Actor Ransomware 🔐 (. Actor File) — Removal Guide

Actor Ransomware 🔐 (. Actor File) — Removal Guide

What is Actor virus?

The scheme of renaming is the following: id[xxxxxxx].[contact_email].actor. After the encryption, a file named, for instance, “report.docx” will be changed to “report.docx.id[1E857D00-2224].[].actor”.

In every directory that contains the encrypted files, a info.txt text file will be found. It is a ransom money note. Therein you can find information about the ways of contacting the racketeers and some other remarks. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. You can obtain this decoding tool after contacting by email. That is it.

NameActor Virus
Ransomware family1Phobos ransomware
Extension.actor
Ransomware noteinfo.txt
Contact
Detection2Trojan:Win32/Ramnit, Trojan:Win32/ExtenBro!MSR, Trojan:Win32/Selfdel.C
SymptomsYour files (photos, videos, documents) have a .actor extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Actor virus

The info.txt file coming in package with the Actor malware provides the following discouraging information:

!!! All of your files are encrypted !!!
To decrypt them send e-mail to this address: .
If we don\'t answer in 48h., send e-mail to this address: 

In the picture below, you can see what a folder with files encrypted by the Actor looks like. Each filename has the “.actor” extension appended to it.

That is how encrypted “.actor” files look.

How did my machine catch Actor ransomware?

There are currently three most exploited methods for malefactors to have ransomware acting in your digital environment. These are email spam, Trojan injection and peer-to-peer networks.

If you access your mailbox and see letters that look just like notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose sender is unknown to you, beware of opening those letters. They are most likely to have a harmful file enclosed in them. Thus it is even riskier to open any attachments that come with emails like these.

Another thing the hackers might try is a Trojan virus scheme3. A Trojan is a program that infiltrates into your computer pretending to be something legal. For example, you download an installer of some program you want or an update for some program. But what is unboxed turns out to be a harmful agent that corrupts your data. As the installation wizard can have any name and any icon, you’d better be sure that you can trust the resource of the things you’re downloading. The best way is to trust the software developers’ official websites.

As for the peer networks like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. So you’d better be using trustworthy websites. Also, it is reasonable to scan the directory containing the downloaded objects with the anti-malware utility as soon as the downloading is complete.

Sophia Al-Mansoor
Author

Sophia Al-Mansoor

Sophia analyzes international trade, startup ecosystems, retail transformation, and supply chain logistics for modern digital publications.