Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Aug 2021

How to remove Lisp ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

Lisp ransomware is the threat that encourages people to pay up within 72 hours with the 50% discount

Lisp ransomware

Lisp ransomware encrypts all non-system data after gaining entry to a computer and then asks for a ransom to unlock the files. This virus works like all ransomware before it. It has two phases – renaming all files by appending an extension and encrypting[1] them, and ransom note generation and placement.

Lisp ransomware virus derives from the ever-growing Djvu family, which consists of more than 260 viruses so far (Sglh, Epor, Agho, to name just a few). First versions were spotted in December of 2018, and new variants are introduced each week. All latest versions are using RSA[2] military-based algorithms to encrypt victim data.

When Lisp virus is encrypting files, it appends a .lisp extension to all personal files, such as photos, videos, documents, archives, etc. Files are rendered useless until decoded. Once that is done, a ransom note _readme.txt is placed in all affected folders so that the victim would find it literally everywhere.

name Lisp ransomware
type Ransomware, cryptovirus
Family Djvu ransomware
Appended file extension .lisp extension is appended to all non-system files
Ransom note _readme.txt
Ransom amount $490 if victims contact the criminals within 72 hours of the attack. $980 if the users are not hasty
 Criminal contact details Two emails are provided to make contact – helpmanager@mail.ch, restoremanager@airmail.cc
 Malware removal You should remove the ransomware from the infected devices with the help of professional anti-malware software
System  Health When the virus removal is completed, use the FortectIntego tool to pinpoint all changes the virus has done to system core files and settings, and restore it

Following successful encryption, ransom notes titled _readme.txt are created in all affected folders. Within these notes, the developers of Lisp ransomware reassure the victims that all their files can be unlocked with their decryption key. To convince users, the cybercriminals are offering to send them one file for a test decryption. Furthermore, they give a link to a video of the decryption tool in action. In simple words, the criminals are trying to persuade the people by all means possible.

Lisp ransomware requested ransom amount is $490 if the victims act quickly, that is, within 72 of the attack. If not, the so-called 50% discount time runs out, and the price for the description software is doubled to $980. A personal ID is appointed, which should be sent to one of two provided email addresses – helpmanager@mail.ch, restoremanager@airmail.cc

Although some of you might think that the ransom isn't very high to get your data back, but think again. When victims pay the criminals, that money fuels their future ventures, i.e., their future attacks. It also finances their whole operation, including research for better distribution, creation of better, more sophisticated malware, other file virus attacks, and so on.

File decryption depends on the offline vs. online key forming during the encryption

Victims of such threats that demand money directly with claims about decryption tools may think that paying is the best solution. However, the issue with decryption tools and file recovery, virus removal stems from the encryption process that gets initiated by Lisp ransomware itself.

It is known that previous versions in August of last year got updates and started to use encryption algorithm mix, online victim IDs, and encryption keys. What does it mean now for .lisp files? Offline keys meant that many victims got the same decryption key formed. Online keys are unique to each device.

So not only virus detection rate[3] affects the elimination and file recovery. using anti-malware tools helps with Lisp ransomware removal, but you need to have a proper decryption tool that works with online keys to get data restored. There are no tools that could work right now. Rely on backups for now.

Lisp file virus

Instead of dealing with the criminals, victims should remove the ransomware from their devices immediately. Security tools, AV detection mechanism-based programs, SpyHunterCombo Cleaner and MalwarebytesMalwarebytes, time-tested antimalware apps should get that done in a matter of minutes. 

After Lisp ransomware removal, users should use the FortectIntego app to scan and fix whatever the virus has done to system files and its settings. Djvu family viruses are known to modify these things to help them thrive in the infected computer.

Message from the creators of the ransomware to the victims, found in _readme.txt files, states:

ATTENTION!

Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-Dz5odBd07y
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.

To get this software you need write on our e-mail:
helpmanager@mail.ch

Reserve e-mail address to contact us:
restoremanager@airmail.cc

Your personal ID:

Spreading the threat silently allows the attack to be quick

Most of Djvu family ransomware, including this article's culprit Lisp file virus, is distributed primarily via illegal activation kits for various software, more popularly known as cracks. These viruses could be camouflaged as the latest game or some expensive software cracks. Please don't fall for it. Refrain from using any illegal software activation kits. Support your desired apps developers by purchasing their products directly from them or official distributors.

Lisp ransomware virus

There are a couple of ways to retrieve your data without having to deal with the perpetrators. The first and the easiest is if you had backups. Then just remove the virus, perform a system tune-up, and you're ready to go. Now, if you didn't have backups, then it gets a bit tougher.

Check out the company Emisoft. They constantly work on their Djvu ransomware family decryption tool. It is not working for all the versions of Lisp ransomware or previously released pieces, but offline IDs might be in use later on or the tool gets needed updates from creators. Keep your fingers crossed, and they might create it sooner than later. Till then, export all your files to external, offline storage.

If you can't just sit and wait, then go to the bottom of this article, where we list some more possible ways with detailed instructions on how to recover your files after the proper ransomware termination and how to rely on some OS features.

Instructions on Lisp ransomware virus removal and system tune-up

Cybercriminals are improving their creations every day so reliable anti-malware software is a must. To remove Lisp ransomware we suggest using time-tested SpyHunterCombo Cleaner or MalwarebytesMalwarebytes apps. Any of these apps will automatically locate, and remove the virus with all its allocated files.

When Lisp ransomware removal is completed, don't rush to get your data back from backups. First, experts[4] recommend using a powerful FortectIntego tool to fix any issues the cryptovirus might have done to system settings and its files. Afterward, when your computer is virus-free and crispy clean, only then restore your files.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.