Home / malware Win32/Shieldcrypt
First posted on 12 September 2017.
Source: MicrosoftAliases :
There are no other names known for Win32/Shieldcrypt.
Explanation :
We have seen that this ransomware may use and install a copy of itself using different names such as:
- %ProgramData% \MicroSoftWare\SmartScreen\SmartScreen.exe
- %ProgramData% \MicroSoftTMP\system32\conhost.exe
It may report and post information to:
- hxxp://45[.]76[.]81[.]110/test_site_scripts/moduls/connects/mailsupload[.]php
- hxxp://107[.]191[.]62[.]136/js/prettyPhoto/images/prettyPhoto/default/infromation[.]php
This ransomware disables and deletes shadow or backup copies of files by running the following command:
vssadmin.exe Delete Shadows /All /Quiet
net stop vss
It also disables startup repair and recovery screen due to failures by running the following command:
bcdedit /set {default} recoveryenabled No
bcdedit /set {default} bootstatuspolicy ignoreallfailures
It changes the following registry entries so that it runs each time you start your PC:
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run
Sets value: "Windows SmartScreen"
With data: "C:\ProgramData\MicroSoftWare\SmartScreen\SmartScreen.exe"
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run
Sets value: "Windows SmartScreen Updater"
With data: ""
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run
Sets value: "Indesing Microsoft"
With data: "C:\ProgramData\MicroSoftWare\SmartScreen\SmartScreen.exe"
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\RunOnce
Sets value: "*Indesing Microsoft"
With data: "C:\ProgramData\MicroSoftTMP\system32\conhost.exe"
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\Run
Sets value: "Indesing Microsoft Updater"
With data: ""
In subkey: HKCU\SoftWare\Microsoft\Windows\CurrentVersion\RunOnce
Sets value: "*Indesing Microsoft Updater"
With data: ""
Encrypts files
This threat searches for and encrypts files with the following file name extensions:
It doesn't encrypt files and folders having the following list:
- $recycle.bin
- appdata
- application data
- boot
- cache
- cookies
- games
- inetcache
- microsoft
- nvidia
- packages
- program files
- program files (x86)
- programdata
- system volume information
- temp
- temporary internet files
- tmp
- webcache
- windows
- winnt
After encrypting files, this ransomware shows a ransom note as an HTML page in your web browser similar to the following:
It also drops plain text file # RESTORING FILES #.TXT with the same information, as follows:
Analysis by: Jireh SanicoLast update 12 September 2017