Remove SeginChile Cryptovirus and Restore .seginchile Encrypted Files - How to, Technology and PC Security Forum | SensorsTechForum.com

Remove SeginChile Cryptovirus and Restore .seginchile Encrypted Files

STF-seginchile-ransomware-segin-chile-cryptovirus-crypto-virus-note-desktop-info

SeginChile is a cryptovirus using an open-source ransomware kit called eda2. What is unique about SeginChile is that the virus does not ask for ransom. The virus will encrypt your files and place .seginchile as an extension. To see how to remove the SeginChile mock ransomware and how to restore your files, you should read this article to the end.

Threat Summary

NameSeginChile
TypeCryptovirus
Short DescriptionThe virus uses an open-source ransomware kit. It encrypts files, but doesn’t demand a ransom for decrypting them.
SymptomsThe virus encrypts files and puts a desktop background to make itself known as well as a instrucciones.html file. All files are locked with .seginchile extension.
Distribution MethodSpam Emails, Email Attachments, Executable Files
Detection Tool See If Your System Has Been Affected by SeginChile

Download

Malware Removal Tool

User ExperienceJoin Our Forum to Discuss SeginChile.

SeginChile Cryptovirus – Delivery Methods

SeginChile cryptovirus could be delivered in a few ways. Viruses usually spread via spam emails and infected computers in a given network. Such emails often have attached files with the malware code inside of them. Opening any attachment will infect your computer. Malicious code may be included the email body, so opening the email could be enough to get infected.

The virus could also spread through other methods, such as social media and file sharing networks. They can deliver the same attachments and files. The virus is hidden inside the files but presented as useful. One of the ways to prevent this is to stay away from suspicious files and do not tamper with links and attachments as well, especially if they are of an unknown origin.

SeginChile Cryptovirus – Technical Information

SeginChile is the name of a cryptovirus that has been spreading around lately. It might be targeting mainly people of the Republic of Chile if we judge by the fact that the Spanish language is used for all files created by the virus.

After a successful encryption, the desktop background of a user is changed. Here is what the file reads:

In Spanish:

Seguridad Informática Chile
Comunidad de Seguridad informática de Chile
TUS ARCHIVOS HAN SIDO CIFRADOS

In English:

Chile Computer Security
Computer Security Community of Chile
YOUR FILES HAVE BEEN ENCRYPTED

And this is how the picture looks like:

STF-seginchile-ransomware-segin-chile-cryptovirus-crypto-virus-note-desktop-info

Alongside the image seen above, another file is created. The other file is called Instrucciones.html.

The file Instrucciones.html contains instructions as the name hints. But no ransom is asked in any way. That becomes clear from the instructions, which read:

In Spanish:

Instrucciones

•Ingresar a https://victima(.)hacking(.)cl
•Ingresar el identificador que se te ha proporcionado mas abajo
•Descargar el archivo para descifrar
•Se generara una clave de descifrado, debes ingresar esa clave en el archivo de descifrado
•IDENTIFICADOR:

In English:

Instructions

• Login to https: //victima.hacking.cl
• Enter the ID that you have provided below
• Download the file to decrypt
• a decryption key is created, you must enter that key in the file decryption
• IDENTIFIER: [random symbols are given]

The ransom note is clear cut. Once you go to that site, you will see that you can input your ID number, and the site will generate a link. From the link, you can download an archive file containing a key for decryption. No ransom money is demanded, and no communication is involved as the system is automatic.

You can preview the site from the snapshot below:

STF-seginchile-ransomware-segin-chile-cryptovirus-crypto-virus-site-for-decryption-file

No explanation exists for now as to why this mock ransomware is on the loose, especially why the site system is implemented.

The SeginChile cryptovirus encrypts files with different extensions. The encryption process uses a 256-bit AES algorithm. The extensions that this virus encrypts are the following:

→.doc, .docx, .html, .txt, .xls, .xlsx, .xml, .jpg, .asp, .aspx, .csv, .mdb, .odt, .pdf, .php, .png, .ppt, .pptx, .psd, .sln, .sql

The list of file extensions above might be little, but these are one of the most widely-spread ones and often store important information. After the encryption process is fully complete, each and every file will have the same extension – .seginchile.

Remove SeginChile Cryptovirus and Restore .seginchile Files

If your PC is infected with the SeginChile cryptovirus, you should have some experience in removing viruses. You should get rid of SeginChile to stop it from encrypting more files and PCs over the network. We recommend that you remove this mock ransomware by following the step-by-step instructions provided here. You will also see how to restore your files.

Manually delete SeginChile from your computer

Note! Substantial notification about the SeginChile threat: Manual removal of SeginChile requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove SeginChile files and objects.
2. Find malicious files created by SeginChile on your PC.
3. Fix registry entries created by SeginChile on your PC.

Automatically remove SeginChile by downloading an advanced anti-malware program

1. Remove SeginChile with SpyHunter Anti-Malware Tool
2. Back up your data to secure it against infections and file encryption by SeginChile in the future
3. Restore files encrypted by SeginChile
Optional: Using Alternative Anti-Malware Tools

Berta Bilbao

Berta is the Editor-in-Chief of SensorsTechForum. She is a dedicated malware researcher, dreaming for a more secure cyber space.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.