How to Recover Files Encrypted by Sage Ransomware?

Issue: Hello, my files have been corrupted in some kind of way, and I can see that they all have .sage file extensions now. I believe my computer was hit by a virus named Sage. Can you help me to recover files encrypted by Sage ransomware, please?

Solved Answer

Sage ransomware is an active threat nowadays, and its authors are taking all possible measures to distribute this malicious program efficiently. They have already created Sage 2.0 ransomware, too. Due to many complaints that Sage ransomware victims express on online forums, we assume that criminals’ efforts to spread this virus pay off. Just like you discovered, Sage virus appends .sage file extensions to files it encrypts and then leaves !Recovery_[6 chars]_ file on the desktop in two different formats – .txt and .html. The virus changes desktop wallpaper with a black image with some red text on it. This text says:

Sage encrypted your files!

After reading all information provided in these files, you probably realized what does this malicious program wants from you. It encrypted your data in order to blackmail you and keep your files locked until you pay an enormous ransom. You should not pay ransoms to cyber criminals – they tend to simply take victim’s money and make off with it. If you do not want to waste your money, better keep it for yourself. Now, we must say that unfortunately, malware analysts weren’t able to find flaws in Sage’s source code and therefore nobody managed to create Sage decryption tool. However, there is still hope to restore at least part of your files. We will list all possible data recovery options below, so do not give up and try all of them out.

Quick tip: Do not forget to remove Sage virus before you start data recovery procedure. You do not want the virus to interrupt this process! We recommend you to follow these Sage removal instructions and use a malware removal tool like FortectMac Washing Machine X9 to get rid of the virus.

How to Recover Files Encrypted by Sage Ransomware?

Technique 1. Use a Data Backup

The best, most efficient and 100% working method to recover files encrypted by Sage ransomware is based on data backups. If you have noticed warning from IT security experts a while ago and created a data backup, count yourself lucky. You can use it now and recreate at least the majority of data that Sage virus corrupted. You need to uninstall the virus first – do not rush to plug the device with data copies into the compromised computer; otherwise the malware might contaminate it as well and this way you could lose your backup! Once you are sure that the virus is gone for good, plug the device into the computer and transfer data copy onto the computer.

TIP: We do not recommend you to delete data that was encrypted. Consider transferring it to a particular folder or moving to an external data storage device. There were some cases when a “miracle” happened, and ransomware decryption keys were released/leaked publicly.

Technique 2. Use Volume Shadow Copies Service

If you didn’t know this yet, Microsoft bundles a special technology into Windows operating systems, which creates automatic or manual backups now and then. Volume Shadow Copies can be used to recreate files that have been deleted or modified in a particular way. It means that they can also be used when files become encrypted. Sometimes viruses delete Volume Shadow Copies, so in such case, you won’t be able to recover files using this method.

  1. Install ShadowExplorer. It is a program that will help you to detect Volume Shadow Copies. You can download ShadowExplorer from its official website.
  2. Open the program and click on a menu in the top left corner of its window. Here, select disk that stores encrypted files.
  3. Select folder that you wish to restore and choose “Export.”

Technique 3. Use Data Recovery Pro

  1. Data Recovery Pro is an advantageous tool that can help you to restore modified files easily. Although it might not be able to break Sage’s encryption, we still recommend you to try this tool.
  2. Download Data Recovery Pro.
  3. Install it on your computer using directions provided by the installation wizard.
  4. Open the program and run a system scan to detect .sage file extension files.
  5. Restore your files.

Technique 4. Restore Files With a Help of a Restore Point

Created a restore point a while ago? Then we believe that you will be able to recover your files using this method.

  1. Right-click on a file that you wish to restore.
  2. A menu will appear. Choose “Properties” from the list. Then go to “Previous Versions” tab.
  3. In “Folder versions,” look for previous file versions, select the one you wish to restore, and hit “Restore” button.

Recover files and other system components automatically

To recover your files and other system components, you can use free guides by experts. However, if you feel that you are not experienced enough to implement the whole recovery process yourself, we recommend using recovery solutions listed below. We have tested each of these programs and their effectiveness for you, so all you need to do is to let these tools do all the work.

do it now!
recovery software Happiness
Compatible with Microsoft Windows
Do you have any trouble?
If you are having problems related to Fortect, you can reach our tech experts to ask them for help. The more details you provide, the better solution they will provide you.
Fortect - a patented specialized Windows repair program. It will diagnose your damaged PC. It will scan all System Files, DLLs and Registry Keys that have been damaged by security threats.
This patented repair process uses a database of 25 million components that can replace any damaged or missing file on user's computer.
To repair damaged system, you have to purchase the licensed version of Fortect malware removal tool.

Access geo-restricted video content with a VPN

Private Internet Access is a VPN that can prevent your Internet Service Provider, the government, and third-parties from tracking your online and allow you to stay completely anonymous. The software provides dedicated servers for torrenting and streaming, ensuring optimal performance and not slowing you down. You can also bypass geo-restrictions and view such services as Netflix, BBC, Disney+, and other popular streaming services without limitations, regardless of where you are.

Don’t pay ransomware authors – use alternative data recovery options

Malware attacks, particularly ransomware, are by far the biggest danger to your pictures, videos, work, or school files. Since cybercriminals use a robust encryption algorithm to lock data, it can no longer be used until a ransom in bitcoin is paid. Instead of paying hackers, you should first try to use alternative recovery methods that could help you to retrieve at least some portion of the lost data. Otherwise, you could also lose your money, along with the files. One of the best tools that could restore at least some of the encrypted files –  Data Recovery Pro.

About the author
Ugnius Kiguolis
Ugnius Kiguolis - The problem solver

Ugnius Kiguolis is the founder and editor-in-chief of UGetFix. He is a professional security specialist and malware analyst who has been working in IT industry for over 20 years.

Contact Ugnius Kiguolis
About the company Esolutions

Read in other languages

What you can add more about the problem: "How to Recover Files Encrypted by Sage Ransomware?"