.Djvut Ransomware Description
.Djvut Ransomware is a cryptolocker malware that was initially active in Brazil, Turkey, Portugal, the USA, England, and Russia but quickly started affecting computer users across the globe. It infiltrates the user's computer and targets the most commonly used file types such as .cat, .csv, .db, .doc, .gif, .htm, .ico, .inf, .ini, .jpg, .png, .ppt, .sam, .shw, .txt, .url, .xls, .xml, .wav, .wb2, .wk4, .wpd, .wpg. It will encrypting the file types using the AES encryption algorithm and making them unusable. Each encrypted file will have ".djvut" appended to each file as a new extension.
.Djvut Ransomware Is a Variant of STOP Ransomware
After analyzing this malware threat, security experts determined that .Djvut Ransomware is a new member of the growing family of STOP Ransomware variants. Most of these newer variants use similar extensions - ".djvu", ".djvu*", ".djvuq", ".udjvu", ".djvuu", ".uudjvu", ".djvur", ".djvus", ".DJVUT", and now ".djvut".
A text file called "_openme.txt" containing a ransom message with instructions and a personal ID key will be created by the ransomware. In the message, the cybercriminals provide two email addresses for contact - "helpshadow@india[.]com" and "helpshadow@firemail[.]cc". They promise that all users who contact them within the first 72 hours will receive a 50% discount. There is also a warning that using a third-party program to decrypt the affected filed could result in the destruction of the files. The full text of the ransom note is:
------------------------ ALL YOUR FILES ARE ENCRYPTED ------------------------
Don't worry, you can return all your files!
All your files documents, photos, databases and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees do we give to you?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information
Don't try to use third-party decrypt tools because it will destroy your files.
Discount 50% available if you contact us first 72 hours.
To get this software you need write on our e-mail:
Reserve e-mail address to contact us:
Your personal ID:
What to Do If Your Files Are Encrypted by .Djvut Ransomware
Dealing with ransomware attacks could be extremely stressful. The most important thing is to remember to never send any money to the creators of the malware. Instead, you should first clean your computer from any traces of the ransomware threat in order to stop it from encrypting any new files or spreading further through the network. The easiest way to do that is to install a legitimate anti-malware program and let it scan your entire computer system. Then, it's best to allow the anti-malware program to remove any malicious files detected by the scan.
As for the encrypted files, there are a couple of options to consider. If you have a backup created before the ransomware had invaded your computer, you could restore your data from it. In the case that a suitable backup is unavailable you could archive the entire drive and wait for a possible decryption tool to be created by the cybersecurity community. Fortunately for the victims of .Djvut Ransomware, there is such a decryptor that might help recover files.
Decryptor Is Available for .Djvut Ransomware Victims
Michael Gillespie, a ransomware specialist, has updated his STOP Decryptor to work with ".djvut" encrypted files. There are a couple of limitations, though. Currently, the decryptor works with only 2 offline keys - "6se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0" and "D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB" (the keys used by the malware if it failed to get a key from its server), or if the user has been provided with a key. It is worth a shot to try and see if the decryptor will be able to restore your files to their original state.
Do You Suspect Your PC May Be Infected with .Djvut Ransomware & Other Threats? Scan Your PC with SpyHunterSpyHunter is a powerful malware remediation and protection tool designed to help provide PC users with in-depth system security analysis, detection and removal of a wide range of threats like .Djvut Ransomware as well as a one-on-one tech support service. Download SpyHunter's FREE Malware Remover
Security Doesn't Let You Download SpyHunter or Access the Internet?Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
- Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
- Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
- Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
- IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.