Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Victim Q&A · First response

My files all have a new extension and won't open - what should I do?

Short answer

Do not rename or repair anything yet. If files of many types share the same unfamiliar appended extension (often with an ID and an email address), text, HTA or HTML notes have appeared in every folder and the wallpaper has changed, it is almost certainly ransomware. If only one file type fails, USB files turned into shortcuts, or names are garbled but content opens, a file association, USB worm or encoding problem is more likely. Until you know, disconnect the network, keep the machine on, and save a sample plus the note for identification.

Key points

  • The classic ransomware combination: one unfamiliar extension across many file types, a ransom note in every folder, and a changed wallpaper or pop-up.
  • Files that are roughly the same size but unreadable point to encryption rather than ordinary corruption.
  • If only files on a USB stick have vanished or turned into same-name shortcuts, a USB worm has usually hidden the originals and the data is still there.
  • Renaming files back does not recover anything and erases identification clues; "repair tools" from the internet can cause further damage.
  • Next: disconnect but keep the power on, keep samples and the note, and identify the family with the identification tool or extension index.

In this order

What to do now

  1. Stop first: disconnect, stay powered on, pause syncing

    Until you know the cause, assume the worst: unplug the network cable, turn off Wi-Fi, disconnect external drives and USB sticks, pause cloud-drive sync, and do not reboot or shut down. If it is ransomware, this stops it reaching shares and cloud copies and preserves evidence in memory; if it turns out not to be, you have lost nothing. On a work computer, tell IT straight away.

  2. Show full file names

    Windows hides extensions for known file types by default, and you cannot judge what you cannot see. In Windows 11 File Explorer choose View > Show > File name extensions; in older versions tick File name extensions on the View tab, or clear Hide extensions for known file types in the folder options' advanced settings. Then look closely: is there something extra after the original .docx or .xlsx?

  3. Look for a ransom note and other signs

    Open a few affected folders and the desktop and look for new .txt, .hta or .html files, typically named with README, RECOVER, HELP, DECRYPT or info; check whether the wallpaper now shows an English message; sort by date modified to see whether large numbers of files changed in the same window; and check whether shares, NAS and colleagues' computers show the same. Compare against the first two sections below.

  4. Keep samples and the note

    Photograph the ransom note and keep the original file; do not delete it. A .txt note can be opened in Notepad; do not double-click an .hta note - open it in Notepad instead. Pick two or three ordinary renamed files as samples, avoiding anything with customer records, financial data or personal information. If you have an unencrypted version of one of those files, such as the original in an email attachment, keep that too; it helps materially with some families.

  5. Identify the family

    Enter the extension, the note's filename or an email fragment into the ransomware identification tool - no upload needed - or compare against the extension table below. No More Ransom's Crypto Sheriff and ID Ransomware accept sample uploads, but send only ordinary, non-sensitive files. Any match is a direction, to be confirmed against the note's content and the samples' structure.

Avoid making it worse

Do not

  • Do not rename files back to their old extensions or batch-rename anything.
  • Do not download "extension repair", "one-click decryption" or "file repair" tools and run them on the original disk.
  • Do not format, reinstall, run chkdsk or accept a Windows prompt to "scan and fix" the drive.
  • Do not delete the new .txt, .hta or .html files in your folders; they are very likely the ransom note.
  • Do not double-click an .hta note, and do not click unknown .exe files or shortcuts on a USB stick.
  • Do not upload files containing customer records, financial data or personal information to public identification sites.
  • Do not contact the email address in the file names or the note.

How can you tell whether it is ransomware?

A changed extension alone is not proof. The more of these signs you see, the more certain it is ransomware:

  • One extension everywhere. Word, Excel, images, archives and database files of different types all carry the same unfamiliar appended extension, usually with the original extension still visible before it, as in report.xlsx.unknown.
  • An ID and an email address inside the file name, in the form originalname.[ID].[attacker email].extension. This is the signature format of families common in China such as Phobos and Makop; other families append only a random string.
  • A new file in every folder, typically named with README, RECOVER, HELP, DECRYPT or info, in .txt, .hta or .html format, containing contact and payment instructions.
  • A wallpaper replaced with a ransom message, or a pop-up after logon.
  • Roughly the same size, but unreadable. In Notepad the file is solid gibberish with none of the original text visible; the size is the same or slightly larger, because some families append encrypted key data to the end of each file.
  • Concentrated in time, wide in scope. Large numbers of files changed within the same window, and files on mapped shares, NAS and external drives changed as well.
  • System-level damage. Previous versions (shadow copies) have all vanished, antivirus has been switched off, and database or backup services have stopped. CISA's advisory on Phobos, for example, records attackers deleting all shadow copies with vssadmin.

