I crypto ransomware sono una categoria di virus ransomware che, oltre a richiedere un certo pagamento, possiedono anche la capacità di cifrare i file. Questa tipologia di virus viene anche chiamata crypto-malware o crypto-virus. Il riscatto richiesto per decifrare i dati criptati, deve essere solitamente trasferito utilizzando una valuta cifrata, solitamente Bitcoins. I file cifrati saranno bloccati e non sarà possibile leggerli dopo che il programma li avrà cifrati, programma che conterrà al suo interno un meccanismo di cifratura. In base a questo i crypto virus vengono anche chiamati crypto-locker o file-locker. Possono operare bloccando lo schermo, impedendo alle vittime di accedere ai loro computer o semplicemente cambiando lo sfondo del desktop con l’immagine di una nota di riscatto. I crypto-malware sono sviluppati dia per colpire individui singoli, che computer appartenenti a reti di grosse società. Questo tipo di minacce informatiche sono classificate tra e più pericolose tra i virus, dato che i loro sviluppatori sfruttano solitamente dei meccanismi di cifratura dati, che potrebbe dare noi anche agli ingegneri più esperti del settore. Di conseguenza, i criminali informatici sono in grado di fare grossi profitti.
La maggior parte dei crypto-locker può essere identificato dalla specifica estensione inserita nel filename allegato ai file criptati. Solitamente si tratta di un’estensione addizionale aggiunta al nome originale del file e della sua estensione. Queste estensioni possono essere semplici e essere una breve combinazione di diversi caratteri o farsi notare come una semplice frase o parola. Molto spesso riflettono il nome del crypto-programma. Tuttavia, alcune di queste estensioni malevole possono anche contenere contatti e-mail, il numero identificativo dell’infezione, l’indirizzo di pagamento di BTC, una stringa di caratteri random, etc. come asset aggiuntivo.
Comunque sia, non tutti i crypto-malware sono stati progettati per utilizzare una particolare estensione, da attaccare ai file criptati. Esistono di programmatori di crypto ransomware, che, per inseguire la gloria del crypto-virus di maggior successo, sviluppano dei programmi di cifratura di file, aggiungendo l’estensione copiata ai file colpiti per falsificare l’infezione di un altro crypto virus. Esistono anche altri crypto-locker, che, invece di colpire certi tipi di file, criptano e bloccano tutto il disco. Altre applicazioni di file-locking non rinominano i file cifrati per rendere il file corrotto non disponibile al riconoscimento quando lo si cerca per titolo. Così, sebbene l’estensione possa essere allegata possa essere un indicatore del ransomware presente, non è possibile utilizzare questo dato come unico segno identificativo per un’infezione crypto-ransomware.
-email-[email_addre...: Azer ransomware virus | .encrypted.decrypte...: Enjey ransomware |
.f41o1: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | !____GLOK9200@gmail....: Rotor Virus(Decryptors: kaspersky) |
!____cocoslim98@gmai...: Rotor Virus(Decryptors: kaspersky) | %random%.EnCrYpTeD: Pickles ransomware |
(encrypted).: HolyCrypt ransomware | *.crypt: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
*нет данных...: Vanguard Ransomware | .!___[email]_.crypt: Gomasom(Decryptors: emsisoft) |
.#<email># i...: Striked ransomware virus | .0000: 0000 ransomware virus |
.01: Amnesia ransomware(Decryptors: emsisoft) | .02: Amnesia ransomware(Decryptors: emsisoft) |
.0402: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .0x0: Ungluk Ransomware |
.1999: Ungluk Ransomware | .1AcTiv7HDn82LmJHaUf...: Crypto1coinblocker , Vista Defender Pro |
