Restorefiles@firemail.cc is an email address that cyber criminals use to contact victims of STOP (DJVU) ransomware. Ransomware is a type of malware that blocks access to files by encrypting them, until the victim pays a ransom.
Restorefiles@firemail.cc virus locks up the files using AES-RSA technology, that makes it impossible to unlock the encrypted data by the victim without obtaining a key and a decryptor, which is the only way to decrypt affected files. It can be obtained only in the case of payment of the required ransom through cryptocurrency wallet. The ransomware virus encrypts almost of database, videos, documents, music, web application-related files, archives and images, including common as:
.xll, .vcf, .hkx, .ltx, .py, .bkf, .mcmeta, .wgz, .wot, .xlgc, .jpg, .yal, .pst, .mddata, .wsd, .sb, .ztmp, .fos, .psd, .syncdb, .wpa, .1st, .jpeg, .xx, .re4, .png, .sidd, .hvpl, .xbplate, .xyp, .xf, .arw, .ppt, .icxs, .2bp, .wmv, .itm, .wpd, .rim, .xyw, .wma, .zdc, .docm, .xlsx, .rwl, .m4a, .wpw, .flv, .bar, .epk, .iwi, .odp, .m2, .mpqge, .zip, .odt, .cas, .xy3, .m3u, .pfx, .menu, .sr2, .cdr, .pef, .mef, .dcr, .pkpass, .snx, .vtf, .x3f, .wbd, .yml, .bik, .pdd, .3ds, .forge, .wcf, .upk, .xpm, .wpg, .odb, .vpp_pc, .3dm, .ws, .xlsx, .z3d, .bc6, .big, wallet, .css, .xxx, .nrw, .dmp, .ibank, .p12, .xlsm, .pak, .wmo, .sav, .p7b, .wri, .bc7, .ntl, .wps, .wpt, .crw, .mdb, .cfr, .ods, .jpe, .zi, .rtf, .lbf, .xar, .kdb, .xlk, .db0, .wire, .sis, .odc, .webdoc, .wpe, .crt, .psk, .vpk, .zw, .wpl, .y, .wdb, .3fr, .accdb, .dxg, .gdb, .esm, .eps, .0, .wbmp, .bay, .arch00, .xls, .pptm, .docx, .tor, .dbf, .cer, .mp4, .wp7, .dazip, .ncf, .map, .txt, .ptx, .mdbackup, .ybk, .xbdoc, .doc, .litemod, .bkp, .xmind, .vfs0, .wbm, .das, .wp4, .hplg, .zif, .pem, .ai, .itdb, .webp, .xml, .mrwref, .wdp, .hkdb, .xlsm, .odm, .srf, .iwd, .bsa, .xdl, .tax, .wbk, .itl, .wotreplay, .raw, .z, .ff, .x3f, .xwp, .r3d, .pdf, .wpb, .rar, .dwg, .fpk, .raf, .ysp, .wmd, .xls, .kf, .gho, .fsh, .sum, .wav, .p7c, .rw2, .sie, .cr2, .rgss3a, .csv, .wbz, .wsh, .wmf, .wb2, .apk, .avi, .vdf, .js, .d3dbsp, .x, .dba, .wma, .zabw, .xmmap, .svg, .indd, .wbc, .layout, .desc, .w3x, .kdc, .xdb, .sql, .1, .asset, .wsc, .wps, .wp6, .zdb, .mdf, .wm, .erf, .orf, .srw, .slm, .wp5, .wp, .x3d, .pptx, .blob
With the encryption process is finished, all encrypted files will now have a new extension appended to them. In every directory where there are encrypted files, Restorefiles@firemail.cc virus drops a file called ‘_readme.txt’. This file contains a ransom note that is written in the English. The ransom message directs victims to make payment in exchange for a key needed to unlock personal files.
Summary
Email address | Restorefiles@firemail.cc |
Related ransomware | STOP (DJVU) family |
Variants of STOP (Djvu) that use this address | Peet, Grod |
Ransom note | _readme.txt |
Ransom amount | $980/$490 |
Removal | Free Malware Removal Tools |
Decryption | Free STOP Djvu Decryptor |
Text presented in “_readme.txt”:
ATTENTION!
Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-7YSRbcuaMa
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.To get this software you need write on our e-mail:
restorefiles@firemail.ccReserve e-mail address to contact us:
gorentos@bitmessage.chYour personal ID:
If you find files called ‘_readme.txt’, then your computer is the victim of ransomware attack. First you need to find and remove Restorefiles@firemail.cc virus. We recommend using free malware removal tools. Only after you are completely sure that the virus has been removed, start decrypting the files.
How to decrypt files encrypted by Restorefiles@firemail.cc virus
Using the STOP decryptor is not difficult, just follow the few steps described below.
- Download STOP Djvu decryptor from here (scroll down to ‘New Djvu ransomware’ section).
- Run decrypt_STOPDjvu.exe.
- Add the directory or disk where the encrypted files are located.
- Click the ‘Decrypt’ button.