Data

Work documents, personal media, project files

Outcome

Recovered around the encryption, not through it

// the brief

What arrived, and what was at stake.

An HP Omen laptop, taken by LockBit. Every user file locked away or unreachable, a note demanding payment, and Windows dead on boot. The antivirus had changed nothing — and that’s no surprise, because antivirus is there to block an infection, not to unpick one that’s already run. No backup existed.

// on the bench

What the diagnosis found.

The encryption we never touched. Nobody could have.

01

The strain was LockBit

read off the ransom note and the file markers. Nothing on this page matters more, because the strain alone decides whether a released decryptor exists — and for LockBit, there isn’t one.

02

The Master Boot Record had been overwritten

the reason the machine wouldn’t boot in the first place.

03

The Volume Shadow Copies had been wiped

ransomware always attempts this — it doesn’t always pull it off in full.

LockBit seals each file behind AES-256 and then locks that key away again under RSA. With the private key in the attacker’s hands and nowhere else, those encrypted files are beyond anyone — us, any lab, any supercomputer. When a recovery firm says it can decrypt a current strain, it’s either leaning on a public tool for a strain that was already cracked, or it’s lying.

We didn’t try to get through the encryption. We went round the side of it.

// the recovery

How it was done.

Going round it means gathering up every copy of the data that the ransomware failed to seal. Working from a full forensic image rather than the drive, we pursued four seams at once. First, the deleted originals still lying in unallocated space — LockBit encrypts a copy and bins the source, and that source is recoverable right up until Windows reuses the space. Second, any scraps of the Volume Shadow Copies that had survived the purge. Third, unencrypted caches and temporary duplicates that applications had scattered elsewhere on the disk. And fourth, the still-readable interiors of the big files the malware had only half-finished encrypting. Not one byte of it came from decryption — and before any of it, we rebuilt the overwritten Master Boot Record so the image would present as a volume at all.

// outcome

What came back.

Data came back, and none of it was decrypted — it came from deleted originals, shadow-copy fragments, unencrypted caches and the intact middles of half-encrypted files. The ransom went unpaid.

The total varies enormously from case to case, and any figure quoted before the drive is imaged is invention. It depends on the strain, on whether it overwrote in place or wrote-then-deleted, and most of all on how quickly the machine was switched off — because those deleted originals are the richest seam of all, and they last only until Windows writes across them.

The one thing it can never include is a file that was cleanly encrypted and whose original was truly overwritten. That file is beyond recovery, full stop — by us or anyone.

// the transferable bit

What to take from this.

When ransomware lands, the next few minutes are what decide how much survives.

01

Cut it off.

unplug the network cable — it travels across shares.

02

Leave it unrebooted.

several strains encrypt in passes, and a restart can let a half-finished job run to the end.

03

Keep the ransom note.

it names the strain, and the strain is what tells you whether a free decryptor is out there.

04

And above all, stop using it.

the deleted originals are the single richest source of recovery, and they last only until something writes over them — and a running computer is writing something every minute.

As for afterwards: the backup that let this business down let it down by never existing. The backup that more often fails is the one left permanently mapped — ransomware encrypts whatever it can reach, so an always-connected backup drive isn’t a backup at all, just a second copy of the disaster.

// read next

Related.

// your turn

Lost something that matters? Free diagnosis, a fixed price, and no fix, no fee.

Drop the drive at our Guildford Business Park reception, or post it to us — it costs nothing to find out what happened. You get a written figure from the fixed bands before any work begins.