STOP Ransomware

Anonymous
2019-01-06T12:04:19+00:00

My all files encrypted to .DJVUS extension ( I'm want my files back) please help me out for this regards..???


**IMPORTANT UPDATE: March 14, 2024**

**StopCrypt: Most widely distributed ransomware now evades detection** [**https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/**](https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/ "www.bleepingcomputer.com")

 **IMPORTANT UPDATE: April 12, 2022**  

**According to information previously provided on the Emsisoft Forum, they no longer have any method to decrypt STOP (DJVU) Ransomware unless the encryption occurred before the 29th of August 2019.**That means there is **no way to decrypt files** with **Online-ID and some recent forms of STOP (DJVU)**. However, victims should at least keep trying the [**Emsisoft Decryptor**](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com") if infected with an OFFLINE KEY.

I**MPORTANT UPDATE: June 6, 2020**

*Beware of fake STOP ransomware decryptor.*

**Fake ransomware decryptor double-encrypts desperate victims' files**  
[https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/](https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/ "www.bleepingcomputer.com")

*A fake decryptor for the STOP Djvu Ransomware is being distributed that lures already desperate people with the promise of free decryption. Instead of getting their files back for free, they are infected with another ransomware that makes their situation even worse.*

**Moderator note: This thread has been pinned as a resource for updates on STOP ransomware and direction for assistance.**

**The following general advice provided by** **quietman7 - MVP**

*Please read the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the*  ***STOP (DJVU) Ransomware Support Topic*** *for an updated summary of this ransomware, it's variants and****possible decryption solutions*** *with instructions.*  

*The decrypter will only attempt to decrypt a file with a known ID (either the hardcoded one or one you provide with a key....any others will be reported and logged, with instructions to archive it in hopes of future decryption.*

*There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.*  ***All support for the STOPDecrypter decryption tool is provided in the below topic****.*

- [*STOP Ransomware (.STOP, .SUSPENDED - !!! YourDataRestore !!! txt)   Support Topic*](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com")

[*https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935*](https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935 "answers.microsoft.com")  

**If you have a different ransomware issue (eg. Grandcrab) please search this forum (Virus & Malware) for similar recent threads or start your own "new thread".**

**IMPORTANT UPDATE:19/10/2019**

*Per the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the* ***STOP (DJVU) Ransomware Support Topic****.*

***STOPDecrypter is no longer supported, has been discontinued AND replaced with the*** [***Emsisoft Decryptor for STOP Djvu Ransomware***](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com")***.*** 

*Be sure to read all the updated information on the first page and please* ***do not****use STOPDecrypter (or decrypter\_2.exe) any more.* ***Going forward, everyone should be using the Emsisoft Decrypter.***

- [*How to use the Emsisoft Decryptorfor STOP Djvu*](https://www.emsisoft.com/ransomware-decryption-tools/howtos/emsisoft_howto_stopdjvu.pdf "www.emsisoft.com")
- [*How to decrypt STOP Djvu Ransomware encrypted files*](https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/ "www.bleepingcomputer.com")

*<Pinned until August 1, 2024>*
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

992 answers

Sort by: Most helpful
  1. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-11-08T14:52:54+00:00

    La extensión .lokf es la variante más nueva y no se puede descifrar sin pagar el rescate y obtener las claves privadas de los delincuentes que crearon el ransomware a menos que las autoridades lo filtren, confisquen y liberen después de realizar un arresto.

    .

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-11-04T03:20:20+00:00

    New variant reported with .meka extension.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-09-20T21:14:16+00:00

    The criminals have made changes and started using proper asymmetrical encryption in newer STOP versions beginning with .coharos, .gero, .hese, .geno, .seto, .peta, .meds, .moka, .kvag, .domm, etc. Unfortunately, these new versions are not decryptable without paying the ransom and obtaining the private keys from the criminals who created the ransomware.

    This means...There no longer is any method to get OFFLINE KEYS for many of these newer variants and no way to decrypt files if infected with an ONLINE KEY without paying the ransom and obtaining the private keys from the criminals who created the ransomware. However, experts are working on ways to obtain OFFLINE KEYS and if they are able to do so, that information will be provided in the support topic

    Emmanuel_ADC-Soft, a Support Service Manager for ADC-Soft and partner with Dr.Web has indicated the .gero, .hese, .meds, .moka, .kvag, .peta variants can be decrypted if they were encrypted with an OFFLINE KEY. See Post #7561 and Post #7612 for instructions.

    .

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-09-06T00:22:35+00:00

    New variant reported with .moka extension.

    .

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-09-03T18:42:39+00:00

    Please read the first page of the STOP (DJVU) Ransomware Support Topic for an updated summary of this ransomware, it's variants and possible decryption solutions with instructions. If there is no OFFLINE KEY available for the variant you are dealing with OR it is one of the newer variants, then we cannot help you at this time since there is no way to gain access to the criminal's command server and reproduce or retrieve these KEYs.

    .

    All support for the STOPDecrypter decryption tool is provided in that topic, not here.

    .

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments