• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

My AntiSpyware

Free antispyware software, Online Scanners, Instructions on how to remove spyware and malware.

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools
Home › Virus › .Shadow file extension ransomware (Restore .shadow files)

.Shadow file extension ransomware (Restore .shadow files)

Myantispyware team December 6, 2018     No Comment    

Experienced security researchers discovered a new variant of ransomware which named .shadow ransomware virus. It appends the .shadow extension to encrypted file names. This article will provide you a brief summary of information related to this new virus and how to recover all encrypted personal files for free.

.shadow ransomware

.shadow ransomware – ransom note

The .shadow ransomware uses a hybrid encryption mode. The virus will encrypt almost all types of files, including common as:

.vfs0, .bik, .xls, .sb, .sr2, .docm, .iwi, .epk, .d3dbsp, .fsh, .ztmp, .t13, .m2, .layout, .xdb, .xpm, .wpd, .wsd, .ybk, .lbf, .cdr, .xld, .zif, .wmo, .wpg, .wri, .mdbackup, .xls, .der, .xwp, .wpt, .ptx, .hkx, .dcr, .rb, .orf, .sie, .zdc, .pptx, .cr2, .xdl, .lrf, .mdb, .srf, .xlsx, .dbf, .xx, .litemod, .rw2, .sql, .odb, .vdf, .odp, .asset, .dwg, .das, .itm, .yal, .bkf, .wbmp, .qic, .wb2, .itdb, .7z, .tor, .hplg, .pst, .blob, .ods, .2bp, .accdb, .xar, .xlsm, .crt, .gdb, .rgss3a, .bsa, .wbz, .y, .mdf, .xll, .raf, .ai, .r3d, .dba, .xmmap, .docx, .odm, .wpb, .eps, .zabw, .p7c, .x3f, .wotreplay, .xxx, .z3d, .mp4, .wbd, .ysp, .png, .xlsm, .syncdb, .rim, .webp, .iwd, .wbm, .py, .forge, .3fr, .3dm, .sis, .css, .wdp, .vpp_pc, .pak, .bkp, .x3d, .wdb, .psd, .wbk, .rwl, .ppt, .re4, .rtf, wallet, .arw, .wn, .odt, .wire, .esm, .tax, .xf, .gho, .pfx, .doc, .hkdb, .raw, .wps, .snx, .wps, .3ds, .xlk, .slm, .wpa, .sidd, .1, .mlx, .0, .erf, .map, .sid, .m3u, .dazip, .wbc, .xbplate, .wsc, .kf, .pem, .ltx, .upk, .p12, .sav, .wmd, .srw, .wpd, .kdc, .vtf, .wgz, .crw, .jpeg, .xyw, .xml, .m4a, .ibank, .nrw, .wp4, .zi, .wmf, .icxs, .pdd, .ntl, .jpg, .xy3, .xlsb, .js, .bar, .wp5, .pptm, .pkpass, .lvl, .xyp, .zdb, .wmv, .x, .rofl, .wpe, .csv, .cfr, .wp6, .mrwref, .wmv, .cer, .qdf, .desc, .ff, .ws, .wp7, .svg, .avi, .xlsx, .apk, .wpl, .x3f, .p7b, .dmp, .bay, .wsh, .1st, .flv, .rar, .wpw, .cas, .arch00, .mddata, .z, .zip, .pdf, .dxg, .wot

When encrypting a file it will append the .shadow extension to each encrypted file name to identify that the file has been encrypted. For example, a file named sample.doc would be encrypted and renamed to sample.doc.shadow.

Once the process is done, it will create a file called ‘!readme.txt’ with ransom demanding message. It includes instructions on how to purchase a private key to decrypt all documents, photos and music. You can see an one of the variants of the ransom note below:

ALL YOUR FILES ARE ENCRYPTED

Don’t worry, you can return all your files!
All your files documents, photos, databases and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees do we give to you?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information
Don’t try to use third-party decrypt tools because it will destroy your files.
Discount 50% available if you contact us first 72 hours.

