How to Recover Files Encrypted by Jaff Ransomware?

by Olivia Morelli - -
12

Question

Issue: How to Recover Files Encrypted by Jaff Ransomware?

Hello, today my files were encrypted by a malicious computer virus called Jaff ransomware. It has corrupted all files and added .sVn file extensions to them. I heard that there is a decrypter for earlier versions of this ransomware, the ones that were using .wlu or .jaff file extensions. Is there any way to decrypt .sVn files for free?

Solved Answer

Recover now! Recover now!
Reimage is recommended to recover required system components. To get a detailed report and in-depth analysis about your system, use the free scanner. To recover needed system components, please, purchase the licensed version of Reimage Reimage recovery tool.

 snapshot

Jaff ransomware virus is a malicious computer program that is rapidly distributed with a help of Necurs botnet. Currently, there are three versions of the ransomware, and each of them adds different file extensions and uses different names for the ransom notes:

  • .jaff file extension virus used to drop ReadMe.txt, ReadMe.html and ReadMe.bmp file;
  • .wlu file extension virus dropped these files: README_TO_DECRYPTI.txt, README_TO_DECRYPTl.bmp, README_TO_DECRYPT.html;
  • .sVn file extension virus uses the following names for the ransom notes: !!!!README_FOR_SAVE FILES.txt and !!!SAVE YOUR FILES.bmp. The latest variants leave !!!!!SAVE YOUR FILES!!!!.txt and !!!SAVE YOUR FILES!.bmp files.

While some security researchers believed that it might be a variant of Locky ransomware, others proved them wrong. In fact, the virus seemed to be extremely dangerous and sophisticated, although experts from Kaspersky proved that it is only the appearance of the virus that was scary. Jaff decryption tool is available, and it works for all versions of the virus, including .jaff, .wlu, and .sVn variants. If your files were encrypted, you must complete some tasks in a specific order if you want to recover your data and continue using it successfully.

Step 1. Remove Jaff ransomware completely

  • Before you try to decrypt your files, remove the ransomware so that it could not interfere with the decryption process.
  • Reboot your PC into Safe Mode (see a guide on how to do it here) and launch anti-spyware software such as Reimage. Scan the system with it.
  • Remove detected malware and related components.

Step 2. Restore .jaff, .wlu, .sVn file extension files

Method 1. Recover your files using RakhniDecryptor

  1. Download RahkniDecryptor from official Kaspersky website.
  2. Check if the decryptor’s version is 1.21.2.1 (or higher).
  3. Click Start scan and then choose the folder that contains files you want to decrypt.
  4. The decryptor should ask you to select a ransom note. Find it, select it and click Open.
  5. Wait until the decryptor restores all files from your selected folder.
  6. Repeat 3-5 step with every folder that contained important files.

In case you were infected with an updated version of the Jaff malware, the decryptor might now work. In such case, try one of the following techniques:

Method 2. Run a scan with Data Recovery Pro

  1. Install Data Recovery Pro according to information provided by its installer.
  2. Launch it and scan the system to detect files that can be recovered.
  3. Restore them.

Method 3. Use Volume Shadow Copies

Volume Shadow Copies can be used in case the computer virus leaves them on the system after encrypting all files. The majority of such malicious programs delete these copies so that the victim couldn’t recover encrypted files without paying the ransom. We have already provided a comprehensive guide on how to restore files using Shadow Volume Copies.

Recover files and other system components automatically

To recover your files and other system components, you can use free guides by ugetfix.com experts. However, if you feel that you are not experienced enough to implement the whole recovery process yourself, we recommend using recovery solutions listed below. We have tested each of these programs and their effectiveness for you, so all you need to do is to let these tools do all the work.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use. By Downloading any provided software you agree to our privacy policy and agreement of use.
do it now!
Download
recovery software Happiness
Guarantee
do it now!
Download
recovery software Happiness
Guarantee
Compatible with Microsoft Windows Compatible with OS X
Do you have any trouble?
If you are having problems related to Reimage, you can reach our tech experts to ask them for help. The more details you provide, the better solution they will provide you.
Reimage - a patented specialized Windows repair program. It will diagnose your damaged PC. It will scan all System Files, DLLs and Registry Keys that have been damaged by security threats.Reimage - a patented specialized Mac OS X repair program. It will diagnose your damaged computer. It will scan all System Files and Registry Keys that have been damaged by security threats.
This patented repair process uses a database of 25 million components that can replace any damaged or missing file on user's computer.
To repair damaged system, you have to purchase the licensed version of Reimage malware removal tool.

About the author

Olivia Morelli
Olivia Morelli - PC & Mac repair expert

Olivia Morelli is a young, but a perspicacious IT expert who is currently just a year away from a Bachelor’s Degree in Software Systems. Her primary passion is cyber security, however, thanks to her detailed understanding of computer networks, operating systems and hardware, she can find a fix for any PC or Mac issue.

Contact Olivia Morelli
About the company Esolutions

What you can add more about the problem: "How to Recover Files Encrypted by Jaff Ransomware?"