.2xx9: DevNightmare Ransomware | .31392E30362E3230313...: Kozy.Jozy Ransomware |
.31392E30362E3230313...: Kozy.Jozy Ransomware | .3P7m: Mischa Ransomware |
.3RNu: Mischa Ransomware | .492: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.4rwcry4w: 4rw5w ransomware | .666: BlackSheep ransomware |
.6Tdp: Sigma Ransomware Analysis | .707: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.725: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .726: Globe Imposter ransomware virus(Decryptors: emsisoft) , Globeimposter 2.0 Ransomware , WebSearchy.com virus |
.777: Ninja Ransomware | .7h9r: 7h9r Ransomware |
.7zipper: 7zipper Ransomware | .911: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.???: Antix Ransomware , Czech ransomware | .ACTUM: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.ANNABELLE: Annabelle ransomware | .ATLAS: ATLAS ransomware |
.AiraCropEncrypted!: AiraCrop Virus | .Alcatraz : Alcatraz Ransomware |
.BONUM: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .BRT92: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.BUSH: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .Bill_Clinton@derpym...: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.BlackRuby: BlackRuby ransomware | .BlackRuby-2: BlackRuby2 virus |
.C-email-[email]-[fi...: ODCODC ransomware(Decryptors: bleepingcomputer) | .CHIP: CHIP virus |
.CRAB: GandCrab 3 Ransomware | .CRRRT: Unlock92 ransomware |
.CRYPTOBOSS: Amnesia ransomware(Decryptors: emsisoft) | .CRYPTOSHIELD: CryptoShield ransomware |
.Cerber2: Cerber 2 Ransomware | .Crab: GandCrab 2 Ransomware |
.Cryp70n1c: Cryp70n1c Virus | .Dale: CHIP virus |
.Dexter: Shade Ransomware | .EMPTY: EMPTY ransomware virus |
.ENCR: AutoEncryptor ransomware , FileLocker ransomware | .ENCRYPTED_BY_LLTP: LLTP ransomware , No Malware |
.Encrypted: aZaZeL virus | .FFF: Virus-encoder |
.GDCB: GandCrab ransomware , Record Checker App | .GRANNY: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.H3LL: Ungluk Ransomware | .HA3: El Polocker Ransomware |
.H_F_D_locked: Blackhat ransomware virus , MoWare HFD ransomware | .HakunaMatata: Hakunamatata Ransomware |
.Hollycrypt: HollyCrypt virus | .I\\'WANT MO...: Jigsaw Ransomware(Decryptors: bleepingcomputer) |
.ID-*8characters+cou...: Apocalypse Ransomware(Decryptors: emsisoft) | .ID-[A-Fo-9],{8}+cou...: Apocalypse Ransomware(Decryptors: emsisoft) |
.JezRoz: Rannoh trojan(Decryptors: kaspersky) , SZFLocker Ransomware(Decryptors: avg) , FenixLocker Ransomware(Decryptors: emsisoft) , KeRanger Ransomware(Decryptors: bleepingcomputer) , LeChiffre Ransomware(Decryptors: emsisoft) , Nemucod ransomware(Decryptors: emsisoft) , Telecrypt Ransomware(Decryptors: box) , CoinVault(Decryptors: kaspersky) , Nemucod-AES ransomware virus(Decryptors: emsisoft) , UmbreCrypt(Decryptors: emsisoft) , 8lock8 ransomware(Decryptors: bleepingcomputer) , InfiniteTear ransomware virus , Win32/Bubnix | .KEYH0LES: Mobef Ransomware |
.KEYHOLES: Yakes Ransomware | .KEYZ: Mobef Ransomware |
.LEGO: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .LIGHTNING: LightningCrypt ransomware |
.LOCKED: GOG ransomware | .LOCKED_BY_pablukl0c...: MADA Ransomware |
.Lime: LimeDecryptor ransomware | .MIKOYAN: Den Svenska Polisen IT-Sakerhet virus , Mikoyan ransomware |
.MOLE: Mole Ransomware | .MRCR1: Merry Christmas ransomware |
.NIGGA: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .NM4: NM4 ransomware |
.NumberDot.: AngryKite ransomware | .OMG!: DirtyDecrypt ransomware |
.OXR: OXAR ransomware virus | .OhNo!: OhNo! ransomware virus |
