What is known about the Rootvirus?
Root adds its own .Root extension to the name of each encoded file. For example, an image entitled “photo.jpg” will be changed to “photo.jpg.Root”. In the same manner, the Excel file named “table.xlsx” will be altered to “table.xlsx.Root”, and so forth.
In every directory that contains the encoded files, a read_it.txt text file will be created. It is a ransom money memo. It contains information about the ways of paying the ransom and some other information. The ransom note usually contains a description of how to buy the decryption tool from the racketeers. That is it.
| Name | Root Virus |
| Ransomware family1 | Chaos ransomware |
| Extension | .Root |
| Ransomware note | read_it.txt |
| Detection2 | Win32/TrojanDownloader.Small.OCD, TrojanDropper:Win32/Vundo.AB, Trojan:MSIL/Tiny.AC!MTB |
| Symptoms | Your files (photos, videos, documents) get a .Root extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Root virus |
In the image below, you can see what a folder with files encrypted by the Root looks like. Each filename has the “.Root” extension added to it.
How did my machine catch Root ransomware?
Nowadays, there are three most popular ways for tamperers to have the Root virus planted in your digital environment. These are email spam, Trojan infiltration and peer-to-peer file transfer.
If you open your inbox and see emails that look just like notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is strange to you, beware of opening those letters. They are very likely to have a malware file attached to them. So it is even more dangerous to download any attachments that come with emails like these.
Another thing the hackers might try is a Trojan file model3. A Trojan is a program that infiltrates into your computer pretending to be something else. For example, you download an installer for some program you need or an update for some service. But what is unpacked turns out to be a harmful agent that encrypts your data. Since the installation file can have any name and any icon, you’d better be sure that you can trust the source of the files you’re downloading. The best thing is to use the software developers’ official websites.
As for the peer-to-peer networks like torrent trackers or eMule, the danger is that they are even more trust-based than the rest of the Internet. You can never know what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the folder containing the downloaded items with the anti-malware utility as soon as the downloading is finished.