Victim Q&A · First response
My files all have a new extension and won't open - what should I do?
Short answer
Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.
Key points
- The classic ransomware combination: one unfamiliar extension across many file types, a ransom note in every folder, and a changed wallpaper or pop-up.
- Files that are roughly the same size but unreadable point to encryption rather than ordinary corruption.
- If only files on a USB stick have vanished or turned into same-name shortcuts, a USB worm has usually hidden the originals and the data is still there.
- Renaming files back does not recover anything and erases identification clues; "repair tools" from the internet can cause further damage.
- Next: disconnect but keep the power on, keep samples and the note, and identify the family with the identification tool or extension index.
In this order
What to do now
Stop first: disconnect, stay powered on, pause syncing
Until you know the cause, assume the worst: unplug the network cable, turn off Wi-Fi, disconnect external drives and USB sticks, pause cloud-drive sync, and do not reboot or shut down. If it is ransomware, this stops it reaching shares and cloud copies and preserves evidence in memory; if it turns out not to be, you have lost nothing. On a work computer, tell IT straight away.
Show full file names
Windows hides extensions for known file types by default, and you cannot judge what you cannot see. In Windows 11 File Explorer choose View > Show > File name extensions; in older versions tick File name extensions on the View tab, or clear Hide extensions for known file types in the folder options' advanced settings. Then look closely: is there something extra after the original .docx or .xlsx?
Look for a ransom note and other signs
Open a few affected folders and the desktop and look for new .txt, .hta or .html files, typically named with README, RECOVER, HELP, DECRYPT or info; check whether the wallpaper now shows an English message; sort by date modified to see whether large numbers of files changed in the same window; and check whether shares, NAS and colleagues' computers show the same. Compare against the first two sections below.
Keep samples and the note
Photograph the ransom note and keep the original file; do not delete it. A .txt note can be opened in Notepad; do not double-click an .hta note - open it in Notepad instead. Pick two or three ordinary renamed files as samples, avoiding anything with customer records, financial data or personal information. If you have an unencrypted version of one of those files, such as the original in an email attachment, keep that too; it helps materially with some families.
Identify the family
Enter the extension, the note's filename or an email fragment into the ransomware identification tool - no upload needed - or compare against the extension table below. No More Ransom's Crypto Sheriff and ID Ransomware accept sample uploads, but send only ordinary, non-sensitive files. Any match is a direction, to be confirmed against the note's content and the samples' structure.
Avoid making it worse
Do not
- Do not rename files back to their old extensions or batch-rename anything.
- Do not download "extension repair", "one-click decryption" or "file repair" tools and run them on the original disk.
- Do not format, reinstall, run chkdsk or accept a Windows prompt to "scan and fix" the drive.
- Do not delete the new .txt, .hta or .html files in your folders; they are very likely the ransom note.
- Do not double-click an .hta note, and do not click unknown .exe files or shortcuts on a USB stick.
- Do not upload files containing customer records, financial data or personal information to public identification sites.
- Do not contact the email address in the file names or the note.
How can you tell whether it is ransomware?
A changed extension alone is not proof. The more of these signs you see, the more certain it is ransomware:
- One extension everywhere. Word, Excel, images, archives and database files of different types all carry the same unfamiliar appended extension, usually with the original extension still visible before it, as in report.xlsx.unknown.
- An ID and an email address inside the file name, in the form originalname.[ID].[attacker email].extension. This is the signature format of families common in China such as Phobos and Makop; other families append only a random string.
- A new file in every folder, typically named with README, RECOVER, HELP, DECRYPT or info, in .txt, .hta or .html format, containing contact and payment instructions.
- A wallpaper replaced with a ransom message, or a pop-up after logon.
- Roughly the same size, but unreadable. In Notepad the file is solid gibberish with none of the original text visible; the size is the same or slightly larger, because some families append encrypted key data to the end of each file.
