Share via

.VYIA files Ransomware Attack Variant

Anonymous
2022-03-10T14:53:57+00:00

So, basically I downloaded a virus, and most of my files became .VYIA files. I tried OneDrive backup, but it also backups the .VYIA files. I don't know how to access the previous things that I saved. Neither does version history help. I can't do anything at this point. It's been 24+ hours since the threat came. Fortunately, hackers aren't able to access my computer as I deleted the files immediately. Problem is, I need to recover my files.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

13 answers

Sort by: Most helpful
  1. quietman7 MVP Alumni 19,735 Reputation points Volunteer Moderator
    2022-03-10T16:10:14+00:00

    You are dealing with a newer variant of STOP (Djvu) Ransomware as explained here by Amigo-A (Andrew Ivanov). Since switching to the new STOP Djvu variants (and the release of .gero) the malware developers have been consistent on using 4-letter extensions.
     
    The .djvu* and newer variants will leave ransom notes named _openme.txtopen.txt or _readme.txt
     
    Please read the first page (Post #1) of the STOP (Djvu) Ransomware Help & Support Topic  AND these FAQs for a summary of this infection, it's variants, any updates and possible decryption solutionsusing the Emsisoft Decryptor.

    In regards to new variants of STOP (Djvu) Ransomware...decryption of data requires an OFFLINE ID with corresponding private key. Emsisoft can only get a private key for OFFLINE IDs AFTER a victim has PAID the ransom, receives a key and provides it to them.
     
    If infected with an ONLINE KEY, decryption is impossible without the victim’s specific private key. ONLINE KEYS are unique for each victim and randomly generated in a secure manner with unbreakable encryption. Emsisoft cannot help decrypt files encrypted with the ONLINE KEY due to the type of encryption used by the criminals and the fact that there is no way to gain access to the criminal's command server and retrieve this KEY. ONLINE ID's for new STOP (Djvu) variants are not supported by the Emsisoft Decryptor

    .

    The Emsisoft Decryptor will also tell you if your files are decryptable, whether you're dealing with an "old" or "new" variant of STOP/Djvu, and whether your ID is ONLINE or OFFLINE.

    Emsisoft has obtained and uploaded to their server OFFLINE IDs for many (but not all) of the new STOP (Djvu) variantsas noted in Post #9297 and elsewhere in the support topic.

    ** If there is no OFFLINE ID for the variant you are dealing with, we cannot help you unless a private key is retrieved and provided toEmsisoft. When and if the private key for any new variant is obtained it will be pushed to the Emsisoft server and automatically added to the decryptor. Thereafter, any files encrypted by the OFFLINE KEY for that variant can be recovered using the Emsisoft Decryptor. For now, the only other alternative to paying the ransom, is to backup/save your encrypted data as is and wait for possible future recovery of a private key for an OFFLINE ID.

    There is no timetable for when or if a private key for an OFFLINE ID will be recovered and shared with Emsisoft and no announcement by Emsisoft when they are recovered due to victim confidentiality. That means victims should keep reading the support topic for updates or run the decryptor on a test sample of encrypted files every week or two to check if Emsisoft has been able to obtain and add the private key for the specific variant which encrypted your data.

    ** If an OFFLINE ID is available for the variant you are dealing with and your files were not decrypted by Emsisoft Decryptor, then you most likely were encrypted by an ONLINE KEY and those files are not recoverable (cannot be decrypted) unless you pay the ransom to the criminals and receive the private key. If infected with an ONLINE ID, the Emsisoft Decryptor will indicate this fact under the Results Tab and note the variant is impossible to decrypt.

    .

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-03-11T01:38:35+00:00

    I cannot run a scan. The newer variant has taken down the ability for scanning and removing it.

    0 comments No comments
  3. Reza-Ameri 45,806 Reputation points Volunteer Moderator
    2022-03-10T16:34:20+00:00

    Try run scan with Microsoft Defender Offline, take a look at Help protect my PC with Microsoft Defender Offline.

    Do you have a sample of the infected file?

    If yes, you may submit sample to Submit a file for malware analysis - Microsoft Security Intelligence.

    0 comments No comments
  4. DaveM121 868.4K Reputation points Independent Advisor
    2022-03-10T15:27:42+00:00

    Hi Shahmir,

    I am Dave, I will help you with this, I am sorry to say, you are the victim of a STOP/DJVU Ransomware attack.

    1

    If you log into OneDrive online, are the original versions of your files still stored there?

    https://onedrive.live.com/

    2

    The only way to get your files back is with the use of a decrypter

    3

    Please Note ransomware decryptors are always made available for free, do not get caught by websites that will claim to be able to decrypt you files, if you purchase their software - that is a scam.

    Full details can be found on the link below

    https://support.emsisoft.com/topic/32045-about-...

    And also this thread on Community is kept up to date with any news on the STOP/DJVU ransomware:

    https://answers.microsoft.com/en-us/protect/for...

    ________________________________________________________

    Standard Disclaimer: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    0 comments No comments
  5. Anonymous
    2022-03-10T14:56:01+00:00

    Also, I can't do scans. They don't work.

    0 comments No comments