.Ordinal: Ordinal ransomware | .PAY: Jigsaw Ransomware(Decryptors: bleepingcomputer) |
.PEGS1: Merry Christmas ransomware | .PHOBOS: Phobos Ransomware virus |
.R5A: 7ev3n Ransomware | .RARE1: Merry Christmas ransomware |
.RENSEMWARE: RensenWare virus , TDSS rootkit | .REVENGE: Revenge ransomware |
.REYPTSON: Reyptson virus | .ReaGan: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.RedEye: RedEye ransomware | .SERVER: Server CryptoMix virus |
.SHARK: Shark ransomware V2 | .SUPERCRYPT: SuperCrypt Ransomware |
.SaherBlueEagleRanso...: BlueEagle ransomware | .SecureCrypted: SecureCryptor Ransomware |
.Spartacus: Spartacus ransomware | .THANATOS: THANATOS ransomware virus |
.TRMT: Amnesia ransomware(Decryptors: emsisoft) | .TheTrumpLockerf: TrumpLocker ransomware |
.TheTrumpLockerp.: TrumpLocker ransomware | .UNLIS: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.VBRANSOM: VBRANSOM virus | .Venusf: VenusLocker ransomware |
.VforVendetta: SamSam Ransomware | .WAmarlocked: Balbaz ransomware |
.WHITEROSE: WhiteRose Ransomware Virus | .WINDOWS: $ UcyLocker virus |
.WORK: WORK ransomware virus | .WSmile: Wannasmile Ransomware |
.Wana Decrypt0r Troj...: Trojan-Syria virus | .Whereisyourfiles: SamSam Ransomware |
.YAYA: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .YYTO: YYTO ransomware |
.ZINO: Security Master , ZinoCrypt ransomware | .ZW: ZONEware ransomware virus |
.Zenis- <2_chars...: Zenis ransomware | .[4 digits random ex...: Deadly ransomware |
.[5 random character...: Alma Locker Ransomware | .[6 letters]: CryptoLocker |
.[Cho.dambler@yandex...: WininiCrypt ransomware virus | .[[email protected]].LOC...: Amnesia ransomware(Decryptors: emsisoft) |
.[[email protected]...: BugWare virus | .[a random combinati...: Princess Locker ransomware |
.[a-z0-9]: Diamond Computer Encryption ransomware virus | .[[email protected]...: Dharma Ransomware |
.[[email protected]].SON...: Amnesia ransomware(Decryptors: emsisoft) | .[chines34@protonmai...: Gryphon ransomware virus |
.[email]: Gingerbread Ransomware | .[email] : OpenToYou ransomware(Decryptors: emsisoft) |
.[email].BRT92: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .[email].aleta: BTCWare Aleta virus |
.[email].xtbl: Green_Ray Ransomware , VegClass ransomware | .[email].xtbl : Redshitline Ransomware |
.[[email protected]]...: Everbe Virus | .[[email protected]...: Gryphon ransomware virus |
.[payment_email].ID[...: CryptoMix virus | .[random]: InfinityLock ransomware virus , LockedByte ransomware , My Decryptor ransomware virus , Skull ransomware virus , Web.mappingdo.net popup |
.[[email protected]....: Skeleton Ransomware | .[[email protected]]...: Napoleon virus |
.[[email protected]]....: Twist ransomware | .[victim_id]_luck: CryptoLuck Ransomware |
._[ID Number].UIWIX: UIWIX ransomware | .__dilmaV1: DilmaLocker ransomware virus |
._xratteamLucked: TeamXRat Ransomware(Decryptors: trendmicro, emsisoft) | .a19: JokeFromMars Ransomware |
.aRpt: Mischa Ransomware | .aaa: TeslaCrypt(Decryptors: avg) |
.ace: WinRarer virus | .adk: Angry Duck ransomware |
.adr: PyteHole ransomware , Virus Total 2010 | .aes: Polski virus |
.aesir: Locky virus | .amnesia: Amnesia ransomware(Decryptors: emsisoft) |
.ap19: JokeFromMars Ransomware | .armadilo1: ArmaLocky ransomware virus |
.asasin: Asasin ransomware | .b10cked
.matrix: Matrix ransomware , Soraxi.com virus |
.bam: Bam! ransomware virus | .bart: Bart Ransomware(Decryptors: avg) |
.bin: Alfa Ransomware | .bitcoin: Bansomqare ransomware |
.bitkangoroo: BitKangoroo ransomware | .blackfeather: Black Feather ransomware |
.bleep: Ungluk Ransomware | .breaking_bad: Shade Ransomware |
