How to Fix Files Changed to UAJS Extension (Ransomware Recovery)
Question details
The user's files have been appended with a .uajs extension and display as unreadable code when opened, indicating a ransomware infection.

- Product
- Windows File System
- Device & OS
- not provided
- Scenario
- The user attempts to access personal or work documents but discovers the file extensions have changed to .uajs and the contents are completely locked.
- Observed behavior
- Files are inaccessible, open as encrypted code instead of standard text, and bear a new .uajs extension.
Immediately disconnect your infected device from all internet connections, Wi-Fi, local networks, and external backup drives to prevent the ransomware from spreading to other systems.
Isolate the Device and Preserve Encrypted Files
Take immediate containment actions to stop the spread of the STOP/DJVU ransomware and preserve evidence for potential future decryption.
The .uajs extension is a strong indicator of a newer variant of the STOP or DJVU ransomware family. Because these often use online encryption keys, immediate decryption might not be available, but preserving the files is critical.
Unplug your ethernet cable and turn off your computer's Wi-Fi. Do not connect USB drives or external hard drives to the infected machine.
Leave the encrypted files with their .uajs extensions intact. Renaming them back to their original extensions will not fix them and may interfere with future decryption tools.
Locate and keep the ransom note (often a text file like '_readme.txt' placed on your desktop or in affected folders). This contains your personal ID which is required if a decryption tool becomes available.
Use a separate, safe device to monitor trusted cybersecurity websites (such as BleepingComputer or the No More Ransom project) for the release of free STOP/DJVU decryptors.

Restore Files from a Clean Offline Backup
If you have a backup of your files from before the infection, you can restore your data after ensuring the malware is completely removed.
Protect and Recover Documents with WPS Cloud Backup
To safeguard your critical documents against future ransomware attacks or data loss, use WPS Office. The built-in WPS Cloud service automatically backs up your files and retains historical versions, allowing you to instantly restore your work to a clean, unencrypted state.
- 1. Enable Cloud Synchronization: Open WPS Office, go to Settings, and turn on Document Cloud Sync to automatically back up your local documents to WPS Cloud.
- 2. Access File History: If a local file is compromised, log into the WPS Cloud web portal on a secure device, locate your document, and select History Versions.
- 3. Restore a Clean Version: Preview the historical versions, select the one saved just before the infection occurred, and click Restore to recover your unencrypted data.

Frequently Asked Questions
Can I fix the .uajs files by simply changing the extension back?
No. Changing the file extension from .uajs back to .docx, .pdf, or .jpg will not decrypt the file. The actual content of the file has been mathematically scrambled, and renaming it will only result in a corrupted file.
Will running an antivirus scan recover my encrypted data?
While a thorough antivirus scan is crucial for removing the active ransomware and preventing further encryption, it cannot unlock or decrypt the files that have already been converted to the .uajs format.
Is there a free decryptor available for the .uajs STOP/DJVU variant?
Because .uajs is a newer variant of the STOP/DJVU family, it typically uses an online key system for which immediate decryption tools are not available. You should preserve your files and periodically check the No More Ransom project or trusted security forums for updated decryption tools.




