If a home PC shows a full-screen lock, a note demanding Bitcoin, or everyday files that suddenly will not open, treat it as ransomware and slow down. Microsoft defines ransomware as malware that encrypts files or blocks the PC until you pay. Microsoft’s support page is blunt: do not pay; even after a payment there is no guarantee you get the files back. The No More Ransom project, a law-enforcement and industry effort, says the same: payment is not guaranteed to unlock anything, and you should never pay. The first hour is for stopping spread, saving evidence, protecting bank and email logins from a different device, and only then planning cleanup. This is not the generic virus-clean article and not the USB backup walkthrough. Use those later: 9 steps to clean a virus-infected Windows PC and How to back up files from a virus-infected computer.

What the first hour is for

The first hour is containment and evidence, not shopping for a decryptor or arguing with the note.

Microsoft says infections often stay quiet until a window or full-screen message demands money, usually after files are already encrypted. It also notes ransomware can spread to other PCs and storage on the same network, including phones in some cases. That is why the first moves are household-network moves, not a long scan while shared drives stay connected.

Confirm you are looking at ransomware, not a scareware pop-up. A browser page that says “call this number or your files are gone” is often a fake warning. See 8 ways to tell a virus warning popup is fake. Real ransomware typically leaves files unreadable (odd extensions, documents that will not open) plus a note on the desktop or in every folder. If the PC is only slow, it may not be ransomware at all: 7 signs your old computer is slow from hardware, not a virus.

First-hour checklist

  1. Do not pay, and do not chat with the inbox or site in the note. Microsoft: even if you pay, there is no guarantee you regain the PC or files. No More Ransom: you should never pay; payment is not guaranteed. Paying also marks you as someone who might pay again.
  2. Photograph the screen. Capture the note, any ID or email the crooks list, the Bitcoin or payment address, and a couple of renamed files. You need that for a bank, an insurer, or a police report. Do not type the payment address into a wallet “just to see.”
  3. Unplug Ethernet. Turn off Wi-Fi. Microsoft warns that ransomware on a networked PC may spread to other computers or storage. Pull the cable. Use the hardware switch or airplane mode if the mouse still works. If the note is actively encrypting (file names changing in front of you), hold the power button to shut the PC down after you have the photo. A hard shutdown can interrupt spread; it is messy and preferred to watching a second drive die.
  4. Unplug USB drives, cameras, and the backup disk if they are still attached. Do not open the backup disk on the infected PC to “see if photos are OK.” That is how backups get encrypted. Recovery planning belongs in the backup guide, on a different machine, after this PC is no longer writing to shared folders.
  5. Tell the rest of the house. Phones, a second laptop, and a NAS on the same Wi-Fi should stop opening shared folders from this PC. Sign out of the home PC’s cloud sync if you can do it from a phone app without turning the infected disk back on. Microsoft notes OneDrive can detect ransomware and restore versions—use that later from a clean browser session, not as an excuse to keep the sick PC online.
  6. Use a different device to lock money and mail. From a phone, change email and bank passwords and turn on multifactor authentication. Assume the infection may have seen whatever was typed on that PC. If card numbers or a Social Security number could have been exposed, use IdentityTheft.gov and watch statements.
  7. If you already paid, call the bank now. Microsoft: contact your bank and local authorities immediately; a credit-card payment may still be blockable. In the United States, report the crime at ReportFraud.ftc.gov and consider IC3.gov.
  8. Do not factory-reset, reinstall, or restore yet. Microsoft says to fully clean the PC with Windows Security before you try to recover files. Cleaning and image restore are hour two and later. When you get there, use the nine-step clean guide and the infected-PC backup guide. Do not copy “just a few files” onto a family USB from this disk until you understand the risk those articles describe.
  9. When the PC is offline and accounts are locked, you can power it on disconnected and run Windows Security (Virus & threat protection → scan options, including Microsoft Defender Offline if a normal scan is not enough). That is cleanup, not decryption. Microsoft’s ransomware page: try fully cleaning before file recovery; do not pay.

No More Ransom hosts free decryptors for some older families. Treat that site as a later check on a clean PC, not a first-hour download onto the infected one. We are not listing exploit steps or walk-throughs for any decryptor.

What not to do in hour one

  • Do not install a random “ransomware removal” from a search ad.
  • Do not keep the backup drive mounted “so it can finish copying.”
  • Do not negotiate. There is no customer service on the other side.
  • Do not wipe the disk in a panic before you know whether a copy exists in OneDrive version history or an offline backup. Wiping is sometimes the right later step; it is a bad first step if it is your only copy of baby photos and you have not checked cloud versions from a phone.

After the first hour

Cleanup: 9 steps to clean a virus-infected Windows PC. File copy decisions: How to back up files from a virus-infected computer. If you want extras such as stronger web filtering after you are stable, that is optional: 5 antivirus extras worth paying for in 2026. Microsoft’s prevention list for next time is ordinary: keep Windows updated, keep Windows Security on, consider Controlled folder access, store important files where versioning exists, use a modern browser, and restart weekly so updates finish.

CyberGuardLab is independent. We are not an official partner of Microsoft or No More Ransom. Buying a suite is not required to follow this checklist.

Do not shop from the infected PC. Paying a ransom is not recommended. A paid suite is optional after the PC is offline and accounts are locked from another device.

FAQ

Should I pay if the note says my photos will be posted?

Microsoft and No More Ransom both say not to pay and that payment does not guarantee recovery. Payment also does not guarantee silence. Lock accounts, report the crime, and work from backups.

The files open but there is a scary banner. Is that ransomware?

Often no. Full-screen browser scares are usually fake support pop-ups. If files still open with their normal apps, read the fake-popup guide before you shut the house network down.

Can Microsoft Defender remove ransomware and unlock files?

Defender can detect and remove malware. Removing the program does not always restore already-encrypted files. Microsoft tells you to clean first, then recover from backups or OneDrive versions. Do not expect a scan to undo encryption.

Is it safe to plug in my backup drive to grab one folder?

Not on the infected PC. Unplug it and follow the backup-from-an-infected-computer guide on a different machine when you are ready. Hour one is keep that drive away.

Who do I report this to in the US?

Microsoft points US readers to consumer fraud reporting. Use ReportFraud.ftc.gov, your local police if money moved, your bank if you paid or a card was stored on the PC, and IC3.gov for an internet-crime report.