Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2017

How to remove SADStory ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

The brief overview of recently discovered SADStory ransomware virus

SADStory ransomware is a new file-encrypting malware written in Python programming language.[1] Spotted at the end of March 2017, this crypto-malware uses a sophisticated encryption algorithm to take victims’ files to hostage. The virus aims at the broad range of widely used file types, such as Microsoft Office documents, OpenOffice files, video, audio, image, pictures, archives, databases, etc. When data encryption is over, all the affected files have the .sad file extension and are moved to a new directory named __SAD STORY FILES__ . Then, SADStory virus generates a ransom note called SADStory_README_FOR_DECRYPT.txt. In this document, developers reveal that the only possible way to restore encrypted files is to use specific decryption program stored in the secret server. Hackers of ransomware often blackmail victims[2] and use scary tactics to motivate them to pay the ransom quickly. According to the ransom note, in every 6 hours, the virus permanently deletes one file. Thus, delaying the payment might lead to the data loss. People are asked to contact cyber criminals via tuyuljahat@hotmail.com or lucifer.fool@yandex.com email address to get information how much money they need to pay to redeem their files. Nevertheless, hackers give 96 hours before the decryption key is deleted; we do not recommend following their orders. The only thing you should rush is SADStory removal.

The main reason why you should not contact hackers and transfer particular amount of Bitcoins is that no one can guarantee that this would actually help to recover your files.[3] People behind SADStory ransomware virus claim to the have the decryptor and promise to send it via email. However, in some cases, file-encrypting viruses are poorly written, and even developers cannot do anything about data recovery. Thus, they might only take your money and leave you with useless files. What is more, of they provide a decryption software, it might be dangerous and infect your PC with other malware.[4] Bear in mind that while SADStory virus resides on the computer, the system becomes vulnerable. Thus, other cyber infections might use security vulnerabilities and attack the computer as well. Therefore, if you do not want to deal with other computer-related problems, install FortectIntego and remove SADStory automatically. Despite the fact that virus removal won’t recover your files, this step is crucial in order to use various data recovery methods to restore encrypted files. At the moment the virus is not decryptable; however, this argument is not valid to risk and pay the ransom.

SADStory ransomware virus

How can I get infected with ransomware?

It seems that developers of the SADStory ransomware apply the most popular malware distribution – malicious spam email attachments. Thus, you can get infected with this and many other file-encrypting viruses after clicking infected file attached to the fraudulent email. This message might trick you into believing that it was sent from reputable organization or company, and provides various important reasons to look at the dangerous document. Hence, in order to avoid ransomware, you should double-check the information before opening any attached file.[5] What is more, SADStory malware might infiltrate the computer using exploit kits, bogus software updates or downloads, and malware-laden ads. If you haven’t encountered ransomware yet, you need to be careful and vigilant when browsing the Web. What is more, you should make data backups in order to protect your files in case of emergency.

How can I remove SADStory virus from the PC?

The only safe way to get rid of the file-encrypting virus is to scan the computer with professional malware removal tools. For SADStory removal we recommend using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If you cannot install any of these programs, please have a look at our prepared instructions down below and reboot your machine to the Safe Mode. In this way, you will disable the virus and will be able to remove it automatically. Do not think about an idea to remove SADStory manually. This might lead to the serious computer-related issues because you might leave some of the malicious files or you might delete safe system files. Thus, you might damage computer’s system.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.