Cerber 5.0.1 Virus - Remove It and Restore Files (Update) - How to, Technology and PC Security Forum | SensorsTechForum.com

Cerber 5.0.1 Virus – Remove It and Restore Files (Update)

1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)

This article aims to help you remove Cerber 5.0.1 Virus successfully and restore your files using alternative tools. Cerber 5.0.1. Is a ransomware virus that was first detected back in November and is now back with a new spam campaign In which the RIG-V exploit kit is used for infection. In proximity to Locky’s latest .osiris file extension, this virus is the other “big player” in the ransomware market, infection number of which can only be compared to Locky. In case you have become a victim of Cerber 5.0.1 ransomware, we urge you to be extremely careful in your actions. Suggestions are to read this article thoroughly and learn more about the updated Cerber 5.0.1 version and how you can remove it and protect yourself I the future.

Threat Summary


Cerber 5.0.1

Short DescriptionThe malware encrypts users files using a strong encryption algorithm, making direct decryption possible only via a unique decryption key available to the cyber-criminals.
SymptomsThe user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .adk has been used.
Distribution MethodVia an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by Cerber 5.0.1


Malware Removal Tool

User ExperienceJoin our forum to Discuss Cerber 5.0.1.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

How Is Cerber 5.0.1 Distributed

A very specific detail about the Cerber 5.0.1 version is that the RIG-V exploit kit is used to aid undetected infection. This new modification and new exploit kit has several advantages over the traditional RIG-E (Empire Pack) exploit kit:

  • Changed and new URLs.
  • More obfuscation on the infection code.
  • Higher RC4 encryption for payload obfuscation.

To spread the exploit kit, Cerber 5.0.1 ransomware uses advanced techniques that allow it to infect successfully. The ransomware may use .hta, .html, .htm files and also javascript types of files (.js) to infect users. The infection is processed via spam e-mails that are disguised as legitimate e-mails sent by services, like PayPal, Amazon, and other services. The e-mails would typically have very specifically designed malicious web links or .hta files sent in them. But this is not the only types of files to beware of. Cerber 5.0.1 may also be distributed via .xls and docx files and also .pdf files that contain malicious macros. One example, spotted in association with 5.0.1 is the following e-mail spreading a malicious document, named 50070223.doc has the following contents:

“Sales receipt is attached”
Attachment password is 2224
Kind wishes
Ref no: 2244212.”

Upon typing the password, the user becomes infected via a malicious macro.

Further Analysis of Cerber 5.0.1

Similar to the conventional Cerber 5.0.1 version spotted back in November 2016, this Cerber iteration also can stop important system processes:


But these are not all the processes, Cerber 5.0.1 may attack. News broke out that the virus is also programmed to eliminate any database processes that are related to various databases, like MySQL, Oracle and Microsoft Access. The processes reported to be in the source code of the Cerber virus are the following:


The Cerber 5.0.1 ransomware may encrypt those processes primarily because they may stand in the way of it encrypting databases, one of the primary focuses of Cerber ransomware’s 5th versions in general.

Concerning file encryption, everything is so far unchanged. The virus still encrypts the many file-types It was initially set out to encipher:

File Types Attacked by Cerber 5.0.1

For the encryption, not much is changed either. Cerber 5.0.1 attacks five blocks of the code of the victim file which are encrypted. The encryption method to encode those files is called RC4, and it works with a 256-bit strength. The algorithm used in combination with this method is reported to be RSA-512 bit cipher which is a very strong cipher, and it’s purpose is to generate a unique decryption RSA key. This key may be for a set of files or even each file. Then, the virus sends traffic information to the command and control servers of the cyber-criminals which help it to communicate with them and probably send decryption information.

Just like the other Cerber iterations, this one also encrypts the files and changes their names as well as their file extension to a random one:

Cerber 5.0.1

After encryption has completed, this Cerber version also makes sure to drop it’s typical _README_.hta type of file which’s purpose is to inform victims of the situation and provide a web link to a “Cerber Decryptor” web page:

Remove Cerber 5.0.1 Ransomware Virus and Restore the Files

If you have had the bad luck of becoming a part of the Cerber 5.0.1 ransomware community, then your options are very limited, and you should act fast. The first suggested course of action is not to pay any ransom and follow the instructions below to get rid of the Cerber 5.0.1 version. In case you do not have experience with malware, it is recommended to download an advanced software that will automatically take care of the removal for you.

After having deleted Cerber 5.0.1 completely, you can now focus on restoring your files. First, it is recommended to make several copies of the encrypted data, since this Cerber version may damage your files if you try to decrypt them yourself. This Is why it is good to use “dummy” copies of the files.

To try and decipher the files that have been encrypted by Cerber, we advise you to focus on seeing the alternative tools we suggested in step “2. Restore Files Encrypted by Cerber 5.0.1” below. They may not be fully effective, but users report on our forums and comments to have restored at least a small portion of the files this way. Also, it is a good temporary solution until a decryptor for Cerber may be released in the future for free, which, If happens, we will post instructions and link them in this article for you to follow.


Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share