Search
Keyword: bat
\README_TO_DECRYPT.html It avoids encrypting files with the following file extensions: exe dll sys msi mui inf cat bat cmd ps1 vbs ttf fon lnk Win64:RansomX-gen [Ransom] (AVAST) Downloaded from the Internet, Dropped by
\HLJkNskOq.README.txt It avoids encrypting files with the following file extensions: 386 adv ani bat bin cab cmd com cpl cur deskthemepack diagcab diagcfg diagpkg dll drv exe hlp hta icl icns ico ics idx key ldf lnk lock
ransom note: {All available directories}/README-RECOVER-ytY81v7ip.txt It avoids encrypting files with the following file extensions: themepack nls diapkg msi lnk exe scr bat drv rtp msp prf msc ico key ocx
\README-RECOVER-VayvEy6cPo.txt It avoids encrypting files with the following file extensions: 386 adv ani bat bin cmd com cpl cur deskthemepack diagcab diagcfg diapkg dll drv exe hlp hta icl icns ico ics idx key lnk lock mod mpa
encrypted files: .FSx0EaYuE It drops the following file(s) as ransom note: {encrypted directory}\FSx0EaYuE.README.txt It avoids encrypting files with the following file extensions: 386 adv ani bat bin cab cmd
files with the following extensions: 3ds 3g2 3gp 7z aac abw ac3 accdb ai aif aiff amr apk app asf asx atom avi bak bat bmp bup bz2 cab cbr cbz cda cdr chm class cmd conf cow cpp cr2 crdownload cs csv cue
the following file(s) as ransom note: {All Available Directories}\README-RECOVER-CcXB9wE4s7.txt It avoids encrypting files with the following file extensions: themepack nls diapkg msi lnk exe scr bat
avoids encrypting files with the following file extensions: 386 adv ani bat bin cab cmd com cpl cur deskthemepack diagcab diagcfg diagpkg dll drv exe hlp hta icl icns ico ics idx key ldf lnk lock mod mpa
bat cmd gandcrab KRAB CRAB zerophage_i_like_your_pictures {Generated random characters appended on encrypted file names} delete shadow copies It checks for the presence of the following antivirus and
msu msi nls scr adv 386 com hlp rom lock 386 wpx ani prf rtp ldf key diagcab cmd spl deskthemepack bat themepack Trojan-Ransom.NetWalker (IKARUS); Ransom:Win32/NetWalker.S!MTB (MICROSOFT) Dropped by
rtp mallox sys nomedia dll hta cur lock cpl Globeimposter-Alpha865qqz ics hlp com spl msi key mpa rom drv bat 386 adv diangcab mod scr theme ocx prf cab diagcfg msu cmd ico msc ani icns diagpkg
the following file extensions: exe dll sys msi mui inf cat bat cmd ps1 vbs ttf fon lnk .quantum Ransom:Win32/QuantumLocker.MAK!MTB (MICROSOFT) Dropped by other malware, Downloaded from the Internet
agdl ai aiff ait al aoi apj arc arw asc asf asm asp aspx asx avi awg back backup backupdb bak bank bat bay bdb bgt bik bin bkp blend bmp bpw brd c cdf cdr cdr3 cdr4 cdr5 cdr6 cdrw cdx ce1 ce2 cer cfg cgm
encrypting files with the following file extensions: 386 adv ani bat bin cab cmd com cpl cur deskthemepack diagcab diagcfg diagpkg dll drv exe hlp hta icl icns ico ics idx key ldf lnk lock mod mpa msc msi msp
icon to the following image: It avoids encrypting files with the following file extensions: 386 adv ani bat bin cab cmd com cpl cur deskthemepack diagcab diagcfg diagpkg dll drv exe hlp hta icl icns ico
avi awg back backup backupdb bak bank bat bay bdb bgt bik bin bkp blend bmp bpw brd c cdf cdr cdr3 cdr4 cdr5 cdr6 cdrw cdx ce1 ce2 cer cfg cgm cib class cls cmd cmt conf config contact cpi cpp cr2 craw
file extensions: 386 adv ani bat bin cab cmd com cpl cur deskthemepack diagcab diagcfg diagpkg dll drv exe hlp hta icl icns ico ics idx key ldf lnk lock mod mpa msc msi msp msstyles msu nls nomedia ocx
application bat cmd com cpl dll exe gadget hta msc msi msp pif scf scr sys It avoids encrypting files with the following file name: p0r4dime.1! thumbs.db It avoids encrypting files within the following folder
NOTES: It searches all drives for files to encrypt except CD_ROM drive. It avoids encrypting files with the following extensions: vb scr reg pif msi exe com cmd bat bas It displays the
following file extensions: bat bin cmd com cpl dat dll drv exe hta ini lnk lock log mod msc msi msp pif prf rdp scr shs swp sys theme Ransom:Win32/NoEscape.MKV!MTB (MICROSOFT) Dropped by other malware,