Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2020

How to remove Roger ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Roger ransomware – Dharma variant that is sometimes spreads via known set of exploits

Roger malware

Roger ransomware is a file-encrypting virus that originally stems from Dharma/Crysis. Just as its predecessors, this malware specializes in encrypting all personal files on the system and then demanding a ransom of various amounts to be paid in Bitcoin cryptocurrency. It uses AES, DES, or RSA algorithms to lock data, which then appends each file with victim ID, an email address, and a .ROGER extension. Ransomware also drops two ransom notes: Info.hta and FILES ENCRYPTED.txt, which state cybercriminals' demands.

Roger virus first showed up in November 2019, with multiple variants showing up since then. The latest variants use support@zimbabwe.su, decoding@tuta.io, and pexdatax@gmail.com email addresses for communication, as well as an appendix within the encrypted files. Also, attackers provide Telegram username @pexdata, which can be used to contact them.

Unfortunately, when it comes to data decryption, most newer Dharma versions, including .roger virus files, can not be decrypted, as a working decryptor only exists for its earlier versions (released in around 2016). Despite this, victims are not advised to pay the ransom, as it would only increase criminals' profits from illegal activities. If you were unlucky enough and your files are appended with .roger extension, you should check out alternative methods below that might be able to help you.

Most malware versions can be detected by security solutions, according to VirusTotal data.[1] Thus, employing powerful anti-malware solutions is mandatory for each of the computer users. Besides, Roger ransomware was seen being spread via a set of known exploits[2] along with LockBit ransomware, so users might see double extensions, such as .roger.lockbit, appended to their files. So don't forget to patch all the installed programs with the latest security updates.

Name Roger ransomware / Roger virus / .roger file
Category Cryptovirus, file locking malware
Family Dharma/Crysis family
Danger level This malware is highly dangerous. Once it penetrates targeted Windows computers, it starts encrypting all files, preventing access until ransom is paid
Appendix .ROGER. Additionally, malware appends email address and a unique ID to each of the affected files. Example of an encrypted file: picture.jpg.id-2M487V00.[btcdecoding@foxmail.com].ROGER
Ransom note FILES ENCRYPTED.txt and Info.hta
Spreading While ransomware makers can use various methods for distribution, it was observed being spread along other ransomware via vulnerabilities and exploits
Main goal Encrypt all personal files on the targeted Windows machines and then extort ransom from users, to be paid in Bitcoin cryptocurrency
Elimination tip You should take immediate action towards the malware removal process once you find the ransomware on your computer system. Employ reliable antivirus software to complete the task
Repair process If the ransomware virus has damaged some system components, you can try repairing them by employing specific system repair software. We recommend trying FortectIntego as this software might appear helpful

Roger ransomware virus can make multiple changes to your Windows computer system and run malicious process in the background. If it would not be for the new extensions and displayed ransom note, you might not even recognize that something has gone wrong until you try to load some type of file and it does not open properly.

However, Roger ransomware wants to make sure that it has been spotted by the victims in order to collect income. In this case, the criminals urge to follow some type of rogue link which can be entered only via the Tor browser:

YOUR FILES ARE ENCRYPTED
Don't worry,you can return all your files!
If you want to restore them, follow this link:zombietry4o3nzeh.onion/?ticket=Rt31ws32vJLxvwudeH_1E857D00
Use Tor Browser to access this address.
If you have not been answered via the link within 12 hours, write to us by e-mail:backdata.company@aol.com
Attention!
Do not rename encrypted files.

Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

You should never trust Roger ransomware authors and avoid its demands. We do not recommend proceeding with the suspicious link as you cannot know where it might take you to. You might be lured into some type of scam, convince to provide a big sum of money, get your identity stolen. Anything can happen on the dark web.

Roger virus

A wiser option would be to remove Roger ransomware from your Windows machine and try other data recovery possibilities. At the end of this article, you will be provided with some data restoring techniques some of which might be very helpful if properly used. Even though there is no 100% guarantee that the software will work, almost any type of option is better than risking to pay the criminals huge sums of money and losing them for nothing.

