.choda File Virus (Jigsaw) – Remove It and Restore Files

.choda File Virus (Jigsaw) – Remove It and Restore Files

This article will help you to remove the .choda File Virus (Jigsaw ransomware) in full. Follow the ransomware removal instructions given at the end of the article.

The .choda File Virus is in actuality from the Jigsaw ransomware family of cryptoviruses. The cryptovirus uses the source code of the original malware. The .choda File virus has a list with around 126 file extensions that seeks to encrypt. All of the files which will get encrypted will receive the extension .choda appended to them. Afterward, a ransom note message will display in the Korean language.

Threat Summary

Name.choda File Virus
TypeRansomware, Cryptovirus
Short DescriptionThe ransomware will encrypt your files and display a screen with the ransom note, which might be themed around the movie “SAW” as the original ransomware is.
SymptomsThe ransomware will encrypt files by placing the .choda extension to all of them.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by .choda File Virus


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss .choda File Virus.

.choda File Virus (Jigsaw) – Spread

Jigsaw ransomware could infect computers using different methods for spreading that infection. Spam e-mails could be spreading its payload dropper. Those types of emails will try to convince you that something important is attached as a file to that e-mail. In actuality, the attachment will look like a legitimate document or one that is archived, but it is a file containing a malicious script. If you open that file, it will launch the payload for the ransomware. You can preview the analysis of one such file on the VirusTotal service:

As you can see above, the payload file is called 초다 랜섬웨어.exe.

Jigsaw ransomware might be using other methods for spreading, like putting the payload file dropper via social media and file-sharing sites. Freeware applications which roam the Internet could be presented as useful but also could hide the malicious files of this virus. Refrain from opening files after you download them, especially if they come from unverified sources, such as links and e-mails. First, you should scan these files with a security tool, and also make sure to check their sizes and signatures for anything that seems unusual. You should read the ransomware preventing tips topic in the forum.

.choda File Virus (Jigsaw) – In Detail

The Jigsaw ransomware ransomware virus keeps on appearing on the radar of malware researchers. This variant displays a text in the Korean language and not themed around the Jigsaw character from the movie series “SAW” as its original Jigsaw Ransomware variant did.

When the Jigsaw virus is executed, it will modify an existing entry in the Windows Registry or create a new one to achieve persistence. That registry entry makes the malware to automatically execute with each boot of the Windows operating system. Afterward, your files will get encrypted, and receive the same extension.

Next, a window will pop-up on your screen that shows the Jigsaw character and text being typed out with green letters. That text is the ransom message with information and instructions for payment.

The text of the ransom note reads:

주확톤 당진희 침퓨터가 지짐각하계 존쟝되었줄끄띠토

당신의 소중한 파일몰온 조다 랜섬웨어에 의해 감염되었습니대
이체 지 지시어 따르신다댄 파일몰 되몰딛 수 았습니다.
파일플온 모두 암호밤되었으니 억세스 형 수 없습니다.

0| 랜섬웨어는 뽀드암호화 방식몰 사듬합니대

따라서 확장자딩몰 바꿔도 소음 없습니다.

돠장자딩옴 바꾸신다띤 지시어 따라도 그 파일믄 되몰림 수 없몰수드 있습니다.

이 장음 닫거나 겅퓨터즐 끄지 마샵시오.

만약 이 장음 닫거나 컴퓨터룰 끈다연′

재시작혔-몰따 파일몰 지우겠습니다.

이 프로그렴몰 제외한 다른 희사의 복호학 프로그렴몰 쓰지 마샵시으.

다른 옥호화 프로그렘몰 사응시, 파일몰 되돌릴 수 없습니다.

이체부터 할 일은 간단합니다.

그저 여기 아테에 있는 칸어 극호화 코드믈 넣으면 극호화가 진행됨니대

The note roughly interpreted with machine translation in English says:

Dangjin of the State of the week, we will be in the summer John Jean!
Your precious files have been infected by the Mall of Jorda Ransomware
Now you can revert the distant files that follow my directives.
All of the files are encrypted and can not be accessed.

This ransomware is based on the Pode encryption method molar.

Therefore, there is no sense in changing the extension drive.

The file extension can not be reversed even if the directive is changed.

Do not close this long sound or turn off the computer, rules.

If this is closed or the computer is shut down, rule is “kite”

I’ll erase the files again.

Please do not use any other company’s extreme luxury pictures except this program.

While other other extreme glamorous prawns, the file can not be reversed.

From now on, things are simple.

Just enter in the space below here, the ultimate security code, and the dramatization will proceed.
Please do your best

The Jigsaw ransomware scares you that it will delete files from your PC every hour until you pay and there is nothing else that you can do to prevent that. But you should NOT under any circumstances pay the ransom as the note is lying to you – the virus is decryptable. Supporting cybercriminals is a bad idea as that will only motivate them to do more criminal acts.

.choda File Virus (Jigsaw) – Encryption

A decrypter tool might be made to decrypt files locked by this ransomware threat.

In case the cryptovirus follows the encryption process of the original ransomware, the list with 126 file extensions that will become encrypted will look like the following:

→.3dm, .3g2, .3gp, .7zip, .aaf, .accdb, .aep, .aepx, .aet, .ai, .aif, .as, .as.txt, .as3, .asf, .asp, .asx, .avi, .bmp, .c, .class, .cpp, .cs, .csv, .dat, .db, .dbf, .doc, .docb, .docm, .docx, .dot, .dotm, .dotx, .dwg, .dxf, .dxf.c, .efx, .eps, .fla, .flv, .gif, .h, .idml, .iff, .indb, .indd, .indl, .indt, .inx, .jar, .java, .jpeg, .jpg, .js, .m3u, .m3u8, .m4u, .max, .mdb, .mid, .mkv, .mov, .mp3, .mp4, .mpa, .mpeg, .mpg, .msg, .pdb, .pdf, .php, .plb, .pmd, .png, .pot, .potm, .potx, .ppam, .ppj, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .prel, .prproj, .ps, .psd, .py, .ra, .rar, .raw, .rb, .rtf, .sdf, .ses, .sldm, .sldx, .sql, .svg, .swf, .tif, .txt, .vcf, .vob, .wav, .wma, .wmv, .wpd, .wps, .xla, .xlam, .xll, .xlm, .xls, .xlsb, .xlsm, .xlsx, .xlt, .xltm, .xltx, .xlw, .xml, .xqx, .zip

The list with the file extensions for encryptions will be updated with if new information is found about it. The encrypted files will have the .choda extension appended to them, after their file name.

The Jigsaw ransomware could be set to erase all the Shadow Volume Copies from the Windows operating system with the help of the following command:

→vssadmin.exe delete shadows /all /Quiet

In case the command stated above is executed that would make the encryption process even more efficient as it will eliminate one of the possible ways for restoring your data. If your computer machine was infected with this ransomware and your files are locked, read on through to find out how you could potentially recover your data.

Remove Jigsaw Ransomware and Restore .choda Files

If your computer got infected with the Jigsaw ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.

Tsetso Mihailov

Tsetso Mihailov

Tsetso Mihailov is a tech-geek and loves everything that is tech-related, while observing the latest news surrounding technologies. He has worked in IT before, as a system administrator and a computer repair technician. Dealing with malware since his teens, he is determined to spread word about the latest threats revolving around computer security.

More Posts

Follow Me:

1 Comment

  1. AvatarRafael

    Hi guys,
    Someone have success to decrypt .stun files?


Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share