Why should you beware of .Cryptohasyou virus?
.Cryptohasyou virus leaves no doubt that it is a dangerous virus and the one you should look out for. It comes from the ransomware branch of viruses including hundreds of virtually identical viruses such as Locky virus, Rokku and Petya. However, as some of the newer versions of the mentioned viruses have been improved to use JavaScript to run, .Cryptohasyou is still using Word Macros to activate itself. However, this by no means suggests that this virus is less dangerous. In fact, looking at other functionalities, it does not differ from more established and well-structured viruses.
.Cryptohasyou enters computers through infected email attachments. Once the downloaded file is opened it asks the user to enable Word Macros, if it is not yet enabled. It allows the virus to run a script and download an executive virus file. If you a see similar message, do not enable it! Otherwise, the virus will start scanning your computer for files and encrypting them using sophisticated AES-256 and RSA-2048 encryption codes, which are impossible to decrypt without special key. This key is of course, not accessible unless the victim pays a ransom to the virus creators. This virus may affect all sorts of files: video, audio files, pictures, documents and archives are among the main targets since they are usually of the most value to the victims.
YOUR_FILES_ARE_LOCKED.txt file added to every infected folder of the computer, after the encryption is executed. It states that the victim must pay $300 in order to retrieve the files. What is more, by every three days the sum is said to increase by $150. Of course, the money must be transferred in BitCoins, through an anonymous Tor network. However, even after paying the ransom, the victims cannot be entirely sure the access to their files will be granted. It is not uncommon for cyber criminals to simply disappear with files and the money as well. Therefore, it is not advisable to follow the ransomers’ conditions and to remove .Cryptohasyou from the computer as soon as you notice any of the signs this virus may have infected it. Use trustworthy anti-malware tools likeFortectIntego to speed up the whole removal process.

How is this virus distributed and how can I protect my files from it?
Peer-to-peer networks, fake email attachment and Trojans are the usual ways through which the .Cryptohasyou virus can enter your computer. The worst part is that it is almost impossible to notice your PC has been infected, and the virus is already carrying out its malicious processes in your system. You may notice system slow-downs or other small errors, but apart from that, there is no indication that your system is in danger. Therefore, security experts advise keeping a backup of your files, just in case. Also, it is advisable to obtain a reputable antivirus system to protect you from catching such viruses. It is also essential to keep your antivirus updated so that it can detect the newest and the updated older virus versions. As for the emails, do not trust your email provider to filter all the potentially hazardous content and place it into the “Spam” folder. Malicious emails may as well appear in your regular inbox, looking like legitimate correspondence. If it is already too late for you to take the mentioned precautions and you are already infected with this ransomware you must take care of the .Cryptohasyou removal before it damages your computer even more.
How can I remove .Cryptohasyou virus from my system?
To remove this infection, you must have the proper equipment. You can use the already mentioned SpyHunter or any other antivirus software you think you can trust. Scan your system with this antivirus tool and it will do the rest for you. However, you may want to disconnect your computer from the network before running the antivirus. If you are certain that .Cryptohasyou removal was thorough and successful, then you can try recovering your files from a backup. Nevertheless, you might notice that your antivirus fails to initiate. If such situation occurs, you can try following the instructions provided just below this article.
Did this guide help?
Be the first to comment