Ransomware Files, Custom Extensions, And Decryptor Notes
A ransomware infection can rename documents with an unfamiliar extension, scramble their contents and leave a text or HTML note demanding payment. The message may claim that a private key or decryptor is available, but it is not proof that the criminals can restore anything.
When ransomware encrypts files with a custom extension and drops a decryptor note, treat the computer as a compromised crime scene. Disconnect it carefully, preserve useful evidence and avoid actions that could overwrite recoverable data or spread the malware to other devices.
| Situation |
Safer response |
Main risk |
| Computer is still encrypting files |
Disconnect Wi-Fi or Ethernet immediately |
Shutting down may interrupt encryption, but unsaved evidence can be lost |
| Note demands cryptocurrency |
Save a copy and do not contact the criminals yet |
Payment may fund further attacks without producing a working key |
| Files have a new extension |
Record the extension and sample filenames |
Renaming files does not decrypt them |
| Backups are available |
Isolate the affected machine before restoring |
Connected backups may also be encrypted |
| Work or customer data is involved |
Notify the responsible organisation and report the incident |
Delayed reporting can worsen privacy and regulatory consequences |
Isolate The Affected Computer
Disconnect the device from Wi-Fi, Ethernet, shared folders and removable storage. On a home network in Sydney, Brisbane or Perth, this may mean switching off Wi-Fi from the router rather than clicking unfamiliar buttons on the infected computer. Unplug external hard drives and USB backup devices without opening their files on the affected system.
If several computers show the same symptoms, isolate them all. Ransomware can move through shared credentials, remote administration tools, vulnerable services or worm-like behaviour. Guidance about related threats is available in the worm security section, which can help explain why one infected endpoint may place other devices at risk.
Do not browse the ransom site, install an unknown “decryptor”, or enter business credentials into the note’s contact portal. Criminals may use that interaction to deliver additional malware or pressure victims into paying quickly.
Preserve The Note And Identify The Strain
Copy the ransom note to a clean USB device or photograph it with a separate phone. Record the new file extension, the note’s filename, email addresses, cryptocurrency wallet details, contact links and the approximate time the encryption began. Keep several encrypted sample files unchanged; researchers may need them to identify the family or test a legitimate recovery tool.
Search the exact extension and wording of the note using a clean device, but treat search results carefully. Some ransomware families have free decryptors, while others use extensions that resemble older variants. A decryptor made for the wrong strain can damage files further. The Australian Cyber Security Centre and reputable security vendors may publish identification resources, while the broader malware removal library provides educational guidance for Windows and Mac threats.
Avoid renaming encrypted documents, deleting the ransom note or running registry cleaners. A custom extension is usually a label added by the malware; changing it back to .docx, .jpg or .pdf does not reverse encryption.
Check Backups Without Reinfecting Them
Use a separate, clean computer to inspect backup status. Cloud services such as OneDrive, Google Drive or Dropbox may offer version history or a recovery window, although synchronisation can also carry encrypted replacements across devices. Pause synchronisation before reconnecting anything, then consult the provider’s restoration process.
Offline backups are safer when they were disconnected before the attack. For a small business in Adelaide or Canberra, ask the IT provider to verify that backup copies are intact, dated and capable of being restored to a freshly installed system. Do not attach a backup drive to the infected computer simply to see whether the files open.
Windows may retain Shadow Copies or File History versions, but ransomware often deletes them. Recovery software can sometimes restore deleted originals from local storage, though continued use of the disk may overwrite them. If the information is irreplaceable, shut down the device and seek qualified digital forensics advice.
Decide Whether Reporting Is Required
Paying a ransom is risky. There is no guarantee the criminals will provide a functional key, remove stolen copies or stop targeting the victim. Payment can also make the organisation a more attractive target. Preserve wallet addresses, chat messages, timestamps and transaction instructions in case investigators request them.
Australian businesses should consider the Privacy Act 1988 and the Notifiable Data Breaches scheme if personal information may have been accessed or stolen, rather than merely encrypted. The Australian Cyber Security Centre accepts cyber incident reports, and organisations may need to notify customers, insurers, regulators or law enforcement. A school, medical clinic or trades business should follow its internal incident plan and avoid making public claims before the facts are checked.
Home users should contact their bank promptly if passwords, identity documents or payment details may have been exposed. Change passwords from a clean device, beginning with email and financial accounts, and enable multifactor authentication wherever possible.
Rebuild Carefully And Reduce Recurrence
A reliable cleanup commonly involves identifying the ransomware, saving evidence, wiping or rebuilding the operating system, patching applications and restoring clean data. Security software can assist with detection, but removal does not decrypt files and should not be confused with recovery. If the infection involved stolen credentials, reset them after the device has been secured.
For Australian households using NBN connections, update the modem or router firmware, replace default administrator credentials and disable remote management unless it is genuinely required. Small businesses should apply the Essential Eight principles where practical, especially multifactor authentication, regular patching, restricted administrator privileges and tested backups.
Keep at least one backup offline or otherwise isolated, and test restoration periodically. Separate personal and work accounts, avoid pirated software and treat unexpected invoices, parcel messages and Microsoft 365 login prompts with suspicion. These everyday phishing lures remain common entry points for ransomware, whether the target is a home office in Melbourne or a larger company in regional New South Wales.