Sage ransomware. How to delete? (Removal tutorial)

removal by Olivia Morelli - - | Type: Ransomware
12

Sage ransomware. Another virus with a well-designed ransom payment page

Sage virus is another professional ransomware that can compete with viruses like Cerber. Just like any other illegal program, Sage malware sneaks into the computer system after making the victim believe that it is a legitimate file. As soon as it gets into the system, it executes itself and encrypts files stored on the system with a RSA-4096 cipher. During this process, the virus also decorates each corrupted file with a .sage file extension. Following a successful encryption, Sage ransomware replaces current computer background with [6 random chars].bmp, which holds information about the cyber attack and says that the victim must open !Recovery_[6 random chars].txt or !Recovery_[6 random chars].html file and learn how to get the encrypted files back. These files contain commands that tell the victim to go to a particular website. First of all, the victim needs to confirm that one is not a robot and enter a combination of symbols shown in a picture. Then, one shall proceed to an individual ransom-payment website, which has five different pages – Home, Payment, Test decryption, Instructions, and Support.

The payment website contains a lot of text regarding the encryption procedure. The virus seeks to convince the victim that there is no way to decrypt files except paying the ransom. Samples of Sage that we have encountered asked for 0.2 – 0.7 Bitcoins, which means that cyber criminals are testing different ransom prices to see how willingly victims pay it. Sadly, ransomware is a powerful virus, and unless the developer is a complete fool, there is no way to restore files without a private key that is created during the encryption process – it is also known as the decryption key, which can be used for data recovery. However, we usually do not advise paying the ransom because cyber criminals rarely show any interest to interact with victims after infecting their computers. They just seek to collect payments; therefore, if you have been infected with such malware, better start Sage removal process instead of buying Bitcoins for cyber criminals and willing to get Sage_Decryptor.exe. To remove Sage virus, we highly recommend using anti-malware program like Reimage or Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus.

Update. At the beginning of 2017, the second version of this virus emerged. Sage 2.0 virus reportedly spreads via .ZIP archives that contain another .ZIP archive inside. The final .ZIP archive has either a malicious Word or JS file, which, once executed, downloads and installs Sage 2.0 ransomware on the system. The updated variant of Sage has excluded the “Test Decryption” page from the ransom payment page, and this time it demands for a much larger ransom – about 2 Bitcoins. The virus also adds .sage file extensions to target files that it encrypts and drops !Recovery_[3 random chars].html ransom note on desktop. More information about Sage v2.0 malware can be found here.

How could I allow ransomware to infect my computer?

Unfortunately, ransomware authors are very sneaky. They craft professional-looking email messages and send them out to thousands of recipients. Such emails usually contain one malicious file attachment that executes the ransomware virus on the system. Additionally, scammers might send out letters with malicious URLs or images that contain URLs to websites that host exploit kits. Exploit kits can be used for ransomware distribution. Finally, it is possible (and very likely) to download malware alongside pirated software. If you want to stay away from shady content online, better not click on anything that raises at least a bit of suspicion to you. Of course, it is highly recommended to install trustworthy anti-malware program for your safety.

How can I remove Sage ransomware from my PC?

If you think that it will be easy to remove Sage virus, you are wrong. Ransomware, unlike legitimate programs, tends to drop dozens of randomly named files on the system, and it is very hard to recognize them. Therefore, we suggest using a special software for ransomware elimination. Our team recommends anti-malware programs because unlike traditional antivirus, they can detect and remove less-dangerous computer threats that belong to spyware or malware category. Below, we provide an informative guide on how to complete Sage removal without a computer technician’s help. If you have any questions, send them to our support team.

We might promote some affiliate products. An entire disclosure is provided in our Terms and Conditions. By Downloading any recommended Anti-spyware software to uninstall Sage ransomware you accept our privacy policy and terms and conditions.
try it now!
Download
Reimage (remover) Happiness
Guarantee
Download
Reimage (remover) Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Computer security experts recommend using Reimage to uninstall Sage ransomware. Reimage scans the entire computer system and checks whether it is infected with spyware/malware or not. If you want to remove computer threats and secure your computer system, you should consider buying the licensed version of Reimage.

You can find more details about this program in Reimage review.

