
Ransomware Decryption Service
Files locked with extensions like .rox, .lockbit or .xor? Don't pay the ransom yet — get our free assessment first. No decryption, no fee.
All your files suddenly have strange extensions, plus a ransom note? That's ransomware. CentralComputer.hk specialises in decrypting ransomware-encrypted files — from common ones like .rox and .lockbit to obscure ones like .weax and .bixi. Remember: paying the ransom is a last resort, and often you never get your files back anyway.
Ransomware Extensions
Encrypted Extensions We Handle
This is only a partial list — even if your extension isn't here, bring it for a free assessment.
Our Services
What Our Decryption Service Covers
Ransomware File Decryption
Professional decryption and data recovery for encrypted extensions including .rox, .lockbit, .xor, .dlock, .taps, .enzo, .sorry, .bixi, .mkp and more.
Emergency On-Site Response
If hit by ransomware, do not panic and do not tamper with the machine. Our technicians provide emergency on-site isolation to stop the infection spreading to other computers and servers.
Free Pre-Decryption Assessment
We first identify the ransomware strain and encryption method to assess decryptability and success rate. Assessment is free — no decryption, no fee.
Post-Decryption Hardening
Decryption is not the end. We remove backdoors, patch vulnerabilities and set up backups so it does not happen again in two weeks.
Process
Our 4-Step Decryption Process
Isolate Immediately, Do Not Power Off
Unplug the network cable (do not power off — decryption clues may live in RAM). Never reinstall Windows or format the drive yourself; that destroys evidence.
Free Ransomware Identification
We analyse the ransom note and encrypted extensions to identify the ransomware family, check for public decryptors, or determine if the encryption algorithm needs reversing.
Decryption & Data Recovery
Files are decrypted with the matching method; where decryption is impossible we use data-recovery techniques to salvage what we can. All work is done in an isolated environment.
Verification & Hardening
You verify each file before we charge a cent. Then we remove malware remnants, apply patches and set up automated backups to prevent recurrence.
Three Things You Must NOT Do
- Don't pay the ransom yet — over 30% of victims who pay never recover their files
- Don't reinstall the OS or format drives — it destroys decryption evidence
- Don't download so-called "decryptors" on the infected machine — many are secondary infections in disguise
Case Study
Real Customer Case
A logistics SME in Kwun Tong came in on a Monday morning to find their entire file server locked by .Devion — over a decade of customs declarations and client records, all unreadable. The boss's first instinct was to pay the HK$80,000 ransom. We told him to hold on and let us assess first.
Our assessment found a flaw in this variant's key management. We spent four days reversing the decryption flow and recovered over 95% of files. The boss didn't pay a cent in ransom — and we hardened his whole network and set up 3-2-1 backups. Two years on, no reinfection.
— Owner of a Kwun Tong logistics firm (anonymised on request)
FAQ
Frequently Asked Questions
Three things: first, unplug the network cable but do not power off; second, do not pay the ransom yet — many victims pay and never get their files back; third, call us for an assessment. One trading-company client had their whole server locked by .lockbit and was about to pay HK$50,000 in ransom; our assessment found a decryption method and we recovered 90% of files without paying a cent.
No — it depends on the strain. Some older or poorly written ransomware has public decryptors with high success rates; some use standard encryption with sloppy key management, which can sometimes be exploited; but some new variants use sound encryption that cannot currently be broken. That is why the assessment is free — we will tell you honestly whether it can be done, and if not, we charge nothing.
It depends on file count and encryption method. A few hundred files typically take 1–3 days; a multi-TB server can take a week. Urgent cases can be expedited — we once recovered a clinic's patient records system within 48 hours so they could open on Monday.
Three essentials: patch systems and software (most ransomware enters through known vulnerabilities); follow the 3-2-1 backup rule (3 copies, 2 media types, 1 offline); and train staff — 90% of intrusions start with one phishing email. After decryption we handle this hardening for you so we do not meet again under the same circumstances.
Yes, it is real. Assessment is free and the quotation states clearly that you only pay on successful decryption. If the assessment shows it cannot be decrypted, or decryption proves impossible mid-process, you pay nothing. Pricing is quoted upfront based on file count and complexity — no hidden charges.
Hit by Ransomware? Every Minute Counts
Don't tamper with it, don't pay yet. Contact us now for a free assessment.