.breeding123: SamSam Ransomware | .brickr: BrickR Ransomware Virus |
.btc: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .btc-help-you: SamSam Ransomware |
.btcbtcbtc: SamSam Ransomware | .bud: Bud ransomware virus |
.cRh8: Mischa Ransomware | .canihelpyou: SamSam Ransomware |
.cerber: Cerber Ransomware | .cerber2: Cerber Ransomware |
.cerber3: Cerber Ransomware | .cfm: CryForMe virus |
.cifgksaffsfyghd: SamSam Ransomware | .code: CryptoMix virus |
.coded: Globe Imposter ransomware virus(Decryptors: emsisoft) , Anubis ransomware , WebSearchy.com virus | .comrade: Comrade Circle Ransomware |
.coverton: Coverton Ransomware | .crack: Anoncrack ransomware virus |
.cradle: Cradle ransomware | .creeper: Creeper ransomware |
.crinf: CryptInfinite(Decryptors: emsisoft) | .crjoker: CryptoJoker ransomware |
.crptd: Naampa ransomware virus | .crptrgr: CryptoRoger ransomware |
.cry: AntiAID , Cry ransomware , CryPy Ransomware , DoNotChange ransomware , Hi Buddy Ransomware | .cry_: PaySafe Generator Ransomware |
.cryakl: Cryakl Ransomware(Decryptors: kaspersky) | .cryp1: CryptXXX ransomware(Decryptors: kaspersky) , UltraCrypter ransomware |
.crypt: CryptXXX ransomware(Decryptors: kaspersky) , Chimera ransomware(Decryptors: kaspersky) , DynA-Crypt ransomware , NoobCrypt Ransomware , R980 Ransomware , Ransomnix virus | .crypt38: Crypt38 ransomware(Decryptors: bleepingcomputer) |
.crypte: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .crypted: Dxh26wam ransomware , Fatboy ransomware , Retis ransomware |
.crypted_file: Kangaroo Ransomware | .crypto: Zimbra Ransomware |
.cryptotorlocker2015...: CryptoTorLocker(Decryptors: ransomwareanalysis) , Personal Anti Malware | .crypz: CryptXXX ransomware(Decryptors: kaspersky) |
.crysis: Crysis Ransomware(Decryptors: kaspersky) | .cuck: RansomCuck Ransomware |
.czvxce: Coverton Ransomware | .damoclis: Damoclis gladius virus |
.decrypt2017 and .hn...: Globe Ransomware(Decryptors: emsisoft) | [email protected]...: Wyvern ransomware |
.ded: DedCryptor ransomware | .deria: DeriaLock ransomware |
.destroy.executioner...: ExecutionerPlus ransomware | .devil: CryptoDevil ransomware |
.diablo6 : Control Manager , Diablo6 ransomware | .dkdfln: Random6 virus |
.dxxd: DXXD Ransomware | .eQTz: Mischa Ransomware |
.ebay: eBayWall Ransomware virus | .ecc: TeslaCrypt(Decryptors: avg) |
.ecrypt: Erebus ransomware , SafetyGuard | .email-[email].[vers...: Vipasana ransomware |
.enc: MadBit Ransomware , TrueCrypt Ransomware | .encedRSA: SamSam Ransomware |
.encry: Iron ransomware | .encrypt: GIBON virus |
.encrypted: Apocalypse Ransomware(Decryptors: emsisoft) , Crypren ransomware(Decryptors: Downloads\Compressed\DecryptCrypren-master) , CuteRansomware Virus(Decryptors: github) , Coin Locker Ransomware , Crypto Wire ransomware , Esmeralda Ransomware , Fake WindowsUpdater ransomware , GX40 ransomware , HugeMe ransomware , Smrss32 Ransomware , Trump Ransomware , Turkish FileEncryptor ransomware , VapeLauncher virus , Vista AntiMalware 2010 , WolfRam Antivirus | .encryptedAES: SamSam Ransomware |
.encryptedRSA: SamSam Ransomware | .encryptile: Encryptile ransomware |
.enigma: Coverton Ransomware , Enigma Ransomware | .enjey: Enjey ransomware |
.evil: Negozl Ransomware | .evillock: EvilLock virus |
.exe: VirLock Ransomware | .exo: Atchbo ransomware |
.exotic: Exotic Ransomware | .explorer: Explorer Ransomware virus |
.ezz: Alpha Crypt Ransomware(Decryptors: bleepingcomputer) | .f**k_you_ av_we_are...: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.fantom: Fantom ransomware | .filock: Popcorn Time Ransomware |
