Cceq ransomware is a dangerous malware that blocks access to all personal files until the ransom is paid

Cceq ransomware is a malicious program designed for Windows operating systems. Its main purpose is to encrypt all personal files on the system, including pictures, videos, documents, databases, etc. Suchlike data is modified in a way (but not destroyed!) that only a unique key can retrieve its functionality – a special marking also becomes visible, as .Cceq extension is appended at the end.
In order to restore data, users require the said key, which is stored on the cybercriminals' servers. They are obviously not willing to give it for free and demand that a ransom of $980 is paid in bitcoin, a digital currency often used by cybercriminals behind ransomware.[1] They provide two contact emails – support@bestyourmail.ch and supportsys@airmail.cc – for communication purposes, although contacting hackers is not advisable. All this information can be found in a ransom note dropped on the desktop, titled _readme.txt.
Cceq ransomware stems from the notorious Djvu malware family with hundreds of variants already in circulation. For example, we described Cceo, Ccyu, and Ccew just recently. While there is no guaranteed method of recovering your files, there are several things you can try instead of paying for a decryption key – we list all the methods below.
| Name | Cceq ransomware |
| Type | Ransomware, file-locking virus |
| Family | Djvu |
| Encryption | RSA is used to lock all personal files on the infected Windows computer |
| File extension | .cceq |
| Ransom note | _readme.txt |
| Contact | support@bestyourmail.ch and supportsys@airmail.cc |
| File recovery | While data recovery without paying cybercriminals is not impossible, it may be difficult. Check the solutions we provide below |
| Malware removal | To perform a full ransomware removal effectively, use powerful SpyHunterCombo Cleaner, MalwarebytesMalwarebytes anti-malware software |
| System fix | Malware can seriously tamper with Windows systems, causing errors, crashes, lag, and other stability issues after it is terminated. To remediate the OS and avoid its reinstallation, we recommend scanning it with the FortectIntego repair tool |
The ransom note
A ransom note is the first communication tool between the attackers and victims. Most ransomware is designed to show the note as soon as the file encryption process is finished. This guarantees that users would see what they can do to recover their data, increasing the chance of a successful payment.
Crooks also often use additional tricks to make them feel more trustworthy, for example, they offer a 50% discount, which reduces the payment to $490, as long as it is made within 72 hours of the infection. This is a typical trick to make users feel like they are running out of time, pushing them to pay the ransom. Here's the full message you would receive after being infected with the Cceq virus:
ATTENTION!
Don’t worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-sac7bmVIKJ
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.To get this software you need write on our e-mail:
support@bestyourmail.chReserve e-mail address to contact us:
supportsys@airmail.ccYour personal ID:
Despite the friendly demeanor, these people are not your friends, and they don't particularly care whether or not you restore your files after paying them money. While it is true that victims get recovery software, this outcome is never guaranteed. Besides, paying cybercriminals only enforces their position in the cybercrime world and justifies infecting more people, as it brings enough profits.

Instead, we recommend following through with the instructions below in order to restore .cceq files without paying money to cybercriminals. However, it is vital that the process is performed in the correct order.
Malware removal
Your first task is to ensure that the virus is removed from the system. While Djvu variants are known to self-destruct after performing the data encryption, they have been previously found with additional data-stealing modules, which need to be eliminated for sure. Likewise, ransomware may also be bundled with other infections, which are important to eliminate.
While manual removal can be possible, it is not recommended for regular users, as the risk of deleting incorrect files or failing to remove all malicious ones remains high. Thus, we recommend you employ a trustworthy solution instead – run a scan with SpyHunterCombo Cleaner or MalwarebytesMalwarebytes security software. This will ensure that all the malicious ransomware components are deleted, along with any secondary infections installed on the device.
Before you proceed with Cceq ransomware removal, you should first ensure that your system is terminated from a network and/or the internet. Proceed with the following steps:
- Type in Control Panel in Windows search and press Enter
- Go to Network and Internet

- Click Network and Sharing Center

- On the left, pick Change adapter settings

- Right-click on your connection (for example, Ethernet), and select Disable

- Confirm with Yes.
Recover your data
There are a lot of misconceptions about ransomware and the way it works – these are especially common among people who get infected with it for the first time. While some people believe they can restore their files back to normal after they remove the virus with anti-malware software, others think that the files have been permanently corrupted because they can't be opened at the time. Neither of these statements is true.
Ransomware uses a sophisticated encryption algorithm RSA[2] to lock files, which is extremely secure. The applied key is essentially a long string of alphanumeric characters which simply can't be guessed. The key is unique, so none of the affected users can share it to restore their files. So, malware removal will not affect the state of the encrypted data, and it will remain unusable.
Unfortunately, only ransomware authors have access to the decryption key. Using alternative known methods is the only way to go around this, and we strongly recommend you try them. First of all, you should make backups of the encrypted files, as they might get corrupted during the recovery process.
First, we recommend trying data recovery software that may work for at least some of your files:
- Download Data Recovery Pro.
- Double-click the installer to launch it.

- Follow on-screen instructions to install the software.

- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders which you want the files to be recovered from.
- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.

- Press Scan and wait till it is complete.
- You can now pick which folders/files to recover – don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.

Your other chance is by using the dedicated decrytpion software from Emsisoft. Keep in mind that it only works if your files were encrypted with an offline ID, which is usually not the case.
- Download the app from the official Emsisoft website.

- After pressing the Download button, a small pop-up at the bottom titled decrypt_STOPDjvu.exe should show up – click it.

- If User Account Control (UAC) message shows up, press Yes.
- Agree to License Terms by pressing Yes.

- After Disclaimer shows up, press OK.
- The tool should automatically populate the affected folders, although you can also do it by pressing Add folder at the bottom.

- Press Decrypt.

From here, there are three available outcomes:
- “Decrypted!” will be shown under files decrypted successfully – they are now usable again.
- “Error: Unable to decrypt file with ID:” means that the keys for this version of the virus have not yet been retrieved, so you should try later.
- “This ID appears to be an online ID, decryption is impossible” – you are unable to decrypt files with this tool.
Other tips
Once you are done with the other steps above, there are a few other tips that could result in a better outcome. First of all, you should remove the blocks that could have been applied via the hosts file – it may prevent visiting security-related websites.

To restore your ability to access all websites without restrictions, you should either delete the file (Windows will automatically recreate it) or remove all the malware-created entries. If you have never touched the “hosts” file before, you should simply delete it by marking it and pressing Shift + Del on your keyboard. For that, navigate to the following location:
C:\Windows\System32\drivers\etc\
You should also employ FortectIntego to repair any damage that could have occurred during the ransomware infection stage. Otherwise, you might start receiving BSODs,[3] registry errors, crashes, and similar issues once the infection is terminated.
We also recommend reporting the ordeal to your local authorities – it would help the investigation that could potentially lead to the malware creators' capture. This would also mean that all the encryption keys would be released to the victims for free. To avoid being a victim of a ransomware attack in the future, please make use of the data backup process.
Did this guide help?
Be the first to comment