Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2016

How to remove .Shit ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

.Shit file extension virus – new ransomware hailing from the family of Locky virus

PC security experts have been widely discussing the popularity of Locky virus. According to them, this ransomware has just switched to .Shit file extension that has been used to block victims’ files. Additional steps used by Shit ransomware are still the same – victim is informed about the encryption of the most valuable files and then asked to pay the ransom in exchange for the special decryption key. There is no doubt that this virus is just another extension of the notorious ransomware which has already released ODIN and Zepto versions before. Shit virus has been first spotted in France where it was spreading via spam emails as an attachment file labeled Receipt. Nevertheless, if you live in some other country, we do not advise letting your guard down either. Due to its active distribution, .Shit malware is very likely to spread to other parts of Europe and, eventually, the rest of the world.

Although the .Shit virus does not sound like an especially sophisticated cyber infection, trust us — it is not a work of amateurs. This parasite is well capable of inflicting serious damage on the PC, similarly to Locky and other ransomware viruses. In fact, its creators seem to have taken the best they could from the category of these particular infections: they have implemented the malware with a military grade AES CBC 256-bit encryption capability which allows locking the infected computer files without leaving their owners any chance of recovery. The same cipher has been used by Locky, ODIN and a bunch of other advanced ransomware before. Besides, following their lead, this virus also changes the located file names to a random row of characters and pins the controversial .Shit extension to all of the encrypted files. This extension is exactly what earned the virus its nasty name. Though it is practically impossible to restore personal documents after the attack of this malware, by no means should you simply leave it be. If you want to continue using your computer safely in the future, you must remove SHIT ransomware virus from the system completely. You can use professional antivirus utilities like FortectIntego to do that. When the removal is done, you may still have a chance to recover at least a small portion of your files.

Image of the .Shit ransomware virus

There are plenty of features of this ransomware that help classify it as a member of the Locky family. Not only does it offer to decrypt your files using the notorious Locky Decrypter, but it also drops three types of files on the infected computer: _WHAT_is.html, _[2_random_numbers]_WHAT_is.html and _WHAT_is.bmp. Similar variants of these files can be found in other virus versions as well. Though the file titles may differ, they usually feature the same ransom note and instructions for the data retrieval. Of course, details such as links to the payment sites, identification numbers or the amount of ransom usually vary with each individual version. Shit ransomware currently demands 0,5 Bitcoin (around 326 USD) for the data decryption, but you should not even consider paying up. This virus is relatively new, so there is no way of knowing whether its creators are really willing to decrypt your files, or will they simply disappear as soon as your money is in their pockets. A safer option is to head straight to the Shit virus removal when you first notice the warning signs suggesting it might have infected your PC. After you can check our recommendations for data recovery provided below the article.

Distribution methods used by this ransomware

Just like Locky and its versions, .Shit ransomware virus is mostly distributed via malicious spam campaigns, possibly the ones that distribute the original infection. The virus usually comes into their potential victim’s inboxes as JavaScript or WS attachments which the users unknowingly download believing that they contain invoice information, speeding ticket, online shopping confirmations or official letters. Opening such emails activate the malicious script which downloads the virus on the computer and it can start encrypting files. You should also make sure you update your software via reputable sources and avoid downloading software updated from unsafe pages or pop-ups that might randomly emerge while browsing the web. It is likely that you will find .Shit ransomware in a few of these.

Tips on .Shit ransomware removal:

If you are worrying that you might not be able to remove .Shit ransomware from your computer yourself, we have some good news for you. We have prepared instructions that will gradually lead you from the initial steps of the .Shit virus removal to the data recovery. The first thing you need to do is test your antivirus, whether the virus does not block its processes. In case it does, you should follow the virus decontamination instructions below. If it doesn’t — just run a full system scan and remove Shit virus from your PC. Below, you will also find a couple of file recovery tips you can use to try retrieving your data after the virus elimination. Though it will probably won’t help you get all of the lost data back, you might still be able to recover at least some of the documents.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.