Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jul 2022

How to remove Jjyy ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Jjyy file virus is the tool used by financially motivated criminals

Jjyy ransomware

Jjyy virus is a dangerous and malicious threat because it can affect documents, images, and video files. This infection focuses on common files as targets directly, so the ransom note will appear on your desktop with instructions for paying. Criminals demand $490 worth of Bitcoin right away, or else people are allegedly risking losing personal information. If someone pays this much money within 72 hours after encryption, they'll get their data back completely free. However, if not the ransom doubles.

The recent increase in ransomware attacks[1] is concerning, but it's not just criminals that are to blame. People don't want the hassle of dealing with something like malware on their own servers or computers but precautionary measures are not taken. These threats like Jjyy ransomware can spread when users install licensed software cracks and game cheats from torrent pages.

These virus creators are not just focused on getting your data back but only on their own financial gain. They will send you emails and place threatening messages everywhere, telling you how much they want or what'll happen if payment isn't made immediately. Do not pay!

Contacting them can also be very dangerous, so stay away from these cyber-criminals as much as possible by clearing out any infections and possibly malicious files. We list possible methods and alternate options since Jjyy ransomware virus decryption officially is not possible at this point.

Name Jjyy file virus
Type Ransomware, cryptovirus
File extension .jjyy
Distribution Torrent platforms, pirating services, malicious email attachments
Ransom note _readme.txt
Ransom amount $490/ $980
Contact emails support@bestyourmail.ch, supportsys@airmail.cc
Family Djvu ransomware
Removal Virus removal tools are anti-malware and these apps can terminate the ransomware
Repair Rely on FortectIntego that can fix issues with the system damage

Removing the infection

The Jjyy ransomware virus is a financially motivated program that can trigger other issues with the machine. The criminals behind this infection will do anything they think it takes to steal your information and money from you, so avoid contact at all costs! Remove any files affected by these harmful programs as soon as possible before the damage becomes irreversible.

Cybercriminals are always up to no good and trying their best not only in scaring the living daylights out of you but also with hacking your computer system. They usually carry back doors for future use, which means that if one version dies down – another takes its place soon after.

Never trust criminals; don't pay them off either because they will just come back again looking even worse than before. The cybersecurity experts[2] have been working hard on deciphering these threats, but the recent improvements in code keep decryption options limited. You need to remove Jjyy ransomware asap, nevertheless.

Jjyy file virus

The developers of this malware encourage you to contact them so they can scare more victims into giving up their money by using threatening language such as “If ignored,” or claiming that your computer will be taken over if not paid off quickly enough. You should run anti-malware tools as soon as those files get locked. These apps are capable of detecting[3] these backdoors and ransomware files easily.

Jjyy virus discount offers are tempting but do not fall for them. It's easy to fake these types of test decryption that might send you a copy-and-paste safe file they extracted from the computer. The encrypted file recovery is not easy, so remove the threat with SpyHunterCombo Cleaner or MalwarebytesMalwarebytes first, and then look for alternate solutions.

Repair system data that got damaged

Jjyy ransomware can damage the machine, and removing it is not enough. Once a system file is damaged by malware, antivirus software is not capable of doing anything about it, leaving it just the way it is. Consequently, users might experience performance, stability, and usability issues, to the point where a full Windows reinstall is required.

Therefore, we highly recommend using a one-of-a-kind, patented technology of FortectIntego repair. Not only can it fix virus damage after the infection, but it is also capable of removing malware that has already broken into the system thanks to several engines used by the program. Besides, the application is also capable of fixing various Windows-related issues that are not caused by malware infections, for example, Blue Screen errors, freezes, registry errors, damaged DLLs, etc.

  • Download the application by clicking on the link above
  • Click on the ReimageRepair.exe
    Reimage download
  • If User Account Control (UAC) shows up, select Yes
  • Press Install and wait till the program finishes the installation processReimage installation
  • The analysis of your machine will begin immediatelyReimage scan
  • Once complete, check the results – they will be listed in the Summary
  • You can now click on each of the issues and fix them manually
  • If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

More about the .jjyy file virus

This is a new virus that can find data with certain file extensions and marks them using unique code. After the encryption process, the virus creates reasons behind direct money extortion by giving discounts for the ransom and offering fake test decryption. The _readme.txt file is filled with lies and false claims. The text presented via this ransom note:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-OIgf49CYf3
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
support@bestyourmail.ch

Reserve e-mail address to contact us:
supportsys@airmail.cc

Your personal ID:

The Jjyy ransomware belongs to a family of dangerous threats. The latest version of the Djvu ransomware virus is now in circulation. These new strains have been improved, and new versions get released weekly, at least. These versions are not much changed from previous variants, and all are not decryptable. The ransom note is the same, and contact emails are not frequently renewed, the text that demands money is the same for at least three years already.

Decryption possibility

Jjyy file virus is using the online IDs during the encryption process, so the decryption is not easy or even impossible. There were cases where offline keys got used that are unique for a version but can be used for many victims. If that is the case with the infection of your device, you might have the option of decryption. Check it with the following tool.

If your computer got infected with one of the Djvu variants, you should try using Emsisoft decryptor for Djvu/STOP. It is important to mention that this tool will not work for everyone – it only works if data was locked with an offline ID due to malware failing to communicate with its remote servers.

Even if your case meets this condition, somebody from the victims has to pay criminals, retrieve an offline key, and then share it with security researchers at Emsisoft. As a result, you might not be able to restore the encrypted files immediately. Thus, if the decryptor says your data was locked with an offline ID but cannot be recovered currently, you should try later. You also need to upload a set of files – one encrypted and a healthy one to the company's servers before you proceed.

  • Download the app from the official Emsisoft website.
  • After pressing Download button, a small pop-up at the bottom, titled decrypt_STOPDjvu.exe should show up – click it.
  • If User Account Control (UAC) message shows up, press Yes.
  • Agree to License Terms by pressing Yes.

  • After Disclaimer shows up, press OK.
  • The tool should automatically populate the affected folders, although you can also do it by pressing Add folder at the bottom.
  • Press Decrypt.

From here, there are three available outcomes:

  1. Decrypted!” will be shown under files that were decrypted successfully – they are now usable again.
  2. Error: Unable to decrypt file with ID:” means that the keys for this version of the virus have not yet been retrieved, so you should try later.
  3. This ID appears to be an online ID, decryption is impossible” – you are unable to decrypt files with this tool.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.