Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2022

How to remove Jjll ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

Jjll file virus can control other threats and cause damage to system features and programs

Jjll ransomware virus can trigger other processes to keep the active virus running and machines further affected. The infection does not show symptoms when the machine is infiltrated, but data gets locked and marked with .jjll at the end of encryption.[1] The virus can be carried in a variety of ways, including through torrents and pirating sites. When the machine is infected, and main processes are done the ransom note _readme.txt appears on the system, so ransom is demanded.

Additional speed and performance issues may arise due to background tasks triggered by the Jjll file virus. However, these problems often get masked as fake Windows Update pop-up alerts and other messages about not related procedures or programs. These threats that are focused on money gains are developed by cybercriminals with one goal – getting money.

Lies of the cryptocurrency extortionists

The _readme.txt file is focused on asking for direct cryptocurrency payments and listing fake claims about the discount and the possibility to recover files via test decryption. Do not fall for these promises. Jjll ransomware virus creators offer to contact them in order to get further instructions, which might be something like an access code or unlocking key, but this can lead to further issues and even malware infections.

They offer a 50% discount on their decryption tool if you pay them in advance, but there's no guarantee that it will work. Criminals also make false claims about how long this process takes. Jjll file virus is a nasty piece of malware that can lurk on your computer undetected for days or weeks before it's finally discovered. Once infected, you may not know about this, but the damage is already done when the ransom note is provided. 

The experts[2] recommend against paying up – any contact with these criminals could lead only to more issues instead of full file recovery as promised by creators. Especially based on the fact that this is not a new threat but an infection spreading since 2018 and has been reported in many countries.

Name Jjll ransomware
Type Cryptovirus, file locker
File extension .jjll
Distribution Torrent platforms, pirating services, malicious email attachments, other threats
Ransom note _readme.txt
Ransom amount $490/ $980
Contact emails support@bestyourmail.ch, supportsys@airmail.cc
Family Djvu ransomware
Removal Virus removal tools are anti-malware and these apps can terminate the ransomware
Repair Rely on FortectIntego that can fix issues with the system damage or virus leftovers

You might be able to restore your data if you have copies on external storage that cannot get damaged, but it will cost money and time. The official Jjll ransomware virus decryption tool does not exist, so rely on alternate methods that we have listed and make sure to remove the infection properly.

Removing the infection

Jjll ransomware is the latest version of the Djvu ransomware virus. It can be a more advanced version than previous ones. In fact, there are some similarities between them, such as demands for ransom payments in Bitcoin with particular sums and even identical contents on the notes that haven't changed much at all over time. Contact emails are often used for many versions too.

There is no guarantee Jjll file virus developers or any other researcher will provide the needed decryption tool. Do not fall for these claims or any other offers online. The only way to get your data back is by uninstalling the virus. There are no other options available for direct file restoration, however.

This will be necessary if you want a safe system that can receive copies of affected files and avoid another encryption round from happening again in the future. Rely on detection tools that can find and terminate this infection fully. Running a system scan will indicate all potential problems and remove any malware that is present.

You should rely on powerful tools and programs that can find infection and other possibly damaging files o the machine. SpyHunterCombo Cleaner or MalwarebytesMalwarebytes can run the check various parts of the system and remove viruses like this Jjll ransomware or additional and related malware, trojans, and malicious files.

Restoring the performance

Once a computer is infected with malware, its system is changed to operate differently. For example, an infection can alter the Windows registry database, damage vital bootup, and other sections, delete or corrupt DLL files, etc. Once a system file is damaged by malware, antivirus software is not capable of doing anything about it, leaving it just the way it is.

Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.

  • Download the application by clicking on the link above
  • Click on the ReimageRepair.exe
    Reimage download
  • If User Account Control (UAC) shows up, select Yes
  • Press Install and wait till the program finishes the installation processReimage installation
  • The analysis of your machine will begin immediately
  • Once complete, check the results – they will be listed in the Summary
  • You can now click on each of the issues and fix them manually
  • If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.Reimage results

Restoring files after the infection: decryption

Jjll ransomware virus is a tricky type of infection that uses strong encryption algorithms, making locked files useless. It's very difficult for people without technical knowledge to decode these encrypted pieces, and they can't be deciphered with just any key. However, it depends on what method was used during their creation- some might have an easier time.

There are two types of keys that can help recover your files after Jjll ransomware: offline and online. Offline keys ensure universal restoration for all victims, but they're not always used. Online keys are unique for specific devices, so are not easily obtained. Threat actors are financially motivated[3] and do not plan to release decryption keys anytime soon.

When the ransomware cannot connect to its command and control servers while encrypting your files, it uses a built-in encryption key -offline ID. These offline keys generally end in t1 and are usually easily identified as they change only with each variant/extension. This means that some of the Jjll ransomware victims can recover their files using the existing tool.

If your computer got infected with one of the Djvu variants, you should try using Emsisoft decryptor for Djvu/STOP. It is important to mention that this tool will not work for everyone – it only works if data was locked with an offline ID due to malware failing to communicate with its remote servers.

Even if your case meets this condition, somebody from the victims has to pay criminals, retrieve an offline key, and then share it with security researchers at Emsisoft. As a result, you might not be able to restore the encrypted files immediately. Thus, if the decryptor says your data was locked with an offline ID but cannot be recovered currently, you should try later. You also need to upload a set of files – one encrypted and a healthy one to the company's servers before you proceed.

  • Download the app from the official Emsisoft website.
  • After pressing Download button, a small pop-up at the bottom, titled decrypt_STOPDjvu.exe should show up – click it.
  • If User Account Control (UAC) message shows up, press Yes.
  • Agree to License Terms by pressing Yes.

  • After Disclaimer shows up, press OK.
  • The tool should automatically populate the affected folders, although you can also do it by pressing Add folder at the bottom.
  • Press Decrypt.

From here, there are three available outcomes:

  1. Decrypted!” will be shown under files that were decrypted successfully – they are now usable again.
  2. Error: Unable to decrypt file with ID:” means that the keys for this version of the virus have not yet been retrieved, so you should try later.
  3. This ID appears to be an online ID, decryption is impossible” – you are unable to decrypt files with this tool.

Jjll ransomware virus is best removed with applications like SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, FortectIntego because these are tools that can find all files related to malicious activities, and this way, infection is properly terminated. You need to clear the machine before anything else can be done to recover data.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.