This article will help you to remove the [email protected] File Virus (Jigsaw ransomware) fully. Follow the ransomware removal instructions given at the end of the article.
The [email protected] File Virus is in actuality Jigsaw ransomware. The cryptovirus keeps the design, interface and code really close to those of the original malware. The virus has a list with around 126 file extensions that seeks to encrypt. All of the files which will get encrypted will receive the extension [email protected] appended to them.
|Name||[email protected] Virus|
|Short Description||The ransomware will encrypt your files and display a screen with the ransom note, which is themed around the movie “SAW”.|
|Symptoms||The ransomware will encrypt files by placing the [email protected] extension to all of them.|
|Distribution Method||Spam Emails, Email Attachments|
|Detection Tool|| See If Your System Has Been Affected by [email protected] Virus |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss [email protected] Virus.|
[email protected] File Virus (Jigsaw) – Infection
Jigsaw ransomware could infect computers using different methods for spreading that infection. Spam e-mails could be spreading its payload dropper. Those types of emails will try to convince you that something important is attached as a file to that e-mail. In actuality, the attachment will look like a legitimate document or one that is archived, but it is a file containing a malicious script. If you open that file, it will launch the payload for the ransomware. You can preview the analysis of one such file on the VirusTotal service:
As you can see from the above image, the payload file is called Xbox-One-Mod-Menu.exe which suggests that the malware could have targeted gamers who were trying to get a menu mod on a USB flash drive, and then launch it via that USB on the Xbox One console for a game such as Grand Theft Auto V/Online.
Jigsaw ransomware might be using other methods for spreading, like putting the payload file dropper via social media and file-sharing sites. Freeware applications which roam the Internet could be presented as useful but also could hide the malicious files of this virus. Refrain from opening files after you download them, especially if they come from unverified sources, such as links and e-mails. First, you should scan these files with a security tool, and also make sure to check their sizes and signatures for anything that seems unusual. You should read the ransomware preventing tips topic in the forum.
[email protected] File Virus (Jigsaw) – Analysis
The Jigsaw ransomware ransomware virus keeps on appearing on the radar of malware researchers. Once more it is themed around the Jigsaw character from the movie series “SAW” as its original Jigsaw ransomware variant.
When the Jigsaw virus is executed, it will modify an existing entry in the Windows Registry or create a new one to achieve persistence. That registry entry makes the malware to automatically execute with each boot of the Windows operating system. Afterward, your files will get encrypted, and receive the same extension.
Next, a window will pop-up on your screen that shows the Jigsaw character and text being typed out with green letters. That text is the ransom message with information and instructions for payment.
The text of the ransom note reads:
I want to play a game with you. Let me explain the rules:
Your personal files are being deleted. Your photos, videos, documents, etc…
But, don’t worry! It will only happen if you don’t comply.
However I’ve already encrypted your personal files, so you cannot access them.
Every hour I select some of them to delete permanently,
therefore I won’t be able to access them, either.
Are you familiar with the concept of exponential growth? Let me help you out.
It starts out slowly then increases rapidly.
During the first 24 hour you will only lose a few files,
the second day a few hundred, the third day a few thousand, and so on.
If you turn off your computer or try to close me, when I start next time
you will get 1000 files deleted as a punishment.
Yes you will want me to start next time, since I am the only one that
is capable to decrypt your personal data for you.
Now, let’s start and enjoy our little game together!
1 file will be deleted.
Please, send at least $150 worth of Bitcoin here:
The Jigsaw ransomware scares you that it will delete files from your PC every hour until you pay and there is nothing else that you can do to prevent that. But you should NOT under any circumstances pay the ransom as the note is lying to you – the virus is decryptable. Supporting cybercriminals is a bad idea as that will only motivate them to do more criminal acts.
[email protected] File Virus (Jigsaw) – Encryption
A decrypter tool is already available thanks to the malware researcher Michael Gillespie. You can find it in the bottom of the article.
The list with 126 file extensions that will become encrypted is split in two inside the code of the ransomware. The full list is the following:
→.3dm, .3g2, .3gp, .7zip, .aaf, .accdb, .aep, .aepx, .aet, .ai, .aif, .as, .as.txt, .as3, .asf, .asp, .asx, .avi, .bmp, .c, .class, .cpp, .cs, .csv, .dat, .db, .dbf, .doc, .docb, .docm, .docx, .dot, .dotm, .dotx, .dwg, .dxf, .dxf.c, .efx, .eps, .fla, .flv, .gif, .h, .idml, .iff, .indb, .indd, .indl, .indt, .inx, .jar, .java, .jpeg, .jpg, .js, .m3u, .m3u8, .m4u, .max, .mdb, .mid, .mkv, .mov, .mp3, .mp4, .mpa, .mpeg, .mpg, .msg, .pdb, .pdf, .php, .plb, .pmd, .png, .pot, .potm, .potx, .ppam, .ppj, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .prel, .prproj, .ps, .psd, .py, .ra, .rar, .raw, .rb, .rtf, .sdf, .ses, .sldm, .sldx, .sql, .svg, .swf, .tif, .txt, .vcf, .vob, .wav, .wma, .wmv, .wpd, .wps, .xla, .xlam, .xll, .xlm, .xls, .xlsb, .xlsm, .xlsx, .xlt, .xltm, .xltx, .xlw, .xml, .xqx, .zip
The list with the file extensions for encryptions seems to be updated with a couple of new ones, but still around the number of 126. The encrypted files will have the [email protected] extension appended to them, after their file name.
The Jigsaw ransomware could be set to erase all the Shadow Volume Copies from the Windows operating system with the help of the following command:
→vssadmin.exe delete shadows /all /Quiet
In case the command stated above is executed that would make the encryption process even more efficient as it will eliminate one of the possible ways for restoring your data. If your computer machine was infected with this ransomware and your files are locked, read on through to find out how you could potentially recover your data.
Remove Jigsaw Ransomware and Restore [email protected] Files
If your computer got infected with the Jigsaw ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.