This article explains the issues that occur when .vaca files virus infects a target system. It also provides a step-by-step guide on how to remove malicious files and how to potentially recover files encrypted by this ransomware.
The .vaca files virus is data locker ransomware identified as a strain ofXorist threat family. The purpose of this threat is to contaminate essential computer settings that will enable it to encode target types of files with the help of sophisticated cipher algorithm. Once it encrypts these files, the ransomware appends the extension .vaca to their names and leaves them completely inaccessible. As a consequence hackers attempt to extort a ransom payment.
|Name||.vaca Files Virus|
|Short Description||The threat encrypts target files stored on your computer, marks them with the .vaca extension and extorts a ransom by displaying a ransom message.|
|Symptoms||Important files are encoded and renamed with .vaca extension. You cannot open them. Hackers demand a ransom payment.|
|Distribution Method||Spam Emails, Email Attachments|
|Detection Tool|| See If Your System Has Been Affected by .vaca Files Virus |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss .vaca Files Virus.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
.vaca Files Virus – Distribution
Security researchers’ reports indicate that this .vaca Xorist ransomware is currently circling around the net in active attack campaigns. Attack campaigns could be set against users worldwide.
The most probable spread channel is malspam. Malspam is a technique that enables hackers to deliver their malicious code on users’ devices with the help of specially crafted emails. Such emails usually contain one or more of the following components:
- A link to compromised web page that is set to download and execute infection files directly on the PC. The URL address to this page may be presented in the form of an in-text link, banner, image, button or full URL address.
- A malicious file attachment that is presented as legitimate document by the text message. It could be uploaded in a .rar or .zip archive. Such a file could be set to evade active security measures and trick you into running the ransomware on your PC.
Other channels that may be part of the distribution strategy for .vaca files virus are malvertising, freeware installers, corrupted web pages, fake software updates, compromised software setups, files shared on forums and other.
.vaca Files Virus – Overview
The infection process with .vaca files virus is triggered by the execution of its payload file on the system. Since this file alone could not fulfill the attack to its very end, .vaca cryptovirus establishes several other malicious files in some of the following folders:
In order to establish these malicious files on the system, .vaca files virus may need to connect a remote command and control server so it can download the files from it. It could also be configured to create them directly on the system. When the threat establishes all needed infection files, it starts executing them in a strictly defined order.
As a result, the settings of various essential system components could be infected. One of these components is likely to be the Registry Editor. To be more precise it’s the registry keys Run and RunOnce that are likely to be infected by .vaca Xorist ransomware. So here are the exact registry locations that should be checked for malicious entries:
The reason for the contamination of these keys is their ability to execute automatically various system processes as well as processes associated with installed apps So once .vaca ransomware has its malicious entries there, it becomes one of the first things that load on your system every time you start it.
Another reason is the possibility to load its ransom note on the screen at the end of the infection. As of the note, it is dropped in a file called HOW TO DECRYPT FILES.txt. What you could read when you open this file is the following:
Attention! All your files are encrypted!
To restore your files and access them,
please send an SMS with the text [ID number] to [hackers’ number].
You have N attempts to enter the code.
When that number has been exceeded,
all the data irreversibly is destroyed.
Be careful when you enter the code!
Apparently, the purpose of this file is to blackmail you into contacting hackers in order to receive further instructions on ransom payment by them. What we could advise you is to avoid what this message states and attempt to cope with ransomware impacts with the help of secure methods that won’t expose your system, privacy, and money at risk of further abuses.
.vaca Files Virus – Encryption Process
Previous iterations of Xorist ransomware were reported to encrypt target files by using the XOR or TEA cipher algorithm. However, at this point, it is confirmed whether .vaca cryptovirus encodes files with the same ciphers or set to use other like RSA and AES.
However, like its predecessors .vaca is likely to scan infected systems for all files that have one of following extensions. Whenever a match is available it encodes the file by transforming parts of its original code:
→.zip, .rar, .7z, .tar, .gzip, .jpg, .jpeg, .psd, .cdr, .dwg, .max, .bmp, .gif, .png, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .txt, .pdf, .djvu, .htm, .html, .mdb, .cer, .p12, .pfx, .kwm, .pwm, .1cd, .md, .mdf, .dbf, .odt, .vob, .ifo, .lnk, .torrent, .mov, .m2v, .3gp, .mpeg, .mpg, .flv, .avi, .mp4, .wmv, .divx, .mkv, .mp3, .wav, .flac, .ape, .wma, .ac3
This ransomware marks all corrupted files with an extension of the same name .vaca. The appearance of this extension in the name of a file is a sure sign that you won’t be able to open this file. The good news is that specialists from Kaspersky team have released a decryptor for the previous Xorist version that is likely to be working for .vaca files recovery tool. Check the guide below for this tool.
Remove .vaca Files Virus and Restore Data
The Xorist ransomware strain associated with .vaca extension is a threat with highly complex code that plagues not only your files but your whole system. So you should properly clean and secure your infected system before you could use it regularly again. Below you could find a step-by-step removal guide that may be helpful in attempting to remove this ransomware. Choose the manual removal approach if you have previous experience with malware files. If you don’t feel comfortable with the manual steps select the automatic section from the guide. Steps there enable you to check the infected system for ransomware files and remove them with a few mouse clicks.
In order to keep your system safe from ransomware and other types of malware in future, you should consider the installation of a reliable anti-malware program. As an additional security layer that could prevent the occurrence of ransomware attacks you could install ananti-ransomware tool.
If you want to understand how to potentially fix encrypted files with the help of alternative data recovery approaches, make sure to read carefully all details mentioned in the step “Restore files”. We remind you that before you begin with the data recovery process, you should back up all encrypted files to an external drive as this will help you to prevent their irreversible loss.