To get this software you need write on our e-mail:
helpshadow@india.com

Reserve e-mail address to contact us:
helpshadow@firemail.cc

Your personal ID:

We recommend you to remove .shadow ransomware virus sooner, until the presence of the ransomware virus has not led to even worse consequences. You need to follow the few simple steps below that will allow you to completely remove .shadow ransomware virus from your machine as well as restore encrypted documents, photos and music, using only few free tools.

Table of contents

  1. How to decrypt .shadow files
  2. How to remove .shadow ransomware
  3. How to restore .shadow files
  4. How to protect your PC from .shadow ransomware

How to decrypt .shadow files

The ransom instructions encourages victim to contact ransomware’s developers via helpshadow@india.com or helpshadow@firemail.cc in order to decrypt .shadow files. These persons will require to pay a ransom (usually demand for $300-1000 in Bitcoins). We don’t recommend paying a ransom, as there is no guarantee that you will be able to decrypt your photos, documents and music. In addition, you must understand that paying money to the cyber criminals, you are encouraging them to create a new ransomware virus.

With some variants of this ransomware virus, it is possible to use Windows Shadow Copies or file recover utilities to recover documents, photos and music that have been encrypted by .shadow ransomware virus. You can use the free utilities listed below in the blog post.

How to remove .shadow ransomware

Most commonly it is not possible to remove the .shadow ransomware virus manually. For that reason, our team developed several removal ways which we have summarized in a detailed tutorial below. Therefore, if you’ve the .shadow ransomware virus on your machine and are currently trying to have it deleted then feel free to follow the guide below in order to resolve your problem. Some of the steps will require you to restart your PC or exit this web-page. So, read this tutorial carefully, then bookmark or print it for later reference.




Run Zemana Anti-malware to delete .shadow ransomware

We recommend you to use the Zemana Anti-malware that are completely clean your computer of this ransomware virus. Moreover, the utility will help you to get rid of PUPs, malicious software, toolbars and ad-supported software that your machine may be infected too.

Zemana remove .shadow ransomware and other security threats

  1. Zemana can be downloaded from the following link. Save it directly to your MS Windows Desktop.
    Zemana AntiMalware
    Zemana AntiMalware
    159513 downloads
    Author: Zemana Ltd
    Category: Security tools
    Update: July 16, 2019
  2. At the download page, click on the Download button. Your internet browser will show the “Save as” prompt. Please save it onto your Windows desktop.
  3. When the downloading process is finished, please close all applications and open windows on your personal computer. Next, run a file named Zemana.AntiMalware.Setup.
  4. This will start the “Setup wizard” of Zemana Free onto your personal computer. Follow the prompts and do not make any changes to default settings.
  5. When the Setup wizard has finished installing, the Zemana will run and display the main window.
  6. Further, press the “Scan” button for checking your personal computer for the .shadow ransomware and other security threats. This procedure may take some time, so please be patient. During the scan Zemana will search for threats exist on your machine.
  7. After Zemana Free has completed scanning, Zemana will show you the results.
  8. Review the scan results and then press the “Next” button. The utility will remove .shadow ransomware virus and other security threats and move threats to the program’s quarantine. After that process is finished, you may be prompted to reboot the system.
  9. Close the Zemana Anti Malware and continue with the next step.

How to remove .shadow ransomware with MalwareBytes Anti Malware

If you’re having issues with the .shadow ransomware removal, then download MalwareBytes Anti Malware. It is free for home use, and detects and deletes various undesired apps that attacks your computer or degrades personal computer performance. MalwareBytes AntiMalware (MBAM) can remove adware, PUPs as well as malware, including ransomware and trojans.

Installing the MalwareBytes Anti-Malware is simple. First you will need to download MalwareBytes Anti-Malware on your PC system by clicking on the link below.

Malwarebytes Anti-malware
Malwarebytes Anti-malware
317583 downloads
Author: Malwarebytes
Category: Security tools
Update: April 15, 2020

After the downloading process is complete, close all windows on your system. Further, open the file named mb3-setup. If the “User Account Control” prompt pops up as on the image below, click the “Yes” button.

MalwareBytes for Microsoft Windows uac dialog box

It will display the “Setup wizard” that will help you setup MalwareBytes Free on the PC system. Follow the prompts and do not make any changes to default settings.