.firecrypt: FireCrypt ransomware | .flyper: Flyper Ransomware |
.frtrss: CryptoFortress virus | .fu*k: Ungluk Ransomware |
.fucked: Malabu ransomware , Rijndael ransomware | .fucku: hc6 ransomware |
.fun: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .gefickt: Jigsaw Ransomware(Decryptors: bleepingcomputer) |
.godra: Godra ransomware | .gotham: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.gotya: hc6 ransomware | .greystars@protonmai...: Greystars ransomware virus |
.gws: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .hacked: In-Development Ransomware |
.hainch: BKRansomware | .happydayzz: HappyDayzz ransomware |
.heisenberg: Shade Ransomware | .help: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.herbst: Herbst ransomware | .hermes: Hermes ransomware |
.horros: Horros ransomware | .hush: Jigsaw Ransomware(Decryptors: bleepingcomputer) |
.hydracrypt: Hydracrypt(Decryptors: emsisoft) | .id-[A NUMBER]_locke...: X3M ransomware |
.id-[A NUMBER]_r9oj: X3M ransomware | .id-[A NUMBER]_x3m: X3M ransomware |
.id-[ID]-[email].inf...: Pizzacrypts Ransomware | .id-[ID].[email].xtb...: Mahasaraswati ransomware |
.id-[ID].okean-1955@...: Okean- 1955 Ransomware | .id-[ID]_[email1]_[e...: Juicylemon ransomware |
.id-[id].[email].are...: Arena ransomware virus , Vista Smart Security 2010 | .id-{ID Number}_fud@...: BandarChor ransomware |
.id_[ID]_[email].rmd: Zeta Ransomware | .id_[ID]_[email].scl: Zeta Ransomware |
.ifuckedyou: SerbRansom virus | .improved: Vurten ransomware |
.ipygh: Karo virus | .isis: EduCrypt ransomware |
.jaff: Jaff ransomware , PC Live Guard | .jeepers: JeepersCrypt ransomware |
.jodis: ScammerLocker ransomware , SecureDefense | .josep: JosepCrypt virus |
.justbtcwillhelpyou: SamSam Ransomware | .karma: Karma Ransomware |
.kcwenc: KCW ransomware | .keepcalm: Keep Calm Ransomware |
.kencf: Kaandsona Ransomware , Total Protect | .kgpvwnr: My Decryptor ransomware virus |
.kirked: Kirk virus | .kkk: Jigsaw Ransomware(Decryptors: bleepingcomputer) , KKK virus |
.kokolocker: KoKo Locker | .kraken: Kraken ransomware |
.lambda_l0cked: LambdaLocker ransomware | .lamo: EyLamo virus |
.lcked: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .letmetrydecfiles: SamSam Ransomware |
.llawex: Random6 virus | .lmao: LMAOxUS Ransomware |
.lock: LockCrypt virus , Zyka ransomware | .lock75: TAR-Fluffy ransomware |
.lock93: Lock93 Ransomware | .locked: Stampado Ransomware(Decryptors: emsisoft) , Globe Ransomware(Decryptors: emsisoft), OzozaLocker Ransomware(Decryptors: emsisoft) , Philadelphia Ransomware(Decryptors: emsisoft) , BitPaymer virus , CrY-TrOwX ransomware , CryptoShocker Ransomware , FabSysCrypto ransomware , File-Locker ransomware virus , GNL Locker Ransomware , Guster ransomware , KoreanLocker ransomware , May ransomware , MMLocker Ransomware , ORX-Locker Ransomware , RedBoot ransomware virus , Russian Eda2 Ransomware , Shark Ransomware , Ultimo Ransomware Virus , VirLock Ransomware , WickedLocker ransomware , Zelta Free ransomware , Zyklon Locker |
.locked-by-mafia: MafiaWare Ransomware | .locklock: LockLock Ransomware |
.locky: Jhash virus , Locky virus , NoobCrypt Ransomware , StorageCrypter Ransomware | .lok: Anatel Ransomware |
.losers: Cry36 Losers virus | .lovewindows: Globe Ransomware(Decryptors: emsisoft) |
.lukitus: Lukitus ransomware virus | .m0on: M0on ransomware |
.madebyadam: Roga ransomware | .maktub: AiraCrop Virus |
.maysomware: May ransomware | .mention9823: SamSam Ransomware |
.mordor: Mordor ransomware | .mrblock: MBRlock ransomware virus |
