PooleZoor – an Iranian ransomware which is based on the HiddenTear code

PooleZoor ransomware is a dangerous cryptovirus which appears to be related to the HiddenTear source code. It was observed that its developers are hailing from Iran. However, the ransomware seems to be attacking all PC users worldwide. The cryptovirus appears on the system as the Peyment.exe file. It starts encrypting files and marks them with the .poolezoor file extension. As a result, PooleZoor ransomware turns this data unusable and then displays a ransom message offering a decryption tool for files' recovery. In exchange, victims need to transfer a certain amount of money to the cybercriminals.
| NAME | PooleZoor |
|---|---|
| TYPE | Ransomware |
| DANGERS | Encrypts important data, convinces naive users to buy the ransom, might open paths for other malware forms, decreases the PC's protection |
| EXTENSION | .poolezoor |
| based on | HiddenTear |
| Hails FROM | Iran |
| prevention TIPS | Stay away from dubious-looking web sources, install antivirus |
| ELIMINATION | Use FortectIntego |
If you spotted files encrypted with the .poolezoore extension and also found the ransom note in every folder, do not rush to pay the ransom. We advise thinking everything twice and removing this virus before you start recovering your encrypted files. Then, follow tips that are given at the end of this post to recover your most valuable data. According to SenzaVirus.it specialists, cybercrooks often do not fulfill their promises. Once the money is transferred, they disappear and leave their victims with nothing.
At the moment of writing, there is no certain information about the ransom amount and currency required by PooleZoor ransomware. However, cybercriminals often urge their victims to use these types of currency:
- Bitcoin;
- Monero;
- Dash;
- PaySafeCard.
However, make sure you never deal with cybercriminals as there is no guarantee that you will be left with nothing. You need to remove PooleZoor virus from your computer to stop the infection from spreading and reaching its further goals. Consider using FortectIntego or any other similar anti-malware tool to fix your computer.
A recommendation after the PooleZoor ransomware removal would be to take care of your data safety in advance. For such purpose, you can use an external hard drive, USB drive[1], icloud and similar methods that could help you keep your data safe. If you store copies of important documents in one of such devices, they will be reachable only for the owner – you. However, note that either an external hard drive or other devices should be disconnected from your computer as ransomware viruses can easily affect the entire network when inside the system.

Prevent ransomware infections by paying more attention to spam
The biggest possibility of getting infected with ransomware is when dealing with dubious spam messages and content included within them. Such phishing messages usually appear as legal content, however, they often carry harmful material, such as infected attachments or links. If you are not expecting anything important and happen to receive a strange-looking email, eliminate it without hesitation to avoid downloading malware to the system. You can also hover the mouse over the link to see if it is safe to be opened.
Malware experts from Ioys.gr[2] also recommend increasing your computer's safety by downloading reputable antivirus program[3]. If you don't have such a tool yet, install one of the anti-malware programs provided below. It will perform regular system scans and look for various cyber threats. Notice, you need to keep it always updated to make sure that it works properly.
Make sure PooleZoor ransomware is removed on time to prevent additional loss of your files
If you want to remove PooleZoor ransomware from your computer system, you need to think about doing it in a professional way as manual elimination is not suitable for this case. We advise installing trusted anti-malware tools such as FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. These programs will guide you thru the whole removal process and will help you get rid of the ransomware infection within several minutes.
After you perform the PooleZoor removal, make sure you carry out some system backups. This is very important because you need to make sure that the virus did not leave any hazardous components behind itself.
Did this guide help?
Be the first to comment