Gerber ransomware 1.0 – a new ransomware that uses old tricks

Gerber ransomware 1.0 is a cryptovirus that was newly discovered by an independent security researcher Petrovic.[1] The malware enters computers with the help of various distribution methods, including unprotected RDP,[2] spam emails, exploits, insecure sites, fake updates, and others. Soon after infiltration, it scans the computer for files to encrypt: videos, images, documents, and similar personal data. Once detected, the files get encrypted by a strong encryption algorithm and the .XY6LR extension added. Additionally, users can view a ransom note DECRYPT.txt inside each of the affected folders. Gerber ransomware 1.0 also opens a GRBR Decryptor program window, which contains the instructions on what to do next. Users are urged to email cybercriminals via the sobachka_thaabah@india.com.
| SUMMARY | |
| Name | Gerber ransomware 1.0 |
| Type | Crypto virus |
| File extension | .XY6LR |
| Ransom note | DECRYPT.txt, GRBR Decryptor |
| Decryptable? | No |
| Elimination | It is yet unknown which AVs detect the threat, but we recommend trying FortectIntego or SpyHunterCombo Cleaner for the elimination |
It is not much known about Gerber virus yet. However, it is clear that bad actors seek to extort money from innocent victims, similarly to other ransomware authors. Typically, victims are asked to pay as much as a few thousand dollars in Bitcoin or another crypto for file decryption. Experts do not recommend contacting criminals and remove Gerber ransomware 1.0 instead. We suggest using comprehensive anti-malware solutions like FortectIntego or SpyHunterCombo Cleaner.
After the Gerber ransomware detects files that it was looking for, it modifies its name the following way: [filename].[extension].XY6LR. Therefore, a picture.jpg is turned into picture.jpg.XY6LR. From that point, users are unable to gain access to any of the encoded files and need to get a decryptor to do so. Unfortunately, at the time of the writing, no decryptor has been created yet, and victims can only rely on backups or third-party software for file recovery.
The ransom note of Gerber ransomware 1.0 states the following:
Gerber Ransomware 1.0
Sorry, your computer was blocked by Gerber Ransomware 1.0.
If you want to restore, follow the steps:
(You can have a mail and file Decrypt.TXT)
- Send to the mail:sobachka_thaabah@india.com file: Decrypt.TXT
- Follow the message-instruction
- Get guarantees
- Decrypt files
Personal id: [redacted]
It is unknown what kind of guarantees crooks are talking about, but, as we already said, do not trust these people. They might simply not send you the key, and keep the money. Alternatively, Gerber ransomware 1.0 authors might send you malware instead, infecting your machine further.
You should perform Gerber ransomware 1.0 removal before trying to recover your data. In case you connect your backup device before the virus is eliminated, all your backup files will be encrypted as well.

Be aware that unsafe browsing can lead to malware infection
There are various ways how people can infect their computers with malware. However, users need to interact with the malicious payload in one way or another, because viruses don't just appear on the machine one day – they need to follow a specific set of instructions that are set by cybercriminals.
One of the most prominent ransomware distribution methods is spam emails. Bad actors employ bots to send out thousands of emails to unsuspecting users. The message either includes an attachment or a link that would redirect to a malicious site. The author of the email uses social engineering to make users click on the hyperlink or execute the attachment.
Other ransomware transmission methods include:
- Exploit kits;[3]
- Unprotected RDP;
- Torrent files;
- Fake updates;
- Etc.
To make sure you avoid malware, you should install reputable security software, patch your system immediately after updates are out, use strong passwords, and avoid suspicious websites, as well as not click on random pop-ups.
Eliminate Gerber ransomware 1.0 by using anti-malware software
Gerber ransomware 1.0 removal should not be performed manually, as malware is complicated and embeds itself deep within system files. Regular users should rely on reputable security software to get rid of malware. To make sure that the process is smooth, you should enter Safe Mode with Networking as explained below. Additionally, you can try System Restore to stop the virus.
As soon as you remove Gerber virus, you can then proceed with file recovery procedure. You should restore your files from a backup or try alternative methods the instructions for we provide below.
Note: if you failed to recover your data, keep the copies of it. Security experts work on decryptors continually. Therefore, the one for Gerber ransomware 1.0 can be created at any time.
Did this guide help?
Be the first to comment