Samas ransomware uses RSA encryption to render files useless
Samas virus (also knowm as Samas DR and Samsam virus) is a typical ransomware-type computer malware[1] which is meant to corrupt all files on the infected system and make the victim beg to get those files back. In other words, criminals use this virus as a tool to blackmail people and get money from them (ransoms). Reportedly, Samas ransomware arrives in the form of gotohelldr.exe[2] file which, once executed, starts scanning the compromised system for target files, encrypts them with RSA-2048 encryption and appends .iloveworld file extension. The latest version of this virus appends .weareyourfriends, .theworldisyours, .whereisyourfiles and .helpmeencedfiles extensions to the target data. If you can see one of these extensions appended to your files, make sure you remove Samas ransomware from your computer. For that you can use one of the most effective tools called FortectIntego.
Once the ransomware encrypts the data, it cannot be accessed in any way, and you cannot reverse the encryption with the help of System Restore[3] or similar techniques. The only way to retrieve the data is to get the unique decryption key. Of course, this is the tool criminals offer to victims – but not for free. After encrypting all files, Samas ransomware saves TRY-READ-ME-TO-DEC.html, PLEASE_READ_FOR_DECRYPT_FILES_{victim’s ID} TXT, CHECK-IT-HELP-FILES.html, WHERE-YOUR-FILES.html or HELP-ME-ENCED-FILES.html which are the ransom notes used to inform the victim about the current situation. In this case, the ransom note tells the victim that files have been locked with a powerful encryption algorithm and that the only way to recover files is to pay a ransom. The ransom is 1.7 BTC, which is more or less 1040 USD. However, this virus can proliferate and infect all PCs connected to a network, so in such case, the virus suggests “premium” deal – decrypt data stored on all computers for 29 BTC, which is approximately 17,800 USD.

Can you imagine someone paying such a huge ransom? Unfortunately, there is a case that we want to mention. In 2016, hosted desktop and cloud provider VESK had to pay this sum of money to restore data encrypted on the computer network.[4] Sadly, in some cases, companies decide that it is better and quicker to pay up rather than lose years of work, but we still strongly advise you not to pay if your computer ever gets infected by ransomware. There are some cases when criminals disappear after receiving the ransom, leaving no hope to recover encrypted data.[5] Therefore, we do not recommend you to risk losing your money and rather try to restore some data from email, data storage devices, or a backup. Before you try to restore your files, remove this virus using anti-malware software. Samas removal can only be completed with an up-to-date virus removal tool, so update the anti-malware software after downloading it.
How does this malware example proliferate?
Speaking of ransomware, we have to say that almost all variants of this malicious computer infection spread using more or less same techniques. The most popular way of infecting the system with victim’s intervention is to send him or her a malicious email letter containing malware in the attached files or links included in the message. Apparently, these attachments and links are concealed and made to look trustworthy, so the victim can easily open the malicious file while thinking that it is a harmless file. Sadly, straight after that victim finds out that all files have been encrypted and cannot be recovered.
Another way that cyber criminals use to distribute malicious programs is known as malvertising. It means that cyber criminals insert malicious scripts into ad-networks and this way they can make malware-laden ads appear even on legitimate websites. After clicking on an infectious ad, the victim can immediately open a link that contains an exploit kit or just quickly drop the malicious file on the system.
How to remove Samas DR malware and restore encrypted data?
We advise you to remove Samas DR virus using one of our recommended malware removal tools. You can find more information about these programs in the “Software” section. However, if you need a quick recommendation, make sure you install FortectIntego or SpyHunterCombo Cleaner anti-spyware program. Please do not try to remove Samas ransomware yourself because you might delete wrong files accidentally. Keep in mind that ransomware-type viruses are capable of using hundreds of different components that you can hardly find using manual removal options. After a successful Samas removal, read data recovery options suggested below to try to restore your encrypted data.
Was this guide helpful?
3 comments