Home Malware Programs Ransomware Healforyou Ransomware

Healforyou Ransomware

Posted: January 25, 2019

The Healforyou Ransomware is a variant of the Globe Imposter Ransomware, a file-locking Trojan family that imitates the Globe Ransomware's Ransomware-as-a-Service. The Healforyou Ransomware blocks files on your computer with an algorithm that keeps them from opening, although a decryptor utility may, in theory, restore them. Have your anti-malware products ready for removing the Healforyou Ransomware immediately and keep backups for less danger to your files from its attacks.

Trojans Offering Expensive Healing after the Hurting

The cyber-security industry is spying another variant of the second version of the Globe Imposter Ransomware's family in 2019. This revision of Globe Imposter 2.0 Ransomware, as per the usual operating procedures, encrypts the victim's files and then tells them that they should contact one of several e-mail addresses for ransoming negotiations. This threat is receiving the label of the Healforyou Ransomware, after one of its symptoms.

The AES-256 encryption is the keystone of this family's payloads, which search for, and lock, media files on Windows PCs. Typical types of content that the Healforyou Ransomware may lock in this way include Word documents, various archives (such as ZIPs), pictures, databases, spreadsheets, slideshows, and the contents of high-traffic locations like the desktop or Downloads directory. However, this inventory is far from exhaustive, and threat actors can quickly modify it for increasing or decreasing the Trojan's scope.

The Healforyou Ransomware's name is from the extension of 'healforyou' that it adds to the ends of each file that it takes captive (for instance: 'your-document.doc.healforyou'). The Healforyou Ransomware also creates ransom notes in a Web page format that malware experts identify with the 2.0 version of its family explicitly, although the only significant information is a pair of e-mail addresses and the victim's ID. Unless the Trojan includes new bugs, the Healforyou Ransomware should, also, erase the Windows Shadow Volume Copies that would make restoring any data easy.

Getting Media Recuperation without a Ransom's Involvement

The most effective protection against nearly every file-locking Trojans' family is saving your files on another PC completely. Any drives that are available over local network connections may experience encryption along with the infected PC's drives. Avoiding storing your files in the locations that are most often under attack by the Healforyou Ransomware and similar threats could be helpful, as well.

There is a decryption tool for the Healforyou Ransomware's family, but malware analysts took note of the Globe Imposter 2.0 Ransomware update's including additional decoding issues previously. The users shouldn't assume that decryptors are always capable of recovering any encrypted content and shouldn't run a decryption program on the only copies of their files. A broad range of anti-malware products, as always, should stop and delete the Healforyou Ransomware before the beginning of any attacks.

Spam e-mail spam is a cliched but powerful infection strategy for the Healforyou Ransomware's family along with other entities in the Ransomware-as-a-Service market. If you don't want your files to become a bargaining chip, being watchful of what you're clicking can be a good step forward.

Loading...