Shrug Ransomware Contains Ways to Unlock Your Files

Written byHeloise Montini
Heloise Montini

Heloise Montini is a content writer whose background in journalism make her an asset when researching and writing tech content. Also, her personal aspirations in creative writing and PC gaming make her articles on data storage and data recovery accessible for a wide audience.

Edited byLaura Pompeu
Laura Pompeu

With 10 years of experience in journalism, SEO & digital marketing, Laura Pompeu uses her skills and experience to manage (and sometimes write) content focused on technology and business strategies.

Co-written byBogdan Glushko
Bogdan Glushko

CEO at SalvageData Recovery, Bogdan Glushko has over 18 years of experience in high-security data recovery. Over the years, he's been able to help restore data after logical errors, physical failures, or even ransomware attacks, for individuals, businesses, and government agencies alike.

I think there's an issue with my storage device, but I'm not sure
Start a free evaluation

The key behind ransomware is to influence your behavior so you’ll comply with their demands. On the surface, the Shrug ransomware is no different in this regard. However, those who developed the ransomware have left the keys available for you to unlock your files.

Further Details on Shrug Ransomware

It works by using drive-by attacks, often in the deployment form of embedding on fake software and gaming apps. Upon downloading the strand, you’ll receive a delightful message from Martha, who will say something along the lines of, “What happened? Well, the answer is quite simple. Before I tell you, promise you will not get mad. Okay. Your PC was a victim of a ransomware attack,” according to a ZDNet report.From there, the ransomware demands a payment of $50 in Bitcoin to return your files. You’ll receive detailed instructions on how to purchase and transfer Bitcoin currency. And similar to other ransomware, it gives you a deadline to pay, which in this case is three days or you’ll lose your files forever. A side note, you can find which files have encryption by searching for the .SHRUG extension. As noted in previous articles, paying the ransom only provides further incentive for the hackers to continue their craft. Furthermore, there’s a way to recover your files because the answer lies in the ransomware code.

How to Recover Your Files From Shrug Ransomware

LMNTRIX, a cybersecurity company, came across an interesting discovery. They revealed the authors of Shrug ransomware kept the keys in the code to unlock the files in the directory. What does this mean? It means you have the ability to recover your files even if you have the ransomware-talk about a new wrinkle.ZDNet does an excellent job of breaking down how to go about this:

  • First, since the ransomware normally disables your ability to use your mouse and keyboard, you’ll want to reboot your device.
  • Upon rebooting, open the file explorer and enter the ransomware path: C:\Users\USERNAME\AppData\Local\Temp\shrug.exe.
  • From here, you can delete the shrug.exe file by pressing shift and delete.
  • The next step is to open the RUN application on Windows-you can find this by typing RUN on Windows’ search panel feature.
  • After opening RUN, type in Regedit, as this will access the registry.
  • Next, type in the following: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.
  • Doing this gives you access to the Shrug key value by which you can delete it. After deleting it, visit your computer’s recycle bin to clear it out.
  • Lastly, restarting your machine removes all traces of the Shrug ransomware.

Ultimately, this ransomware variant isn’t a common one in that it provides a gateway to unlock your files. In most cases, if you become a ransomware victim, you’ll need a team of data recovery specialists to help; this is where the team at Salvage Data comes in.We have the resources and expertise to help you regain access to your files, even if hackers encrypted them. You’ll find our recovery process informative, secure, and quick. Best of all, we are offering a 10% discount for the month of July. Enter the promo code SAVE10 at checkout to save money on our services today!

Share this article

Related services

These are the most commonly requested data recovery services. At our headquarters' cleanroom lab, our certified engineers conduct a thorough review of any type of physical storage device, determining if there is logical or physical damage and carefully restoring all of the lost files.ces.

External Drive Data Recovery

We recover data from both external SSD and HDD drives. Rely on certified experts to restore your important files from damaged or corrupted external drives.

/services/data-recovery/external-drive/

Hard Drive Data Recovery

Recover data from all brands of HDD, PC hard drives, and hybrid disks. Our specialists ensure fast and secure recovery for any data loss scenario.

/services/data-recovery/hard-drive/

NAS Data Recovery

Recover data from NAS devices, including RAID configurations. Our team handles all types of NAS systems and ensures data recovery with minimal downtime.

/services/data-recovery/nas/

RAID Data Recovery

Our RAID data recovery services cover RAID 0, 1, 5, 10, and other configurations. We offer expert solutions for failed, degraded, or corrupted RAID arrays.

/services/data-recovery/raid/

SAN Data Recovery

Our team specializes in handling SAN devices from leading manufacturers like Dell EMC, HP, and IBM, ensuring efficient recovery with minimal disruption to your operations.

/services/data-recovery/san/

SD Card Data Recovery

Our recovery experts specialize in restoring data from SD and memory cards. We guarantee quick recovery with a no-data, no-charge policy.

/services/data-recovery/sd-card/

SSD Data Recovery

Our data recovery experts handle all SSD data loss scenarios with advanced tools, ensuring maximum recovery with high-security protocols.

/services/data-recovery/ssd/

USB Flash Drive Data Recovery

Recover lost data from USB flash drives, regardless of the damage or brand. We offer free in-lab evaluations to assess data recovery needs.

/services/data-recovery/usb-flash-drive/

If you’re unsure about which data recovery service to choose, let our team assist you in selecting the appropriate solutions. We understand the anxiety that comes with a sudden drive failure, and we are more prompt in our actions compared to other recovery service providers.