Ehiz ransomware – a hazardous virus that prevents victims from accessing their files until a ransom is paid

Ehiz ransomware is actively spreading on the internet, and as soon as it infects a computer, it immediately locks all non-system files. That's done so the threat actors behind it could demand a ransom. If it's paid, the cybercriminals will supposedly send the necessary software to decrypt the files.
If your computer is infected with this ransomware, you can identify it by the .ehiz extension that's appended to all original filenames. Although the infection is developed to encrypt only personal files (documents, archives, databases, audio/video, etc.), it does extensive damage to system data as well.
The main goal of a ransomware attack is to extort Bitcoins from victims. The asking price for the Ehiz ransomware decryption tool sold by the assailants depends on the victim's quickness. It's stated in the _readme.txt ransom note that if victims contact the criminals via provided emails (helpmanager@airmail.cc, helpteam@mail.ch) within 72 hours of the attack, a 50% discount will be applied to the sum.
That would lower the amount from $980 to $490. However, we highly advise against reaching out to the assailants, or needless to say, paying the ransom. There might be other methods to regain your precious files, and this article will cover all those possibilities.
We're also going to explain the spreading techniques, functionality peculiarities, and of course, provide the removal options for the article's culprit, which belongs to the infamous Djvu ransomware family. Viruses from this lineage have been roaming around since 2018, and since we've been researching them from the get-go, we sure know a thing or two.

If you'd ask us “how Ehiz ransomware got on my computer?”, the answer would be most likely through a software (game, application, etc.) crack that you've downloaded from a file-sharing platform. Although other means of infection are possible, this one is the most probable.
The most important thing when your computer gets infected with ransomware is not to panic. The deed is done. Now all that matters is how you respond to this mishap. It's easy for us to say that you should remove Ehiz virus from your device when it's not our data that's been encrypted.
But since we're doing this for a long time, we still highly recommend withholding from the urge to end this nightmare by succumbing to the assailants' demands. They could use that money to infect more computers of random innocent people like you, so the responsible thing would be to eliminate it. Below you'll find a brief summary of the threat and comprehensive instructions for its removal and possible file recovery options.
| name | Ehiz virus |
|---|---|
| Type | Ransomware, file-locking parasite, cryptovirus |
| Family | Djvu/STOP |
| Infection symptoms | All personal files are renamed, and you cannot open any of them; ransom note appears on the desktop and in random folders |
| appended file extension | .ehiz |
| Ransom note | _readme.txt |
| Distribution | This family of malware tends to spread around using game cracks, pirated software, and other files distributed via torrent sites and malicious pages. Ransomware creators can deliver the payload of this virus via email attachments |
| File recovery | You might be able to recover encrypted files with the Emsisoft decryption tool or other software. All possible techniques are explained below |
| Elimination | Removal should be done with trustworthy anti-malware software that will ensure that the cryptovirus infection won't renew |
| System health check | This type of infection causes havoc on system files and settings, resulting in various abnormal system behavior. Resolve all system-related irregularities by running a scan with the FortectIntego PC diagnostics tool |
When the ransomware infects the machine and locks those commonly used files, the system can get slower during encryption. Other than that, there are no particular symptoms of the threat. Users might not notice the infection because the Djvu ransomware family that the Ehiz virus belongs to tends to show Windows Update and other process messages to mask the computer's slowness.
Users get scared when the ransom message is delivered, so many questions get asked by victims. One of the more common – does paying help to decrypt files? The short answer to that is no. It is very rare for criminals to send reliable decryption tools after the payment is received. In most cases, threat actors leave the system encoded and disappear without giving any solution for the victim.
After the ransomware infection, what you can do instead of paying the demanded ransom depends on the severity of the infection. We have a few pointers before you move on to termination and file recovery:
- Distribution of such malicious files and holding property for ransom is a criminal act, so you can report the encryption to law enforcement.
- Avoiding contact with criminals is advised because it is rarely possible to get your files decrypted by them.
- Removing infection is important, but that is not the same as unlocking those files.
- Malware elimination can be done using proper AV tools that can detect the infection.
- Decryption tools get developed over time, but not all victims might get help from those since threat actors often change their tactics.
- Djvu family relies on offline IDs vs Online IDs system, so some of the people can rely on existing decryption tools, but others need additional solutions.

