Elder Virus (. Elder Files) — How to Remove?
What Is Known About the Eldervirus? the Renaming Will Be Done According to the Following Scheme: Id[Xxxxxx]. [Contact_Email]. Elder. in the Course of...
What is known about the Eldervirus?
The renaming will be done according to the following scheme: id[xxxxxx].[contact_email].Elder. In the course of encryption, a file named, for example, “report.docx” will be renamed to “report.docx.id[1E857D00-2397].[].elder”.
In every directory with the encoded files, a info.txt text document will be created. It is a ransom money note. Therein you can find information about the ways of paying the ransom and some other information. The ransom note most probably contains a description of how to buy the decryption tool from the racketeers. You can obtain this decryptor after contacting by email. That is how they do it.
| Name | Elder Virus |
| Ransomware family1 | Phobos ransomware |
| Extension | .Elder |
| Ransomware note | info.txt |
| Contact | |
| Detection2 | Trojan:Win32/RedLineStealer.PS!MTB, Ransom:Win32/Ciluf, MSIL/Agent.VIF |
| Symptoms | Your files (photos, videos, documents) have a .Elder extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Elder virus |
The info.txt file coming in package with the Elder malware states the following:
!!!All of your files are encrypted!!! To decrypt them send e-mail to this address: . If we don\'t answer in 24h., send e-mail to this address:
In the image below, you can see what a folder with files encrypted by the Elder looks like. Each filename has the “.Elder” extension appended to it.
How did my machine catch Elder ransomware?
There are currently three most popular ways for malefactors to have ransomware settled in your digital environment. These are email spam, Trojan infiltration and peer networks.
If you open your inbox and see emails that look just like notifications from utility services providers, postal agencies like FedEx, Internet providers, and whatnot, but whose mailer is strange to you, beware of opening those letters. They are most likely to have a malicious file attached to them. Thus it is even more dangerous to download any attachments that come with letters like these.
Another option for ransom hunters is a Trojan file model3. A Trojan is an object that infiltrates into your computer disguised as something legal. Imagine, you download an installer of some program you want or an update for some service. However, what is unboxed reveals itself a harmful program that compromises your data. Since the installation file can have any name and any icon, you’d better be sure that you can trust the resource of the stuff you’re downloading. The optimal way is to trust the software developers’ official websites.
As for the peer-to-peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is a good idea to scan the directory containing the downloaded files with the antivirus as soon as the downloading is complete.