Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.
Work through these checks
0 of 4 complete01Disconnect the affected computer immediately from local networks and the internet to halt spreading.
Disconnect the affected computer immediately from local networks and the internet to halt spreading..
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
02Boot the system into Safe Mode with Command Prompt to bypass startup malware vectors.
Boot the system into Safe Mode with Command Prompt to bypass startup malware vectors..
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
03Trigger a Microsoft Defender Offline scan to locate and clean persistent trojans.
Trigger a Microsoft Defender Offline scan to locate and clean persistent trojans..
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
04Restore decrypted documents exclusively from a secure, isolated offline backup source.
Restore decrypted documents exclusively from a secure, isolated offline backup source..
Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.
Possible causes
- Executing unverified attachments or cracked software payloads.
- Compromised Server Message Block (SMB) exposures on local networks.
- Outdated security configuration allowing remote code execution.
Was this helpful?
Your progress is saved on this device.