Why ransomware shadow copy recovery is harder than it used to be
Short answer: VSS (Volume Shadow Copy Service) shadow copies — the automatic Windows backups stored locally on your drive — have been a first-target for ransomware since 2016. Modern ransomware running in India (LockBit variants, STOP/DJVU, Phobos, and newer families) deletes shadow copies as its first action before encrypting files. Windows 11 24H2 introduced Protected Shadow Copies — a feature that marks specific VSS snapshots as tamper-resistant — but most ransomware already runs with SYSTEM privileges obtained through UAC (User Account Control) bypass and can still delete them. Shadow copies are no longer a reliable ransomware recovery path for most infections in 2026. The real recovery paths are: free decryptors from nomoreransom.org, external backup restoration, or cloud service versioned restore.
The correct sequence after a ransomware attack on Windows 11 in India
Step 1: Isolate immediately — do not shut down
The moment you see ransom note files (.txt, .html) or encrypted file extensions appearing, disconnect all networks — Wi-Fi, ethernet, any Bluetooth file transfer. This stops the ransomware from spreading to network shares, USB drives, or cloud sync folders (OneDrive/Google Drive will sync encrypted files if left connected). Do not shut down the laptop. Some ransomware variants hold the master decryption key in memory (RAM) until reboot — forensic labs can sometimes extract this key from a memory image if the laptop stays powered on. Only shut down if you cannot prevent additional encryption any other way.
Step 2: Check shadow copies and nomoreransom.org
Open an Administrator Command Prompt and run: vssadmin list shadows. If any shadow copies survived, right-click any folder in Windows Explorer > Properties > Previous Versions to restore specific files. Then visit nomoreransom.org — it is the authoritative catalogue of free decryptors donated by security researchers and law enforcement. Upload a sample encrypted file and the ransom note; the site identifies the ransomware family and links to a decryptor if one exists. Over 40% of ransomware variants affecting Indian consumers have free decryptors available — checking this first costs nothing.
Step 3: Restore from cloud-versioned backup if shadow copies are gone
If OneDrive (Microsoft 365 subscription) or Google Drive with versioning was active before the attack, files may be restorable to a pre-encryption version. OneDrive has a built-in "Files Restore" feature (OneDrive > Settings > Restore your OneDrive > select a date before the attack). Google Drive retains 30 days of version history. The critical issue: if the ransomware ran while OneDrive was syncing, the encrypted versions may have already uploaded. Act quickly — most cloud services retain deleted/overwritten files for 30 days but this window closes. Our earlier guide on ransomware data recovery in India covers the cloud-restore steps in detail.
Step 4: The India angle — STOP/DJVU is the dominant family
In India, STOP/DJVU (a ransomware family spreading primarily through cracked software downloads from Indian piracy sites) accounts for a disproportionate share of consumer laptop ransomware cases. STOP/DJVU has a well-documented free decryptor from Emsisoft available at nomoreransom.org, but only for offline-key infections (where the ransomware could not connect to its server). If the laptop was online during infection and used an online key, Emsisoft's decryptor cannot help for that specific encryption session. The single most common source of STOP/DJVU infections in India is downloading cracked software, games, or pirated Adobe products. Our data recovery team handles several STOP/DJVU cases monthly — the offline-key variant has a high success rate with the Emsisoft decryptor.
When to call a specialist (and what it costs)
When to stop DIY attempts
If the ransomware family is identified but no free decryptor exists, and your external/cloud backup predates the infection — stop. Every additional attempt to "fix" or run suspect decryptors risks overwriting recoverable file fragments or introducing secondary malware. Get a forensic memory image taken (if laptop is still on) and consult a specialist.
Typical India cost range
Ransomware identification + free decryptor assistance: ₹1,000–₹2,500. Cloud versioned restore assistance (OneDrive/GDrive): ₹800–₹1,500. Forensic memory image capture (laptop must be on): ₹3,000–₹6,000. Full OS reinstall + clean recovery setup after ransomware removal: ₹1,500–₹3,000.
A note from the LRW Engineer Team
The safest position against ransomware is not an antivirus — it is an offline backup. A ₹1,500 external drive, backed up weekly and then unplugged, cannot be encrypted by ransomware. Most customers who come to us after an attack did not have an external backup or had it permanently connected. The two minutes it takes to plug in a drive, copy new files, and unplug it is the most cost-effective data protection available in India today.