Windows 10: What happens if you rename a file extension to a ransomware extension?

Discus and support What happens if you rename a file extension to a ransomware extension? in AntiVirus, Firewalls and System Security to solve the problem; Hi,So I was reading about the SOVA ransomware when suddenly I started wondering about what would happen if I changed the file extension of a safe file... Discussion in 'AntiVirus, Firewalls and System Security' started by Joe13 B- 2.0, Sep 17, 2022.

  1. What happens if you rename a file extension to a ransomware extension?


    Hi,So I was reading about the SOVA ransomware when suddenly I started wondering about what would happen if I changed the file extension of a safe file to a ransomware's file extension for example, picture.jpg converts to picture.djvu, the extension for one of the oldest variants of the STOP ransomware. Obviously, Google didn't show anything related to my doubt.I believe that the file won't actually become corrupt and wouldn't infect other files. Any insights? Thanks,Joe13 B- 2.0PS: apologies if this shouldn't be in the V&M forum, but I felt it's more apt.

    :)
     
    Joe13 B- 2.0, Sep 17, 2022
    #1

  2. Bug in massive file extension renaming

    I'm found a wrong behavior in changing the file extension for more than one file.

    Having selected many file by the standard win10 file browser (Win10 v1909), I try to change the extension in one shot (by F2 key, by context menu, by Ribbon too).

    The regular box (on the file name to rename it) is opened and I can change/add the extension.

    When I press Return, all the selected file are renamed (I need to take care just of ext, not about name)

    The behavior I expect is to see the new extension on all files.

    Instead, previous ext is manteined and it is duplicated. The new extension simply discarted.

    Esample on two files, selected and pressing F2 on the first one
    (3).delme
    (4).delme

    Case "A": Changing/sustitution of current ext ".delme" by ".xml", they remains:

    (3).delme

    (4).delme

    case "B" : Adding the further extension ".xml" (to abtain "(3).delme.xml"), they became:
    (3).delme.delme
    (4).delme.delme

    Then, I suppose is not possible a massive file renaming for just extensions.
     
    paolo guccini, Sep 17, 2022
    #2
  3. Files encrypted by TeslaCrypt (.vvv extension) ransomware

    You're computer is infected with a newer variant of
    TeslaCrypt/Alpha Crypt
    .

    The following is a copy/paste of another reply of quietman7 MS MVP in another Bleeping Computer thread:

    http://www.bleepingcomputer.com/forums/t/598923/cryptolocker-telsadecoder/


    QUOTE

    You are dealing with a newer variant of
    TeslaCrypt/Alpha Crypt
    . TeslaCrypt includes several known versions with various extensions for encrypted files to include: .ecc, .ezz, .exx, .zzz, .xyz, .aaa, .abc, .ccc., .vvv...as described

    here
    . Some of the new variants are
    disguised as CryptoWall
    .


    Any files that are encrypted with the newer variant of TeslaCrypt will have the
    .exx, .xyz, .zzz, .aaa,
    .abc, .ccc or .vvv extension appended to the end of the filename. The .aaa/.abc/.ccc/.vvv variants leave .html, .txt, files (ransom notes) with names like RECOVERY_FILE_*****.txt, restore_files_*****.txt, recover_file_*****.txt,
    HOWTO_RESTORE_FILES_*****.txt, howto_recover_file_*****.txt, _how_recover_*****.txt, how_recover+***.txt (where * are random characters). More information in these BC news articles:


    A repository of all current knowledge regarding TeslaCrypt,
    Alpha Crypt and newer variants is provided by
    Grinler
    (aka
    Lawrence Abrams
    ), in this topic:
    TeslaCrypt and Alpha Crypt Ransomware Information Guide and FAQ


    Information about and support for decrypting files affected by Alpha Crypt & TeslaCrypt ransomware can be found in this topic:

    There is an ongoing discussion in this topic where you can ask questions and seek further assistance.

    Rather than have everyone start individual topics, it would be best (and more manageable for staff) if you posted any questions, comments or requests for assistance in that topic discussion. Doing that will also ensure you receive proper assistance from
    our crypto malware experts since they may not see this thread.


    UNQUOTE

    ===================================================================

    Also please see the replies of
    RickCP


    here:
    http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/files-encrypted-by-teslacrypt-ransomware/77b05496-fb09-4e01-ab36-db92213dd825?page=2&msgId=c26b605a-420f-40bc-9541-584492bab180


    and

    here:
    http://answers.microsoft.com/en-us/protect/forum/mse-protect_scanning/ransomhtmltescryptd/163bb48e-4932-4296-bc0c-18e25732e2a8?msgId=db3497db-8c32-4241-9c9c-4e08bf793457


    Cheers,

    J

    Later EDIT: Pls see RickCP's UPDATED INFO (January 2016) here:
    http://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning/files-encrypted-by-teslacrypt-vvv-extension/77b05496-fb09-4e01-ab36-db92213dd825?page=2&msgId=0c010b83-a5a8-441f-8950-a268dd83ea18
     
    Jsssssssss, Sep 17, 2022
    #3
  4. What happens if you rename a file extension to a ransomware extension?

