SeginChile is a cryptovirus using an open-source ransomware kit called eda2. What is unique about SeginChile is that the virus does not ask for ransom. The virus will encrypt your files and place .seginchile as an extension. To see how to remove the SeginChile mock ransomware and how to restore your files, you should read this article to the end.
|Short Description||The virus uses an open-source ransomware kit. It encrypts files, but doesn’t demand a ransom for decrypting them.|
|Symptoms||The virus encrypts files and puts a desktop background to make itself known as well as a instrucciones.html file. All files are locked with .seginchile extension.|
|Distribution Method||Spam Emails, Email Attachments, Executable Files|
|Detection Tool|| See If Your System Has Been Affected by malware |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss SeginChile.|
SeginChile Cryptovirus – Delivery Methods
SeginChile cryptovirus could be delivered in a few ways. Viruses usually spread via spam emails and infected computers in a given network. Such emails often have attached files with the malware code inside of them. Opening any attachment will infect your computer. Malicious code may be included the email body, so opening the email could be enough to get infected.
The virus could also spread through other methods, such as social media and file sharing networks. They can deliver the same attachments and files. The virus is hidden inside the files but presented as useful. One of the ways to prevent this is to stay away from suspicious files and do not tamper with links and attachments as well, especially if they are of an unknown origin.
SeginChile Cryptovirus – Technical Information
SeginChile is the name of a cryptovirus that has been spreading around lately. It might be targeting mainly people of the Republic of Chile if we judge by the fact that the Spanish language is used for all files created by the virus.
After a successful encryption, the desktop background of a user is changed. Here is what the file reads:
Seguridad Informática Chile
Comunidad de Seguridad informática de Chile
TUS ARCHIVOS HAN SIDO CIFRADOS
Chile Computer Security
Computer Security Community of Chile
YOUR FILES HAVE BEEN ENCRYPTED
And this is how the picture looks like:
Alongside the image seen above, another file is created. The other file is called Instrucciones.html.
The file Instrucciones.html contains instructions as the name hints. But no ransom is asked in any way. That becomes clear from the instructions, which read:
•Ingresar a https://victima(.)hacking(.)cl
•Ingresar el identificador que se te ha proporcionado mas abajo
•Descargar el archivo para descifrar
•Se generara una clave de descifrado, debes ingresar esa clave en el archivo de descifrado
• Login to https: //victima.hacking.cl
• Enter the ID that you have provided below
• Download the file to decrypt
• a decryption key is created, you must enter that key in the file decryption
• IDENTIFIER: [random symbols are given]
The ransom note is clear cut. Once you go to that site, you will see that you can input your ID number, and the site will generate a link. From the link, you can download an archive file containing a key for decryption. No ransom money is demanded, and no communication is involved as the system is automatic.
You can preview the site from the snapshot below:
No explanation exists for now as to why this mock ransomware is on the loose, especially why the site system is implemented.
The SeginChile cryptovirus encrypts files with different extensions. The encryption process uses a 256-bit AES algorithm. The extensions that this virus encrypts are the following:
→.doc, .docx, .html, .txt, .xls, .xlsx, .xml, .jpg, .asp, .aspx, .csv, .mdb, .odt, .pdf, .php, .png, .ppt, .pptx, .psd, .sln, .sql
The list of file extensions above might be little, but these are one of the most widely-spread ones and often store important information. After the encryption process is fully complete, each and every file will have the same extension – .seginchile.
Remove SeginChile Cryptovirus and Restore .seginchile Files
If your PC is infected with the SeginChile cryptovirus, you should have some experience in removing viruses. You should get rid of SeginChile to stop it from encrypting more files and PCs over the network. We recommend that you remove this mock ransomware by following the step-by-step instructions provided here. You will also see how to restore your files.
- Guide 1: How to Remove SeginChile from Windows.
- Guide 2: Get rid of SeginChile from Mac OS X.
- Guide 3: Remove SeginChile from Google Chrome.
- Guide 4: Erase SeginChile from Mozilla Firefox.
- Guide 5: Uninstall SeginChile from Microsoft Edge.
- Guide 6: Remove SeginChile from Safari.
- Guide 7: Eliminate SeginChile from Internet Explorer.
How to Remove SeginChile from Windows.
Step 1: Boot Your PC In Safe Mode to isolate and remove SeginChile
Step 2: Uninstall SeginChile and related software from Windows
Step 3: Clean any registries, created by SeginChile on your computer.
The usually targeted registries of Windows machines are the following:
You can access them by opening the Windows registry editor and deleting any values, created by SeginChile there. This can happen by following the steps underneath:
Get rid of SeginChile from Mac OS X.
Step 1: Uninstall SeginChile and remove related files and objects
1. Hit the ⇧+⌘+U keys to open Utilities. Another way is to click on “Go” and then click “Utilities”, like the image below shows:
- Go to Finder.
- In the search bar type the name of the app that you want to remove.
- If all of the files are related, hold the ⌘+A buttons to select them and then drive them to “Trash”.
In case you cannot remove SeginChile via Step 1 above:
You can repeat the same procedure with the following other Library directories:
Tip: ~ is there on purpose, because it leads to more LaunchAgents.
Step 2: Scan for and remove malware from your Mac
Remove SeginChile from Google Chrome.
Step 1: Start Google Chrome and open the drop menu
Step 2: Move the cursor over "Tools" and then from the extended menu choose "Extensions"
Erase SeginChile from Mozilla Firefox.
Step 1: Start Mozilla Firefox. Open the menu window
Step 2: Select the "Add-ons" icon from the menu.
Step 3: Select the unwanted extension and click "Remove"
Uninstall SeginChile from Microsoft Edge.
Step 1: Start Edge browser.
Step 2: Open the drop menu by clicking on the icon at the top right corner.
Step 3: From the drop menu select "Extensions".
Step 4: Choose the suspected malicious extension you want to remove and then click on the gear icon.
Step 5: Remove the malicious extension by scrolling down and then clicking on Uninstall.
Remove SeginChile from Safari.
Step 1: Start the Safari app.
Step 3: From the menu, click on "Preferences".
Step 4: After that, select the 'Extensions' Tab.
Step 5: Click once on the extension you want to remove.
Step 6: Click 'Uninstall'.
A pop-up window will appear asking for confirmation to uninstall the extension. Select 'Uninstall' again, and the SeginChile will be removed.
Eliminate SeginChile from Internet Explorer.
Step 1: Start Internet Explorer.
Step 2: Click on the gear icon labeled 'Tools' to open the drop menu and select 'Manage Add-ons'
Step 3: In the 'Manage Add-ons' window.