HellsRansomware hackers try to earn users’ trust with empty promises

HellsRansomware virus, or alternatively called as UEFI ransomware, is another file-encrypting threat ready to lock sensitive users’ data. To IT security specialists’ amusement, the developers claim the virus to be “the only legit ransomware which will give you your files back unlike the others which do not.”
At the moment, the ransomware is detectable as Win32:Malware-ge, Trojan.Ransom.Uefi (A), Ransom_HELLSCRYPT.A, etc. It still happens to be in the development stage as it does not launch its own GUI, but leaves the ransom note incorporated in the binary of decrypt.txt message.
Interestingly, the threat still manifests the capability to encode files. It spreads with the assistance of malicious ok.exe file. Its distribution rate is still low, however, several samples of it already wander on the cyber space. If you happen to get infected with the malware, it is time for you to remove Hells/UEFI malware.
Envying the success of WannaCry
Though this Windows infection still needs improvement to call itself a full-fledged crypto-malware, the hackers leave references to the notorious WannaCry attack[1]:
Oops Your files Have Been Encrypted With Strong Encryption.
In Order to Get Your Files Back, Please send 350$ worth of Bitcoin to this address: 1Hp8VBKehCPvArm6VRUNzPCte3EgdjYiY.
Once You Have Paid You will receive a special decryption software with which you can easily decrypt your files.
They also mention http://paxful.com website to help users buy bitcoins in case one has not had the experience of buying bitcoins. Besides the mentioned decrypt.exe file, the malware also leaves memes.jpg. For some this threat may seem to be a joke. However, you should not meddle with the malware if you got already infected. Initiate HellsRansomware removal right away. FortectIntego or MalwarebytesMalwarebytes will come in handy.
Enumerating transmission tendencies
Like other samples of this category, the malware may target users via multiple distribution channels. Besides spam emails, weak remote desktop protocols happen to be another channel for distribution.
Do not forget exploit kits[2] and infected software updates. In relation to this note that HellsRansomware threat happens to function via ok.exe file. As you have heard, Adobe Flash Player happened to serve hackers’ malicious misdeeds.
Thus, arming yourself up with a couple of security applications may not be sufficient. Pay attention to the spam folder and the features as well as apps you are about to download.Likewise, you will be able to decrease the risk of HellsRansomware hijack.
HellsRansomware termination options
HellsRansomware removal may take less time than the elimination process of a full file-encrypting threat. Note that manual elimination is not recommended as the virus may have spread its files among the registry files.
Entrust the process to malware elimination utility. Update it before scanning the system. In case you encounter any difficulties and cannot remove HellsRansomware virus from the first attempt, check below guidelines. Note that even if you reside in the country with a supposedly lower cyber crime rate such as Sweden[3], you should still be vigilant not to encounter this threat.
Did this guide help?
Be the first to comment