MalwareBytes for Microsoft Windows install wizard

Once installation is done successfully, press Finish button. Then MalwareBytes will automatically run and you may see its main window as shown in the figure below.

MalwareBytes for Microsoft Windows

Next, press the “Scan Now” button to perform a system scan with this utility for the .shadow ransomware virus related files, folders and registry keys. This procedure can take some time, so please be patient. While the utility is scanning, you can see how many objects and files has already scanned.

MalwareBytes Anti-Malware for Microsoft Windows scan for .shadow ransomware virus and other kinds of potential threats such as malicious software and PUPs

Once the scan is done, the results are displayed in the scan report. Once you’ve selected what you wish to delete from your computer click “Quarantine Selected” button.

MalwareBytes Anti Malware (MBAM) for Microsoft Windows, scan for ransomware is finished

The MalwareBytes Free will get rid of .shadow ransomware and other kinds of potential threats such as malware and potentially unwanted applications. Once that process is complete, you may be prompted to reboot your PC system. We suggest you look at the following video, which completely explains the procedure of using the MalwareBytes to remove hijacker infections, ad-supported software and other malware.

Scan your computer and remove .shadow ransomware with KVRT

KVRT is a free removal utility which can scan your computer for a wide range of security threats such as the .shadow ransomware virus, ad supported software, PUPs as well as other malicious software. It will perform a deep scan of your computer including hard drives and MS Windows registry. When a malware is found, it will help you to delete all found threats from your system with a simple click.

Download Kaspersky virus removal tool (KVRT) on your personal computer by clicking on the following link.

Kaspersky virus removal tool
Kaspersky virus removal tool
123860 downloads
Author: Kaspersky® lab
Category: Security tools
Update: March 5, 2018

After downloading is finished, double-click on the KVRT icon. Once initialization procedure is complete, you’ll see the Kaspersky virus removal tool screen as displayed in the following example.

Kaspersky virus removal tool main window

Click Change Parameters and set a check near all your drives. Click OK to close the Parameters window. Next click Start scan button . KVRT program will scan through the whole computer for the .shadow ransomware virus and other trojans and malicious software. This procedure may take some time, so please be patient. When a threat is detected, the number of the security threats will change accordingly. Wait until the the checking is complete.

Kaspersky virus removal tool scanning

Once KVRT has finished scanning, Kaspersky virus removal tool will display you the results as on the image below.

KVRT scan report

Next, you need to click on Continue to start a cleaning task.

How to restore .shadow files

In some cases, you can recover files encrypted by .shadow ransomware virus. Try both methods. Important to understand that we cannot guarantee that you will be able to restore all encrypted documents, photos and music.




Run ShadowExplorer to recover .shadow files

In order to recover .shadow personal files encrypted by the .shadow ransomware from Shadow Volume Copies you can run a utility called ShadowExplorer. We suggest to use this way as it is easier to find and recover the previous versions of the encrypted files you need in an easy-to-use interface.

Visit the following page to download the latest version of ShadowExplorer for Windows. Save it directly to your Microsoft Windows Desktop.

ShadowExplorer
ShadowExplorer
419062 downloads
Author: ShadowExplorer.com
Category: Security tools
Update: September 15, 2019

After the downloading process is complete, open a directory in which you saved it. Right click to ShadowExplorer-0.9-portable and select Extract all. Follow the prompts. Next please open the ShadowExplorerPortable folder as shown on the image below.

ShadowExplorer folder

Double click ShadowExplorerPortable to start it. You will see the a window as displayed in the following example.

ShadowExplorer

In top left corner, select a Drive where encrypted photos, documents and music are stored and a latest restore point as on the image below (1 – drive, 2 – restore point).

ShadowExplorer

On right panel look for a file that you want to recover, right click to it and select Export as shown on the screen below.

ShadowExplorer recover file

Use PhotoRec to recover .shadow files

Before a file is encrypted, the .shadow ransomware makes a copy of this file, encrypts it, and then deletes the original file. This can allow you to restore your files using file recover applications such as PhotoRec.

Download PhotoRec on your Windows Desktop by clicking on the link below.

