Rejg ransomware – cryptovirus targeting Windows computers and demanding Bitcoins

Rejg ransomware is a perilous computer virus that encrypts all personal files on an infected device and demands a ransom in cryptocurrency Bitcoins to regain access to them. The assailant demands and instructions are listed in a ransom note titled _readme.txt that can be found on the desktop after a successful attack.
All personal data on the infected machine is renamed by appending a .rejg extension. According to the criminals, the only way to retrieve the data is by contacting them via helpmanager@airmail.cc or helpteam@mail.ch and paying them either $980 or $490, depends whether the victims establish contact within 72 hours of the attack.
We strongly advise against that. There could be other ways to regain access to your encrypted files. Free decryption software from Emsisoft is constantly updated and might decrypt your files for free. If that doesn't help, try other data recovery options. We've listed a couple of them at the bottom of this article.
Rejg virus is a new version from the Djvu ransomware family, which has been terrorizing innocent people worldwide since 2018. By reading this article, you'll find out how to evade such hazardous malware, how to remove it if it infected your PC, and how to recover your system's overall health.
| name | Rejg ransomware |
|---|---|
| Type | Malware, cryptovirus, file-locker |
| Family | Djvu/STOP ransomware |
| Appended file extension | .rejg |
| Ransom note | _readme.txt appears on the Desktop and in various folders with encoded files |
| Ransom amount | $980 is the starting amount, but a discount to $490 is offered for the first 72 hours since the ransom note appears |
| Criminal contact details | helpmanager@airmail.cc, helpteam@mail.ch |
| Elimination | Remove this perilous infection by scanning your infected computer with a reliable anti-malware tool |
| System health fix | This virus causes havoc on system files to establish persistence. Due to this, your device might exhibit a lot of strange behavior such as freezing, crashing, etc. Perform system diagnostics with the FortectIntego tool to restore your computer back to normal |
Djvu ransomware family is one of the biggest and fastest-growing ones. It's introducing new versions of its dangerous file-lockers each week or even more frequently. The latest examples are Wrui virus, Lmas virus, Urnb virus, and Fdcz virus. All of these parasites are similar, but they have their differences too.
One of the traits that never change in cryptoviruses from this family is their ransom notes. They are almost identical. They start by briefly explaining what happened to the victim files and that the only way to retrieve them is by purchasing their decryption tool.
Within the note, the developers of Rejg virus are bending over backward to persuade you into paying the ransom. The criminals offer free decryption of one file from the infected PC. Furthermore, they offer a 50% discount for victims who reach out to them within 72 hours of attacks.

This discount is made to push you into making rash decisions. There might be other data recovery options, but the assailants don't want to provide you any time for thinking. The whole note with the instructions and demands reads:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-9CYW99VhUR
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpteam@mail.chReserve e-mail address to contact us:
helpmanager@airmail.ccYour personal ID:
Although the amount doesn't seem that big to get your precious data back, paying your assailants is the worse thing you could do. That money would motivate them to attack more people and provide funds for the development of more advanced malware[1] and ways to distribute it.
Therefore, our recommendation is to remove Rejg ransomware. If the Emisoft decryptor and alternative tools can't recover your locked files, please copy them to an offline storage device. Then download and install a trustworthy anti-malware tool such as MalwarebytesMalwarebytes or SpyHunterCombo Cleaner.
Perform a full system scan and remove the threat. Sometimes, malware can prevent you from launching security software. In that case, reboot your computer in Safe Mode with Networking (instructions are below if you're unsure how to do that) and then proceed with the removal.
Afterward, you need to restore altered Windows Registry values, clean up host files, and edit other core system files for your device to work properly again. This task should be completed only by highly experienced users. If you're not one of them, then perform system diagnostics with the FortectIntego system repair tool, which will automatically take care of all system irregularities.

Keep your PC free of Djvu ransomware by not using torrent websites
The internet is a scary place nowadays because malware is lurking everywhere. You can get your computer infected by opening a phishing email, downloading fake Flash Player updates, installing software from a bundle, etc. Some viruses could even infect your device instantly through drive-by downloads.[2]
Although there's a myriad of ways Djvu family ransomware could be spread, our research suggests that it's mainly distributed through file-sharing platforms, particularly the most popular torrent pages. This method could be preferred as these sites lack end-to-end security, and it requires the least work.
Evil-doers have to think of an alluring name and upload the virus payload file camouflaged as something else. Most ransomware could be hidden as popular game cracks (illegal activation tools), game cheats, pirated expensive software, and alike. Thus please think twice before downloading anything from such portals.
Remove Rejg ransomware safely with our comprehensive instructions
Ransomware can infect anyone's device. If you didn't keep backups of crucial data, then the recovery road might be a bit bumpy. Try using recommended recovery software at the bottom of this article. If none of it helps, then extract encrypted files to an offline storage device, and wait for a decryption tool to be made available.
To safely remove Rejg virus, you will need a reliable security tool. Free but trustworthy AV engines like MalwarebytesMalwarebytes and SpyHunterCombo Cleaner should locate, isolate, and eliminate the threat with all of its pieces. As we've mentioned before, if the ransomware prevents you from opening your anti-malware software, do that in Safe Mode with Networking (instructions below).
Once the removal process is done, you need to take care of your device's overall health. Djvu family ransomware modifies the Registry, host files, and other essential system settings and files. If these changes are left unattended, the device might exhibit various abnormal behavior such as BSoDs, freezing, and other system failures.
You could try to fix all these issues manually, but that's recommended only for IT experts, as more harm could be done. Therefore, cybersecurity specialists[3] highly recommend entrusting this task to the time-tested FortectIntego system diagnostics tool that will accomplish it automatically.
Was this guide helpful?
Be the first to comment