Anti-Ransomware File System Resource Manager Lists

What is FSRM?

FSRM actively monitors your Windows Server shares and files and could alert you of any malicious activity you specify.

How can FSRM protect my network?

File System Resource Manager is a role that can be added for free to any Windows Server 2008 or later instance. By setting up what is called a "File Group" which is just a collection of filename patterns (e.g. "*.xyz" or "*.ctbl") to watch for, you can prevent crypto-variant viruses from writing encrypted files to your server.

FSRM can also be configured to then send you an email notification when a file matching that pattern is detected so that you can immediately shutdown the infected workstation and begin the cleanup process (imaging the PC, etc.) This process has been informally dubbed "creating a crypto canary", to refer to the fact that the message is akin to the idea of a "canary in a coal mine".

How do I set it up? Is it hard?

Setting up FSRM is incredibly easy, even if you're doing it manually, but thankfully we have modified a PowerShell script originally created by zarathustar that automatically installs the FSRM Role Feature if it's missing, and then downloads the latest file groups from this website.

One of your filescreens is blocking legitimate files! Help!

With some ransomware only using 3 character file extensions, that leaves a possible space of 46,656 combinations (26 letters + 10 numbers to the power of 3) which means that it's possible that they may choose an extension that is already in use by a legitimate piece of software. If this happens and non-dangerous files in your environment end up being caught inadvertently, there is a simple way to edit your script to ignore a particular extension from our list.

If you are using the script from GitHub

The first time you run the updated script, it will create a file in the directory called "SkipList.txt". Simply add a new line for each file extension you want to always ignore and never worry again about a legitimate file type accidentally being blocked. We suggest adding all known good file extensions proactively to this list to avoid any future headaches.

If you are using the manual method

Just add one of the following to the Invoke-WebRequest to remove it:

(Invoke-WebRequest -Uri "https://fsrm.experiant.ca/api/v1/get" -UseBasicParsing).content.replace("filter",$null)
You can also chain multiple of these together like this:
(Invoke-WebRequest -Uri "https://fsrm.experiant.ca/api/v1/get" -UseBasicParsing).content.replace("filter1",$null).replace("filter2",$null)
For example, to block the "*.cfk" filescreen, you would do this:
(Invoke-WebRequest -Uri "https://fsrm.experiant.ca/api/v1/get" -UseBasicParsing).content.replace("*.cfk",$null)

How can I help?

Know of a filter that we don't have yet? Submit it!


Find this site useful? Send us a beer!


Site Changelog:

Feb. 23, 2017

  • Added instructions for how to ignore a particular or collection of filescreens

Dec. 19, 2016

  • Updated unclear text to reflect FSRM is available on Windows Server 2008 and later

Sept. 30, 2016

  • Updated page to reflect usage of our own GitHub repository
  • Added -UseBasicParsing to Server 2012 / 2012 R2 command
  • Updated installation page to explain why DeployCryptoLocker.ps1 script is necessary, due to 4KB limit

Last updated: April 22, 2017 @ 6:07PM (America/Edmonton)

Current File Group Count: 890

Unauthenticated API: https://fsrm.experiant.ca/api/v1/combined


PowerShell command for new Server 2012 / 2012 R2 FSRM installations:

new-FsrmFileGroup -name "Anti-Ransomware File Groups" -IncludePattern @((Invoke-WebRequest -Uri "https://fsrm.experiant.ca/api/v1/combined" -UseBasicParsing).content | convertfrom-json | % {$_.filters})

PowerShell command for updating existing Server 2012 / 2012 R2 FSRM installations:

set-FsrmFileGroup -name "Anti-Ransomware File Groups" -IncludePattern @((Invoke-WebRequest -Uri "https://fsrm.experiant.ca/api/v1/combined" -UseBasicParsing).content | convertfrom-json | % {$_.filters})

Raw List

*.JEEPERS
PAYMENT-INSTRUCTIONS.TXT
*.LOCKOUT
*.ATLAS
[email protected]
*.AES-NI
*.DEXTER
*.CONFICKER
*.ONION
*.[[email protected]].WALLET
*.LCKD
*.MOLE
*.RANSOM
*.lambda.l0cked
009-READ-FOR-DECCCC-FILESSS.html
_READ_THI$_FILE_*
*.I'WANT MONEY
*.gembok
!Decrypt-All-Files-*.txt
*.[[email protected]],CRP
*.SERP
*.kilit
0_HELP_DECRYPT_FILES.HTM
HUR_DEKRYPTERA_FILER.html
HUR_DEKRYPTERA_FILER.txt
*.LAMBDA.LOCKED
[email protected]
*.SKJDTHGHH
*.LOCK75
*.B10CKED
[email protected]
*.IWANT
*.Fuck_You
Recupere seus arquivos aqui.txt
READ TO UNLOCK FILES.salsa.*.html
*.SALSA222
*.NUMBERDOT
How Decrypt My Files.lnk
How_Decrypt_My_Files
*.CRADLE
*.ID-7ES642406.CRY
READ ME ABOUT DECRYPTION.txt
*.Do_not_change_the_file_name.cryp
*.pr0tect
*.android
*_READ_THIS_FILE_*_*
*.btcware
[email protected]*
*.AngleWare
*.zorro
*.CIFGKSAFFSFYGHD
*.A9V9AHU4
*.payfordecrypt
OKU.TXT
ZINO_NOTE.TXT
*.ZINO
*.kirked
*.CRPTXXX
HOW_TO_FIX_!.TXT
*.[[email protected]].BRAINCRYPT
*.pizdec
*.REVENGE 
!!!READ_TO_UNLOCK!!!.TXT
[email protected]
*.warn_wallet
*.nemo-hacks.at.sigaint.org
*.MATRIX
Crytp0l0cker.Upack.dll
Crytp0l0cker.dll
Crytp0l0cker.exe
decrypted_files.dat
padcryptUninstaller.exe
PadCrypt.exe
Vape Launcher.exe
READ_ME_!.txt
*.enjey
Aescrypt.exe
*.GG
*.[[email protected]]
[email protected]
*.CEBER3
IF_WANT_FILES_BACK_PLS_READ.html
*.iaufkakfhsaraf
_HELP_HELP_HELP_*
zXz.html
*.zXz
VictemKey_*_*
HVORDAN_DU_GENDANNER_FILER.html
HVORDAN_DU_GENDANNER_FILER.txt
HELP_ME_PLEASE.txt
!_RECOVERY_HELP_!.txt
PLEASE-READIT-IF_YOU-WANT.html
*.filegofprencrp
COME_RIPRISTINARE_I_FILE.*
fattura_*.js
[email protected]_
COMO_ABRIR_ARQUIVOS.txt
[email protected][email protected]
*.kr3
COMO_RESTAURAR_ARCHIVOS.txt
COMO_RESTAURAR_ARCHIVOS.html
*.ENCR
*.[[email protected]].mails
[email protected]*
*.tmp.exe
What happen to my files.txt
[email protected]
*.BarRax
*.damage
*.locked-*
*.jey
*.CRYPTOSHIEL
*.cfk
ASSISTANCE_IN_RECOVERY.txt
#_DECRYPT_ASSISTANCE_#.txt
*.lfk
_HELP_HELP_HELP_*.hta
_HELP_HELP_HELP_*.jpg
BTC_DECRYPT_FILES.txt
*.TheTrumpLockerp
*.TheTrumpLockerf
*.d4nk
*.x3mpro
READ-READ-READ.html
*.weencedufiles
*.jse
*.powned
[KASISKI]*
INSTRUCCIONES.txt
@_USE_TO_FIX_*.txt
*.happydayzz
*.hasp
001-READ-FOR-DECRYPT-FILES.html
DECRYPT_INFORMATION.html
Rans0m_N0te_Read_ME.txt
[email protected]*
*.hnyear
[email protected]
*.wowwhereismyfiles
*.decryptional
*.wowreadfordecryp
*.7zipper
*.youransom
*.gui
*.Harzhuangzi
*.encryptedyourfiles
*HERMES
[[email protected]].wallet
*.wcry
*.velikasrbija
*.razarac
*.serpent
*.msj
*.szesnl
_DECRYPT_INFO_szesnl.html
000-IF-YOU-WANT-DEC-FILES.html
*.evillock
*.letmetrydecfiles
*.yourransom
*.lambda_l0cked
*.gefickt
[email protected] 
*.HakunaMatata
*.CRYPTOSHIELD
*.weareyourfriends
MERRY_I_LOVE_YOU_BRUCE.hta
How decrypt files.hta
[email protected]*
[email protected]*
*.potato
*.otherinformation
*.vxLock
*.rdmk
*.paytounlock
TRY-READ-ME-TO-DEC.html
EMAIL_*_recipient.zip
*.sage
[email protected]
LEER_INMEDIATAMENTE.txt
*.killedXXX
*.doomed
*.sifreli
*.MERRY
000-No-PROBLEM-WE-DEC-FILES.html
*.noproblemwedecfiles
WE-MUST-DEC-FILES.html
*.powerfulldecrypt
*.stn
[email protected]
*.id-3044989498_x3m
*.x3m
READ_ME_TO_DECRYPT_YOU_INFORMA.jjj
*.wuciwug
*.kencf
*.file0locked
file0locked.js
CryptoRansomware.exe
*.VBRANSOM
_HELP_Recover_Files_.html
*.oops
*.deria
*.RMCM1
*.Locked-by-Mafia
*.кибер разветвитель
*-filesencrypted.html
decrypt_Globe*.exe
*.hnumkhotep
 *.decrypt2017
DecryptFile.txt
*.L0CKED
NFS-e*1025-7152.exe
firstransomware.exe
HELP-ME-ENCED-FILES.html
*.helpmeencedfiles
*EdgeLocker*.exe 
*.edgel
*.XBTL
*.firecrypt
YOUR_FILES_ARE_DEAD.hta
*.MRCR1
*.PEGS1
*.RARE1
*.airacropencrypted!
*[[email protected]].*
WHERE-YOUR-FILES.html
*.Whereisyourfiles
[email protected]
C-email-*-*.odcodc
*.maktub
*.hush
*.bript
_*_README.hta
_*_README.jpg
HOW_OPEN_FILES.hta
*.gangbang
GJENOPPRETTING_AV_FILER.html
GJENOPPRETTING_AV_FILER.txt
!!! HOW TO DECRYPT FILES !!!.txt
*.braincrypt
INSTRUCTION RESTORE FILE.TXT
*.lesli
Survey Locker.exe
!!!!!ATENÇÃO!!!!!.html
Receipt.exe
WindowsApplication1.exe
HWID Lock.exe
VIP72.exe
DALE_FILES.TXT
*.DALE
*.8637
*.kok
HOW_TO_RESTORE_YOUR_DATA.html
*.paymrts
*.paymds
RESTORE_CORUPTED_FILES.HTML
[email protected]
Cyber SpLiTTer Vbs.exe
*.flyper
000-PLEASE-READ-WE-HELP.html
[email protected]
*.VforVendetta
popcorn_time.exe
*.filock
*.wallet
*_.rmd
*.uDz2j8mv
OSIRIS-*.htm
DesktopOsiris.htm
*[[email protected]]*
*.no_more_ransom
[email protected]
*.lovewindows
*.osiris
*.R.i.P
Important!.txt
!_HOW_TO_RESTORE_*.txt
HOW_TO_RESTORE_FILES.txt
_README_*.hta
*.Zzzz
*[[email protected]].wallet
*.coin
*.crypted_file
*.EncrypTile
*.hcked
_README_.hta
Runsome.exe
Payment_Advice.mht
lblBitcoinInfoMain.txt
lblFinallyText.txt
lblMain.txt
*.hannah
*.vindows
How to decrypt your files.jpg
How to decrypt your files.txt
