Cadq ransomware – a file-locking computer infection that demands a ransom in cryptocurrency

Cadq ransomware is a cryptovirus created to encrypt non-system files on an infected computer and demands a ransom in Bitcoins for a decryption toolkit. It does that through a generated ransom note named _readme.txt, where criminal instructions and demands are presented. During the encryption, all personal data, such as documents, pictures, archives, etc., is renamed by appending a .cadq extension. For example, a file called “1.pdf” would be turned into “1.pdf.cadq.”
Like all Djvu family ransomware members, this virus alters the system registry, files, and other core system settings to establish persistence. That makes its elimination troublesome but not impossible. If your machine got infected with this file-locker, you came to the right place to find out how that might have happened, how to evade such perils, and how to get rid of it.
The main goal of the threat actors is to push their victims into contacting them via two given emails (helpteam@mail.ch and helpmanager@airmail.cc) and to make them pay the ransom ($490/$980). Fortunately, companies are dedicating their work to help ransomware victims. Please don't pay the criminals, as there might a way to recover your files without spending a dime.
| name | Cadq ransomware |
|---|---|
| Type | File-locking virus |
| Family | Djvu |
| Ransom note | _readme.txt |
| Ransom amount | The original ransom sum is $980. If victims contact criminals within 72 hours, a 50% discount is applied to lower the price to $490 |
| Appended file extension | .cadq |
| Distribution | File-sharing platforms, software cracks |
| criminal contact details | Assailants provide two emails to get in touch with them – helpteam@mail.ch and helpmanager@airmail.cc |
| Malware removal | Trustworthy anti-malware tools should be used to safely eliminate this ransomware along with any other malware or junkware |
| System repair | File-lockers alter system files, services, and settings, which could cause various system irregularities or even infection renewal. Use the powerful FortectIntego system repair tool to fix all system inconsistencies |
The ransom note of the virus doesn't differ much from other versions of Djvu family ransomware. It contains an appointed user ID, two contact email addresses, a statement that only the criminals can decrypt locked data, and techniques to convince victims to jump to rash decisions and forward Bitcoins to the assailants:
- an offer to decipher one encrypted file for free,
- a hyperlink to a video where the supposed decryptor can be seen in action,
- a 50% discount on the ransom amount for victims that reach out to the threat actors within 72 hours of the attack.
The entire message, in the _readme.txt ransom note, reads:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-Wl6WKEBetp
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpteam@mail.chReserve e-mail address to contact us:
helpmanager@airmail.ccYour personal ID:
Djvu family file-lockers have been around for a while now, and it's still developing new infections each week. In fact, reports show,[1] that in the third quarter of 2020, almost 70% of all reported ransomware attacks were performed by cryptoviruses of this lineage. Here are some of the latest versions:
All variations have many similarities. Their ransom notes are practically identical. Contact emails almost never change. All recent versions use the RSA 2048 encryption algorithms,[2] and all of them alter system files and settings to establish persistence.

Due to their pervasiveness, some companies, like Emisoft, have dedicated themselves to helping ransomware attack victims by developing free decryption software. There's no guarantee that such a tool will work if your device is infected with Cadq file virus, but it won't hurt to try.
The only way to stop cybercriminals from spreading cryptoviruses is to stop paying ransoms. If the cash flow stops, the attacks will stop as well. Therefore, you should remove ransomware from your infected Windows devices. We suggest doing that with reliable anti-malware tools such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
As we've mentioned before, file-lockers alter various system settings and files, which may result in BSoD, freezing, severe lag, or even infection renewal. That's why cybersecurity experts at LesVirus.fr[3] highly recommend using the FortectIntego system diagnostics tool after all malware and its malicious files are eliminated from the system.
Djvu family ransomware are infecting computers of file-sharing platform users
Cybercriminals are actively exploiting users who try to cheat the system by downloading copyrighted software for free from file-sharing platforms, particularly the most popular torrent sites. Most of these portals don't have end-to-end security, meaning no one is inspecting the uploaded content.
This is one of the main reasons why threat actors are using these platforms to spread their creations. The other one is that they can reach broad audiences around the world. And the last one – there's not much work to do. Mainly, hackers just need to think of a catchy name that would lure the soon-to-be victims to download the camouflaged infection.
Our cybersecurity team has reported that most ransomware was disguised either as game cracks or pirated commercial software. But that doesn't mean that other torrents can be harvesting malware too. So please think twice before downloading anything from such websites, as you can get yourself in heaps of trouble.
Remove malware with security tools and run system diagnostics
Having your device infected with ransomware is no joke, and the action should be taken immediately. First off, please don't even consider paying hackers as that's the most risky thing to do. Ransom money would be used to infect more innocent people's computers and expand the hackers' illegal empire.

If you had a security tool, it clearly failed you by letting the cyber infection through. Get a trustworthy anti-malware tool that will be able to automatically remove Cadq ransomware from your device and protect it from such attacks in the future. We advise acquiring either SpyHunterCombo Cleaner or MalwarebytesMalwarebytes.
But before you eliminate the cryptovirus, give free Emisoft decryptor a go. Maybe you'll be lucky, and it will unlock your files. If not, try our suggestions at the bottom of the page. There you'll also find instructions on how to launch your device in safe mode if the file-locker prevents you from opening a security tool.
And last but definitely not least, after you get rid of the infection, you have to run system diagnostics because this infection probably altered key system attributes, such as the registry, host files, and so on. All these modifications could result in various abnormal pc behavior, such as crashing, freezing, or even infection renewal. To fix all system-related issues and get your device to a pre-contamination phase with a push of a button, we highly recommend using the powerful FortectIntego system tune-up tool.
Was this guide helpful?
Be the first to comment