Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2021

How to remove HugeMe ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

HugeMe – a virus that derives from an established malware family

The image of HugeMe ransomware virus

HugeMe ransomware was first seen spreading around the internet in early 2017, although some infections might occur even today. Deriving from a HiddenTear/EDA2 open-source project,[1] it can lock personal files with the AES[2] + RSA encryption algorithms and then provide the ransom demands within the DECRYPT_ReadMe.txt or DECRYPT.txt text files. According to cybercriminals, victims have to pay 1 BTC within the first five days of the infection, to be transferred into a provided Bitcoin wallet address.

Paying the attackers is dangerous, as they might never fulfill the promises of sending the decryptor back to you. Instead, you should rely on alternative solutions you can find at the bottom of this post.

Name HugeMe ransomware
Type File-locking virus, crypto-malware
Main executable HugeMe.exe
Ciphers A combination of AES and RSA
File extension .encrypted
Contact information myqjs01@gmail.com, olv100@mail.ru or vegeta85@safe-mail.net
Ransom size Cybercriminals demand 1 BTC to be paid for the decryptor
Malware removal Perform a full system scan with antivirus software – SpyHunterCombo Cleaner or MalwarebytesMalwarebytes
System fix Malware can seriously damage Windows system files, which may later result in crashes or errors. To remediate this damage automatically, we recommend using FortectIntego

Security researchers have noticed that the activity of this virus has spiked once again. It seems that cybercriminals continue this nasty job and tries to swindle more money from computer users. 

Since malware stems from the notorious HiddenTear project, it does not have any significant or unique features. Just like ordinary crypto-malware, it uses traditional infiltration methods, encrypts targeted files, and demands paying the ransom.

Malware targets around 470 different file types and locks them using a strong encryption algorithm. During data encryption, it also locks the files by appending .encrypted file extension. Sadly, HugeMe ransomware removal won’t help to rescue encrypted data. However, deleting a virus from the system should be your primary task!

While malware resides on the system, your computer and privacy are at risk. After infiltration, the virus might also make entries in the Registry and launch malicious processes inside the OS. These modifications allow starting the virus automatically every time you turn on the computer. You should also keep in mind that ransomware might damage Windows system components. To restore them to the original form, use FortectIntego repair software.

Malware[3] developers are aware that most computer users do not make data backups, and losing access to the files looks like the end of the world. Following data encryption, the HugeMe virus drops a ransom note, where hackers inform about data encryption and the only expensive possibility to rescue the files.

After stating the demands for the payment, the attackers also ask to send an email to one of these emails:

  • myqjs01@gmail.com
  • olv100@mail.ru
  • vegeta85@safe-mail.net.

After contacting cybercriminals, victims have to wait until hackers send the decryption key and necessary program. Nevertheless, this ransomware is still not decryptable; we highly recommend keeping your money in the pocket.

After making the transaction, you may not receive an email with the necessary tools. In this case, your loss will be bigger. We recommend concentrating on the virus elimination process. Professional malware removal tools, like SpyHunterCombo Cleaner, will help to remove HugeMe from the computer immediately. Data recovery might be complicated because ransomware is capable of detailing Shadow Volume Copies[4]. However, you can try other additional recovery methods.

HugeMe.exe sample detection rate

Methods of distribution

The main distribution method for ransomware-type parasites remains malicious email attachments or embedded hyperlinks. Cybercriminals find lots of creative and convincing ways to trick people into an opening attached document, which includes malware executable.

If you haven't been infected with ransomware yet, please be careful with receive emails! Before opening any email attachment, double-check the information about the sender, look for grammar or spelling mistakes, and other details[5] that may expose cybercriminals.

What is more, such malware might also be distributed via social networks or file-sharing services. Bear in mind that you cannot trust all received links or files even though your friends sent them. They may not know about being infected and spreading malicious content.

The step-by-step guide for HugeMe ransomware removal

First of all, you should no even think about manual elimination of ransomware, as it requires extensive IT knowledge and understanding of how malware works on a Windows machine. You should instead let security software to perform this task – it can automatically detect and delete all the malicious files at once.

As previously mentioned, malware might damage system files and cause the OS to crash continuously – in some cases to the point that Windows would have to be reinstalled. However, there is no need to do that, as you can replace damaged sectors with a repair tool FortectIntego.

Finally, you can then look for decryption solutions for your files. There are several methods available, and we list them below. Keep in mind that the most secure and reliable method remains data backups – you will also find guidelines on preparing them for the future.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.