Sigrun Virus 🔐 (. Sigrun Files) — How to Remove?
Sigrun Virus: What Is Known So Far? Sigrun Adds Its Extra. Sigrun Extension to Every File’s Name. for Example, a File Entitled “Photo. Jpg” Will Be Turned into...
Sigrun virus: what is known so far?
Sigrun adds its extra .sigrun extension to every file’s name. For example, a file entitled “photo.jpg” will be turned into “photo.jpg.sigrun”. In the same manner, the Excel file named “table.xlsx” will become “table.xlsx.sigrun”, and so forth.
In each directory containing the encoded files, a RESTORE-SIGRUN.txt text document will be found. It is a ransom money memo. It contains information on the ways of contacting the racketeers and some other remarks. The ransom note usually contains a description of how to buy the decryption tool from the Sigrun developers. You can obtain this decryptor after contacting through email. That is basically the scheme of the felony.
| Name | Sigrun Virus |
| Extension | .sigrun |
| Ransomware note | RESTORE-SIGRUN.txt |
| Ransom | $500-$1500 |
| Contact | |
| Detection1 | Trojan.Ransom.VirLock, Ransom:MSIL/Cryptolocker.EK!MTB, Ransom:Win32/MedusaLocker.B!MTB |
| Symptoms | Your files (photos, videos, documents) have a .sigrun extension and you can’t open them. |
| Fix Tool | See If Your System Has Been Affected by Sigrun virus |
The RESTORE-SIGRUN.txt document accompanying the Sigrun malware states the following:
~~~~~~SIGRUN RANSOMWARE~~~~~~~~~ Dear user, all your important files have been encrypted! Don\'t worry! Your files still can be restored by us! In order to restore it you need to contact with us via e-mail. As a proof we will decrypt 3 files for free! Please, attach this to your message: -
In the screenshot below, you can see what a directory with files encrypted by the Sigrun looks like. Each filename has the “.sigrun” extension appended to it.
How did Sigrun ransomware end up on my PC?
Nowadays, there are three most exploited ways for malefactors to have ransomware settled in your digital environment. These are email spam, Trojan introduction and peer-to-peer networks.
If you open your mailbox and see emails that look like familiar notifications from utility services companies, delivery agencies like FedEx, Internet providers, and whatnot, but whose “from” field is strange to you, beware of opening those emails. They are most likely to have a viral item attached to them. So it is even more dangerous to download any attachments that come with letters like these.
Another option for ransom hunters is a Trojan virus model2. A Trojan is a program that infiltrates into your machine pretending to be something else. For example, you download an installer for some program you want or an update for some service. However, what is unpacked reveals itself a harmful program that encodes your data. As the update file can have any title and any icon, you’d better be sure that you can trust the source of the things you’re downloading. The optimal way is to use the software companies’ official websites.
As for the peer-to-peer networks like BitTorrent or eMule, the danger is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is reasonable to scan the directory containing the downloaded items with the anti-malware utility as soon as the downloading is done.