Virus .udjvu

Anonymous
2018-12-23T10:14:35+00:00

Yesterday I was using my computer normally then suddenly a popup showed telling me that there was updates installing and I knew that it's not from Microsoft  as when I opened the source from task manger I found that it's not related to Microsoft updates so I click on end task then I tried to open Windows defender but it showed this message " page not available Your IT administrator as limited access to some areas of this app, and the item you tried to access is not available. Contact IT helpdesk for more information. Then I found that a program called windows powershell is installed by itself .. Then the screen blacked out showing only this message when I tried to open Task manger " Task manger has been disabled by your administrator" 

SO I tried to restart the my computer but couldn't open start...after managing to restart by pressing the  power button for awhile to restore windows from a restore points , there was three but all failed and also repair failed so click on reset my computer but keep my files ..when it finished I found all my files "pictures , programs , pdfs, doxc, " all of it ended with this extension

.udjvu

like in the picture attached 

So How can I get my files back and open them?

"when I tried to use snap tool I didn't find it"

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

52 answers

Sort by: Newest
  1. Anonymous
    2019-01-17T11:25:37+00:00

    QUOTE

    A few notes. This decrypter currently only works for personal ID 6se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0 (the offline key used if the malware failed to get a key from its server), or if you have the key.

    UNQUOTE

    Make sure to read the entire post!

    https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/page-21#entry4667165

    Further questions best posted in above bleepingcomputer.com thread.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-01-17T10:35:44+00:00

    I tried to run the STOPDecrypter but it says no key found, When I try to enter my key that is in this ransom note:

    "

    Your personal ID:

    01754VJYnWSx4hqnQ2EkpQmM5xvO7HUDa6IkSTT5xuW

     ""

    the STOPDecrypter asks for password...

    what should I enter there ???

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2019-01-17T08:47:55+00:00

    The STOPDecrypter 2.0.0.0 for the .djvu* variants has been updated to support the following extentions: djvu, .djvuq, .djvur, .djvut, .djvuu, .pdff, .tfude, .tfudeq, .tro, .udjvu, .tfudet.

    STOP ransomware (.STOP, .SUSPENDED - !!! YourDataRestore !!! txt) Support Topic

    https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/?p=4667165

    ~bhringer

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-01-16T20:18:22+00:00

    We have learned that the infection only encrypts the first 0x25800 bytes of the file so the rest of the file is decrypted and recoverable.

    Another update from Demonslay335 (aka Michael Gillespie)

    QUOTE

    "Currently, if your ransom note has the "personal ID" ending with 6se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0, we will be able to help soon. This ID is also present at the end of the encrypted files (open with a hex editor or notepad, it's the last 40 characters of the file before the "{36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}").

    If your personal ID is different than the above, then we will not be able to help you currently. In that case, it is best to archive your encrypted files, and take note of the MAC address of the infected machine. You may send this info to kNN or myself for archiving should a solution arise in the future.

    I have updated ID Ransomware to identify if you have a decryptable ID when an encrypted file is uploaded, and it will tell you explicitly if so. So if you are unsure about checking the personal ID, you can just upload an encrypted file to the site and it will be able to tell."

    Was this answer helpful?

    0 comments No comments
  5. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2019-01-14T18:22:23+00:00

    Update: Demonslay335 (aka Michael Gillespie), a ransomware researcher/analyst with the MalwareHunterTeam, advises victims of the newer .djvu, .djvuu, .udjvu, .djvuq, .uudjvu, .djvus, .djvur, .djvut, .djvup, .djuvq,.pdff, .tro and .tfude STOP Ransomware variants to send their ransom note, personal ID found in the ransom note, MAC address and an encrypted and original file pair to member kNN for possible future decryption of their data (see here). Victims need to follow these instructions when sending messages to kNN...be aware that time is an important factor and this is not a guarantee of decryption. You can use a third-party sharing site (Google Drive, OneDrive, DropBox SendSpace, Mega, etc.) to send the file pair and provide a link in your PM.

    .

    QUOTE by kNN

    "Send only what is neccesary and send it as soon as possible. A lot of you won't be able to decrypt your files because the time has passed and there is no way to recover the encryption key. Time is VERY important.

    Was this answer helpful?

    0 comments No comments