This article aims to help you remove Cerber 5.0.1 Virus successfully and restore your files using alternative tools. Cerber 5.0.1. Is a ransomware virus that was first detected back in November and is now back with a new spam campaign In which the RIG-V exploit kit is used for infection. In proximity to Locky’s latest .osiris file extension, this virus is the other “big player” in the ransomware market, infection number of which can only be compared to Locky. In case you have become a victim of Cerber 5.0.1 ransomware, we urge you to be extremely careful in your actions. Suggestions are to read this article thoroughly and learn more about the updated Cerber 5.0.1 version and how you can remove it and protect yourself I the future.
|Short Description||The malware encrypts users files using a strong encryption algorithm, making direct decryption possible only via a unique decryption key available to the cyber-criminals.|
|Symptoms||The user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension .adk has been used.|
|Detection Tool|| See If Your System Has Been Affected by Cerber 5.0.1 |
Malware Removal Tool
|User Experience||Join our forum to Discuss Cerber 5.0.1.|
|Data Recovery Tool||Windows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.|
How Is Cerber 5.0.1 Distributed
A very specific detail about the Cerber 5.0.1 version is that the RIG-V exploit kit is used to aid undetected infection. This new modification and new exploit kit has several advantages over the traditional RIG-E (Empire Pack) exploit kit:
- Changed and new URLs.
- More obfuscation on the infection code.
- Higher RC4 encryption for payload obfuscation.
“Sales receipt is attached”
Attachment password is 2224
Ref no: 2244212.”
Upon typing the password, the user becomes infected via a malicious macro.
Further Analysis of Cerber 5.0.1
Similar to the conventional Cerber 5.0.1 version spotted back in November 2016, this Cerber iteration also can stop important system processes:
But these are not all the processes, Cerber 5.0.1 may attack. News broke out that the virus is also programmed to eliminate any database processes that are related to various databases, like MySQL, Oracle and Microsoft Access. The processes reported to be in the source code of the Cerber virus are the following:
The Cerber 5.0.1 ransomware may encrypt those processes primarily because they may stand in the way of it encrypting databases, one of the primary focuses of Cerber ransomware’s 5th versions in general.
Concerning file encryption, everything is so far unchanged. The virus still encrypts the many file-types It was initially set out to encipher:
For the encryption, not much is changed either. Cerber 5.0.1 attacks five blocks of the code of the victim file which are encrypted. The encryption method to encode those files is called RC4, and it works with a 256-bit strength. The algorithm used in combination with this method is reported to be RSA-512 bit cipher which is a very strong cipher, and it’s purpose is to generate a unique decryption RSA key. This key may be for a set of files or even each file. Then, the virus sends traffic information to the command and control servers of the cyber-criminals which help it to communicate with them and probably send decryption information.
Just like the other Cerber iterations, this one also encrypts the files and changes their names as well as their file extension to a random one:
After encryption has completed, this Cerber version also makes sure to drop it’s typical _README_.hta type of file which’s purpose is to inform victims of the situation and provide a web link to a “Cerber Decryptor” web page:
Remove Cerber 5.0.1 Ransomware Virus and Restore the Files
If you have had the bad luck of becoming a part of the Cerber 5.0.1 ransomware community, then your options are very limited, and you should act fast. The first suggested course of action is not to pay any ransom and follow the instructions below to get rid of the Cerber 5.0.1 version. In case you do not have experience with malware, it is recommended to download an advanced software that will automatically take care of the removal for you.
After having deleted Cerber 5.0.1 completely, you can now focus on restoring your files. First, it is recommended to make several copies of the encrypted data, since this Cerber version may damage your files if you try to decrypt them yourself. This Is why it is good to use “dummy” copies of the files.
To try and decipher the files that have been encrypted by Cerber, we advise you to focus on seeing the alternative tools we suggested in step “2. Restore Files Encrypted by Cerber 5.0.1” below. They may not be fully effective, but users report on our forums and comments to have restored at least a small portion of the files this way. Also, it is a good temporary solution until a decryptor for Cerber may be released in the future for free, which, If happens, we will post instructions and link them in this article for you to follow.
Manually delete Cerber 5.0.1 from your computer
Note! Substantial notification about the Cerber 5.0.1 threat: Manual removal of Cerber 5.0.1 requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.