Recovery and removal instruction for Ehiz virus
As we've mentioned before, the worst that could've happened already happened. We're very glad that you chose us to guide you through this journey. Below you'll find four steps. Please don't skip any of them so that the removal is done correctly, and the ransomware won't have any chances of renewal on your infected device, and afterward, you could enjoy it anew. The message in _readme.txt might seem convincing, but criminals should never be trusted and ransom paying is not the solution.
Step 1.
If you discover Ehiz file virus attack taking place, disconnect your internet cable and disable WiFi immediately. Also, disconnect any media connected to your device, such as USB drives, NAS (Network Attached Storage), and similar. When the ransomware is done with its bidding, a ransom note will appear on the desktop and in random folders.
Then, if you didn't keep backups, you have to copy all (or essential) encrypted data into an offline storage device (SSD, USB, etc.). The locked data doesn't hold any malicious code, so it's safe to keep it, meaning it won't encrypt any other data saved on your choice of storage device. Only then proceed to the further step.
Step 2.
Download MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. Either of these reputable anti-malware tools is essential to remove Ehiz virus successfully. When you install the AV engine, update its virus signatures. Then perform a full system scan. A proper tool will identify,[1] locate, and delete the infection with all additional modules or any other malware.
Sometimes, ransomware can edit system files and settings, preventing you from accessing security-related websites and launching security software. If that's the case, you'll have to perform this step in Safe Mode with Networking. For your convenience, instructions on how to accomplish that are posted at the bottom of the article.

The need for a reliable anti-malware tool is once more reiterated in the VirusTotal report[2] which clearly shows that 55 out of 70 AV engines have identified Ehiz file virus and prevented it from infecting the computer. Here are some of its detection names:
- Win32:RansomX-gen [Ransom]
- A Variant Of Win32/Kryptik.HLAP
- Trojan.MalPack.GS
- Trojan:Win32/Azorult.RT!MTB
- ML.Attribute.HighConfidence
It would be great if everyone understood the dangers of ransomware attacks. The best way to defend against them is to make a habit of updating your anti-malware software and scanning your computer with it at least twice a week.
Step 3.
All Djvu family ransomware causes havoc on your computer's system files and settings to prolong its unwelcomed stay. Ehiz ransomware edits the Registry, modifies the host file, deletes Shadow Volume Copies,[3] and so on. We've briefly mentioned the outcome of that in the previous step.
Thus when the removal is completed, you have to repair everything that the infection has done. To fix everything manually, you have to have extensive IT knowledge. If you don't consider yourself a professional when it comes to computers, IT professionals[4] highly advise downloading the patented FortectIntego PC repair tool.
It will ensure that the Registry keys and values are in order and take care of other elements on your device, preventing it from crashing, freezing, exhibiting any other abnormal behavior, most importantly, Ehiz virus renewal. To make things easier, here are detailed instruction on how to accomplish this step:
- Download the application by clicking on its name above
- Click on the ReimageRepair.exe that appears on your browser

- If User Account Control (UAC) shows up, select Yes
- Press Install

- The analysis of your machine will begin immediately after the program is successfully installed

- The results will be listed in the Summary
- You can now click on each of the issues and fix them one by one
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

By employing FortectIntego, you would not have to worry about future computer issues, as most of them could be fixed automatically. Most importantly, you could avoid the time-consuming and irritating process of Windows reinstallation in case things go very wrong.
Step 4.
Only after you've completed each and every of the last three steps can you proceed to data recovery. If you had backups of all your data, you could safely retrieve them. As we've mentioned before, Ehiz file virus belongs to the Djvu ransomware family. Since it's one of the most perversive malware strains circulating the internet, there are companies helping victims to recover files for free.
One of those companies is Emsisoft. It offers free decryption software that might help recover data encrypted by ransomware from the lineage mentioned above. Although, there's no guarantee that it will work because the article's culprit is a brand new variant. Either way, stay hopeful and try it:
- Download the app from the official Emsisoft website.

- After pressing the Download button, a small pop-up at the bottom, titled decrypt_STOPDjvu.exe, should appear – click it.

- If User Account Control (UAC) message pops up, click Yes.
- Agree to License Terms by pressing Yes.

- After Disclaimer appears, press OK.
- The tool should automatically identify the affected folders, although you can also do it by pressing Add folder at the bottom.

- Press Decrypt.

There are three possible outcomes:
- “Decrypted!” is shown under files that have been successfully unlocked and can be used again.
- “Error: Unable to decrypt file with ID:” means that the keys for Ehiz ransomware have not yet been retrieved, so you should try later.
- “This ID appears to be an online ID, decryption is impossible” – this tool won't help you decrypt your locked data.
If the Emsisoft decryptor doesn't work and your files are stilled locked up, that doesn't mean that you can't recover Ehiz files. There might be other ways to do that, and we've included them at the bottom of the article. Please try them out, as succumbing to the assailants' demands is the worst option that you could take.
Criminals could use that money to expand their empire of dirt. The ransom money would finance the development of more sophisticated computer threats and means to distribute them. Please do the responsible thing and don't forward any money to your assailants.
Was this guide helpful?
Be the first to comment