.mtk118: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .nWcrypt: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.needdecrypt: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .needkeys: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.neitrino: Neitrino ransomware | .nightmare: Foxy Ransomware |
.no_more_ransom: Shade Ransomware | .novalid: Locked-in virus |
.ocean: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .odcodc: ODCODC ransomware(Decryptors: bleepingcomputer) |
.odin: Locky virus , ODIN ransomware | .oni: Oni ransomware |
.only-we_can-help_yo...: SamSam Ransomware | .oops: OopsLocker virus |
.osiris: Locky virus | .padcrypt: PadCrypt |
.payforunlock: CryptoGod virus | .payransom: Invisible Empire Ransomware |
.paytounlock: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .pec: PEC 2017 ransomware |
.pluss.executioner: ExecutionerPlus ransomware | .pmxkab: Random6 virus |
.pnr: Pendor ransomware virus | .porno: CryptoHitman Ransomware |
.poshcoder: POSHCODER | .potato: Potato ransomware |
.pr0tect: Pr0tector ransomware | [email protected]: Project34 ransomware |
.protected: Protected Ransomware | .pscrypt: PSCrypt virus |
.psh: PshCrypt ransomware | .pubg: PUBG ransomware |
.purge: Globe Ransomware(Decryptors: emsisoft) | .pwned: Decryption Assistant ransomware |
.qwerty: QwertyCrypt ransomware | .rack: RackCrypt Ransomware |
.rand: RandomLocker virus | .ransomcuck: RansomCuck Ransomware |
.rapid: Rapid Ransomware | .razy: Razy ransomware |
.rdm: Radamant ransomware(Decryptors: emsisoft) | .rdmk: CryptoMix virus |
.reaGAN: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | [email protected]....: Globe Ransomware(Decryptors: emsisoft) |
.resurrection: Resurrection virus | .rip: KillerLocker ransomware |
.robinhood: RobinHood Ransomware | .rokku: Rokku Ransomware |
.rose: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .rrk: Radamant ransomware(Decryptors: emsisoft) |
.rumblegoodboy: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .sad: SADStory ransomware |
.sage: Sage 2 ransomware , Sage Ransomware , Secure Veteran | .sanction: Sanction Ransomware |
.sea: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .serp: Serpent virus |
.serpent: Serpent virus | .sexy: MyPcSecure , PayDay Ransomware |
.shit: Locky virus | .skjdthghh: SamSam Ransomware |
.skunk: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .sorry: Sorry Ransomware Virus |
.spider: File Spider ransomware , HDD Tools | .stn: DeadEye , Satan ransomware |
.styx: Styx ransomware | .suppose666: SamSam Ransomware |
.sux: Jigsaw Ransomware(Decryptors: bleepingcomputer) | .switch: KillSwitch ransomware |
.tastylock: TastyLock ransomware | .tdelf: TheDarkEncryptor virus |
.theworldisyours: SamSam Ransomware | .thor: Locky virus |
.triple_m
.info: McAVG 2011 , TripleM Ransomware | .ttt: TeslaCrypt(Decryptors: avg) |
[email protected]...: Jigsaw Ransomware(Decryptors: bleepingcomputer) | [email protected]: Globe Ransomware(Decryptors: emsisoft) |
.upzbrf: Random6 virus | .versiegelt: Versiegelt ransomware |
.via: ViaCrypt Ransomware Virus | .viiper: ViiperWare virus |
.viki: CryptoViki ransomware | .vindows: Vindows Locker Ransomware |
.vvv: Win Defender 2009 | .wallet: Sanctions Ransomware |
.wannacry: Trojan-Syria virus | .wcry: Wcry virus |
.wflx: WildFire Locker virus(Decryptors: mcafee) | .whycry: WhyCry virus |
.wndie: WanaDie virus | .wnx: Onyx virus |
.write_me_[btc2017@i...: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus | .write_on_email: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.xdata: PC Internet Security 2010 , SystemArmor , XData ransomware | .xtbl: Scarab-XTBL Ransomware , Shade Ransomware |