- Concentrated in time, wide in scope. Large numbers of files changed within the same window, and files on mapped shares, NAS and external drives changed as well.
- System-level damage. Previous versions (shadow copies) have all vanished, antivirus has been switched off, and database or backup services have stopped. CISA's advisory on Phobos, for example, records attackers deleting all shadow copies with vssadmin.
Keep two exceptions in mind: a few families do not rename files at all and leave only a note, and others replace the entire file name with random characters, which looks like garbled names. So the real test is not the extension but whether the content is encrypted and whether there is a ransom note.
If it isn't ransomware, what else could it be?
These situations also make it look as if "the extensions changed and nothing opens", but the data is usually still there:
| What you see | More likely cause | How to tell |
|---|---|---|
| Only one type of file won't open or its icon changed; names and extensions unchanged | The default app (file association) was changed, or that application is broken | Right-click, Open with, pick the right application; if it opens, it isn't encrypted |
| Names suddenly show .docx or .jpg at the end | Someone turned on "show file name extensions"; those extensions were always there | The extensions are ordinary formats and files open normally |
| Files on a USB stick "vanished" or became same-name shortcuts or .exe files | A USB worm set the originals to hidden and system, then planted decoys | Used space on the stick has not dropped; the originals are usually still there - never click the decoys |
| File names are garbled but the files open | Name encoding mismatch when extracting an archive or copying between systems | Content is intact; only one archive or one copy operation is affected |
| "The file or directory is corrupted and unreadable", a prompt to format, or 0-byte files | Failing hard disk, USB stick or partition | No common extension and no note, often with slow reads, errors or noises |
USB worms. Huorong's January 2026 guidance explains that these worms give files the system attribute, so ticking "show hidden items" is not enough to see them. Use your security software's USB repair function, or open Command Prompt as administrator, switch to the USB drive letter and run attrib -S -H /S /D to clear the system and hidden attributes.
Disk failure. Stop reading and writing immediately, do not format, do not keep re-plugging the device and do not run disk repair; image the media first and recover from the image - see our data recovery service.
If nothing in the table fits and several signs from the previous section do, treat it as ransomware.
What do common ransomware extensions look like, and which family do they suggest?
The table only covers formats already documented in this site's family library and common in China. The note column matters: a judgement is only reliable when the extension and the note agree.
| What the name or extension looks like | Likely family | Note you should also find |
|---|---|---|
| report.xlsx.id[8 characters-4 digits].[email].faust; also .elbie, .eight, .devos and others | Phobos lineage | info.txt and info.hta |
| report.xlsx.id-8 hex digits.[email].bip; also .arena, .java, .harma and others | Crysis/Dharma | info.hta and FILES ENCRYPTED.txt |
| report.xlsx.[8-character ID].[email].mkp; also .makop, .baseus and others | Makop | readme-warning.txt |
| An English word plus 4444 (e.g. .Dragon4444) or a Greek god plus 666 (e.g. .Ares666) | GlobeImposter | how_to_back_files.html |
| .mallox, .malox, .bitenc and others | Mallox | FILE RECOVERY.txt and similar |
| .rox, .weax, .wxx | Weaxor | RECOVERY INFO.txt |
| .beijing, .360, .520 and others | BeijingCrypt | !RECOVER.txt or !HELP!.txt |
| Four random lowercase letters, e.g. .bbil (common on personal PCs) | STOP/Djvu | _readme.txt |
| 9 or 16 random letters and digits | LockBit 3.0 / 5.0 | A README.txt starting with the same string, or ReadMeForDecrypt.txt |
| .locked | Shared by several families, e.g. TellYouThePass and Mallox's Linux / ESXi variant | You must read the note; TellYouThePass uses README.html and similar |
Two caveats. Attackers can change extensions and name formats at will, and one format can be shared - the Phobos format also appears with 8Base, and Makop is often mistaken for Phobos - so this table only points a direction. And an extension like .360 deliberately borrows a well-known vendor's name and has nothing to do with that company. More extensions can be looked up in the extension index.
