RIG EK spreads CryptoShield 1.1 ransomware in 2017
CryptoShield 1.1 virus is a brand new copy of Cryptoshield 1.0 ransomware, which first emerged at the end of January 2017[1]. However, traits of this ransomware were discovered a while ago[2], because security researchers state that it is just a rework of CryptoMix ransomware. After infecting the target system, the ransomware eventually scans all folders and checks each extension of files stored on the system. If the extension matches one that the virus’ target list includes, the ransomware encrypts it. An encrypted file gets .CRYPTOSHIELD file extension (after the original one). CryptoShield virus then creates a ransom note, which reportedly is named # RESTORING FILES #.TXT and saves some information into it. The ransom note is designed to inform the victim about the encryption. It says that the virus used RSA-2048 encryption to corrupt files, and these can be restored only with a help of a “decrypt program.” The ransom note insolently demands to pay a ransom to cyber criminals to get personal data back. According to the ransom note, the victim needs to follow commands and contact scammers via email first. There are three emails provided in the message: restoring_sup@india.com, restoring_reserve@india.com, and restoring_sup@computer4u.com. The message urges the victim to obey the commands in a rush, otherwise, it says, the ransom price will be doubled.

Speaking about data recovery, we would like to ask you not to pay the ransom for your own good. First of all, there are way too many cases when victims paid the ransom and never received any help from cyber criminals[3]. Secondly, we understand that your files are valuable and important, but just think – do you want to motivate frauds by paying them? If not, just remove CryptoShield 1.1 virus from the system without any hesitation. To carry out CryptoShield 1.1 removal smoothly, use an anti-malware program. Our team suggests using FortectIntego or MalwarebytesMalwarebytes programs.
How could I get infected?
CryptoShield 1.1 malware mainly spreads via email spam, however, recently another distribution method was spotted. It appears that one of the most dangerous exploit kits, known as RIG EK[4], started pushing CryptoShield 1.1 and Cerber ransomware[5]. The exploit kit is reportedly hosted on compromised websites, and if the victim visits them while having some outdated programs on the system, the exploit kit uses security vulnerabilities of such programs and injects ransomware into the target computer. To protect yourself from such highly-sophisticated attacks, install anti-malware software and enable automatic updates for it. Remember that malware can lurk on various third-party websites, be hidden in various torrent files or travel alongside pirated software. You should stay away from shady Internet websites and downloads if you want to keep your PC clean and safe.
How can I remove CryptoShield 1.1 virus from my system?
In case your computer got attacked by the latest version of the virus, do not waste your valuable time and remove CryptoShield 1.1 virus as soon as possible. It is not recommended to try to delete the virus manually. It contaminates the system with various files and in order to gather all of them and delete them at once, you need a professional malware removal tool. We strongly suggest you restart your compromised PC into a Safe Mode with Networking and begin CryptoShield 1.1 removal process right away.
Was this guide helpful?
4 comments