Infected with Java Ransomware? Need to decrypt your files?

What is Java Ransomware

Java Ransomware is crypto-virus, that belongs to Crysis/Dharma family and appends following extensions to affected files:

.id-{id}.[gettkey@qq.com].java, .id-{id}.{mazma@india.com}.java, .id-{id}.{decrypthelp@qq.com}.java, .id-{id}.{faremar@cock.li}.java, .id-{id}.[black.mirror@qq.com].java, .id-{id}.[stopstorage@qq.com].java, .id-{id}.[btc2018@qq.com].java, .id-{id}.[bacon@oddwallps.com].java, .id-{id}.[sabantui@tutanota.com].java.

This ransomware uses AES asymmetric cryptography algorithm. After successful encryption, Java Ransomware creates text file README.TXT and opens windows with following content:

All your files have been encrypted!
All your files have been encrypted due to a security problem with your PC. If you want to restore them, write us to the e-mail sabantui@tutanota.com
Write this ID in the title of your message B8F053EC
In case of no answer in 24 hours write us to theese e-mails:udacha@cock.li
You have to pay for decryption in Bitcoins. The price depends on how fast you write to us. After payment we will send you the decryption tool that will decrypt all your files.
Free decryption as guarantee
Before paying you can send us up to 5 files for free decryption. The total size of files must be less than 10Mb (non archived), and files should not contain valuable information. (databases,backups, large excel sheets, etc.)
How to obtain Bitcoins
The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click 'Buy bitcoins', and select the seller by payment method and price.
https://localbitcoins.com/buy_bitcoins
Also you can find other places to buy Bitcoins and beginners guide here:
http://www.coindesk.com/information/how-can-i-buy-bitcoins/
Attention!
Do not rename encrypted files.
Do not try to decrypt your data using third party software, it may cause permanent data loss.
Decryption of your files with the help of third parties may cause increased price (they add their fee to our) or you can become a victim of a scam.

Malware demands ransom from $500-$1000 in Bitcoins. Java Ransomware targets most important user data, which makes it effective for malefactors. These are MS Office documents, OpenOffice, PDF, text files, databases, photos, music, videos, image files, archives, web page files and other web files, educational, application and specialized files, and other files. Currently, files infected or encoded by this threat are non-decryptable, but there are certain methods to restore .java files manually. Follow instructions below to remove Java Ransomware completely from Windows 10, 8, 7 and decrypt your files.

Java Ransomware

.java extension infected files

Update: Use following service to identify the version and type of ransomware you were attacked by: ID Ransomware. Also check following website for possible decryptor: Emsisoft Decryptors.

How Java Ransomware infected your PC

.java ransomweare distribution

At this moment, we know that several e-mails are used to distribute .docx files with malicious macroses. E-mails are distributed all over the world. You can also get this ransomware on file-sharing networks, including torrent files. Ransom is asked to be paid in BitCoins, that also makes the task difficult for the police, as the user in this network is often anonymous. Encryption starts in the background. Way to protect your computer from such threats is to use antiviruses with crypto-protection like HitmanPro.Alert with CryptoGuard.

First of all, don’t panic. Follow these easy steps below.

1. Start your computer in Safe Mode with networking. To do that, restart your computer before your system starts hit F8 several times. This will stop system from loading and will show Advanced boot options screen. Choose Safe mode with networking option from the options list using up and down arrows on your keyboard and hit Enter.
2. Log in to the system infected with the Java Ransomware virus. Launch your Internet browser and download a reliable anti-malware program and start a full system scan. Once the scan is complete, review scan results and remove all entries detected.

Recommended Solution:

Norton is a powerful removal tool. It can remove all instances of newest viruses, similar to Java Ransomware – files, folders, registry keys.

 

Download Norton*Trial version of Norton provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Norton.

Step 2: Remove following files and folders of Java Ransomware:

Remove following registry entries:

no information

Remove following files and folders:

no information

How to decrypt files infected by Java Ransomware (.java files)?

Use automated decryption tools

kaspersky rakhni decryptor for Java Ransomware

There is ransomware decryptor from Kaspersky that can decrypt .java files. It is free and may help you restore .java files encrypted by Java Ransomware virus. Download it here:

Download Kaspersky RakhniDecryptor

You can also try to use manual methods to restore and decrypt .java files.

Decrypt .java files manually

Restore the system using System Restore

system restore

Although latest versions of Java Ransomware remove system restore files, this method may help you partially restore your files. Give it a try and use standard System Restore to revive your data.

  1. Initiate the search for ‘system restore
  2. Click on the result
  3. Choose the date before the infection appearance
  4. Follow the on-screen instructions

Roll the files back to the previous version

Previous versions can be copies of files and folders created by Windows Backup (if it is active) or copies of files and folders created by System Restore. You can use this feature to restore files and folders that you accidentally modified or deleted, or that were damaged (in our case – Java Ransomware by Java Ransomware). This feature is available in Windows 7 and later versions.

windows previous versions

  1. Right-click the file and choose Properties
  2. Open the Previous Version tab
  3. Select the latest version and click Copy
  4. Click Restore

Restore .java files using shadow copies

shadow explorer gui

  1. Download and run Shadow Explorer.
  2. Select the drive and folder where your files are located and date that you want to restore them from.
  3. Right-click on folder you want to restore and select Export.
  4. Once the scanning process is done, click Recover to restore your files.

Protect your computer from ransomware

hitmanpro alert with cryptoguard

Most modern antiviruses can protect your PC from ransomware and crypto-trojans, but thousands of people still get infected. There are several programs that use different approach t protect from ransomware and lockers. One of the best is HitmanPro.Alert with CryptoGuard. You may already know HitmanPro as famous cloud-based anti-malware scanner. Check out ultimate active protection software from SurfRight.

Download HitmanPro.Alert with CryptoGuard

Information provided by: Alexey Abalmasov

6 Comments

  1. Bonjour
    mon ordinateur a ete endommage. tous les extension des fichier a transfermer en .id-EA523F6A.[decrypthelp@qq.com].java j’ai essyer tous les solutations de decryptages des fichier . mais aucune resultat
    s’il vous plais est c qel ya des autres solutions par ce que jai perdus des fichiers tres important

  2. We have the Dharma/Crisis .java ransom on one of our SBS 2008 R2 servers and the backup HD. What procedure (Since we cannot log to this server from a station in Safe mode/networking should we use?

Leave a Reply

Your email address will not be published. Required fields are marked *