ViroBotnet ransomware is a new ransomware that modifies the target systems and encrypts user data with a strong algorithm, the resulting files will be marked with the .enc extension. At the moment the captured samples are an intermediate release, we expect that future versions will be made.
Our article provides an overview of the virus operations and it also may be helpful in attempting to remove the virus.
|Short Description||The ransomware encrypts files by placing the .enc extension on your computer system and demands a ransom to be paid to allegedly recover them.|
|Symptoms||The ransomware will encrypt your files and leave a ransom note with payment instructions.|
|Distribution Method||Spam Emails, Email Attachments|
|Detection Tool|| See If Your System Has Been Affected by ViroBotnet ransomware |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss ViroBotnet ransomware.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
ViroBotnet Ransomware – Distribution Tactics
The ViroBotnet ransomware is a newly discovered infection that appears to target computer systems worldwide. It uses an extensive distribution mechanism that relies on several approaches.
The criminals behind it may attempt to embed the virus code in various ways. One of the most common methods is to coordinate the creation of a SPAM email campaign. The crafted emails use phishing tactics that coerce the users that they are viewing a legitimate message from a service they use or well-known company. The virus files can be either directly attached or linked in the body contents. Another method is to make download sites that may take the form of vendor download sites or other locations that may be accessed by the targets. A common tactic is to use similar sounding domain names or security certificates.
To further increase the chance of infecting computer users the hackers can embed the ransomware files in payload carriers. Two examples are the following:
- Documents — The infection can follow through interaction with macro-infected documents: rich text documents, spreadsheets, presentations and databases. Once they are opened a notification prompt will appear asking the users to enable the built-in scripts.
- Infected Application Installers — The hackers can embed the infection commands into installers of various types. They typically target software that is widely used by end users — system utilities, creativity suites and productivity solutions.
Advanced ViroBotnet ransomware infections can be caused by the interaction with malicious web browser plugins. They are uploaded to the relevant plugin repositories hosted by the software developers of the browsers and make use of stolen or fake developer credentials, as well as user reviews. The most common ways to identify them is by looking out for claims that promise dramatical upgrades to the web browser or the addition of new features that may greatly improve them. The descriptions offered by the criminals contains promises that may confuse the users. Upon installation the users will find out that their settings will be changed to a hacker-controlled address. Finally the ransomware infection will be delivered and started after that.
In some cases the hackers may also spread the infected files via file-sharing networks like BitTorrent or post links to social networks and forums. They taget communities that are active and focus on infecting those sections that deal with downloads.
ViroBotnet Ransomware – In-Depth Analysis
The ViroBotnet ransomware has undergone a security analysis revealing that it is a new virus threat that is still being developed. At the moment there is no information available about the developer or criminal collective behind it. What we know about the threat is that the captured samples are based on a modular platform allowing them to be further extended.
We anticipate that future versions will follow the behavior patterns associated with other similar threats. A typical start of the infection process would begin by calling a data collection module used to automatically hijack sensitive data available on the system. There are two main groups of data that are generally distinguished:
- Optimization Data — The criminals can acquire information that can help them optimize the attacks. Examples of the hijacked information include a report on the installed hardware components, user-set options and parameters used by the operating system. They can help the criminals to coordinate their future attacks and better carry out their current ones.
- Sensitive User Data — The criminals can automate the extraction of data that can expose the identity of the victim users. The resulting use of this information can lead to crimes such as identity theft and financial abuse. The ransomware component will hijack strings related to the user’s name, address, phone number, location, interests and any stored account credentials.
The information can also be scanned and used by another component called stealth protection. It is used to protect the virus engine from being discovered by security software and services. This is done by performing scans that look for signatures belonging to anti-virus software, firewalls, sandbox environments and virtual machine hosts. This allows the ViroBotnet ransomware to effectively take over control of the whole system. When this stage of the infection has been reached the malicious engine will be able to initiate various advanced infiltration actions.
The Windows Registry may be modified so that it can affect the values of the operating system itself or individual user-installed applications. This can render certain functions unavailable or make the whole system unstable as its performance will be affected. Creation of ransomware entries is linked to a process called persistent installation which will automatically set the engine to start upon system startup. Other consequences include the inability to enter into the recovery boot menu and also block the launch of other applications.
To further make system recovery more difficult the hackers may order it to remove important files such as Shadow Volume Copies and System Restore Points. This means that full computer restore is only possible by using a combination of a virus removal method with a restore program.
Be aware that further updates to the ViroBotnet ransomware strains may be programmed to initiate a Trojan infection. The most common method would be to connect to a hacker-controlled server which allows the criminal operators to spy on the victims in real time, take over control of their computers and also drop other viruses.
WARNING! We received reports that the virus samples seem to interact with Microsoft Outlook. If the popular email client is installed then the list of contacts will be hijacked and the virus will automatically send phishing emails originating from the infected machines.
Some of the application names and services that the ViroBotnet ransomware impersonates includes “Office Updater” and “Office updater background task”.
ViroBotnet Ransomware – Encryption Process
Once all prior components have finished execution the encryption component is launched. The captured samples belonging to the ViroBotnet ransomware family appear to use the common example of adhering to a built-in list of target files. A typical list would target the following file types:
A ransomware sample has been found to encrypt the following extensions:
txt, doc, docx, xls, xlsx, ppt, pptx, odt,
jpg, png, csv, sql, mdb, sln, php, asp, aspx,
html, xml, psd, pdf, odt, swp
As a result of the encryption process the affected files will be marked with the .enc extension. They will not be accessible to the user and interacting with them may lead to system performance issues. Following the tradition of other common virus types a ransomware note will be created, the captured samples will generate a plain-text file called README.txt. It will read the following message ” Vos fichiers personnels ont été chiffrés. Lisez les instructions du logiciel”. A translation from French shows that the message reads “Your personal files have been encrypted. Read the software instructions”. The next step is to initiate a lockscreen that will block the ordinary computer interaction until the threat is completely different. The displayed lockscreen message can change periodically depending on the ongoing attack campaign, ransomware version and other factors.
Remove ViroBotnet Ransomware and Restore .enc Files
If your computer system got infected with the ViroBotnet ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.
Note! Your computer system may be affected by ViroBotnet ransomware and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of ViroBotnet ransomware.