ViroBotnet ransomware is a virus that modifies the targeted system and marks files with .enc extension

ViroBotnet ransomware — cryptovirus that demands 500 EUR ransom from French-speaking users. File-locking virus encrypts files using an army-grade AES encryption algorithm and marks encoded data with the .enc file extension. File modification that makes your data useless is only the start of the ransomware attack. After this process, virus developers ask for a payment in the ransom note README.txt and locks your screen with the ransom message displayed.
| Name | ViroBotnet |
|---|---|
| Type | Ransomware |
| Encryption method | AES |
| Category | Cryptovirus |
| File extension | .enc |
| Ransom amount | 500 EUR |
| Ransom note | README.xt |
| Targeted people | French-speakers |
| Distribution | Outlook emails with infected file |
| Elimination | Use FortectIntego for ViroBotnet ransomware removal |
ViroBotnet virus gets distributed using common techniques, such as spam emails, malicious websites and by using brute-force attacks. Once installed, the malware uses the executable Office Updater.exe which then sends our thousands of emails to every person on the contact list of the victim. The process creates a Botnet – a combination of infection computers that are predetermined to execute certain tasks (in most cases, re-distribute the infection).
ViroBotnet ransomware virus appears to be still in development, and new versions are to be expected to be developed. Researchers believe that Botnet capabilities will expand the extent of the ransomware infections all over the world.
Immediately after infiltration ViroBotnet virus scans the system and detects various files that later on get encrypted with AES encryption chipher[1]. All modified files get .enc file extension that shows which ones are encoded. In every folder that contains encrypted data, virus places a ransom note called README.txt.
Also, this threat locks your screen and displays a ransom note on this black window. The message contains information about the attacks and payment methods, amount. Ransomware developers give 72 hours to pay before the key is deleted, but you shouldn't listen to these hackers. Paying the ransom doesn't ensure that your files will be decrypted.
Ransom note reads as follows(translated from French):
Vos fichiers personnels ont été chiffrés. Lisez les instructions du logiciel. (Your personal files are encrypted. Read the instructions for the program.)
Lock screen displays the message:
Vos fichiers personnels ont été chiffré. Pour les déchiffrer, envoyez 500€ de bitcoins à cette adresse: 1BoatSLRHtKNngkdXEeobR76b53LETtpyT
Toute tentative de destruction de ce logiciel entraînera la destruction de la clé de déchiffrement.
Toute tentative de déchiffrement avec une clé erronée entraînera la perte définitive de vos fichiers.
Vous avez 72 heures pour effectuer le paiement. Après quoi, la clé de déchiffrement sera supprimée.
Clé de déchiffrement :
Déchiffrer mes fichiers(Your personal files were encrypted. For their decipherment came bitkoins for 500 € to this address:1BoatSLRHtKNngkdXEeobR76b53LETtpyT
Any attempt to destroy this program will destroy the decryption key.
Any attempt to decrypt with the wrong key will damage your files.
You have 72 hours to pay. After that, the decryption key will be deleted.
The decryption key:
Decrypt my files:
ViroBotnet ransomware is a serious cyber threat, but only 19 from 68 AVs detect[2] the ransomware file as malicious. You can find that OfficeUpdater.exe is detected as:
- TR/Dropper.Gen
- DeepScan:Generic.Ransom.Hiddentear.A.13B5B1E9
- HEUR:Trojan.Win32.Generic
- Malware.Generic.CN1 (A)
- Trojan.Win32.Generic.pak!cobra
- Trojan.MSIL.gen.b.7.
You should remove ViroBotnet ransomware with the help of reputable anti-malware tools because ransomware can install additional programs on your device. Programs like FortectIntego can detect possible threats and get rid of them and ransomware itself. The application is capable of repairing all the damage done by the virus.
ViroBotnet ransomware removal should be performed before the file recovery procedure. If you do have backups ready, DO NOT connect them to the infected PC, as all the backup data will be encoded as well as soon as you connect it. Same goes for backup files stored on a remote server – do not access them before virus removal. If you do not have backups, use the third-party software we recommend below. Note that chances of recovering the data are low; however, you need to try all the resources before giving up (if you care for your data, of course).

Ransomware developers distribute the threat using email attachments
Typical ransomware payload spreads via social engineering attacks when spam email attachments are infected with malware or hyperlinks redirect users to malicious websites. Hackers use company logos, styling, similar email address, etc., to make the scam look more believable.
However, researchers[3] note that this particular virus uses a slightly different distribution technique. Using Outlook service this virus sends emails to every contact on every account that has been logging on the infected device. This email contains OfficeUpdater.exe file or infects ransomware on the machine directly from the email.
ViroBotnet ransomware termination should be done without any delays
If you found your files locked with .enc extension, make sure to remove ViroBotnet ransomware as soon as possible. There is no need to delay, and also no need to pay attention to hackers warnings (looking at how they try to scare users that the decryption key will be destroyed within 72 hours).
For ViroBotnet ransomware removal, you should use FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes because it is the best solution for malware elimination. Anti-malware tools perform a full system scan and remove threats from your device. After the thorough malware elimination, you can attempt data replacement or recovery. Below the article, you can find a few suggestions for file recovery.
Did this guide help?
Be the first to comment