The fresh news about SerbRansom virus
SerbRansom virus (also known as SerbRansom 2017) is a recently emerged ransomware[1] which is not only capable of encrypting files but also spreads some political ideas. The developer of this virus is the ultranationalist hacker from Serbia which is known under the name R4z0rx0r. The developer is also associated with creating “Google Dorker for SQL Injection” app for hacking Croatian websites and developing other shady applications. However, at the moment of writing this brand new ransomware is not a hazardous cyber threat and haven’t started spreading widely yet. SerbRansom ransomware uses AES[2] encryption algorithm to damage targeted files on the computer and appends .velikasrbija file extension. However, added extension may change because malware is created via builder which allows modifying various settings of the ransomware. Hackers can use this tool to change the list of targeted files, Bitcoin wallet ID, contact email address, camouflage ransomware binary files, and the decryptor necessary for the data recovery. Distribution methods of the SerbRansom malware are still unknown; however, it is expected to use traditional infiltration methods[3].
SerbRansom 2017 virus behaves like an ordinary file-encrypting virus. Once data encryption is over, it drops a ransom note. However, this ransom-demanding message is quite unique because in the background it plays a Serbian national song[4] associated with “Kosov in Serbia” movement. The ransom note includes personal information about the victim: username, PC name, and IP address. Hacker asks to pay 500 USD in Bitcoins and send a screenshot of the transaction via provided email address. Cyber criminals use terrifying tactics to encourage people to rush with the payment. According to the ransom message, the virus deleted one random file after every 5 minutes. Even though it’s a lie, victims should not let this cyber threat to stay long on the computer. It’s important to perform SerbRansom removal immediately. The best way to terminate the virus is to run a full system scan with FortectIntego or other reputable anti-malware software. We want to point out that automatic removal is the only one safe option to terminate the virus from the computer. Do not try to remove SerbRansom 2017 manually. It’s a tough task, and you may damage your machine even more.

How can you get infected with ransomware?
SerbRansom virus hasn’t started spreading actively; therefore, its distribution methods are still unclear. However, the developers of the ransomware probably use the same strategies as other hackers. Hence, if you want to avoid malware and protect your data from the encryption, you should learn about the most popular ransomware distribution methods. The highest chances to encounter ransomware is to open a spam email and its malicious attachment. Malware often is obfuscated as safe-looking Word or PDF files, and the content of the email gives misleading reasons to open it. Moreover, some examples trick users into installing bogus software or its updates by providing misleading online ads. Bear in mind that malware-laden ads may be delivered on the legitimate websites too. However, browsing on unsafe websites might end up with ransomware attack as well. Therefore, if you want to avoid SerbRansom 2017 or other viruses, you should be attentive and take all necessary precautions[5] when using the computer.
What should you do if you got infected with SerbRansom ransomware virus?
After malware attack, you should think about anything else but SerbRansom removal. Keeping ransomware on the computer may lead to the data loss or cause another malware attacks. Virus removal requires employing a strong and reputable malware removal tools such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If you cannot install security tools or scan the system, reboot your computer to the Safe Mode and try again. Unfortunately, it’s not enough to remove SerbRansom to get back access to your files. For that, you will need to use data backups or try additional data recovery methods presented below.
Did this guide help?
3 comments
Migel
500 USD???? Are they crazy??? Greedy hackers!
Sue
hopefully, the virus wont start spreading worldwide. We have so much cyber threats already :/
user78
Please, stop creating file-encrypting viruses!!