How to get data back.txt
zcrypt.exe 
*.zycrypt
*.sgood
*.zzzzz
xort.txt
DOSYALARINIZA ULAŞMAK İÇİN AÇINIZ.html
HOWTO_RECOVER_FILES_*.TXT
HELP_RESTORE_FILES_*.TXT
Recovery+*.html
Recovery+*.txt
_H_e_l_p_RECOVER_INSTRUCTIONS+*.png
_H_e_l_p_RECOVER_INSTRUCTIONS+*.html
help_recover_instructions+*.html
help_recover_instructions+*.BMP
_how_recover+*.html
_how_recover+*.txt
ThxForYurTyme.txt
_HOW_TO_Decrypt.bmp
_RECOVER_INSTRUCTIONS.ini
###-READ-FOR-HELLPP.html
rtext.txt
DECRYPTION INSTRUCTIONS.txt
decrypt explanations.html
_WHAT_is.html
_HOWDO_text.html
readme_liesmich_encryptor_raas.txt
_Adatok_visszaallitasahoz_utasitasok.txt
How to restore files.hta
locked.bmp
README_TO_RECURE_YOUR_FILES.txt
Your files encrypted by our friends !!!.txt
ATTENTION.url
@WARNING_FILES_ARE_ENCRYPTED.*.txt
README!!!.txt
# README.hta
!Recovery_*.html
YourID.txt
recover.bmp
recover.txt
README HOW TO DECRYPT YOUR FILES.HTML
READ_IT.txt
*.lock93
*.!emc
*.adk
svchosd.exe
 *_luck
*.aesir
*.CHIP
*.happy
*.angelamerkel
*.razy1337
*.zendr4
*.dharma
*.locked3
*.duhust
*.exploit
*_crypt
*_help_instruct*.*
*!DMAlock*
*.GSupport3
*.rnsmwr
*.dCrypt
ransomed.html
*.Alcatraz
*_WHAT_is.html
readme.hta
*.96e2
*.thor
*.dxxd
*.usr0
*.shit
*.coded
*.raid10
*.realfs0ciety*
*.rip
*.okean*
*.globe
*.nuclear55
*.1txt
*.kostya
*.k0stya
*.comrade
*.exotic
*.fuck
*.Yakes
*.Zimbra
email-salazar_slytherin10@yahoo.com.ver-*.id-*-*.randomname-*
*._AiraCropEncrypted!
README_RECOVER_FILES_*.txt
README_RECOVER_FILES_*.png
README_RECOVER_FILES_*.html
*.~HL*
[email protected]___*
*.zc3791
*.venusp
*.shino
*.bleepYourFiles
*.crashed
*.amba
*.7h9r
*.已加密
*.암호화됨
*.b5c6
*.ap19
*.a19
_*_HOWDO_text.html
*_HOWDO_text.bmp
*_HOWDO_text.html
*.odin
*.zypto*
zzzzzzzzzzzzzzzzzyyy
zycrypt.*
*decrypt your file*.*
*_nullbyte*
*.bart
*.axx
_H_e_l_p_RECOVER_INSTRUCTIONS+*.txt
HOW-TO-DECRYPT-FILES.HTML
HOW_TO_DECRYPT.HTML
exit.hhr.obleep
UnblockFiles.vbs
README_DECRYPT_HYDRA_ID_*.txt
DECRYPT_Readme.TXT.ReadMe
Decrypt All Files *.bmp
HowDecrypt.gif
HELP_YOURFILES.HTML
HOW TO DECRYPT FILES.HTML
BUYUNLOCKCODE
BitCryptorFileList.txt
*.crjocker
*.POSHKODER
*.hydracrypt_ID_*
*.CTBL2
*.unbrecrypt_ID_*
*.padcrypt
*.rekt
*.CCCRRRPPP
*.SecureCrypte
*.windows10
*.pdcr
[email protected]
*.breaking_bad
*.cryptowall
*.xorist
*.crypt1
How_to_decrypt_your_files.jpg
How_to_restore_files.hta
*.cerber3
*.a5zfn
*.purge
*.fantom
*.cerber2
!readme.*
