What is Actor virus?
The scheme of renaming is the following: id[xxxxxxx].[contact_email].actor. After the encryption, a file named, for instance, âreport.docxâ will be changed to âreport.docx.id[1E857D00-2224].[].actorâ.
In every directory that contains the encrypted files, a info.txt text file will be found. It is a ransom money note. Therein you can find information about the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. You can obtain this decoding tool after contacting by email. That is it.
| Name | Actor Virus |
| Ransomware family1 | Phobos ransomware |
| Extension | .actor |
| Ransomware note | info.txt |
| Contact | |
| Detection2 | Trojan:Win32/Ramnit, Trojan:Win32/ExtenBro!MSR, Trojan:Win32/Selfdel.C |
| Symptoms | Your files (photos, videos, documents) have a .actor extension and you canât open them. |
| Fix Tool | See If Your System Has Been Affected by Actor virus |
The info.txt file coming in package with the Actor malware provides the following discouraging information:
!!! All of your files are encrypted !!! To decrypt them send e-mail to this address: . If we don\'t answer in 48h., send e-mail to this address:
In the picture below, you can see what a folder with files encrypted by the Actor looks like. Each filename has the â.actorâ extension appended to it.
How did my machine catch Actor ransomware?
There are currently three most exploited methods for malefactors to have ransomware acting in your digital environment. These are email spam, Trojan injection and peer-to-peer networks.
If you access your mailbox and see letters that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose sender is unknown to you, beware of opening those letters. They are most likely to have a harmful file enclosed in them. Thus it is even riskier to open any attachments that come with emails like these.
Another thing the hackers might try is a Trojan virus scheme3. A Trojan is a program that infiltrates into your computer pretending to be something legal. For example, you download an installer of some program you want or an update for some program. But what is unboxed turns out to be a harmful agent that corrupts your data. As the installation wizard can have any name and any icon, youâd better be sure that you can trust the resource of the things youâre downloading. The best way is to trust the software developersâ official websites.
As for the peer networks like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. So youâd better be using trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded objects with the anti-malware utility as soon as the downloading is complete.