Mpaj Virus. How to Decrypt. Mpaj Files? (+ Restore Pc)
What Is “Mpaj”? Ransomware Is a Specific Kind of Virus That Encrypted Your Documents and Then Forces You to Pay to Restore Them. Djvu (Aka Stop) Ransomware...
What is “Mpaj”?
Ransomware is a specific kind of virus that encrypted your documents and then forces you to pay to restore them. DJVU (aka STOP) ransomware family was first revealed and analyzed by virus analyst Michael Gillespie">2.
Mpaj is similar to other ransomware like: Jope, Mado, Opqz. It encrypted all popular file types. Hence, users cannot use the your documents . Mpaj adds its particular “.mpaj” extension into all files. For example, the file “video.avi”, will be changed into “video.avi.mpaj”. As soon as the encryption is accomplished, Mpaj creates a specific text file “_readme.txt” and adds it into all folders that contain the modified files.
| Ransomware family3 | DJVU/STOP4 ransomware |
| Extension | .mpaj |
| Ransomware note | _readme.txt |
| Ransom | From $490 to $980 (in Bitcoins) |
| Contact | , |
| Detection5 | Trojan.Agent.DXKD, Win32/Packed.Themida.BUW, Trojan.ShellStartup.lmGfaObDRVlc |
| Symptoms | Your files (photos, videos, documents) have a .mpaj extension and you can’t open it |
| Fix Tool | See If Your System Has Been Affected by .mpaj file virus |
This text asking payment is for restore files via decryption key:
The scary alert demanding from users to pay the ransom to decrypt the encoded data contains these frustrating warnings
The cryptography algorithm used by Mpaj is AES-256. So, if your files got encrypted with a specific decryption key, which is totally distinct and there are no other copies. The sad reality is that it is impossible to restore the information without the unique key available.
In case if Mpaj worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a remote server owned by the frauds who distribute the Mpaj virus.
For receiving decryption key the payment should be $980. To obtain the payment details the victims are encouraged by the message to contact the frauds by email (), or via Telegram.
Do not pay for Mpaj!
_readme.txt file also indicates that the computer owners must get in touch with the Mpaj representatives during 72 hours starting from the moment of files where encrypted. On the condition of getting in touch within 72 hours, users will be granted a 50% rebate, thus the ransom amount will be minimized down to $490). Yet, stay away from paying the ransom!
I strongly recommend that you do not contact these crooks and do not pay. The one of the most real working solution to recover the lost data – just using the available backups, or use Decrypter tool.
And that’s not just words. Ransomware developers would do everything to force you to pay them. They can try to show you that they are fair-playing, offering to decrypt one or two of your files. Nonetheless, that’s no warranty that croocks will decrypt your files after your payment. No one can force them to do what they promised.
But croocks are usually not so friendly to their victims. The typical conversation with them usually finish with the phrase like “pay us, or we’ll delete all files from your PC”. Also, we have an approved fact that they are collecting all e-mails of their victims to database, that is supposed to be sold in future to another fraudsters, that will spam your e-mail with annoying ads or so.
The peculiarity of all such viruses apply a similar set of actions for generating the unique decryption key to recover the ciphered data.
Ransomware can run the encryption with offline or online key. First type is much easier to decrypt, because it’s usually located on your PC and can be found even manually. Online key is much harder, because it’s stored on ransomware developers’ server. So, an online key may be got only after the federal law interference.
You can check if your files were encrypted with online or offline key. Find a PersonalID.txt in the SystemID folder on your C:\ disk. If this file contains any entity which ends on “t1” – you’ve been encrypted with an offline key, and it could be easily decrypted as soon as this keys will appear in the database of decryptor.
Thus, unless the ransomware is still under the stage of development or possesses some hard-to-track flaws, manually recovering the ciphered data is a thing you can’t really perform. The only solution to prevent the loss of your valuable data is to regularly make backups of your crucial files.
Note that even if you do maintain such backups regularly, they ought to be put into a specific location without loitering, not being connected to your main workstation.
This advice is recomended to follow, because ransomware can counter-act your backups in many ways. The most popular way – it can just inject itself in the backup file, or, if Mpaj ransomware will be “asleep” for a long time, you can accidentaly create a backup with ransomware inside by yourself.
In spite of injecting it’s files in your backups, Mpaj ransomware also able to disable an access to the backups that are created using basic Windows backup creation tools. So, even if you have a backup that surely does not contain ransomware inside, you can just lost an access to them. That’s why it’s recomended to use another backup-creating tools.
And that’s not the only mean action Mpaj ransomware does with your PC. It can also add Microsoft update server into hosts file. Hence, your Windows loses an ability to get the updates, so the operating system is not able to perform “self-cleaning”, wiping out changes that ransomware did in system files and registry.
For instance, the backup may be kept on the USB flash drive or some alternative external hard drive storage. Optionally, you may refer to the help of online (cloud) information storage.
Needless to mention, when you maintain your backup data on your common device, it may be similarly ciphered as well as other data.
For this reason, locating the backup on your main computer is surely not a good idea.
Like all STOP/Djvu ransomware family, Mpaj ransomware has a significant troubles with large files encryption. Videos, archives, 3D models or other files that can easily reach the size of 1+GB are very hard to encrypt. Ransomware can just add it’s .mpaj extension to such files without real encryption, and then left them. You can just delete an .mpaj extension from the file name, and then launch it in common way.
Also, beware of using OneDrive backup methods. It creates a backup in a background mode without any notifications about start of the process, and it literally rewrites your old backup with a new one. So, if you suddenly got a ransomware attack and your OneDrive decides to create a so-called “restore point”, it can rewrite normal files with encrypted one.