Dear my PC is protected now as I've scanned all my drives with Microsoft Security Essentials & malwarebytes anti-virus several times, all the viruses has been removed already, but I'm looking for any decrypter to open my encrypted files. I've number of files in various formats but non of them is accessible.
STOP Ransomware
My all files encrypted to .DJVUS extension ( I'm want my files back) please help me out for this regards..???
**IMPORTANT UPDATE: March 14, 2024**
**StopCrypt: Most widely distributed ransomware now evades detection** [**https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/**](https://www.bleepingcomputer.com/news/security/stopcrypt-most-widely-distributed-ransomware-now-evades-detection/ "www.bleepingcomputer.com")
**IMPORTANT UPDATE: April 12, 2022**
**According to information previously provided on the Emsisoft Forum, they no longer have any method to decrypt STOP (DJVU) Ransomware unless the encryption occurred before the 29th of August 2019.**That means there is **no way to decrypt files** with **Online-ID and some recent forms of STOP (DJVU)**. However, victims should at least keep trying the [**Emsisoft Decryptor**](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com") if infected with an OFFLINE KEY.
I**MPORTANT UPDATE: June 6, 2020**
*Beware of fake STOP ransomware decryptor.*
**Fake ransomware decryptor double-encrypts desperate victims' files**
[https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/](https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/ "www.bleepingcomputer.com")
*A fake decryptor for the STOP Djvu Ransomware is being distributed that lures already desperate people with the promise of free decryption. Instead of getting their files back for free, they are infected with another ransomware that makes their situation even worse.*
**Moderator note: This thread has been pinned as a resource for updates on STOP ransomware and direction for assistance.**
**The following general advice provided by** **quietman7 - MVP**
*Please read the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the* ***STOP (DJVU) Ransomware Support Topic*** *for an updated summary of this ransomware, it's variants and****possible decryption solutions*** *with instructions.*
*The decrypter will only attempt to decrypt a file with a known ID (either the hardcoded one or one you provide with a key....any others will be reported and logged, with instructions to archive it in hopes of future decryption.*
*There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.* ***All support for the STOPDecrypter decryption tool is provided in the below topic****.*
- [*STOP Ransomware (.STOP, .SUSPENDED - !!! YourDataRestore !!! txt) Support Topic*](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com")
[*https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935*](https://answers.microsoft.com/message/eaff7029-b288-4da7-8a05-fba9c76cf13e?threadId=bdab87f9-ba8f-4928-bf72-159d42dcb935 "answers.microsoft.com")
**If you have a different ransomware issue (eg. Grandcrab) please search this forum (Virus & Malware) for similar recent threads or start your own "new thread".**
**IMPORTANT UPDATE:19/10/2019**
*Per the* [***first page***](https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic/ "www.bleepingcomputer.com") *of the* ***STOP (DJVU) Ransomware Support Topic****.*
***STOPDecrypter is no longer supported, has been discontinued AND replaced with the*** [***Emsisoft Decryptor for STOP Djvu Ransomware***](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu "www.emsisoft.com")***.***
*Be sure to read all the updated information on the first page and please* ***do not****use STOPDecrypter (or decrypter\_2.exe) any more.* ***Going forward, everyone should be using the Emsisoft Decrypter.***
- [*How to use the Emsisoft Decryptorfor STOP Djvu*](https://www.emsisoft.com/ransomware-decryption-tools/howtos/emsisoft_howto_stopdjvu.pdf "www.emsisoft.com")
- [*How to decrypt STOP Djvu Ransomware encrypted files*](https://www.bleepingcomputer.com/news/security/stop-ransomware-decryptor-released-for-148-variants/ "www.bleepingcomputer.com")
*<Pinned until August 1, 2024>*
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
992 answers
Sort by: Most helpful
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Deleted
This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Comments have been turned off. Learn more
-
Anonymous
2019-01-06T13:32:06+00:00 -
quietman7 MVP Alumni 19,665 Reputation points Volunteer Moderator2019-01-06T13:48:19+00:00 All .djvu* variants (.djvuu, .udjvu, .djvuq, .uudjvu, .djvus, .djvur, .djvut, .djvup, .djuvq) plus .pdff, .tro, .tfude, .tfudeq, .tfudet, .rumba, .adobe,.adobee and**.blower** extensions are all newer variants of STOP (DJVU) Ransomware which will leave a ransom note named _openme.txt or _readme.txt as explained here.
Dr.Web is able to decrypt some variants of STOP Ransomware (i.e. .DATAWAIT, .INFOWAIT). Unfortunately, Dr.Web cannot decrypt other STOP Ransomware variants at this time...see here
.
Demonslay335 (aka Michael Gillespie) released a free decryption tool (STOPDecrypter) for victims of the .puma, .pumas and .pumax variants. The decrypter includes a BruteForcer only for .puma based variants which use XOR encryption, a simple symmetric cipher that is relatively easy to break. The decrypter tool requires victims to provide an encrypted and original file pair greater than 150KB.
The newer variants are not decryptable at this time without paying the ransom and obtaining the private key from the criminals who created the ransomware unless it is leaked or seized & released by authorities. Without the master private RSA key that can be used to decrypt your files, decryption is impossible. If feasible, your best option is to restore from backups, try file recovery software or backup/save your encrypted data as is and wait for a possible solution at a later time. Ignore all Google searches which provide links to bogus and untrustworthy removal/decryption guides.
There is an ongoing discussion in this topic where victims can post comments, ask questions and seek further assistance. Other victims have been directed there to share information, experiences and suggestions.
When or if a decryption solution is found, that information will be provided in the above support topic and victims will receive notification if subscribed to it. In addition, a news article most likely will be posted on the Bleeping Computer front page. Amigo-A (Andrew Ivanov) will also update the applicable Coders Crypto-Ransomware Information page.
-
quietman7 MVP Alumni 19,665 Reputation points Volunteer Moderator2019-01-21T20:58:04+00:00 Update 01/17/19:
STOPDecrypter v2.0.0.0 has been updated to include decryption support for the .djvu* variants (.djvu, .djvuu, .udjvu, .djvuq, .djvur, .djvut, .pdff, .tro, .tfude, .tfudeq, .tfudet). A list of all supported extensions is provided in the About section . STOPDecrypter will also check the filemarker at the end of files so it can support future extensions...the criminals have been releasing new variants almost on a daily basis. More information can be found in Post #305.
--Note: The decrypter will be able to decrypt your files if your personal ID is 6se9RaIxXF9m70zWmx7nL3bVRp691w4SNY8UCir0 (supports the OFFLINE KEY used if the malware failed to get a key from its server or if you have been provided a key). If the decrypter skips your files and your personal ID is different than the one above, then we will not be able to help you at this time. If you were provided a key by kNN or Demonslay335, enter it via the Settings -> Set Djvu Key option. Be careful...entering anything incorrectly will destroy data.
Update 01/21/19:
STOPDecrypter v2.0.1.0.has been updated to include support for the .rumba variant and the new encrypted file format if you were hit by the OFFLINE KEY as explained in Post #451. As of now there is a new OFFLINE KEY embedded in the decrypter tool along with the previous key.
--Note: The decrypter will be able to decrypt your files if your personal ID is D02NfEP94dKUO3faH1jwqqo5f9uqRw2Etn2lP3VB. If the decrypter skips your files and your personal ID is different than the one above, then we will not be able to help you at this time.