PhotoRec
PhotoRec
208904 downloads
Author: CGSecurity
Category: Security tools
Update: March 1, 2018

When the downloading process is finished, open a directory in which you saved it. Right click to testdisk-7.0.win and select Extract all. Follow the prompts. Next please open the testdisk-7.0 folder as displayed in the following example.

testdisk photorec folder

Double click on qphotorec_win to run PhotoRec for Microsoft Windows. It will open a screen like below.

PhotoRec for windows

Choose a drive to recover as displayed below.

photorec select drive

You will see a list of available partitions. Choose a partition that holds encrypted documents, photos and music as shown in the figure below.

photorec choose partition

Click File Formats button and choose file types to recover. You can to enable or disable the restore of certain file types. When this is done, press OK button.

PhotoRec file formats

Next, press Browse button to choose where restored documents, photos and music should be written, then click Search.

photorec

Count of restored files is updated in real time. All restored photos, documents and music are written in a folder that you have selected on the previous step. You can to access the files even if the restore process is not finished.

When the recovery is done, click on Quit button. Next, open the directory where restored photos, documents and music are stored. You will see a contents as shown in the figure below.

PhotoRec - result of recovery

All recovered personal files are written in recup_dir.1, recup_dir.2 … sub-directories. If you’re searching for a specific file, then you can to sort your restored files by extension and/or date/time.

How to protect your PC from .shadow ransomware

Most antivirus applications already have built-in protection system against the ransomware. Therefore, if your system does not have an antivirus program, make sure you install it. As an extra protection, use the CryptoPrevent.

Use CryptoPrevent to protect your PC from .shadow ransomware

Download CryptoPrevent by clicking on the link below. Save it to your Desktop so that you can access the file easily.

www.foolishit.com/download/cryptoprevent/

Run it and follow the setup wizard. Once the install is finished, you’ll be displayed a window where you can choose a level of protection, as displayed on the screen below.

CryptoPrevent

Now click the Apply button to activate the protection.

Finish words

Now your computer should be clean of the .shadow ransomware. Delete MalwareBytes and KVRT. We recommend that you keep Zemana Free (to periodically scan your PC system for new malware). Make sure that you have all the Critical Updates recommended for MS Windows OS. Without regular updates you WILL NOT be protected when new virus, harmful apps and ad-supported software are released.

If you are still having problems while trying to get rid of .shadow ransomware from your PC system, then ask for help here.

 

Virus

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply




New Guides

Doparnelychme.com Click Allow Scam
Doparnelychme.com Virus Removal Guide
Flixtagger.com Flix Tagger
Flixtagger.com Review: Is This Netflix Tagger Opportunity Legitimate?
Link For Captcha virus Click Allow Scam
Link For Captcha Virus (removal guide)
MetaMask Email Scam
Metamask Email Scam: What You Need to Know to Stay Safe Online
Basicstester.com Amazon Product Tester
Basicstester.com Review: Is It a Scam or Legit Way to Become an Amazon Product Tester

Follow Us

Search

Useful Guides

How to reset Mozilla Firefox (Updated Apr. 2018)
Managed by your organization chrome virus
Chrome Managed by your organization malware removal guide
remove android virus
How to remove virus from Android phone
How to reset Google Chrome settings to default
How to remove browser hijacker virus (Chrome, Firefox, IE, Edge)

Recent Posts

Zemana AntiMalware scan is done
How to remove Jcecn.exe trojan/coin miner [Virus removal guide]
How to remove Trojan.Shelma.cmj [Virus removal guide]
How to remove KingMiner malware [Virus removal guide]
Moviepin pop-ups
How to remove Moviepin pop-ups [Chrome, Firefox, IE, Edge]
Theseoffersforyou.com
How to remove Theseoffersforyou.com pop-ups [Chrome, Firefox, IE, Edge]

MYANTISPYWARE.COM

  • About Us
  • Contact Us
  • Privacy Policy

NEED A HELP ?

If you're seeing unwanted pop-ups or ads in your web-browser, you might have an adware installed on your computer. Use the following guide to stop pop-up ads and remove malicious software. Or ask for help here.

Links

  • Downloads
  • Instructions
  • Questions and Answers
  • Free Malware Removal Tools
Copyright © 2004 - 2023 MASW - Myantispyware.com.