Shifr Ransomware – Remove and Restore .Shifr Files

Shifr Ransomware – Remove and Restore .Shifr Files

This article will aid you to remove the Shifr ransomware efficiently. Follow the ransomware removal instructions provided at the end of the article.

Shifr ransomware is a cryptovirus. The extension it puts to all files after encryption is .shifr. After encryption, a ransom note named HOW_TO_DECRYPT_FILES.html will load with payment instructions inside an HTML page. The sum of 0.1 Bitcoin is demanded by the cybercriminals for paying the ransom. Read on through and find out what ways you could try to potentially recover some of your files.

Threat Summary

Short DescriptionThe ransomware encrypts files on your computer system and it shows a ransom note afterward.
SymptomsThis ransomware virus will encrypt your files and place the .shifr extension on each one of them.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by Shifr


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Shifr.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Shifr Ransomware – Delivery Tactics

The Shifr ransomware might be delivered by utilizing different tactics. The payload dropper file which initiates the malicious script for the ransomware is can be circling the Internet. Malware researchers have found a sample of the payload which could infect users.

The Shifr ransomware might be using other ways to deliver the payload file, in question, such as social media sites or file-sharing services. Freeware applications found on the Web could be promoted as helpful but also could hide the malicious script for this virus. Before opening any files after you have downloaded them, you should instead scan them with a security program. Especially if they come from suspicious places, such as emails or links. Also, don’t forget to check the size and signatures of such files for anything that seems out of place. You should read the ransomware preventing tips given in the forum.

Shifr Ransomware – Technical Description

The Shifr ransomware is a cryptovirus. After the Shifr ransomware encrypts your files it will place the .shifr extension to every one of them. Then, a ransom note will be placed on your Desktop.

The Shifr ransomware might make new registry entries in the Windows Registry to achieve a higher level of persistence. Those entries are usually designed in a way that will start the virus automatically with every launch of the Windows Operating System, like in the example provided below, such as the example given down here:


The ransom message will be put inside your computer system and more precisely, on your Desktop, right after the encryption process is finished. The ransom note file is called “HOW_TO_DECRYPT_FILES.html” and it will load a page in HTML. Once that page loads, the following message will show up:

If you click the “here” hyperlink that will load the following ransom message with instructions:

Your files have been encrypted!
To decrypt your files, send 0.1 Bitcoin to this address: 1EdN1ZaPAAo6hCruBDhkFnNt68QoJATNLa
After your payment is complete, you can decrypt files with decryption program.
Download decryption program here.
Decryption key: Not paid yet.
Question: Where can I get Bitcoin wallet?
Answer: Simple and easy to use wallet.
Question: Where can I buy Bitcoins?
Answer: Guide to various methods of buying Bitcoin.

The developers of the Shifr cryptovirus demand that you pay a ransom sum of 0.1 Bitcoin, which is the equivalent of over 120 US dollars at the moment of writing this article. However, you should NOT meet that demand, nor contact those crooks under any circumstances. Financially supporting the cybercriminals does not guarantee that you will restore your files back to normal. Also, it is generally a bad idea to pay to extortionists like that, as it might motivate them further in making more ransomware viruses or get involved with other criminal acts. To add to that – you have no guarantee that if the crooks make a new ransomware you won’t get your files infected again.

Shifr Ransomware – Encryption Process

There is no official list with file extensions that the Shifr ransomware seeks to encrypt at this moment. However, this article will get duly updated if there anything new about this matter surfaces. All encrypted files will receive the .shifr extension, which will be appended to them. The following files are most likely to get encrypted, as they are the most commonly used ones on the Windows OS:

→.7z, .bmp, .doc, .docm, .docx, .html, .jpeg, .jpg, .mp3, .mp4, .pdf, .php, .ppt, .pptx, .rar, .rtf, .sql, .tiff, .txt, .xls, .xlsx, .zip

The Shifr cryptovirus is very likely to delete the Shadow Volume Copies from the Windows Operating System by executing the following command:

→vssadmin.exe delete shadows /all /Quiet

If the command stated above is initiated, that will make the encryption process a bit more effective, as one of the ways for file recovery will be lost. Continue reading and find out what kinds of methods you can try out to potentially restore some of your files.

Remove Shifr Ransomware and Restore .Shifr Files

If your computer got infected with the Shifr ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.

Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share