Keep two exceptions in mind: a few families do not rename files at all and leave only a note, and others replace the entire file name with random characters, which looks like garbled names. So the real test is not the extension but whether the content is encrypted and whether there is a ransom note.

If it isn't ransomware, what else could it be?

These situations also make it look as if "the extensions changed and nothing opens", but the data is usually still there:

What you seeMore likely causeHow to tell
Only one type of file won't open or its icon changed; names and extensions unchangedThe default app (file association) was changed, or that application is brokenRight-click, Open with, pick the right application; if it opens, it isn't encrypted
Names suddenly show .docx or .jpg at the endSomeone turned on "show file name extensions"; those extensions were always thereThe extensions are ordinary formats and files open normally
Files on a USB stick "vanished" or became same-name shortcuts or .exe filesA USB worm set the originals to hidden and system, then planted decoysUsed space on the stick has not dropped; the originals are usually still there - never click the decoys
File names are garbled but the files openName encoding mismatch when extracting an archive or copying between systemsContent is intact; only one archive or one copy operation is affected
"The file or directory is corrupted and unreadable", a prompt to format, or 0-byte filesFailing hard disk, USB stick or partitionNo common extension and no note, often with slow reads, errors or noises

USB worms. Huorong's January 2026 guidance explains that these worms give files the system attribute, so ticking "show hidden items" is not enough to see them. Use your security software's USB repair function, or open Command Prompt as administrator, switch to the USB drive letter and run attrib -S -H /S /D to clear the system and hidden attributes.

Disk failure. Stop reading and writing immediately, do not format, do not keep re-plugging the device and do not run disk repair; image the media first and recover from the image - see our data recovery service.

If nothing in the table fits and several signs from the previous section do, treat it as ransomware.

What do common ransomware extensions look like, and which family do they suggest?

The table only covers formats already documented in this site's family library and common in China. The note column matters: a judgement is only reliable when the extension and the note agree.

What the name or extension looks likeLikely familyNote you should also find
report.xlsx.id[8 characters-4 digits].[email].faust; also .elbie, .eight, .devos and othersPhobos lineageinfo.txt and info.hta
report.xlsx.id-8 hex digits.[email].bip; also .arena, .java, .harma and othersCrysis/Dharmainfo.hta and FILES ENCRYPTED.txt
report.xlsx.[8-character ID].[email].mkp; also .makop, .baseus and othersMakopreadme-warning.txt
An English word plus 4444 (e.g. .Dragon4444) or a Greek god plus 666 (e.g. .Ares666)GlobeImposterhow_to_back_files.html
.mallox, .malox, .bitenc and othersMalloxFILE RECOVERY.txt and similar
.rox, .weax, .wxxWeaxorRECOVERY INFO.txt
.beijing, .360, .520 and othersBeijingCrypt!RECOVER.txt or !HELP!.txt
Four random lowercase letters, e.g. .bbil (common on personal PCs)STOP/Djvu_readme.txt
9 or 16 random letters and digitsLockBit 3.0 / 5.0A README.txt starting with the same string, or ReadMeForDecrypt.txt
.lockedShared by several families, e.g. TellYouThePass and Mallox's Linux / ESXi variantYou must read the note; TellYouThePass uses README.html and similar

Two caveats. Attackers can change extensions and name formats at will, and one format can be shared - the Phobos format also appears with 8Base, and Makop is often mistaken for Phobos - so this table only points a direction. And an extension like .360 deliberately borrows a well-known vendor's name and has nothing to do with that company. More extensions can be looked up in the extension index.

Why not rename the files back or run a repair tool?