Como descriptografar seus arquivos.txt
[email protected]@0Xr@
*.domino
*cerber2
*.cawwcca
how_to_unlock*.*
!Recovery_*.txt
Read_this_file.txt
*.legion
*.encoderpass
*.cryptolocker
*.7z.encrypted
ATTENTION!!!.txt
HELP_DECRYPT.lnk
how to decrypt aes files.lnk
restore_files.txt
HowDecrypt.txt
$RECYCLE.BIN.{*-*-*-*}
*.heisenberg
*.breaking bad
*.razy
*.Venusf
.~
[email protected]
winclwp.jpg
wie_zum_Wiederherstellen_von_Dateien.txt
tox.html
strongcrypt.bmp
qwer2.html
qwer.html
pronk.txt
paycrypt.bmp
maxcrypt.bmp
how_decrypt.gif
how to get data.txt
help_recover_instructions*.txt
help_recover_instructions*.html
help_recover_instructions*.bmp
help-file-decrypt.enc
enigma_encr.txt
enigma.hta
default432643264.jpg
default32643264.bmp
decypt_your_files.html
de_crypt_readme.txt
de_crypt_readme.html
de_crypt_readme.bmp
cryptinfo.txt
crjoker.html
_how_recover*.txt
_how_recover*.html
_Locky_recover_instructions.bmp
_H_e_l_p_RECOVER_INSTRUCTIONS*.txt
_H_e_l_p_RECOVER_INSTRUCTIONS*.png
_H_e_l_p_RECOVER_INSTRUCTIONS*.html
_HELP_instructions.txt
_HELP_instructions.bmp
_DECRYPT_INFO_*.html
Your files encrypted by our friends !!! txt
Your files are locked !.txt
Your files are locked !!.txt
Your files are locked !!!.txt
Your files are locked !!!!.txt
YOUR_FILES_ARE_LOCKED.txt
YOUR_FILES_ARE_ENCRYPTED.TXT
YOUR_FILES_ARE_ENCRYPTED.HTML
YOUGOTHACKED.TXT
UNLOCK_FILES_INSTRUCTIONS.txt
UNLOCK_FILES_INSTRUCTIONS.html
SIFRE_COZME_TALIMATI.html
SHTODELATVAM.txt
Read Me (How Decrypt) !!!!.txt
RESTORE_FILES_*.txt
RESTORE_FILES_*.*
READ_THIS_TO_DECRYPT.html
README_HOW_TO_UNLOCK.TXT
README_HOW_TO_UNLOCK.HTML
README_DECRYPT_UMBRE_ID_*.txt
README_DECRYPT_UMBRE_ID_*.jpg
README_DECRYPT_HYRDA_ID_*.txt
READ ME FOR DECRYPT.txt
READ IF YOU WANT YOUR FILES BACK.html
Payment_Instructions.jpg
ONTSLEUTELINGS_INSTRUCTIES.html
OKSOWATHAPPENDTOYOURFILES.TXT
MENSAGEM.txt
KryptoLocker_README.txt
Instructionaga.txt
ISTRUZIONI_DECRITTAZIONE.html
INSTRUCTIONS_DE_DECRYPTAGE.html
INSTRUCCIONES_DESCIFRADO.html
INSTALL_TOR.URL
IMPORTANT.README
IMPORTANT READ ME.txt
Howto_RESTORE_FILES.html
How to decrypt your data.txt
How to decrypt LeChiffre files.html
Help Decrypt.html
Hacked_Read_me_to_decrypt_files.html
HOW_TO_UNLOCK_FILES_README_*.txt
HOW_TO_RESTORE_FILES.html
HOW_DECRYPT.URL
HOW_DECRYPT.TXT
HOW_DECRYPT.HTML
HOWTO_RECOVER_FILES_*.*
HOW TO DECRYPT FILES.txt
HELP_YOUR_FILES.html
HELP_YOUR_FILES.PNG