.xxx: TeslaCrypt(Decryptors: avg) | .yl: ChinaYunLong virus |
.ytbl: Shade Ransomware | .zCrypt: zCrypt Ransomware |
.zXz: AP Manager , RanRan ransomware | .zepto: Locky virus , Zepto ransomware |
.zn2016: ZeroCrypt ransomware | .zuzya: Globe Imposter ransomware virus(Decryptors: emsisoft) , WebSearchy.com virus |
.zyklon: Zyklon Locker | .~: Tilde ransomware |
.~HL: HadesLocker virus | 8-random-characters....: Gedantar ransomware |
@kee: Kee ransomware | ENC: UnblockUPC Ransomware |
HUSTONWEHAVEAPROBLEM...: Matroska Ransomware | Heimdall---: Heimdall Ransomware |
KK_.: KK_ ransomware | Lock.: MIRCOP Ransomware(Decryptors: kaspersky) , Aviso Ransomware |
Locked-jCandy: jCandy ransomware virus | N/A: Hand of God Virus |
[customised]: Goliath Ransomware , Ransom32 ranswomare | [[email protected]].gryph...: Gryphon ransomware virus |
[email].xtbl: Ecovector Ransomware | [email]___: SATANA Ransomware |
[full disk]: Petya ransomware | [gladius_rectus@aol....: Gryphon ransomware virus |
[id]=hernansec@proto...: Kristina ransomware virus | [[email protected]]....: MaxiCrypt ransomware |
[none]: BadBlock Ransomware(Decryptors: avg, emsisoft) , DMA-Locker ransomware(Decryptors: emsisoft) , NanoLocker Ransomware(Decryptors: github) , Alphabet virus(Decryptors: bleepingcomputer) , Adonis ransomware , Advanced Virus Remover System Warning , All_Your_Documents ransomware , Bad Rabbit virus , Blooper virus , CryptoDark virus , CryptoJacky ransomware , CyberSplitter ransomware , CYR-Locker ransomware , Defray ransomware virus , Extreme Security 2010 , FadeSoft ransomware , InterYield pop-up , Jew Crypt ransomware , Kaenlupuf virus , Karmen ransomware , Kryptonite virus , LataRebo Locker ransomware , LockeR ransomware , Meteoritan virus , Monument ransomware , Mood Tube App , My Security Suite , NTK ransomware , PC Antivirus Pro , PetrWrap ransomware , qkG ransomware , Radiation virus , Ranion ransomware , Red Cross Antivirus , SkyName ransomware , Spora virus , TowerWeb ransomware , Trojan-BNK.Win32.Keylogger.gen , VHDLocker Ransomware , WannaBeHappy ransomware , WannaCryptor ransomware | [random]: HELP_YOUR_FILES virus , Maktub Locker , Princess Locker 2.0 ransomware , Registry Defender Platinum |
[restoreassistant2@t...: Locked_File ransomware virus | [suupport@protonmail...: Scarab Ransomware |
[[email protected]]....: Master virus | [unknown]: Locker ransomware(Decryptors: bleepingcomputer), \"Your Computer was Automatically Blocked. Reason: Pirated Software\" ransomware , ABCLocker ransomware virus , Buyunlockcode ransomware , Cryptobot virus , Cryptorbit virus , FileFrozr ransomware , Gruxer ransomware , J. Sterling ransomware , Katafrack ransomware , KEYHolder , Kripto64 ransomware , R ransomware , Schwerer ransomware |
[user_ID]: Sad ransomware | _: TBlocker virus |
_Ink.HavocCrypt!: Havoc ransomware | _[[email protected]]: Relock ransomware virus |
_[original_extension...: Computer Fix , VisionCrypt ransomware | ____tarTrojan-Ransom...: Rotor Virus(Decryptors: kaspersky) |
_crypt: Crypton ransomware(Decryptors: emsisoft) | _crypt0.: Crypt0 Ransomware |
[email protected] _: Best-click-scanner.info , FLKR Ransomware | _nullByte: NullByte ransomware |
iaufkakfhsaraf: SamSam Ransomware | id-[ID].{payfornatur...: Payfornature Ransomware |
id-[affiliate_id].[a...: Paradise Ransomware | id.-[ID].[email].xtb...: JohnyCryptor ransomware |
none: Ender Ransomware , FCP ransomware | oorr.: LowLevel04 Ransomware |
picture.id-xxx.[vauv...: Arrow ransomware virus | unknown: LockOn Virus |
various: 8chan ransomware virus | ╘: Zlocker virus |