Hey you,
BE IN THE KNOW!

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:


Cerber 5.0.1 Virus – Remove It and Restore Files (Update)

This article aims to help you remove Cerber 5.0.1 Virus successfully and restore your files using alternative tools. Cerber 5.0.1. Is a ransomware virus that was first detected back in November and is now back with a new spam campaign In which the RIG-V exploit kit is used for infection. In proximity to Locky’s latest .osiris file extension, this virus is the other “big player” in the ransomware market, infection number of which can only be compared to Locky. In case you have become a victim of Cerber 5.0.1 ransomware, we urge you to be extremely careful in your actions. Suggestions are to read this article thoroughly and learn more about the updated Cerber 5.0.1 version and how you can remove it and protect yourself I the future.

Threat Summary

Name

Cerber 5.0.1

Type Ransomware
Short Description The malware encrypts users files using a strong encryption algorithm, making direct decryption possible only via a unique decryption key available to the cyber-criminals.
Symptoms The user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .adk has been used.
Distribution Method Via an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by Cerber 5.0.1

Download

Malware Removal Tool

User Experience Join our forum to Discuss Cerber 5.0.1.
Data Recovery Tool Data Recovery Pro by ParetoLogic Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

How Is Cerber 5.0.1 Distributed

A very specific detail about the Cerber 5.0.1 version is that the RIG-V exploit kit is used to aid undetected infection. This new modification and new exploit kit has several advantages over the traditional RIG-E (Empire Pack) exploit kit:

  • Changed and new URLs.
  • More obfuscation on the infection code.
  • Higher RC4 encryption for payload obfuscation.

To spread the exploit kit, Cerber 5.0.1 ransomware uses advanced techniques that allow it to infect successfully. The ransomware may use .hta, .html, .htm files and also javascript types of files (.js) to infect users. The infection is processed via spam e-mails that are disguised as legitimate e-mails sent by services, like PayPal, Amazon, and other services. The e-mails would typically have very specifically designed malicious web links or .hta files sent in them. But this is not the only types of files to beware of. Cerber 5.0.1 may also be distributed via .xls and docx files and also .pdf files that contain malicious macros. One example, spotted in association with 5.0.1 is the following e-mail spreading a malicious document, named 50070223.doc has the following contents:

“Sales receipt is attached”
Attachment password is 2224
Kind wishes
Jimmy
Ref no: 2244212.”

Upon typing the password, the user becomes infected via a malicious macro.

Further Analysis of Cerber 5.0.1

Similar to the conventional Cerber 5.0.1 version spotted back in November 2016, this Cerber iteration also can stop important system processes:

bootsect.bak
iconcache.db
ntuser.dat
thumbs.db

But these are not all the processes, Cerber 5.0.1 may attack. News broke out that the virus is also programmed to eliminate any database processes that are related to various databases, like MySQL, Oracle and Microsoft Access. The processes reported to be in the source code of the Cerber virus are the following:

msftesql.exe
sqlagent.exe
sqlbrowser.exe
sqlservr.exe
sqlwriter.exe
oracle.exe
ocssd.exe
dbsnmp.exe
synctime.exe
mydesktopqos.exe
agntsvc.exeisqlplussvc.exe
xfssvccon.exe
mydesktopservice.exe
ocautoupds.exe
agntsvc.exeagntsvc.exe
agntsvc.exeencsvc.exe
firefoxconfig.exe
tbirdconfig.exe
ocomm.exe
mysqld.exe
mysqld-nt.exe
mysqld-opt.exe
dbeng50.exe
sqbcoreservice.exe

The Cerber 5.0.1 ransomware may encrypt those processes primarily because they may stand in the way of it encrypting databases, one of the primary focuses of Cerber ransomware’s 5th versions in general.

Concerning file encryption, everything is so far unchanged. The virus still encrypts the many file-types It was initially set out to encipher:

File Types Attacked by Cerber 5.0.1

For the encryption, not much is changed either. Cerber 5.0.1 attacks five blocks of the code of the victim file which are encrypted. The encryption method to encode those files is called RC4, and it works with a 256-bit strength. The algorithm used in combination with this method is reported to be RSA-512 bit cipher which is a very strong cipher, and it’s purpose is to generate a unique decryption RSA key. This key may be for a set of files or even each file. Then, the virus sends traffic information to the command and control servers of the cyber-criminals which help it to communicate with them and probably send decryption information.

Just like the other Cerber iterations, this one also encrypts the files and changes their names as well as their file extension to a random one:

Cerber 5.0.1

After encryption has completed, this Cerber version also makes sure to drop it’s typical _README_.hta type of file which’s purpose is to inform victims of the situation and provide a web link to a “Cerber Decryptor” web page:

Remove Cerber 5.0.1 Ransomware Virus and Restore the Files

If you have had the bad luck of becoming a part of the Cerber 5.0.1 ransomware community, then your options are very limited, and you should act fast. The first suggested course of action is not to pay any ransom and follow the instructions below to get rid of the Cerber 5.0.1 version. In case you do not have experience with malware, it is recommended to download an advanced software that will automatically take care of the removal for you.

After having deleted Cerber 5.0.1 completely, you can now focus on restoring your files. First, it is recommended to make several copies of the encrypted data, since this Cerber version may damage your files if you try to decrypt them yourself. This Is why it is good to use “dummy” copies of the files.

To try and decipher the files that have been encrypted by Cerber, we advise you to focus on seeing the alternative tools we suggested in step “2. Restore Files Encrypted by Cerber 5.0.1” below. They may not be fully effective, but users report on our forums and comments to have restored at least a small portion of the files this way. Also, it is a good temporary solution until a decryptor for Cerber may be released in the future for free, which, If happens, we will post instructions and link them in this article for you to follow.

Manually delete Cerber 5.0.1 from your computer

Note! Substantial notification about the Cerber 5.0.1 threat: Manual removal of Cerber 5.0.1 requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove Cerber 5.0.1 files and objects
2.Find malicious files created by Cerber 5.0.1 on your PC

Automatically remove Cerber 5.0.1 by downloading an advanced anti-malware program

1. Remove Cerber 5.0.1 with SpyHunter Anti-Malware Tool and back up your data
2. Restore files encrypted by Cerber 5.0.1
Optional: Using Alternative Anti-Malware Tools

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.