Why not rename the files back or run a repair tool?
Renaming does not undo encryption. Ransomware changes the content; the extension is just the mark it leaves. Rename report.xlsx.mkp back to report.xlsx and it still won't open, and Office may call it corrupted and nudge you towards "repair". Worse, the ID, email address and extension in the name are themselves the evidence for identifying the family and version, so batch-renaming wipes out clues. Some families even store the encrypted original path at the end of the file, and ad hoc renaming only makes later reconciliation harder.
Unknown repair tools are riskier still. Programs circulating as "ransomware decryptors" or "extension repair" include a great deal of malware that can encrypt again or steal data; even a genuine decryptor can corrupt files from a mismatched version; and any tool running on the original disk writes to it, overwriting remnants that might still have been recoverable. Legitimate free decryptors come only from law enforcement and security vendors, and all of them require the family and version to be confirmed first - see ransomware decryption tools.
Be careful with the note too. An .hta file is not a web page but an application run by the Windows component mshta; CISA's Phobos advisory records attackers using mshta to launch the info.hta ransom page. Reading it in Notepad is all you need.
For the same reason, hold off on disk checks, System Restore and one-click restores of previous versions: they all write to the original disk. If you do need them, work on a copy.
Once it is confirmed as ransomware, what next?
Once confirmed, follow the full response in what to do if you've been hit by ransomware: isolate, preserve evidence, identify the family, assess recovery paths, report, and harden before reconnecting. A few reminders:
- On a personal PC, infections mostly come from cracked software, activation tools and game cheats, and STOP/Djvu is the usual culprit. K7 Labs documented it downloading the Vidar stealer before encrypting, taking saved browser credentials, cookies and cryptocurrency wallets - so change important passwords from a different, clean device.
- A work computer that can reach file shares, NAS or servers makes this an organisational incident; the machine that was noticed is rarely the only one hit.
- Recoverability depends on the family, the version and the backups, not on paying. For an honest assessment see can encrypted files be recovered.
- Send us the extension and a screenshot of the note, and the first read on the family and viable recovery paths is free.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
- First response
What should we do when a server is hit by ransomware?
Isolate first and do not reboot: cut the affected server off at the switch or in the cloud security group, but leave it running. Then snapshot or image the system and data disks, keep the ransom note and encrypted samples, and check read-only whether shadow copies, cloud snapshots and backups survived. If several servers are down, set a restore order by business dependency, and bring nothing back online until the entry point is closed and every credential has been changed. What can be recovered depends on the family, the encryption mode and the backups.
- Systems & software
What should we do when a Linux server or BT Panel is hit by ransomware?
First work out which kind of incident you have: website and database files that have genuinely been encrypted (new extensions, ransom notes in the directories), or databases that were dropped and replaced with a ransom table. The second involves no encryption, nobody can prove beforehand that the attacker kept a copy, and paying is not a recovery path. In both cases cut public access but keep the host running, do not reinstall or keep restarting the database, snapshot or image the data partition, then look for the data in backups, binlogs and disk remnants - and remove every back door before going live again.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
Related ransomware families
- Free decryptor available
Phobos
Phobos is a RaaS family that relies mainly on brute-forced RDP and has spawned a long list of variants (.eking, .faust, .elbie, .devos and more). It has been a persistent presence in Chinese server-ransomware cases, and in July 2025 Japan's National Police Agency released a free decryptor covering part of the lineage.
- No public decryptor
Makop
Makop has operated as a RaaS since 2020, with affiliates breaking in mainly through brute-forced remote desktop credentials and deploying by hand. Extensions include .makop, .mkp and .baseus, with a readme-warning.txt note. It ranks consistently high in Chinese infection statistics and has no public decryptor.