HELP_TO_SAVE_FILES.bmp
HELP_RESTORE_FILES_*.*
HELP_DECRYPT.URL
HELP_DECRYPT.PNG
HELP_DECRYPT.HTML
GetYouFiles.txt
File Decrypt Help.html
FILES_BACK.txt
ENTSCHLUSSELN_HINWEISE.html
DecryptAllFiles*.txt
DESIFROVANI_POKYNY.html
DECRYPT_YOUR_FILES.txt
DECRYPT_YOUR_FILES.HTML
DECRYPT_ReadMe1.TXT
DECRYPT_INSTRUCTIONS.html
DECRYPT_INSTRUCTION.URL
DECRYPT_INSTRUCTION.HTML
DECRYPTION_HOWTO.Notepad
Comment débloquer mes fichiers.txt
BUYUNLOCKCODE.txt
AllFilesAreLocked*.bmp
4-14-2016-INFECTION.TXT
*_ryp
*_HELP_instructions.html
*.xcrypt
*.unavailable
*.szf
*.porno.pornoransom
*.plauge17
*.neitrino
*.kimcilware.locked
*.iwanthelpuuu
*.herbst
[email protected]
*.h3ll
*.gws.porno
*.fuckyourdata
*.encrypted.locked
*.cryptz
*.crypttt
*.cripttt
*.criptokod
*.criptiko
*.btc.kkk.fun.gws
*.aga
*._ryp
*.Where_my_files.txt
*.Read_Me.Txt
*.RSplited
*.KEYZ.KEYH0LES
*.How_To_Get_Back.txt
*.How_To_Decrypt.txt
*.Contact_Here_To_Recover_Your_Files.txt
*.31392E30362E32303136_*
# DECRYPT MY FILES #.vbs
# DECRYPT MY FILES #.txt
# DECRYPT MY FILES #.html
!Where_are_my_files!.html
!!!README!!!*.rtf
!!!-WARNING-!!!.txt
!!!-WARNING-!!!.html
*.magic_software_syndicate
[email protected]
*.crypt
*.bitstak
*.wflx
*.CRRRT
howtodecryptaesfiles.txt
!satana!.txt
*.akaibvn
*.cRh8
*.YTBL
*.krypted
*.tzu
*.6FKR8d
*.sshxkej
*.eclr
*.epic
*.paybtcs
*.AFD
*.paymst
*.payms
*.isis
*.zepto
*.bart.zip
*.kratos
*.31342E30362E32303136*
*.SecureCrypted
*.crptrgr
*.rtyrtyrty
!DMALOCK3.0*
*.evil
*.crypt38
*.asdasdasd
*.ded
*.bloccato
*.canihelpyou
*.crypz
decrypt-instruct*.*
*files_are_encrypted.*
*decryptmyfiles*.*
help_instructions.*
*-recover-*.*
de_crypt_readme.*
*!recover!*.*
*recover}-*.*
*rec0ver*.*
_help_instruct*.*
*_recover_*.*
*+recover+*.*
*warning-!!*.*
*decrypt my file*.*
help_file_*.*
recovery+*.*
readme_for_decrypt*.*
install_tor*.*
readme_decrypt*.*
howtodecrypt*.*
howto_restore*.*
how_to_recover*.*
how_recover*.*
how_to_decrypt*.*
how to decrypt*.*
help_restore*.*
help_your_file*.*
help_recover*.*
help_decrypt*.*
decrypt_instruct*.*
cryptolocker.*
*recover_instruction*.*
*.hydracrypt_ID*
*gmail*.crypt
*.cryptotorlocker*
*.xxx
*.xyz
*.xtbl
*.xort
*.xrtn
*.vvv
*.vscrypt
*.trun
*.ttt
*.surprise
[email protected]_com
*.sport
*.scl
*.ryp
*.sanction
*.RRK
*.rokku
*.remind
[email protected]_com
*.RDM
*.RADAMANT
*.R5A
*.R4A
*.PoAr2w
[email protected]_com
*.p5tkjw
[email protected]_com
*.oshit
*.oor
