Sabs Ransomware (. Sabs Files) — How to Remove Virus?

What is known about the Sabsvirus?

Sabs will add its own .SABS extension to every file’s name. For example, an image named “photo.jpg” will be turned into “photo.jpg.SABS”. Just like the Excel table named “table.xlsx” will end up as “table.xlsx.SABS”, and so on.

In each folder with the encrypted files, a RESTORE_FILES_INFO.txt file will appear. It is a ransom money note. It contains information on the ways of contacting the racketeers and some other information. The ransom note most probably contains a description of how to buy the decryption tool from the ransomware developers. That is pretty much the scheme of the malefaction.

NameSabs Virus
Extension.SABS
Ransomware noteRESTORE_FILES_INFO.txt
Detection1Virus.VirLock.1, Ransom:Win32/StopCrypt.PAH!MTB, Ransom:Win32/Shade!MSR
SymptomsYour files (photos, videos, documents) get a .SABS extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Sabs virus

In the picture below, you can see what a folder with files encrypted by the Sabs looks like. Each filename has the “.SABS” extension appended to it.

An example of encrypted .SABS files.

How did my machine catch Sabs ransomware?

Nowadays, there are three most exploited ways for tamperers to have the Sabs virus planted in your system. These are email spam, Trojan infiltration and peer file transfer.

If you access your mailbox and see letters that look just like notifications from utility services providers, delivery agencies like FedEx, web-access providers, and whatnot, but whose sender is unknown to you, be wary of opening those emails. They are very likely to have a viral file attached to them. Therefore, it is even more dangerous to open any attachments that come with letters like these.

Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that infiltrates into your PC disguised as something legal. For instance, you download an installer of some program you need or an update for some software. But what is unpacked reveals itself a harmful program that corrupts your data. As the installation wizard can have any name and any icon, you have to make sure that you can trust the source of the files you’re downloading. The best way is to trust the software developers’ official websites.

As for the peer-to-peer file transfer protocols like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Internet. You can never guess what you download until you get it. So you’d better be using trustworthy resources. Also, it is a good idea to scan the folder containing the downloaded objects with the anti-malware utility as soon as the downloading is done.

Robert Thorne

Robert Thorne

Automotive & Future Transportation Editor

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.

Share this article
Twitter Facebook Pinterest