Renaming does not undo encryption. Ransomware changes the content; the extension is just the mark it leaves. Rename report.xlsx.mkp back to report.xlsx and it still won't open, and Office may call it corrupted and nudge you towards "repair". Worse, the ID, email address and extension in the name are themselves the evidence for identifying the family and version, so batch-renaming wipes out clues. Some families even store the encrypted original path at the end of the file, and ad hoc renaming only makes later reconciliation harder.

Unknown repair tools are riskier still. Programs circulating as "ransomware decryptors" or "extension repair" include a great deal of malware that can encrypt again or steal data; even a genuine decryptor can corrupt files from a mismatched version; and any tool running on the original disk writes to it, overwriting remnants that might still have been recoverable. Legitimate free decryptors come only from law enforcement and security vendors, and all of them require the family and version to be confirmed first - see ransomware decryption tools.

Be careful with the note too. An .hta file is not a web page but an application run by the Windows component mshta; CISA's Phobos advisory records attackers using mshta to launch the info.hta ransom page. Reading it in Notepad is all you need.

For the same reason, hold off on disk checks, System Restore and one-click restores of previous versions: they all write to the original disk. If you do need them, work on a copy.

Once it is confirmed as ransomware, what next?

Once confirmed, follow the full response in what to do if you've been hit by ransomware: isolate, preserve evidence, identify the family, assess recovery paths, report, and harden before reconnecting. A few reminders:

  • On a personal PC, infections mostly come from cracked software, activation tools and game cheats, and STOP/Djvu is the usual culprit. K7 Labs documented it downloading the Vidar stealer before encrypting, taking saved browser credentials, cookies and cryptocurrency wallets - so change important passwords from a different, clean device.
  • A work computer that can reach file shares, NAS or servers makes this an organisational incident; the machine that was noticed is rarely the only one hit.
  • Recoverability depends on the family, the version and the backups, not on paying. For an honest assessment see can encrypted files be recovered.
  • Send us the extension and a screenshot of the note, and the first read on the family and viable recovery paths is free.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related questions

Related ransomware families

Related solutions

FAQ

Follow-up questions

  • Only one kind of file won't open, say Excel - could that be ransomware?

    Unlikely, but check two things. If names and extensions are unchanged and just one file type fails to open or shows a new icon, the default app has probably changed or the application is broken; try Open with and pick another program. If those files really did gain an unfamiliar extension, be careful: ransomware usually skips system folders and program files and concentrates on documents, spreadsheets, images and databases, so Excel may simply be what you noticed first. Look for a ransom note in other folders, on the desktop and on shared drives.

  • The file names haven't changed, but everything opens as gibberish. Is it ransomware?

    It can be. A few families, Aurora among them, encrypt without renaming files or adding an extension, so folder listings look normal and the damage only shows when a file is opened - easily mistaken for an application or storage fault. Check folders and the desktop for new README-style files. If only a few files are garbled and there is no note, file corruption, an encoding mismatch or a sync conflict is more likely. When unsure, stop writing to the disk before deciding.

  • Files on our cloud drive or external disk changed too - what now?

    They were connected or syncing when encryption ran. Disconnect the external disk and pause the sync client so encrypted versions stop overwriting the cloud copy. Then check the cloud service's web interface for earlier versions or a recycle bin, but only restore once the infected computer is offline and cannot sync again. Do not plug the external disk into another computer to see what happens; deal with it after the infection is removed and samples are preserved.

  • Can we upload encrypted files to an online identification site?

    Yes, but only ordinary files. No More Ransom's Crypto Sheriff accepts two encrypted files of up to 1 MB each, plus any email address, URL or bitcoin address from the note; ID Ransomware accepts the note and encrypted samples but states plainly that it cannot guarantee files are kept 100% confidential. So choose samples with no customer records, financial data or personal information. Our identification tool needs no upload at all - just the extension, the note's filename or an email fragment. Any result is a direction; the same trait can match more than one family.

  • We already renamed the files back. Is it too late?

    Renaming usually leaves the content itself unchanged, but it makes identification harder. Stop renaming now and do not run any repair tools. If some encrypted files still have their original appended names, keep them as samples, and try to recall what the extension looked like. Keep the renamed files as well - do not delete them, and do not open them with Office's repair feature and save over the originals.