    Files encrypted by Extension (.ghfghfghfgh) ransomware

    Globe Ransomware will leave files (ransom notes) named How to restore files.hta but it uses a different extension so you may be dealing with a new variant or something entirely new.

    I suggest you read and follow these instructions...How to Post a Topic Asking for Help With
    Ransomware


    Samples of any encrypted files, ransom notes or suspicious executables (installer, malicious files, attachments) that you suspect were involved in causing the infection can be submitted
    here with a link to the new topic you start asking for assistance. Doing that will be helpful with
    analyzing and investigating by our crypto experts.

    These are some
    common folder variable
    locations malicious executables and .dlls hide:

    %SystemDrive%\ (C:\)

    %SystemRoot%\ (C:\Windows, %WinDir%\)

    %Temp%\

    %AllUserProfile%\

    %UserProfile%\

    %AppData%\

    %LocalAppData%\

    %ProgramData%\
     
    quietman7 - MVP, Sep 17, 2022
    #4
Thema:

What happens if you rename a file extension to a ransomware extension?

Loading...
  1. What happens if you rename a file extension to a ransomware extension? - Similar Threads - happens rename file

  2. Ransomware convert my file extensions to .hoop

    in AntiVirus, Firewalls and System Security
    Ransomware convert my file extensions to .hoop: Hi ,I'm using windows 10 Pro. Recently I got a virus in my pc. It attaches .hoop extension in every files. And it leaves a readme file shown below . How can I remove this virus? Please somebody help me. I have so many important files.[Original Title: .hoop Virus]...
  3. Ransomware qlkm extension.

    in AntiVirus, Firewalls and System Security
    Ransomware qlkm extension.: Split from this thread. Please read the first page of theSTOP DJVU Ransomware Support Topic for an updated summary of this ransomware, it's variants andpossible decryption solutions with instructions. The decrypter will only attempt to decrypt a file with a known ID...
  4. ".erif" file extension ransomware need solution on this!!

    in AntiVirus, Firewalls and System Security
    ".erif" file extension ransomware need solution on this!!: Hello, My laptop has got infected with ".erif" extension ransomware which has encrypted all my data in laptop i can't access any of my files. Even i can't access start button and anything on taskbar. This ransomware has slow down my laptop and when i open any browser window...
  5. Bug in massive file extension renaming

    in Windows 10 Network and Sharing
    Bug in massive file extension renaming: I'm found a wrong behavior in changing the file extension for more than one file. Having selected many file by the standard win10 file browser Win10 v1909, I try to change the extension in one shot by F2 key, by context menu, by Ribbon too. The regular box on the file name...
  6. Ransomware with ".wlzfgvn" file extension

    in AntiVirus, Firewalls and System Security
    Ransomware with ".wlzfgvn" file extension: Split from this thread. I have a ransomware attack, and the files end with ".wlzfgvn". I dont know what to do. https://answers.microsoft.com/en-us/protect/forum/all/ransomware-with-wlzfgvn-file-extension/7be18b02-73b5-4ad7-acad-094e4dc790d9
  7. HEROSET ransomware .heroset extension

    in AntiVirus, Firewalls and System Security
    HEROSET ransomware .heroset extension: I am unable to open any documents and photos or pdf file(all file is decrypted). .heroset extension is showing. ATTENTION! Don't worry, you can return all your files! All your files like photos, databases, documents and other important are encrypted with strongest...
  8. Files encrypted by (.ACFJKSO extension) ransomware

    in AntiVirus, Firewalls and System Security
    Files encrypted by (.ACFJKSO extension) ransomware: Dear Team, I am facing an issue with my windows 10 PC that some of my documents are renamed with '.ACFJKSO' extension. If I am trying to rename the file nothing is happening. From these symptoms I realized that it is a Torjan- Ransom like CBT- Locker. Does any one have a...
  9. Ransomware- TRO file extension

    in AntiVirus, Firewalls and System Security
    Ransomware- TRO file extension: I have been attacked by a ransomware virus and at the same time my windows was crashed. When reinstalled the window i notify that i am hunted by some bad person. Know i am unable to use my files. All the files are added with file extension .tro, please help me. * Moved from...
  10. RANSOMWARE VIRUS .DJVUS extension

    in AntiVirus, Firewalls and System Security
    RANSOMWARE VIRUS .DJVUS extension: My all files encrypted to .DJVUS extension ( I'm want my files back) please help me out for this regards..??? https://answers.microsoft.com/en-us/protect/forum/all/ransomware-virus-djvus-extension/bdab87f9-ba8f-4928-bf72-159d42dcb935