Shrug ransomware — malware that locks up files using AES cipher

Shrug ransomware is a virus that infiltrates the system silently and makes changes to it, like modifying Windows settings to gain persistence. Next, the malware scans the operating system for data to encrypt and locks up files using a sophisticated AES encryption code. As soon as that is complete, the malicious program adds .SHRUG extension to databases, spreadsheets, image, video, audio, and other personal files. Ransomware also drops a ransom note and a screen-locker, making it impossible to operate the PC in normal mode. Hacker(s), under the name of “Martha,” demand $50 worth of Bitcoins for data release.
| Name | Shrug |
|---|---|
| Type | Ransomware |
| Ransom amount | $50 |
| Encryption method | AES |
| Extension | .SHRUG |
| Ransom message | Displayed in Shrug.exe |
| Distribution | Spam email attachments |
| Decryption | No official decryptor created yet. Nevertheless, users should contact security researcher Michael Gillespie who can help with file recovery |
| Elimination | Use FortectIntego for virus removal |
Shrug virus displays a very informative ransom message, which includes detailed instructions on how to proceed with the payment. According to hackers, victims only have three days before the key that can unlock their files is destroyed.
The ransom message states the following:
Oh shit waddup ¯\_(ツ)_/¯
—
I know what you’re thinking. “What happened?”
Well, the answer is quite simple. Before I tell you, promise me you will not get mad. Okay. Your PC was victim of a Ransomware attack.
That means every important file is now encrypted and you can’t access them. Oh, and there is this screen locker too. You don’t have access to your PC anymore.
What a shame, huh?
There is only one way to get your stuff back. $50. It isn’t that much, cmon! I’ll give you instructions on how to pay. Alright. To successfully pay the ransom and unlock all your sh*t, you will need Bitcoins. But wait, it is only 50 USD in Bitcoins, no worries. Nothing to worry about. You can buy it in the internet.
Oh, and don’t even Google “how to remove a ransomware” because it will not help. When buying Bitcoins you will need a wallet. You can create one at a website called Blockchain. Now find a way to buy 50 USD in BTC. Google is your friend.
Then you must send the Bitcoins to the wallet specified in the right of the screen. After that, write your wallet inside that text box and finally click the button “I paid!”. Wait some time until I confirm your payment and fix your files.
– Martha
The message author is trying to be witty, implying that $50 is “not that much.” Nevertheless, it is still a hefty sum, considering you need to give that money away for cybercriminals. Therefore, security experts and IT professionals advise not to pay the ransom. There is a possibility that the bad actors will merely snatch your money and disappear, leaving your data inaccessible and useless.
Although no official decryption tool for .SHRUG has been released yet; you can contact security researcher Michael Gillespie[1] for file decryption. But before you do, make sure that Shrug ransomware removal is executed promptly.
The crypto-extortionist can also compromise your machine, and render it vulnerable to other infections. Keyloggers, trojans, crypto-mining malware – you name it – you can get them all, as your system is extremely weakened. Malware modifies Windows registry, prevents normal operation of security software, and attempts to delete Shadow Volume Copies – automatic Windows back-ups.
In order to have a well-working computer again, you need to remove Shrug ransomware. In case you try to decrypt files before you get rid of the virus, the copies will be locked up too. We suggest you not even attempt to delete malware manually, as it will result in a failure. Instead, use reputable security software, such as FortectIntego.

Spam emails can spread malware, including ransomware
Email box quickly fills up with letters that often they look safe and legitimate, so people open them without hesitation. This activity is more dangerous than it seems because spam emails and their attachments can contain malicious macros[2] that lead to malware infiltration.
Phishing emails have been used by cybercriminals for a very long time as a prominent malware distribution method, simply because it is the most effective method. What is more, bad actors utilize the help of botnets, that can infect thousands of machines in a short period. Therefore, do not open attachments from unknown sources, as well as refrain yourself from clicking on any cleverly-disguised hyperlinks.
You should delete those letters and clean your spam email box more often if you want to avoid any cyber infections. Also, often cybersecurity specialists[3] recommend you change your passwords frequently and include a combination of numbers, upper and lower case letters when creating one.
Shrug ransomware elimination is vital for the security of your device
To remove Shrug virus from your PC, you need to employ anti-malware tool because manual elimination is almost impossible. This is a vital step in a file recovery procedure, because, as we already mentioned, data can be encrypted again if any traces of malware are present.
You can use FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes for the Shrug ransomware removal. Alternatively, you can pick any other legitimate anti-virus software. If you check below, you will also find file recovery instructions. Not all of these methods may be successful, but will not know until you try. Your best bet is if the malware did not delete Shadow Volume Copies.
Did this guide help?
Be the first to comment