Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Dec 2018

How to remove Shadow ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Shadow ransomware is a crypto virus that uses .shadow extension and is related to BTCWare malware

Shadow virus

Shadow ransomware is a set of viruses that belong to BTCWare ransomware family. It encrypts data with the help of AES-256 encryption algorithm and adds .shadow file extension. Additionally, victims' IP and the contact email address of the hackers is embedded into appending, so the full extension looks like this: .[email]-id-[ID].shadow (for example picture.jpg.paydayz@cock.li-id-1420.shadow). After the encryption procedure is complete, Shadow ransomware opens a pop-up window called payday.hta or !! RETURN FILES !!.txt, explaining to victims what to do next. Typically, users are asked to pay ransom in Bitcoins for file release. Several email addresses are tied to the .shadow extension. However, in late December 2018, victims' machines started to be infiltrated by a STOP ransomware variant that also uses .shadow file extension.

Summary
Name Shadow ransomware
A variant of BTCWare ransomware
Extension .shadow
Cipher used AES-256
Decryptable? No
Infection methods RDP, spam emails, exploits, fake updates, insecure sites, etc.
Elimination Use security software like FortectIntego to uninstall malicious components

Shadow BTCWare ransomware uses a strong encryption algorithm to corrupt files on the affected machine. Crypto-malware continues spreading by taking advantage of unprotected remote desktop servers.

Once inside, the malicious program makes changes to the system. It might create or modify Windows Registry in order to boot on system startup, disable security software and make other needed changes. Then Shadow virus starts data encryption procedure.

When files are successfully locked by .shadow file extension virus, malware shows the same ransom note. The only difference here is – new contact email. Now victims have to contact crooks via paydayz@cock.li email address. Additionally, they can send test files for free decryption in order to make sure that thieves are not lying about decryption software:

Free decryption as guarantee
Before paying you can send us up to 3 files for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

Image of Shadow ransomware

However, free decryption possibility might be just a trickery used for convincing you into paying the ransom. Once you make the transaction, crooks might disappear because the main purpose of Shadow ransowmare is the same as any other file-encrypting virus’ – to obtain Bitcoins illegally.

After ransomware attack, you should focus on Shadow ransowmare removal instead of trying to get back your files by paying the ransom. Nevertheless, virus elimination won’t recover your files; you have to clean the system from malicious components. Additionally, you will be able to use backups or try alternative recovery methods to retrieve corrupted data.

In order to remove Shadow ransomware entirely, you have to run a full system scan with professional malware removal[1] program. We suggest using FortectIntego because this tool is capable of detecting all latest cyber threats and eliminating them properly.

Ransom note by Shadow ransomware

Poor remote desktop services allows ransomware to enter into the system

This crypto-virus is designed to attack devices via poor or unprotected remote desktop services. Thus, it’s important to create strong passwords and limit admin access to avoid ransomware attack.

However, the cyber security team from Les Virus[2] note that previous versions of BTCWare were spreading via malicious spam email emails and Trojans too. Therefore, you should be careful when:

  • opening email attachments;
  • downloading freeware or shareware;
  • installing software updates;
  • clicking on ads.

In order to avoid ransomware attack, you have to click or download needed content only if you are absolutely sure that it’s a legitimate and safe entry. Thus, stay away from suspicious spam emails,[3] unknown file-sharing websites, and pop-ups that warn about detected cyber threats.

Shadow BTCWare removal instructions

Computer users, who have suffered from ransomware attack, are advised to rely on professional security software in order to wipe out malware from the system. Automatic Shadow removal ensures that all malicious components are removed from the system entirely. Meanwhile, this task is nearly impossible to perform manually.

However, if you cannot install or start security software, you should check the guide below and follow it carefully. The instructions will show you how to deal with the obstacles and remove Shadow ransomware virus with FortectIntego, MalwarebytesMalwarebytes or your chosen anti-malware software.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.