Hard drive (external) affected by sglh ransomware

Status
Not open for further replies.

Nicky Dsouza

New Member
Thread author
Nov 24, 2020
2
My files have been replaced with file.jpg.sglh . I have tried to quarantine the virus using malwarebytes but when i try to decrypt the files using emsisoft tool it says something like "has an online Id, unable to deccrypt".
Any help would be highly appreciated.
Thank You.
 
  • Like
Reactions: upnorth

struppigel

Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
656
Hello Nicky Dsouza

I am Karsten and will gladly help you with any malware-related problems.

Please familiarize yourself with the following ground rules before you start.
  • Read my instructions thoroughly, carry out each step in the given order.
  • Do not make any changes to your system, or run any tools other than those I provided. Do not delete, fix, uninstall, or install anything unless I tell you to.
  • If you are unsure about anything or if you encounter any problems, please stop and inform me about it.
  • Stick with me until I tell you that your computer is clean. Absence of symptoms does not mean that your computer is free of malware.
  • Back up important files before we start.
  • Note: On weekends I might be slow to reply
-------------------------------------------------------------------

The ransomware your system has been infected with is called STOP ransomware. It commonly distributed via pirated software and bad software downloads.
This ransomware is not decryptable if your files have been encrypted with an online key. That you have an online key was already confirmed by using Emsisofts decrypter.

Your options without a backup:

1) Recovery: In rare cases ransomware fails to delete shadow volume copies or fails to delete the original files properly. You can try to recover files via shadow volume copies and file recovery software.
2) Repair: Certain file types, mainly video and audio files, can possibly be repaired with tools like MediaRepair. But these files will loose some data.
3) Wait: Backup encrypted files and a ransom note and wait in case a solution comes up later. Maybe law enforcement gets hands on the keys or the criminals publish the keys as it happened with, e.g., GandCrab. I suggest reading the news on this. Emsisoft will update their decrypter if that happens.
4) Pay: There is the option of paying the criminals, but we highly recommend against this step. You will just fund later attacks. You may also pay without getting your files back. These are criminals and as such not trustworthy.

Please let me know if you want assistance with recovery or repair.
 

Nicky Dsouza

New Member
Thread author
Nov 24, 2020
2
Hey @struppigel Thanks for the reply.
I need to recover the files but since they are already infected backup won't be an option right??(External HDD infected)
If there is a way to recover the files despite it being encrypted by an online key , will i lose some data??
It will be really helpful if you let me know the recovery process if any.
Thank you for the help.

Regards,
Nicky
 

struppigel

Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
656
Hello Nicky.

If your backup got encrypted, you have no working backup anymore. The options above apply to you.
The chances are low that you get your files back with file recovery because ransomware takes precautions that these don't work.
File repair only works for certain file types (audio, video) and with data loss.

  • Please download Shadow Explorer
  • Right-click on the Shadow Explorer archive, click Extract all.. and confirm to extract the files
  • In the extracted folder, double-click on ShadowExplorerPortable.exe to run the program
  • Now you can see previous versions of the files on the system. Make sure the correct drive letter is selected (usually "C:" )
  • There is a date on the upper bar. Check if there is a date available that was before the ransomware attack. If the date isn't available, you don't have any shadow volume copies from before and recovery is not possible.
  • Within Shadow Explorer, navigate to files or folders you want to recover
  • To recover: Right-click and click Export... then choose a folder to save the files to and click OK
Let me know if this works.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top