When ransomware hides files and makes them read-only
Ransomware can change more than the contents of your documents. Some variants alter Windows file attributes so folders appear empty, files become hidden, or data is marked read-only. These changes can make a recovery problem look like permanent deletion, even when the files are still stored on the drive.
The most important action is to stop using the affected computer. Disconnect Wi-Fi and Ethernet, unplug external drives, and avoid opening suspicious attachments or launching unfamiliar recovery tools. If the device belongs to a business in Sydney, Melbourne, Brisbane or elsewhere in Australia, isolate it from shared office storage as quickly as possible.
Read-only status does not usually mean that ransomware has securely erased a file. It is an attribute that limits ordinary editing, while the hidden setting controls whether the item appears in File Explorer or Finder. Encryption, damaged file headers, deleted shadow copies and locked user accounts are separate issues that need separate checks.
Do not rename, move, overwrite or “repair” the affected files before making forensic copies where possible. A rushed change can destroy useful evidence or reduce the chance of successful decryption. Home users should document the ransom note, altered extensions and affected folders, while organisations may need to follow Australian Privacy Act and Notifiable Data Breaches obligations.
Confirm what has changed
On Windows, right-click an affected file, select Properties and check the Attributes area. A hidden file may become visible after enabling hidden items in File Explorer, but this does not prove that its contents are usable. Compare the file size, extension, modified time and location with a known-good copy.
Use caution with Command Prompt commands such as attrib. Removing the hidden or read-only flags can restore visibility, but it will not decrypt ransomware-locked data. If files become visible after the attributes are cleared, copy them to a separate storage device in read-only form and preserve the originals.
On a Mac, inspect Finder’s Get Info panel and check whether the item is locked. Terminal commands can modify permissions and flags, but running them broadly across the disk may affect system files and backup metadata. Take screenshots and record the exact paths before changing anything.
Isolate the infection safely
Disconnect the computer from the internet and nearby network shares. Ransomware may continue scanning mapped drives, NAS devices, USB storage or cloud-synchronised folders. Pause synchronisation services from a clean device if possible, because encrypted or hidden files can otherwise propagate to OneDrive, Dropbox or other accounts.
Do not reboot repeatedly unless a technician advises it. Some threats load during startup or remove recovery options after rebooting. If the malware appears active, shut down the machine after isolating it, then use a clean computer to research the ransomware note and prepare trusted rescue media.
Australian businesses should inform their managed service provider, insurer and incident response contact early. A small retailer in Perth or a professional practice in Adelaide may rely on shared accounting and point-of-sale systems that can be affected beyond the original workstation.
Preserve evidence before cleaning
Keep the ransom note, email, wallet address, contact instructions, suspicious executable and a sample of encrypted files. Store copies on a clean external drive, not in the same folder as the incident. Do not pay or communicate with the attacker before receiving independent advice; payment offers no reliable guarantee of a working decryptor.
Record when the incident began, which accounts were logged in and which drives were connected. This timeline helps identify whether the malware reached backups or other endpoints. If the computer may contain personal information, seek professional guidance promptly rather than deleting logs or reinstalling immediately.
A boot-level infection may require a different approach from ordinary file-encrypting ransomware. Guidance on boot sector malware cleanup explains why startup-related threats should be assessed before normal Windows tools are trusted.
Choose a recovery path
The correct recovery method depends on whether the files are merely hidden, encrypted, deleted or corrupted. Use a clean machine to identify the ransomware family by comparing the extension, ransom note and file markers. Search reputable security vendors and law enforcement resources for an official decryptor; avoid random tools that demand payment or upload confidential files.
| What you observe |
Likely meaning |
Safer next step |
| Files are visible after hidden items are enabled |
Attribute change or Explorer setting |
Copy originals and scan the system |
| Names have a strange new extension |
Possible encryption |
Identify the ransomware family |
| File size is unchanged but access is denied |
Permissions or read-only flag |
Preserve a copy before changing access |
| Files are zero bytes or missing |
Deletion, failed encryption or cleanup |
Check offline backups and forensic recovery |
| Backups contain the same damaged files |
Synchronisation spread the incident |
Stop sync and locate an older clean version |
A reputable decryptor may recover data without paying, but it can fail if the wrong variant is selected. Test it on copies, read its documentation and retain the original encrypted files. If no decryptor exists, consider offline backups, previous file versions and specialist data recovery, accepting that success is not guaranteed.
Clean the computer without destroying data
Malware removal should happen after evidence and recovery copies are secured. Use a trusted antivirus or rescue environment updated from a clean device. A full scan can identify the payload, scheduled tasks, browser changes and persistence mechanisms that keep ransomware active.
Do not assume that deleting the ransom note removes the infection. Check startup folders, scheduled tasks, unusual services and newly created administrator accounts. If the system has signs of adware or browser tampering as well, review this guide about injected website pop-ups, since multiple unwanted programs can exist together.
For highly sensitive workstations, reinstalling the operating system from verified media may be safer than trying to clean it in place. Change passwords from a separate clean device, enable multifactor authentication and revoke active sessions after the machine is rebuilt.
Restore files and validate backups
Restore only after the device and network are clean. Begin with a small group of non-critical files and open them in their normal applications. Check spreadsheets, databases, photos and documents for corruption rather than relying only on file names and sizes.
Use backups that were disconnected or protected from modification during the incident. An external drive left permanently attached, or a cloud folder with immediate synchronisation, may contain the encrypted version rather than a usable backup. Keep at least one offline or immutable copy and test restoration regularly.
If recovery fails, retain encrypted samples for future decryptor releases. File recovery specialists may sometimes retrieve deleted originals, but repeated use of the disk can overwrite recoverable data. Avoid unverified “magic” software that promises instant restoration.
Prevent a repeat incident
Apply security updates to Windows, macOS, browsers, VPN clients and internet-facing appliances. Remove unused remote-access software, restrict administrator rights and block macros or scripts where they are not required. Employees should know how to report suspicious invoices, delivery notices and Microsoft 365 login prompts.
Use separate backup credentials, versioned backups and an offline rotation. For Australian organisations, align incident procedures with the Australian Cyber Security Centre’s guidance and check whether a serious personal-data breach must be reported under the Notifiable Data Breaches scheme.
Keep recovery instructions offline, including supplier contacts and licence details. If you need specialist assistance interpreting an incident, use the site’s support contact page rather than sending sensitive files through an unknown service.