Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2022

How to remove Hheo ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Hheo file virus developers can seem trustworthy, but none of their claims are true

Hheo file virus is the infection that relies on scare tactics, so people pay up, thinking that this is the only solution to get access to their devices again. The ransomware can affect various files once it is on the machine, and this infection spreads silently, so these issues with locked files appear out of nowhere. Victims can get tricked into believing that the system slowness is caused by additional processes when fake Windows update pop-ups get shown, so those files marked with .hheo appendix come suddenly.

After that, the _readme.txt file also appears placed in various folders and on the desktop. This is the direct message from the cybercriminals behind the threats. This ransom note will advise people to pay up if their data has been encrypted by Hheo file locker malware. However, there's no guarantee for complete recovery as these payments go only towards unlocking databases rather than restoring them completely. Also, claims can be fake, and criminals might disappear after the transfer is made.

Name Hheo file virus
Type Ransomware, cryptovirus
File marker .hheo appears at the end of every affected piece of file
Family STOP virus/ Djvu ransomware
Distribution The infection spreads using pirating platforms and software cracks, licensed versions of software, or free game packages
Ransom note _readme.txt
Ransom amount $490/ $980
Contact email support@bestyourmail.ch, supportsys@airmail.cc
Elimination Threats require anti-malware tools for the removal, so all files get deleted
Repair You should run FortectIntego for the proper system recovery

Hheo ransomware virus is coming from the family of threats that can be considered most active and dangerous at this time because the infection releases new versions once or twice a week. The latest ones on the list of Djvu ransomware variants list were Hhwq and Hhew. These versions are not much changed from the ones that came out earlier this year or even last year.

Asking for large sums of Bitcoin cryptocurrency

Criminals are demanding $490 worth of Bitcoin immediately, or else people's personal files will be lost. If someone pays this much money within 72 hours after receiving an informing email from the creators, then they should receive decryption tools in return. Do not pay, however. The discount that is offered for the first 72 hours is not valid in any shape or form. 

The ransom note reads:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-FGXsqIcjpu
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@bestyourmail.ch

Reserve e-mail address to contact us:
supportsys@airmail.cc

Your personal ID:

Payments do not guarantee anything. No matter if you pay the full $980 price or the discounted amount. The Hheo ransomware virus can detect what type of files you have on your PC and which ones are more used, hence valuable. It will change the original code of those files and encrypts[1] data like this to make files useless.

Criminals might try to offer the test decryption, but these are fake claims also. Do not believe anything criminals list on that _readme.txt file. You should ignore them and try not to do what they request from you. You can try to recover the machine as soon as possible, and that can be possible by removing the Hheo file virus properly. The worrying about the lost data.

Try to find the option for decryption

If your computer got infected with one of the Djvu variants, you should try using Emsisoft decryptor for Djvu/STOP. It is important to mention that this tool will not work for everyone – it only works if data is locked with an offline ID due to malware failing to communicate with its remote servers.

Hheo ransomware virus version is using the online IDs primarily, so unique keys are formed for each affected device. However, these C&C server connections can sometimes fail, so the procedure of encryption relies on offline key methods, and the decryption can be possible, These IDs often end in t1, so you can identify the offline key right away.

Even if your case meets this condition, somebody from the victims has to pay criminals, retrieve an offline key, and then share it with security researchers at Emsisoft. As a result, you might not be able to restore the encrypted files immediately. Thus, if the decryptor says your data was locked with an offline ID but cannot be recovered currently, you should try later. You also need to upload a set of files – one encrypted and a healthy one to the company's servers before you proceed.

  • Download the app from the official Emsisoft website.
  • After pressing Download button, a small pop-up at the bottom, titled decrypt_STOPDjvu.exe should show up – click it.
  • If User Account Control (UAC) message shows up, press Yes.
  • Agree to License Terms by pressing Yes.

  • After Disclaimer shows up, press OK.
  • The tool should automatically populate the affected folders, although you can also do it by pressing Add folder at the bottom.
  • Press Decrypt.

From here, there are three available outcomes:

  1. Decrypted!” will be shown under files that were decrypted successfully – they are now usable again.
  2. Error: Unable to decrypt file with ID:” means that the keys for this version of the virus have not yet been retrieved, so you should try later.
  3. This ID appears to be an online ID, decryption is impossible” – you are unable to decrypt files with this tool.

Eliminating the infection

Their decryption tool is offered for a 50% discount if you pay in the first 72 hours. But there's no guarantee that it will work or that the tool even exists. Criminals also make false claims about how long this process takes and what other people experience with their service.

Hheo file virus can lurk on your computer undetected for days or weeks without causing any issues. Nevertheless, once the system gets infected, the damage has already been done because ransomware runs on the machine, trying to improve its persistence. This is why you need to remove the virus before doing anything else.

The expert[2] advice is to stay away from these criminals and avoid any contact which could lead only further issues instead of a full file recovery as promised. Especially since this isn't just an old threat but one that's been reported in many countries since 2018. Remove Hheo ransomware with SpyHunterCombo Cleaner or MalwarebytesMalwarebytes and make sure to double-check to terminate the active virus fully.

Restoring the system after the infection

Hheo ransomware can cause other issues with the machine, so besides the AV detection[3] tool and virus removal, your machine should be scanned for virus damage and system repair procedures. The machine cannot work properly if those changes caused by the infection are not altered.

Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system, thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.

  • Download the application by clicking on the link above
  • Click on the ReimageRepair.exe
    Reimage download
  • If User Account Control (UAC) shows up, select Yes
  • Press Install and wait till the program finishes the installation processReimage installation
  • The analysis of your machine will begin immediately
  • Once complete, check the results – they will be listed in the Summary
  • You can now click on each of the issues and fix them manually
  • If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.Reimage results

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.