Ransom

What is “Ransomware.ShinoLock.A3”?

Malware Removal

The Ransomware.ShinoLock.A3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransomware.ShinoLock.A3 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to delete volume shadow copies
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
shinolocker.com
edgedl.me.gvt1.com

How to determine Ransomware.ShinoLock.A3?


File Info:

crc32: 09FE9D2B
md5: ef600fb60363fbd41c4d45f141932f6e
name: EF600FB60363FBD41C4D45F141932F6E.mlw
sha1: 10ca94050f44bc43c99f830a9d383eda002a41b9
sha256: 624f6eed2873f6a28b7c555ed7d22cb9dd1106ed9f55cdcf26401957b718e609
sha512: ecee14bdd1ab5a14d1d4ca3f3392dda05f0426e5fd78a9a7324927c0afdeb4f27423aac58148a29f9814c132c249f5b7c926d56541af116531c18f5e73a0fe9d
ssdeep: 3072:46w9+FrD19ZQb5MmFdPrY7zE551QGWiE55k:jubG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: ShinoSec Inc.
Assembly Version: 1.0.0.1
InternalName: ShinoLockerMain.exe
FileVersion: 1.0.0.1
CompanyName: ShinoSec Inc.
LegalTrademarks: ShinoLocker
Comments: Ransomeware Simulator
ProductName: ShinoLocker
ProductVersion: 1.0.0.1
FileDescription: ShinoLocker
OriginalFilename: ShinoLockerMain.exe

Ransomware.ShinoLock.A3 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25429
ClamAVWin.Ransomware.Shinolock-6841434-0
CAT-QuickHealRansomware.ShinoLock.A3
ALYacGen:Variant.Ransom.Shinolock.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0050feb31 )
K7AntiVirusTrojan ( 0050feb31 )
CyrenW32/Shinolock.A.gen!Eldorado
SymantecInfostealer.Limitail
ESET-NOD32a variant of Win32/Filecoder.ShinoLocker.A
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Shinolock.3
ViRobotTrojan.Win32.Ransom.195074
MicroWorld-eScanGen:Variant.Ransom.Shinolock.3
TencentTrojan-Ransom.Win32.ShinoLocker.a
Ad-AwareGen:Variant.Ransom.Shinolock.3
SophosML/PE-A + Mal/Shinolock-A
BitDefenderThetaGen:NN.ZemsilF.34088.lm0@aWDhCJl
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_SHINOLOCK.SMI0
McAfee-GW-EditionGenericRXAH-SX!EF600FB60363
FireEyeGeneric.mg.ef600fb60363fbd4
EmsisoftGen:Variant.Ransom.Shinolock.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Deshacop.rk
AviraHEUR/AGEN.1120356
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1A2F14E
MicrosoftRansom:MSIL/ShinoLock.A
ArcabitTrojan.Ransom.Shinolock.3
GDataGen:Variant.Ransom.Shinolock.3
TACHYONTrojan/W32.DN-Deshacop.195072
AhnLab-V3Trojan/Win32.Agent.R189022
McAfeeGenericRXAH-SX!EF600FB60363
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesRansom.ShinoLocker
TrendMicro-HouseCallRansom_SHINOLOCK.SMI0
RisingRansom.ShinoLocker!1.D833 (CLASSIC)
YandexTrojan.Deshacop!8/MlAXCuBpY
IkarusTrojan-Ransom.Shinolocker
MaxSecureWin.MxResIcn.Heur.Gen
FortinetMSIL/Generic.AP.15EDD4!tr
AVGWin32:RansomX-gen [Ransom]
Qihoo-360HEUR/QVM03.0.4E5B.Malware.Gen

How to remove Ransomware.ShinoLock.A3?

Ransomware.ShinoLock.A3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment