Ransom

Ransom:Win32/Shieldcrypt!rfn malicious file

Malware Removal

The Ransom:Win32/Shieldcrypt!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Shieldcrypt!rfn virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ransom:Win32/Shieldcrypt!rfn?


File Info:

crc32: 63421072
md5: aa67bd6c65156f09180537231dd2f55f
name: AA67BD6C65156F09180537231DD2F55F.mlw
sha1: bd822b33fdc5abccea3fecab4369a9dbecca12e3
sha256: 90d07a800d5356ed36af7e4f05e1bd1c6b93812e42632e59dff3d0c0596027c4
sha512: 6086042c58b144d56aa35497c66219d798b85ec4a7aa2b6318891f674620243f9edbe66016c6807b4c1393dcf5658873318916b5769ae283174094ffbdaf0a6d
ssdeep: 1536:hEWYjd5bARZscNWAsWjcd31L08NSJBfv+y91vWb7pWK6cSlIVYrN60K:h4jXkzIFIUSTWM1v+dRVYrN6L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1995 - 2017
InternalName: SecurityProducte Protect(C)
FileVersion: 8.3.6.9
CompanyName: SecurityProducte Protect(C)
ProductName: Security
ProductVersion: 8.3.6.9
FileDescription: SecurityProducte Protect(C)
OriginalFilename: ms conhost.exe
Translation: 0x1404 0x04b0

Ransom:Win32/Shieldcrypt!rfn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051cba61 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.HydraPack.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051cba61 )
Cybereasonmalicious.c65156
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.WJS
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Dropper.Win32.Dycler.ywd
BitDefenderGen:Variant.Ransom.HydraPack.1
NANO-AntivirusTrojan.Win32.Dycler.evfltb
MicroWorld-eScanGen:Variant.Ransom.HydraPack.1
TencentWin32.Trojan-dropper.Dycler.Lnnz
Ad-AwareGen:Variant.Ransom.HydraPack.1
SophosMal/Generic-S
ComodoMalware@#3jqs2n0fnpr9w
BitDefenderThetaGen:NN.ZexaF.34678.hq0@a0jxmJpO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionTrojan-FLLJ!AA67BD6C6515
FireEyeGeneric.mg.aa67bd6c65156f09
EmsisoftGen:Variant.Ransom.HydraPack.1 (B)
AviraHEUR/AGEN.1113083
MicrosoftRansom:Win32/Shieldcrypt!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ransom.HydraPack.1
AhnLab-V3Trojan/Win32.CryptoShield.C1818632
McAfeeTrojan-FLLJ!AA67BD6C6515
MAXmalware (ai score=99)
VBA32BScope.TrojanRansom.Agent
PandaTrj/CI.A
RisingTrojan.Cryptoshield!1.A960 (CLOUD)
YandexTrojan.DR.Dycler!DfrKh0MzkcM
IkarusTrojan.Win32.Krypt
FortinetW32/Krytik.FPAF!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwoCEpsA

How to remove Ransom:Win32/Shieldcrypt!rfn?

Ransom:Win32/Shieldcrypt!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment