Prestige Ransomware 🔐 (. Enc File) — Removal Guide
What Is Known About the Prestigevirus? Prestige Adds Its Extra. Enc Extension to Every File’s Name. for Example, an Image Entitled “Photo. Jpg” Will Be Changed...
What is known about the Prestigevirus?
Prestige adds its extra .enc extension to every file’s name. For example, an image entitled “photo.jpg” will be changed to “photo.jpg.enc”. Likewise, the Excel file with the name “table.xlsx” will become “table.xlsx.enc”, and so forth.
In each directory containing the encoded files, a README.txt file will be created. It is a ransom money note. It contains information about the ways of contacting the racketeers and some other information. The ransom note usually contains instructions on how to purchase the decryption tool from the racketeers. That is basically the scheme of the crime.
| Name | Prestige Virus |
| Extension | .enc |
| Ransomware note | README.txt |
| Detection1 | Backdoor:Win32/Farfli.BI!MTB, UDS:Trojan-Ransom.Win32.PolyRansom, Win64/Expiro.DR |
| Symptoms | Your files (photos, videos, documents) get a .enc extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Prestige virus |
In the image below, you can see what a folder with files encrypted by the Prestige looks like. Each filename has the “.enc” extension added to it.
How did my machine catch Prestige ransomware?
There are currently three most popular ways for criminals to have ransomware acting in your digital environment. These are email spam, Trojan injection and peer file transfer.
If you access your mailbox and see letters that look like familiar notifications from utility services companies, postal agencies like FedEx, web-access providers, and whatnot, but whose addresser is strange to you, be wary of opening those emails. They are very likely to have a malicious file attached to them. Therefore, it is even more dangerous to open any attachments that come with emails like these.
Another thing the hackers might try is a Trojan virus model2. A Trojan is an object that infiltrates into your computer pretending to be something different. For instance, you download an installer of some program you need or an update for some program. However, what is unboxed turns out to be a harmful agent that compromises your data. Since the installation package can have any title and any icon, you have to make sure that you can trust the source of the files you’re downloading. The optimal thing is to use the software companies’ official websites.
As for the peer-to-peer networks like torrent trackers or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is reasonable to scan the folder containing the downloaded items with the antivirus as soon as the downloading is finished.