Weui ransomware – crypto-malware that might result in a complete loss of pictures, documents and other files

Weui ransomware is a cryptovirus that encrypts victims' personal data and demands a ransom. The malware belongs to the ever-growing Djvu ransomware family, which has over 250 variants threatening everyday computer users since December of 2018, with viruses like Lisp, Vvoa, Iiss, and many others.
As soon as ransomware gets access to a computer, it starts the encryption process instantly. During this process, all files are appended with a .weui extension and thus are rendered inaccessible. Since the latest version from this family are using an army-grade RSA encryption algorithm, it's very hard to decrypt the data without the necessary tools.
When all personal files, like pictures, documents, archives, etc., are renamed and encrypted, Weui virus generates ransom notes (_readme.txt) and places them in every folder so that the victims could find them easily. Within these notes cybercriminals state instructions and their demands. They also leave two emails for communication purposes – helpmanager@mail.ch and restoremanager@airmail.cc.
| name | Weui ransomware |
|---|---|
| Type | Ransomware |
| Family | Djvu ransomware |
| Ransom note | _readme.txt |
| Ransom amount | $980 if the victims are not hasty and don't contact/pay within 72 hours of infection. If the users are quick, a 50% discount is given, lowering the ransom to $490 |
| Appended file extension | .weui is appended to all non-system files |
| Criminal contact details | As usual with Djvu family viruses, two emails are provided to establish contact: helpmanager@mail.ch, restoremanager@airmail.cc |
| Virus removal | Professional anti-malware software should be used to eliminate the virus from the system fully |
| System Clean-up | The FortectIntego system tune-up tool should be used after malware's elimination to find and fix any system issues the virus might have caused |
Ransom notes among the viruses from this lineage differ very slightly if at all. First, the creators of Weui file virus explain that all personal data was encoded and that the only method to unlock it is by purchasing their decryption tool. Then they offer a free decryption of one file to prove to the victims that the necessary tool really exists. They even provide a link to a video where such a tool can be seen in action.
The middle part of the ransom note is all about the ransom amount. The price of the Weui ransomware decryption tool is $980. But if the victims are hasty and contact the hackers within 72 hours of the attack, the cybercriminals are nice enough to offer a 50% discount, reducing the ransom amount to $490. The preferred payment method isn't mentioned, but we can speculate that the ransom will be asked to forward using cryptocurrency Bitcoins.
The last part of the Weui ransomware money extortion note consists of two emails (helpmanager@mail.ch and restoremanager@airmail.cc) that the cybercriminals provide to establish contact and an appointed unique victim ID. No threats not to try renaming files or use third-party decryption tools are submitted.

We always advise against dealing with the cybercriminals and suggest to remove Weui ransomware instead. Professional anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes should be trusted with this process as manual removal could be a lengthy and difficult task even for experienced computer users.
When Weui ransomware removal is done with, and the device is virus-free, experts[1] recommend using a powerful system tweaking tool like the FortectIntego app, to restore any changes that the cryptovirus might have caused to the system registry, its files, and settings. Only after a system tune-up, the victims should restore their data from backups.
Weui virus developers send this message with their ransom notes:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-Dz5odBd07y
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpmanager@mail.chReserve e-mail address to contact us:
restoremanager@airmail.ccYour personal ID:
Evading .Weui file virus and other versions of Djvu family
Nowadays, there are various types of malware[2] circulating around the internet. From sensitive information collecting keyloggers to irritative adware. These kinds of malware could be distributed in various ways. But Djvu family ransomware, including the .Weui file virus is typically spread with game/software cracks.[3]
These illegal activation toolkits are used to unlock commercial, licensed software and the hackers love to exploit it. They name the ransomware payload file as a new game or expensive software crack and upload it to file-sharing platforms like The Pirate Bay, BitTorrent, and alike. So the .Weui ransomware virus executable is downloaded alongside other pirated files.

As soon as such a tool is downloaded an infection and encryption starts immediately and within a few minutes, all data on the computer could be rendered useless. Please refrain from using cracks. Instead, support your beloved game or desired software creators by purchasing their products either directly from them or from official distributors. You can avoid such Weui ransomware removal.
How to recover .weui files? Here are a few answers to this very important question
Without a doubt, it must be scary to see .weui virus files on your computer, especially if contents are important, e.g., related to work or school projects. Cybercriminals are preying on this fact; that is why ransomware targets the most common file types on a Windows computer – .doc, .zip, .jpg, .mp4, and many others.
Many users mistakenly believe that they can get their data back as soon as they eliminate the infection from the system. However, this is a very misleading assumption, as file encryption and virus infection are independent processes, although the former is not possible without the latter. This means that even if you delete the infection from your computer, it will not remove .weui extension from your files.
Once files are locked by ransomware, there are very few chances to recover them without using backups. Unfortunately, not many people are practicing keeping data backups, resulting in devastating consequences in case of a ransomware attack.
If you have no backups but want to recover .weui files, you should not rush paying criminals. There are several other methods that could help you, although keep in mind that the chance of success is relatively low. Here are a few options that you have (you need to backup the encrypted data, delete the malware and only then try them):
- Use Emsisoft's decryption tool. This option is only available for those who have their files encrypted with an offline ID (which you can find out after employing the tool). Keep in mind that it might take some time before a decryption key is available, as a victim of the same malware version needs to pay the ransom, retrieve the key from criminals, and then share it with the researchers so they can update the decryption tool.
- Try third-party recovery software such as Data Recovery Pro. In some cases, you might be able to restore at least some copies of files from your hard drive with recovery tools.
- In case malware failed to delete Shadow Copies, you should be able to retrieve .weui files either manually or by using automated programs for the purpose. To find out more, check the bottom section of this article.
Guidelines for Weui virus removal and system health check
Paying off the criminals and regaining access to the encrypted data might seem like the easiest way out, but by doing it victims endorse and motivate cybercriminals to expand their attacks and research new, more sophisticated malware and spreading techniques. People should focus on Weui ransomware removal instead.
We strongly advise to remove Weui ransomware with the help of reliable and powerful anti-malware software like SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Run a full system scan with any of these apps, and they should be able to locate, isolate, and delete the cryptovirus immediately.
As already mentioned, Weui file virus elimination won't decrypt your files. But if you had backups don't rush to use them right away. First, you need to perform a full system scan with a system tune-up app like the FortectIntego to make sure the virus didn't do any harm to system files, and its settings. If it did, system repair apps will take care of it. Only then you're safe to retrieve info from your backups.
If you didn't keep backups, and there's no public decryption tool available, then export all encrypted files to offline storage, like USB drives or any other, and get back to us later. We always update our readers with all the latest news on ransomware, its prevention, and available decryption methods. You could also try some of our suggested data recovery methods listed at the bottom of this article. Remember to clear the malware first and ensure that Weui virus is not going to renew the infection.
Did this guide help?
Be the first to comment