You can find more details about this program in Reimage review.
Press mentions on Reimage
Press mentions on Reimage
Sage ransomware screenshot
The website of Sage ransomware

Manual Sage Virus Removal Instructions:

Eliminate Sage using Safe Mode with Networking

You can detect malware using Reimage.
You need to purchase a licensed version of it to remove threats.
More details about Reimage.

  • Step 1: Restart your computer in Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Go to Start Shutdown Restart OK.
    2. As soon as your computer starts, start pressing F8 key repeatedly before the Windows logo shows up.
    3. Choose Safe Mode with Networking from the list Choose 'Safe Mode with Networking' option

    Windows 10 / Windows 8
    1. Click on the Power button at the Windows login screen, and then press and hold Shift key on your keyboard. Then click Restart.
    2. Then select Troubleshoot Advanced options Startup Settings and click Restart.
    3. Once your computer starts, select Enable Safe Mode with Networking from the list of options in Startup Settings. Choose 'Enable Safe Mode with Networking' option
  • Step 2: Remove Sage

    Sign in to your account and launch any Internet browser. Download a legitimate anti-malware software, for instance, Reimage. Make sure you update it to the latest version and then run a full system scan with it to detect and eliminate all malicious components of the ransomware to remove Sage completely.

If your ransomware does not allow you to access Safe Mode with Networking, please follow the instructions provided below.

Eliminate Sage using System Restore

You can detect malware using Reimage.
You need to purchase a licensed version of it to remove threats.
More details about Reimage.

  • Step 1: Restart your computer in Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Go to Start Shutdown Restart OK.
    2. As soon as your computer starts, start pressing F8 key repeatedly before the Windows logo shows up.
    3. Choose Command Prompt from the list Choose 'Safe Mode with Command Prompt' option

    Windows 10 / Windows 8
    1. Click on the Power button at the Windows login screen, and then press and hold Shift key on your keyboard. Then click Restart.
    2. Then select Troubleshoot Advanced options Startup Settings and click Restart.
    3. Once your computer starts, select Enable Safe Mode with Command Prompt from the list of options in Startup Settings. Choose 'Enable Safe Mode with Command Prompt' option
  • Step 2: Perform a system restore to recover files and settings
    1. When the Command Prompt window appears, type in cd restore and press Enter. Type 'cd restore' without quotes and hit 'Enter'
    2. Then type rstrui.exe and hit Enter.. Type 'rstrui.exe' without quotes and hit 'Enter'
    3. In a new window that shows up, click the Next button and choose a restore point that was created before the infiltration of Sage and then click on the Next button again. When 'System Restore' wizard comes up, click 'Next'. Choose a preferable restore point and click 'Next'
    4. To start system restore, click Yes. Hit 'Yes' and start system restore
    After restoring the computer system to an antecedent date, install and check your computer with Reimage to uncover any remains of Sage.

Bonus: Restore your files

Using the tutorial provided above you should be able to eliminate Sage from the infected device. novirus.uk team has also prepared an in-depth data recovery guide which you will also find above.

If you have a backup, just remove the virus and plug the data storage disk/drive into your computer to import files. If you do not have it, try methods described below.

There are a couple of methods you can apply to recover data encrypted by Sage:

Use Data Recovery Pro tool

As long as there are no tools capable of decrypting .sage file extension files, we advise using this data recovery software.

  • Download Data Recovery Pro (https://novirus.uk/download/data-recovery-pro-setup.exe);
  • Install Data Recovery on your computer following the steps indicated in the software’s Setup;
  • Run the program to scan your device for the data encrypted by Sage ransomware;
  • Recover the data.

Look for Windows Previous Versions

If you have created a system restore point, you can use this method now. You can recover individual files with a help of this trick:

  • Right-click on the encrypted document you want to recover;
  • Click “Properties” and navigate to “Previous versions” tab;
  • In the “Folder versions” section look for the available file copies. Choose the desired version and press “Restore”.

It is strongly recommended to take precautions and secure your computer from malware attacks. To protect your PC from Sage and other dangerous viruses, you should install and keep a powerful malware removal tool, for instance, Reimage, Plumbytes Anti-MalwareWebroot SecureAnywhere AntiVirus or Malwarebytes Anti Malware.

About the author

Olivia Morelli
Olivia Morelli

If you found this free removal tutorial helpful, please consider making a donation to support us. Even the smallest amount will be appreciated and will help to keep this service alive.

More information about the author

Source: http://www.2-spyware.com/remove-sage-ransomware-virus.html

Uninstall guides in different languages