Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2018

How to remove InfinityShadow ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

InfinityShadow ransomware comes back with a new malicious version

The ransom note by InfinityShadow

InfinityShadow virus (alternatively known as InfiniteTear) is a ransomware-type infection which uses sophisticated ciphers like AES and RSA to encrypt personal data stored on the computer[1]. Note that this malicious program has multiple names, including InfiniteTear and The_Last ransomware. The latter title comes from the name of the executable file used by the malware — The_Last.exe.

Recently, experts have found a new variant of Infinite ransomware which appends .Infinite file extension to the corrupted data. Currently, SenzaVirus[2] team has spotted it spreading across Italy and Mexico. However, remember that criminals tend to release updates of the malicious programs regularly and expand the range of targets.

In this recent .Infinite extension virus hackers deliver a ransom note with a different name. Now victims receive a How_Decrypt_Files.txt ransom note where they are urged to pay the ransom. It is currently unknown how much money people are demanded to pay for InfinityShadow decryptor. However, people should not make the transaction despite the price.

The original InfinityShadow version mostly spreads via malicious spam emails. After the infiltration, it connects to the Telegram API for communication with its Command and Control (C&C) servers and transfers technical information about the targeted computer. It aims at the most popular files, such as documents, pictures or multimedia. When these records are encrypted, malware drops a ransom note on the desktop called Important_Read_Me.txt and opens it automatically.

The picture of InfinityShadow ransomware virus

In the ransom-demanding message of InfiniteTear, cybercriminals inform that victims have to transfer $260 in Bitcoins within 7 days. Otherwise, the decryption key will be deleted and users lose their chance to get back the files entirely. The fraction of the ransom note is the following:

What happened to my computer?

All of your personal files, such as documents, photos, videos, databases and files that you need, have been removed from your secure cryptography.
You need to pay for your personal files to be decrypted.
Maybe you’re looking for a way out of the internet to reopen your files. We will endow you no one but us able to reopen your encrypted files!

In order to give guarantee for the victims, crooks offer free decryption of the two files. They leave a contact email address InfinityShadow@Protonmail.com where people are supposed to send corrupted data for test decryption. However, we do not recommend having business with hackers. We recommend scanning your device with FortectIntego or another security software that will help to remove InfinityShadow from the PC.

Unfortunately, ransomware elimination won’t help to recover files, but it’s necessary for keeping computer’s work smooth and safe. Do not hesitate to get rid of the malware since you will be able to try alternative data recovery tools afterward. Additionally, if you cannot install or run malware elimination tool, scroll down to the end of the article where you find detailed InfinityShadow removal instructions.

Hackers take advantage of credulous people to spread the infection

Despite the ransomware awareness campaigns, people still recklessly browse on the suspicious websites and open letters from unknown senders. Such behavior directly leads to file-encrypting virus infection which has successfully attacked people in the United States, Italy, Mexico and can spread across other countries like Spain, France, etc. 

Typically, file-encrypting viruses spread with the help of malicious spam emails,[3] exploit kits, malware-laden ads, and fake/illegal downloads. Therefore, to avoid the attack, it’s important to follow these simple security tips:

  1. Do not install illegal or questionable files or programs;
  2. Do not click on aggressive ads;
  3. Do not visit gaming, gambling, adult-themed or other high-risk websites;
  4. Keep OS and programs updated;
  5. Invest in reputable antivirus.
  6. Create backups and update them regularly.

Eliminating InfiniteTear ransomware from the system 

Firstly, manual InfinityShadow removal is not an option. You should NOT try to get rid of ransomware by yourself since it might lead to permanent computer damage. Instead, boot your system into Safe Mode to disable the virus and pick a security software to help you with the elimination.

You are advised to use the instructions below which will show you how to reboot your PC and uninstall InfinityShadow from your system. For the termination procedure we recommend using FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. They are designed to get rid of all types of computer hazards safely.

Once you remove Infinite ransomware from the PC, you can try to recover files using alternative methods presented at the end of the article. The official decryptor is not available yet, so you should not have high expectations of bringing back the majority of encrypted files.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.