Roger file virus might be able to launch PowerShell commands that delete or destroy Shadow Copies[3] of encrypted data. This is used to harden the decryption process for the victims. Also, the malware might be able to permanently damage the Windows hosts file to prevent access to security-related forums and websites.

Once you are completing the Roger ransomware removal process, do not forget to eliminate the hosts file, otherwise, you might still be forbidden from visiting some pages online. In addition, the malware might inject certain processes and entries that would allow the parasite to boot up every time the system is turned on or avoid antivirus detection.

Moreover, Roger ransomware might carry other malicious infections such as trojans, cryptocurrency miners, and other parasites to the Windows computer system. If you do not get rid of the ransomware fast, you might end up with multiple severe cyber threats on the machine and experience unrepairable system damage.

Once you are eliminating the cyber threat, you should check the entire system for all possibly-damaged locations that might have been infected by Roger ransomware. If you find some corrupted components, you can try repairing them with the help of FortectIntego software or any other tool from your own likings.

Roger ransomware virus has been seen using the following contact emails:

backdata.company@aol.com
decoding@zimbabwe.su
covid-123@tutanota.com
leebob78@aol.com
btc3301@messageden.com
filecrypts@protonmail.com
b1tcoin2020@protonmail.com
supp0rtdecrypti0n@aol.com
bossi_tosi@protonmail.com
helpdecoder@firemail.cc
backdata@qbmail.biz
decoding@qbmail.biz
dinanit@protonmail.com
cryptfiles@protonmail.com
telegram_@spacedatax
johnlibber@tuta.io
sjen6293@gmail.com
recoverysql@protonmail.com
anna.kurtz@protonmail.com
admin@spacedatas.com
wang.chang888@tutanota.com
admin@datastex.club
style777@keemail.me
dlt0181309@protonmail.com
anna_adm1n@aol.com
teamdecrypt@disroot.org
johncastle@zimbabwe.su
johncastle@msgsafe.io
crypt@zimbabwe.su
telegram_spacedatax
easybackup@protonmail.com
johnsmith@zimbabwe.su
05t@tuta.io
1o5t@protonmail.com
richardkeyd@aol.com
richardkeyd@tutanota.com
support@zimbabwe.su
decoding@tuta.io
pexdatax@gmail.com
btcdecoding@foxmail.com
easybackup@aol.com
decrypt@files.mn
viginare@aol.com
@pexdata

Roger ransomware

Ransomware delivery techniques

According to security experts from NoVirus.uk,[4] ransomware infections are intensively spread by using deceptive and social engineering techniques. The criminals often target computer systems that hold weak protection and are easy to compromise. Lacking antivirus software might be an indicating factor for hackers to attack you.

However, these people use email spam as a way to reach the victim. They send official-looking messages that supposedly come from reliable shipping firms such as FedEx, DHL, banking organizations, healthcare, etc. The crooks insert the malicious payload in a hyperlink and leave it in the message itself or attach an infected file/document to the email.

A tip from us would be to always identify the sender and check in case the message is coming from an unrecognizable email address. Also, verify the entire text and look for grammar/style mistakes that usually would be spottable. Last but not least, do not open any clipped attachments before scanning them with reliable antimalware software.

Furthermore, ransomware viruses might be distributed via third-party sources such as p2p networks through indirect downloading links of software cracks. Also, RDPs that include weak password protection or are left unprotected at all, are also the main targets of cybercriminals that can enter the targeted systems via the hacked RDP.

Roger ransomware virus

It is advisable to use only antimalware for Roger ransomware removal

We want to warn all users that Roger ransomware is a dangerous cyber threat that can scatter malicious products all over the Windows computer system. Regarding this fact, automatic elimination would be the best option.

To remove Roger ransomware from the infected system, you need strong system software. Also, you should try to find infected components on your machine by employing a program such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Afterward, try fixing all damaged objects by using FortectIntego as it might be helpful in some cases.

After Roger ransomware removal, you should go to the end of this article where you will be able to find some data recovery tips. Even though there is no 100% guarantee that this software will be helpful, giving a try to these products is still a way better decision than paying the criminals and taking risks of getting scammed.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.