*.one-we_can-help_you
*.OMG!
*.nochance
[email protected]_com
*.micro
*.LOL!
*.locky
*.locked
*.LeChiffre
*.kraken
*.korrektor
*.kkk
*.kimcilware
*.KEYZ
[email protected]_com
*.KEYHOLES
*.justbtcwillhelpyou
*.infected
[email protected]_net
*.hb15
*.ha3
[email protected]_com
*.gws
*.fun
*.fucked
*.enigma
*.encryptedped
*.encryptedRSA
*.encryptedAES
*.Encrypted
*.encrypt
*.encedRSA
*.EnCiPhErEd
[email protected]_com
*.czvxce
*.darkness
*.ctbl
*.CrySiS
*.CryptoTorLocker2015!
*.crypted
*.cry
*.crjoker
*.crinf
*.crime
*.coverton
*.code
*.clf
[email protected]_com
*.cerber
*.cbf
*.btcbtcbtc
*.btc-help-you
*.btc
*.bloc
*.better_call_saul
*.AES256
*.{CRYPTENDBLACKDC}
*.73i87A
*.zzz
*.abc
*.aaa
vault.txt
vault.key
recovery_key.txt
vault.hta
message.txt
recovery_file.txt
confirmation.key
enc_files.txt
last_chance.txt
*.vault
*want your files back.*
*.frtrss
*.exx
*.ezz
*.ecc
*help_restore*.*
*how_to_recover*.*
*restore_fi*.*
*ukr.net*
*qq_com*
*keemail.me*
*decipher*
*install_tor*.*
[email protected]*
[email protected]_com_*
*.*obleep
*.*exx
*.*locked
*.*nochance
*.*kraken
*.*kb15
*.*darkness
*.*crypto
*.*cry
_Locky_recover_instructions.txt
help_recover_instructions+*.txt
recoverfile*.txt
Howto_Restore_FILES.TXT
recoveryfile*.txt
_how_recover.txt
howrecover+*.txt
restorefiles.txt
howto_recover_file.txt
HowtoRESTORE_FILES.txt
RECOVERY_FILE*.txt
RECOVERY_FILES.txt
help_decrypt_your_files.html
HELPDECYPRT_YOUR_FILES.HTML
IHAVEYOURSECRET.KEY
SECRET.KEY
SECRETIDHERE.KEY
READTHISNOW!!!.TXT
IAMREADYTOPAY.TXT
HELLOTHERE.TXT
FILESAREGONE.TXT
DECRYPT_ReadMe.TXT
Read.txt
About_Files.txt
_secret_code.txt
ReadDecryptFilesHere.txt
Coin.Locker.txt
HOW_TO_DECRYPT_FILES.TXT
DECRYPT_INSTRUCTION.TXT
encryptor_raas_readme_liesmich.txt
Help_Decrypt.txt
YOUR_FILES.url
How_To_Recover_Files.txt
YOUR_FILES.HTML
INSTRUCCIONES_DESCIFRADO.TXT
DECRYPT_INSTRUCTIONS.TXT
HELP_TO_SAVE_FILES.txt
DecryptAllFiles.txt
HELP_RECOVER_FILES.txt
HELP_RESTORE_FILES.txt
HELP_TO_DECRYPT_YOUR_FILES.txt
HELP_YOUR_FILES.TXT
HELPDECRYPT.TXT
*.CTB2
*.SUPERCRYPT
*.magic
*.1999
*.toxcrypt
*.bleep
*.0x0
*.good
*.R16M01D05
*.pzdc
*.XRNT
*.crypto
*.ccc
*.da_vinci_code
*.payransom
*.KEYH0LES
oor.*
*.zyklon
*.zcrypt
*.Z81928819
*.Silent
*.RSNSlocked
*.RAD
*.porno
*.pornoransom
*.odcodc
_ryp
[email protected]*.net
*.only-we_can-help_you
*.cryp1
*.fileiscryptedhard
*.blocatto
*.8lock8
*.777

© 2016 - Experiant Consulting | Facebook