Towz ransomware is the infection that demands payments for false decryption promises

Towz file virus is a version of ransomware that locks data on the machine and promises to recover files for a fee. However, these threat actors do not offer proper tools and cannot recover files this easily. The infection marks files using .towz appendix, and this is the indication for encoded files on the machine.
The problem with this infection is that it involves money extortion[1] and damage to commonly used files. Towz ransomware virus can infiltrate the system silently and affect the performance of the computer. The infection not only triggers the encryption but also disables programs and system functions on purpose.
The threat locks data and asks for the payment that should be exchanged for the decryption. However, these people should not be trusted, and the fee is not going to guarantee that these files will get recovered. Towz ransomware asks for a huge sum, and this is never a good idea to pay criminals.
Especially when this threat comes from the DJVU ransomware family that has been known since 2018 and is releasing versions weekly with more improved coding methods that make variants no longer decryptable. It is not advised by experts[2] to even write people behind the threat.
| Name | Towz ransomware |
|---|---|
| Type | File-locker, cryptovirus |
| Issues | The infection locks files, making them useless, so there is a reason for direct money demands |
| Ransom note | _readme.txt |
| Ransom amount | $490/ $980 |
| Contact details | support@bestyourmail.ch or datarestorehelp@airmail.cc |
| Removal | Threat removal can be possible with apps like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes that detect the infection and makes malware-related pieces harmless |
| Repair | Repair the damaged system file or any corrupted pieces with FortectIntego |
Paying vs. decryption?
Towz file virus releases the _readme.txt file on the machine once those files get locked and marked using a unique file extension. This file lists claims and possible options for victims, but the payment of $980 or even the discounted $490 cannot guarantee that the recovery software can reach people.
The threat asks for this payment, offers a discount in the first 72 hours, and even tries to fake the trust by offering the test decryption of one file. However, this is the family known for years, and these versions are not that altered or changed, so the goal of criminals remains the same – your money.
Towz ransomware virus creators do not care about your data or belongings and any losses that they cause. Make sure to remove the virus and do not pay or contact people running these operations. Ransomware decrytpion with official tools is also not possible because these versions do not have the particular tool, but there are older apps that worked before.

Possible decryption for the Djvu family
Towz ransomware is the version of the infection that gets improvements with each weekly release of the threat bundle. This is the infection that can damage a lot of pieces on one machine that is infected. You need to take care of the security and stop the virus so then the infection leftovers can be removed and damaged files possibly recovered.
If your computer got infected with one of the Djvu variants, you should try using Emsisoft decryptor for Djvu/STOP. It is important to mention that this tool will not work for everyone – it only works if data is locked with an offline ID due to malware failing to communicate with its remote servers.
Even if your case meets this condition, somebody from the victims has to pay criminals, retrieve an offline key, and then share it with security researchers at Emsisoft. As a result, you might not be able to restore the encrypted files immediately. Thus, if the decryptor says your data was locked with an offline ID but cannot be recovered currently, you should try later. You also need to upload a set of files – one encrypted and a healthy one to the company's servers before you proceed.
- Download the app from the official Emsisoft website.

- After pressing Download button, a small pop-up at the bottom, titled decrypt_STOPDjvu.exe should show up – click it.

- If User Account Control (UAC) message shows up, press Yes.
- Agree to License Terms by pressing Yes.

- After Disclaimer shows up, press OK.
- The tool should automatically populate the affected folders, although you can also do it by pressing Add folder at the bottom.

- Press Decrypt.

From here, there are three available outcomes:
- “Decrypted!” will be shown under files that were decrypted successfully – they are now usable again.
- “Error: Unable to decrypt file with ID:” means that the keys for this version of the virus have not yet been retrieved, so you should try later.
- “This ID appears to be an online ID, decryption is impossible” – you are unable to decrypt files with this tool.
Terminating the infection
Towz file virus is not a simple infection, and this threat needs to be removed from the system properly. That is achievable with proper detection[3] tools that run AV engines and can indicate all sorts of threats that run on the machine and can cause issues with the system.
Running a proper system scan with AV tools can be crucial because removing the infection makes the computer useful again and users can properly recover files damaged by the Towz ransomware virus if they use proper recovery options. Alternate methods for recovery can be found online, but the infection should be removed before anything like this happens.
If you replace damaged data using proper co[ies from the backup, but the virus is still actively running on the machine, the threat can damage those pieces, and you lose your data permanently. That is dangerous, and if you do so, the virus still gets files locked again, resulting in total losses of money and files. Remove Towz ransomware as soon as possible.
The proper security tool like MalwarebytesMalwarebytes or SpyHunterCombo Cleaner can check the machine and find all possibly malicious files related to the infection or additionally injected programs. These threats, like ransomware, can rely on applications like trojans or different malware and install them to keep the persistence of this file-locker up, so the machine is running all needed malicious processes, so all dangerous operations of the Towz file virus cannot be disrupted. To achieve that, the ransomware can damage or disable functions or programs on the PC.
Repair the damage on the system
Once a computer is infected with malware, its system is changed to operate differently. For example, an infection can alter the Windows registry database, damage vital bootup and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software is not capable of doing anything about it, leaving it just the way it is. Consequently, users might experience performance, stability, and usability issues, to the point where a full Windows reinstall is required.
Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.
- Download the application by clicking on the link above
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

Did this guide help?
Be the first to comment