Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2019

How to remove Heets ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

Heets ransomware is one of many slightly changed Dharma ransomware versions that marks files using .heets extension

Heets ransomwareHeets ransomware is the cryptovirus that affects users files with the goal of ransom demanding. This is one of many new ransomware variants hailed from Dharma ransomware that came out in February 2019. The virus family is known for three years now, and developers are not changing much about each version. Ransom note remains the same, payment instructions also delivered in the same file as before – HTML window. This fact that versions remain similar for years allows cybercriminals to release version after version regularly. However, the contact email for this version is heetsdecoding@cock.li. That and victim's ID gets revealed in the ransom note which is placed on the system when all encrypted files get .id-[bestdecoding@cock.li].heets appendix.

Name Heets ransomware
Type Cryptovirus
Virus family Dharma ransomware
A full patter of file extension .id-[bestdecoding@cock.li].heets
Ransom note Placed in the HTML window with payment instructions
Contact emails bestdecoding@cock.li; heetsdecoding@cock.li
Distribution method Spam email attachments, other malware
Decryption There is no specific tool for Heets ransomware decryption. Terminate the virus and then use data recovery methods
Elimination Use FortectIntego to remove Heets ransomware virus damage and clear the system before data recovery

If you encountered suspicious system changes or slowness of the computer, you already have malware on the system. However, Heets ransomware virus is not waiting for anything, and you cannot notice its infiltration or background processes. Cryptovirus immediately starts with file encryption[1] and marks your photos, documents, archives, databases, audio or video files with .id-[bestdecoding@cock.li].heets appendix.

Once this is done, Heets ransomware already made wanted changes on your system and the only thing left to do for the cybercriminals behind the threat is to collect your money for the encoded files. The information about payment methods and other possible solutions delivered in the HTML window that hasn't been changed since the first version of Dharma.

This so-called ransom note is placed on your screen after the successful Heets ransomware encryption and reads:

All your files have been encrypted!

All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail heetsdecoding@cock.li
Write this ID in the title of your message [ID] In case of no answer in 24 hours write us to theese e-mails: heetsdecoding@cock.li
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.

Free decryption as guarantee
Before paying you can send us up to 1 file for free decryption. The total size of files must be less than 1Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)

How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click ‘Buy bitcoins’, and select the seller by payment method and price.
https://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-can-i-buy-bitcoins/

Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

Heets ransomware is related to one of the most dangerous ransomware – Dharma.[2] This is why many researchers[3] recommend staying away from contacting people who developed this notorious threat. There is no need to trust the possible free decryption or the complete file recovery after payment promise. In most cases, these malicious actors disappear when the payment is transferred, and your files remain locked.

You need to forget about the encrypted data for a bit and focus on Heets ransomware removal first. This is crucial for your device because ransomware can encrypt your files again what makes data unrecoverable this way. Use your anti-virus program and terminate this cryptovirus as soon as possible.

Do not wait and remove Heets ransomware once you notice the encrypted files or get notified about the attack. Then you should clean the system using FortectIntego and fix virus damage. Data recovery is a complicated process especially when you don't have file backups on secure cloud service or external device.

For files encrypted by Heets ransomware, you can use data restoring software or tools. There is no official decryption tool, so this is the only solution besides data backups. We offer a few methods below the article alongside virus elimination tips.

Heets ransomware virus

Distribution ways used to spread ransom demanding threats

Ransomware infections might get delivered using various methods. A payload dropper gets spread around the world via the internet. Once this malicious script gets initiated on the device ransomware directly spreads on the system. If the malevolent file lands on the targeted computer there is a one step that allows launching the embedded content.

Payload file, in most cases, gets attached to the email as a document, executable, PDF or placed as a hyperlink. Unfortunately, an unsuspected victim can press one button without noticing the purpose and launch malicious macros on the system. Then the device gets infected, and cryptovirus can initiate any necessary process. 

If you want to avoid these infections, you need to pay more attention to emails you get without expecting and the contents attached to it. If you notice suspicious email with a subject line that makes no sense keep away and delete the email immediately. Financial information, Invoice or Order details shouldn't get sent to random users from companies or services.

Terminate Heets ransomware and fix any issues caused by this infection

To remove Heets ransomware completely from the system, you need to employ reputable tools like FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. This way you can clear the system entirely and make sure all possibly related files get removed. The termination process gets difficult due to altered registry entries and added malicious system files. You need to get rid of them all. 

Since Heets ransomware removal requires professional anti-malware tools, make sure to choose wisely and get the software from the official website or reputable source. It ensures safe installation and positive virus elimination results.

When you are completely sure that Heets ransomware virus is deleted from the device, double-check and try data recovery methods listed below or use your file backups from an external device. DO NOT plug in the or load backup files on an infected system.  

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.