SpyHunter ransomware is malware that tries to destroy the reputation of legitimate anti-malware software

SpyHunter ransomware is a new variant of GarrantyDecrypt, a cryptovirus[1] that was first spotted by cybersecurity experts in November 2018, and is progressively expanding its operations. While the threat is unusual when it comes to its functionality and the goal, its name is extremely controversial, as it tries to incorporate a renown anti-virus vendor Enigma and its security software SpyHunter 5.
SpyHunter ransomware was first spotted in April 2019 spreading by hiding the malicious payload SpyHunter5.exe alongside other files as email attachments.[2] It appended .spyhunter file extension and dropped a ransom note $HOWDWCRYPT$.txt, which explained that victims have 72 hours to pay the ransom, yet failed to inform what would happen after the threshold.
In most cases, hackers claim they would delete the encryption key needed to recover personal files like pictures, documents, databases, videos, etc. Victims are offered a contact email – spyhunter5s@aol.com, which is again using the anti-virus vendor's name.
| Name | SpyHunter ransomware |
|---|---|
| Type | Cryptovirus |
| Main executable file | SpyHunter5.exe |
| Related | GarrantyDecrypt ransomware |
| Ransom note | $HOWDWCRYPT$.txt |
| Contact email | spyhunter5s@aol.com |
| Poses as | Enigma Spyhunter company |
| File marker | .spyhunter |
| Distribution | Spam email attachments with infected files |
| Removal tips | Use a reputable anti-malware program and remove SpyHunter ransomware. We can recommend FortectIntego for this job |
It is yet unknown why cyber thieves decided to use SpyHunter's name, but the deed was probably done as a joke or as an attempt to destroy Enigma's reputation. Nonetheless, there is no connection between the malicious actors behind SpyHunter ransomware and its legitimate counterpart.[3]
The ransomware attacks start with a system scan, during which SpyHunter virus finds files for encryption and checks if the system was encrypted before. Various formats of personal data get affected during this process:
- photos;
- images;
- videos;
- audio files;
- documents;
- archives;
- databases.

Once this is done, SpyHunter ransomware virus informs victims about the process and further steps in the ransom note which reads the following:
All your files are encrypted by Enigma SpyHunter5s!
Our company SpyHunter is guaranteed to decrypt your files.
Creating and removing viruses is our vocation.
We will provide you with professional support.
You have 72 hours to contact us.
Email us at :
spyhunter5s@aol.com
Your unique ID
SpyHunter ransomware also uses the name of software to mask the malicious processes running in the background. Users report that Task Manager shows SpyHunter.exe as the process causing some usage of resources. This fact probably makes this threat less noticeable since users may commonly use the legitimate program all over the world.
You need to remove SpyHunter ransomware from the machine because during the time that threat runs on the system it may affect more significant parts of the computer. It is known that ransomware alters Windows Registry keys to make the processes running after each reboot.
So based on various alterations, you may need to enter the Safe Mode with networking before SpyHunter ransomware removal. However, the best tool for this purpose is professional anti-malware programs like FortectIntego. These tools can clean the system and eliminate virus damage besides the main cryptovirus.

Macro virus-filled file attachments include malicious script
When it comes to ransomware or any other more severe malware programs, the primary technique used to spread these cyber infections is spam email campaigns, during which files infected with macros or hyperlinks with direct downloads and installs get attached to legitimate-looking emails.
Experts[4] note to be aware that such emails may pose as:
- financial information from a company or service;
- receipts or order information;
- invoices;
- notifications from a bank or even work, government.
You should pay more attention to emails you receive and check the sender before opening the email or even downloading the attached file. Delete all suspicious emails before opening them and do this more often so there is no risk of getting infections on the machine.
Eliminate SpyHunter ransomware with professional tools and safely recover affected data
For the SpyHunter ransomware virus termination, you should employ reputable programs that are designed to detect and fight malware. Manual cryptovirus termination is not recommended because ransomware installs other files besides the main payload. You need to find and delete them all to end all the processes completely.
You can remove SpyHunter ransomware using automatic solutions. Employing professional anti-malware tools for this job gives the opportunity to eliminate all associated files and programs. So get FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes and scan the system fully.
After SpyHunter ransomware removal, you should check the system again and make sure that all parts of the malicious program got deleted completely. This way there is no risk to your files when you try to recover them using your file backups.
Did this guide help?
Be the first to comment