Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2020

How to remove Hhmgzyl ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Hhmgzyl ransomware is a malicious program that holds files hostage until ransom is paid to cybercriminals

Hhmgzyl ransomware

Hhmgzyl ransomware is yet another addition to the broad family of Snatch malware. Just like its predecessors, the virus encrypts all pictures, videos, music, documents, archives, and other files on the compromised computer with the help of AES cipher and then demands a ransom for their release. Suchlike modified data is also appended with .hhmgzyl extension and can no longer be accessed by victims.

Besides encrypting all personal files on the system, the Hhmgzyl virus also places a ransom note HOW TO RESTORE YOUR FILES.TXT on the desktop and multiple other locations on the PC. These files can typically be opened in a Notepad or another text program. The message discloses the intentions of cybercriminals to users and asks them to email them via retrnyourfiles23@cock.li or retrnyoufiles@tutanota.com to negotiate the ransom size. According to criminals, the contact needs to be made within 48 hours of the infection, or persona key that could unlock .hhmgzyl files will be deleted permanently.

Name Hhmgzyl ransomware
Type File locking virus, crypto-malware
Family  Snatch ransomware. Attackers typically go “big game hunting” by attacking companies and businesses instead of regular users. Hackers also threaten to publish sensitive corporate data stolen during an attack if the ransom is not paid within a particular time frame
Extension  Each of the affected files is appended with .hhmgzyl extension. Example of an encrypted file – “picture.jpg.hhmgzyl”
Ransom note HOW TO RESTORE YOUR FILES.TXT, which is dropped on the desktop and other places on the computer where encrypted files are located
Contact retrnyourfiles23@cock.li or retrnyoufiles@tutanota.com
File recovery The only secure way to restore files is by using data backups. If such are not available, options for recovery are very limited – we provide all relevant information below
Malware removal Each of the infected machines should first be disconnected from the network and then a full computer scan with anti-malware, such as SpyHunterCombo Cleaner, to be initiated for a full termination
System fix Malware can often damage several Windows components, and result in the OS corruption. To repair such damage done by the virus, we recommend using a repair program, such as FortectIntego

Before encrypting all data on the local and networked drives, Hhmgzyl ransomware performs a variety of system changes to ensure that the encryption process is successful. For example, it modifies Windows registry keys in order to establish persistence, deletes Shadow Volume Copies to prevent easy file recovery, creates new processes and drops hundreds of files for operation, etc.

Suchlike modifications can sometimes damage the system file integrity, resulting in corrupted Windows. Thus, after Hhmgzyl ransomware removal is performed, users are recommended to scan their devices with FortectIntego repair software that would be able to eliminate software bugs created by the infection.

During the infection stage, malware contacts a remote C&C server to retrieve a unique ID, and that is used for identification purposes. Researchers observed some Snatch ransomware variants rebooting the system in Safe Mode during the file encryption process to avoid being stopped by security software.[1] If the opposite happens, the system can successfully remove Hhmgzyl ransomware before it could manage to inflict any damage.

After the encryption is complete, Hhmgzyl ransomware would drop a ransom note HOW TO RESTORE YOUR FILES.TXT, which explains the following:

Hello! All your files are encrypted and only we can decrypt them.

Contact us:

retrnyourfiles23@cock.li or retrnyoufiles@tutanota.com

Write us if you want to return your files – we can do it very quickly!

The header of letter must contain extension of encrypted files.
We always reply within 24 hours. If not – check spam folder, resend your letter or try send letter from another email service (like protonmail.com or cock.li).

Attention!
Do not rename or edit encrypted files: you may have permanent data loss.

To prove that we can recover your files, we am ready to decrypt any three files (less than 1Mb) for free (except databases, Excel and backups).

HURRY UP!
If you do not email us in the next 48 hours then your data may be lost permanently.

As evident, the attackers attempt to convince users that the only way to regain access to locked files is by paying a ransom to them. They even offer a free test decryption service that would allow them to recover one file for free. On the other side, they also try to scare victims by claiming that the key is required to get .Hhmgzyl files restored will be deleted within 48 hours of the infection.

Security experts[2] do not advise victims paying the ransom, as there is a chance they might not retrieve the required key even after the payment. Additionally, the more ransoms crooks receive, the more drive they will have to create new virus versions and infect more targets. Nonetheless, some companies/people might not have another choice, which is one of the most devastating traits of a ransomware infection.

Hhmgzyl ransomware virus

Hhmgzyl ransomware developers threaten to disclose stolen files publicly if ransom is not paid

Hhmgzyl file virus is not the first version of Snatch ransomware that has been released in the wild since its initial release back in December 2018. Previous versions include Gdjlosvtnib, Eknkfwovyzb, EGMWV, Pywdu, and many others. Malicious actors behind the strain usually target corporate networks and businesses via weakly protected Remote Desktop (RDP) connections, although other infection means can be used as well.

Threat actors do not rush to deploy Hhmgzyl ransomware as soon as they break into the network of a particular company but instead move laterally, gaining administrator access connected to a server. In most cases, hackers spend on the network for at least a week before they launch a malware payload, which consequently encrypts all files. During this time, the intrusion can be stopped successfully if background activity is spotted.[3]

Unfortunately, most of the cases show that these attacks are successful. Before deploying ransomware, the attacks steal corporate files and other documents that are secret. This information is later used for blackmailing purposes, as .hhmgzyl file virus authors threaten to publish it in case the ransom is not paid.

Based on previous examples of Snatch malware attacks, threat actors asked for as much as 1 – 5 bitcoins for a decryption tool. Nonetheless, Hhmgzyl ransomware is one of the newer variants, and they might ask for much larger sums to keep the stolen files safe.

If the backups were indeed encrypted or were not retained, there a few possibilities of data recovery, although third-party recovery software or built-in Windows recovery solutions might work in cases where the Hhmgzyl virus failed to perform correctly.

Hhmgzyl ransomware encrypted files

Hhmgzyl ransomware removal instructions and data recovery

If the attackers behind Hhmgzyl virus do not disable the anti-virus that is employed, the infection could be detected under the following names – according to Virus Total:[4]

  • HEUR:Trojan-Ransom.Win32.Gen.vho
  • Trojan.Ransom.Snatch
  • Ransom:Win64/Snatch.A!MTB
  • A Variant Of Win64/Filecoder.BL
  • Win64:Trojan-gen
  • Gen:Variant.Ransom.GoRansom.2, etc.

To remove Hhmgzyl ransomware, a compromised computer should be immediately disconnected from the network, and then a scan with powerful anti-malware, such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes, should be performed. In some cases, accessing Safe Mode with networking is the correct way to perform this process – we provide guidelines on how to access this mode below.

Only after Hhmgzyl ransomware removal, the data recovery process can be undertaken – either from backups or using alternative methods, we provide below.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.