You can check the latest ransomware information.
[ Faust ransomware ]
[Virus/Malware Activity Report: Faust Ransomware]
Due to a breach believed to be in the form of Faust ransomware, 
  we would like to confirm the situation and provide a warning as follows.
Faust ransomware
The ransomware is called Faust and has filename.extension.id[private key].[icanrestore@onionmail.org]. It appears that all files are being changed with the extension faust.
How it works
file version
 

[Figure 1 File version]
 
 

[Figure 2 File properties]
behavioral process
Register startup program
Registers itself in the startup program to automatically re-run when Windows starts.
 

[Figure 3 Startup program registration]
 
Turn off firewall
Disable firewall settings to make your PC less secure.
 

[Figure 4 Disable firewall]
 
Deleting shadow copies
Deletes shadow copies to make recovery difficult after infection.
 

[Figure 5 Deleting shadow copies]
 
Infection results
Information files are created in each folder with the names info.txt / info.hta, and when encryption is performed, the files are changed to <file name.extension.id[private key].[icanrestore@onionmail.org].faust>. It's possible.
 

[Figure 6 Infection result 1]
 
 

[Figure 7 Infection result 2]
 
 

[Figure 8 Infection result 3]
 
White Defender compatible
It supports real-time automatic restoration of files that will be encrypted before the malicious actions and blocking of WhiteDefender ransomware.
 
[Figure 9 Block message]
 
[Figure 10 Block message]
Watch the Faust blocking video
