cuteRansomware uses Google Docs to store victim’s data:
cuteRansomware virus originates from a Chinese open-source experiment called my-Little-Ransomware. The developers of this new virus have modified the simple code of the experimental ransomware to create something a little bit more dangerous. The virus is primarily targeted at Chinese audience though it might easily spread throughout other countries as well. It is different from other viruses of the same category because it uses never-before-tried methods of storing the victim’s data and the file decryption key. For that, it uses Google Docs, which is also used as the virus’s Command and Control server as well. We should remind you that the decryption key is essential for the file recovery after the virus encrypts the data on the hijacked computer using complex, military-grade algorithm, depriving the user of accessing it. Without this key, the file decryption is virtually impossible. We should point out that Google Docs is not the only cloud-based platform that can be used for spreading ransomware. Other cloud systems can easily be exploited as well which is a great challenge to the cyber security experts. The major problem with such cloud-based viruses is that they transfer data via SSL, making the antivirus systems, firewalls and other virus prevention measures practically powerless. Although you can attempt the cuteRansomware removal using FortectIntego or other reputable anti-malware utilities, you might require some additional help from a professional.

Besides the intricate way the cuteRansomware makes use of the virtual platforms, it works the same as the majority of similar infections. The virus encrypts the files using RSA cipher and appends an “.encrypted” extension to the infected documents. The ransom note that pops up on the victim’s screen after the encryption is done and the extensions that change the regular ones are all in Chinese, which confirms the theory of this virus being specific country-boud. It is not clear what is the demanded payment for the files and what payment system do the criminals use. It is certain, though, that any collaboration with cyber criminals can end up in financial loss, and there is a high chance that the encrypted data will be lost too. Unfortunately, there is no way to eliminate the damage made by the virus, but you can remove cuteRansomware and the malicious files it creates in the %TEMP% directory from your computer.
How can you avoid being infected with this virus?
This malicious application spreads mostly through random downloads. The downloaded programs that are infected with cuteRansomware’s malicious script activate it and create conditions for data encryption. Because of the nature of this virus, there is really nothing that can be done stop the infection. Thus, if the infection cannot be avoided, you have to protect your data some other way. The most guaranteed way to do that is by making extra copies of your files. Backups can be stored on some external drives, including USB, DVD, CD and other devices which should be unplugged from the computer while they are not in use.
Dealing with the cuteRansomware removal:
Unfortunately, since this virus is relatively new and uses unconventional techniques to operate, there is no to clearly developed way to remove cuteRansomware from the computer. Though, you can still try eliminating this infection using the usual ransomware removal methods. The automatic virus-fighting utilities should be able to take care of the cuteRansomware removal, yet, as we have already mentioned, the successfulness of this method is not guaranteed. That is why it is crucial to create backups of your files before this infection hits your computer.
Was this guide helpful?
3 comments