- Some versions decryptable
Crysis / Dharma
Crysis (CrySiS) and its successor Dharma have been active since 2016, breaking in through brute-forced RDP and spawning many variants including .cezar, .arena, .bip, .combo and .java. Early versions have free decryptors; the .cezar family from 2017 onward does not.
- Some versions decryptable
GlobeImposter
GlobeImposter has been active since 2017 and is highly prevalent in China through its Chinese-zodiac variants (such as .Dragon4444) and Olympian-gods variants (such as .Ares666). It spreads by brute-forcing RDP/SMB and moving laterally, and caused widespread hospital infections in China in 2018. Mainstream variants have no decryptor.
- Some versions decryptable
STOP / Djvu
STOP/Djvu is one of the highest-volume ransomware families worldwide, infecting individuals and micro-businesses mainly through software cracks, activators and game cheats. Extensions are typically four random lowercase letters and the note is _readme.txt. Files encrypted with an offline key can be decrypted free with Emsisoft's tool.
- No public decryptor
BeijingCrypt
BeijingCrypt takes its name from the .beijing extension used by early builds. It is a persistently prevalent family in China, deployed by hand after brute-forcing remote desktop or database credentials, and has cycled through .beijing, .360, .520, .halo and .bixi variants. No public decryptor exists.
Related solutions
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related services
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
FAQ
Follow-up questions
Only one kind of file won't open, say Excel - could that be ransomware?
Unlikely, but check two things. If names and extensions are unchanged and just one file type fails to open or shows a new icon, the default app has probably changed or the application is broken; try Open with and pick another program. If those files really did gain an unfamiliar extension, be careful: ransomware usually skips system folders and program files and concentrates on documents, spreadsheets, images and databases, so Excel may simply be what you noticed first. Look for a ransom note in other folders, on the desktop and on shared drives.
The file names haven't changed, but everything opens as gibberish. Is it ransomware?
It can be. A few families, Aurora among them, encrypt without renaming files or adding an extension, so folder listings look normal and the damage only shows when a file is opened - easily mistaken for an application or storage fault. Check folders and the desktop for new README-style files. If only a few files are garbled and there is no note, file corruption, an encoding mismatch or a sync conflict is more likely. When unsure, stop writing to the disk before deciding.
Files on our cloud drive or external disk changed too - what now?
They were connected or syncing when encryption ran. Disconnect the external disk and pause the sync client so encrypted versions stop overwriting the cloud copy. Then check the cloud service's web interface for earlier versions or a recycle bin, but only restore once the infected computer is offline and cannot sync again. Do not plug the external disk into another computer to see what happens; deal with it after the infection is removed and samples are preserved.
Can we upload encrypted files to an online identification site?
Yes, but only ordinary files. No More Ransom's Crypto Sheriff accepts two encrypted files of up to 1 MB each, plus any email address, URL or bitcoin address from the note; ID Ransomware accepts the note and encrypted samples but states plainly that it cannot guarantee files are kept 100% confidential. So choose samples with no customer records, financial data or personal information. Our identification tool needs no upload at all - just the extension, the note's filename or an email fragment. Any result is a direction; the same trait can match more than one family.
We already renamed the files back. Is it too late?
Renaming usually leaves the content itself unchanged, but it makes identification harder. Stop renaming now and do not run any repair tools. If some encrypted files still have their original appended names, keep them as samples, and try to recall what the extension looked like. Keep the renamed files as well - do not delete them, and do not open them with Office's repair feature and save over the originals.
Sources
- Microsoft Support - Common file name extensions in Windows
- 火绒安全 - U盘文件突然「消失」?这样解决超管用!(2026-01-13)
- CISA - #StopRansomware: Phobos Ransomware (AA24-060A, 2024-02-29)
- No More Ransom - Crypto Sheriff
- MalwareHunterTeam - ID Ransomware
- K7 Labs - STOP/DJVU Employs Vidar Stealer Before Encrypting Files (2022-07-15)
- 国家互联网应急中心 - 勒索软件防范指南(2021-07-23)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated