Can anyone help me?
I seem to have been affected by the Cerber Ransomware 4.1.5
What do I do? They say I have to buy the decryptor!!!
I have done a quick search on my files and apparently they all show random numbers/letters followed by the same suffix:
.be5c
Note: (a dot before the “b”)
Thank you for your question; as we can see, you have just become a victim of a ransomware attack. Unfortunately, we have to disappoint you and say that Cerber 4.1.5 is currently not decryptable. However, you should not lose your hope and be patient; this is one of the most active computer viruses nowadays, and there are hundreds of computer users who complain about it. Therefore, malware researchers do their best trying to crack this virus and build a free decryption tool that everybody could use.
Cerber 4.1.5 is a modification of the fourth virus version. The fourth version creates a specific file extension for each victim and appends it to encrypted data after the distorted filename.
Do you have any backups? Maybe you have some important files in DropBox, USB, removable hard drive or elsewhere? You can use these to recover at least part of your files. The virus authors are trying to blackmail you and convince you to buy a Cerber Decryptor from them; however, there is NO guarantee that it works. You might just lose your money if you pay that ransom. Therefore, we do not recommend you to pay it.
Before trying to recover your files (if you do not plan to pay the ransom), remove Cerber 3.1.5 virus. Otherwise, it might encrypt these healthy files from a backup as well. You can find more information about this virus in the article that we have prepared: Cerber 4.1.5 ransomware virus. How to Remove? (Uninstall Guide).
We recommend using FortectIntego software for Cerber removal.
Can the values of the crypted file and the decrypted one be compared to find the decryption key??