Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2016

How to remove Cerber 5.0.1 ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Lucia Danes · Virus researcher

Cerber continues to evolve: Cerber 5.0.1 version has been unleashed

New Cerber 5.0.1 ransomware — another malicious file-locking virus has just surfaced the web. In fact, this is the latest version of the notorious Cerber virus family which has been announced as one of the most active and profitable ransomware businesses this year. It is interesting that this new variant of Cerber has appeared almost simultaneously with the release of the new Locky virus version, which gives us a sense of competition between the two. This is, perhaps, the very reason Cerber developers have decided to put up a new variant of the virus just a few days after Cerber 5 was released. These programs are not even that different. Both of them infiltrate computers with the help of the new RIG-V exploit kit (also employed for Locky distribution) and use RSA and AES encryption algorithms to lock the victim’s data. The file types that the virus targets are the same as well — images, Office document, archives, etc. As in all of its previous versions Cerber 5.0.1 malware does not change the payment and the decryption sites either, although their links that are normally provided in the ransom note are different. What also differs is the sum that the hackers demand for the private data decryption key, but it fluctuates not only with different virus versions but with each individual case of infection. The extortionists may adjust its size according to the importance and volume of the encrypted files. As with any of the previous cerber versions, our advice remains the same — do not allow the attackers get rich and don’t pay the ransom! Let reputable antivirus software like FortectIntego to remove Cerber 5.0.1 from your PC and let the hackers have a taste of their own bitter medicine.

Illustration of the Cerber 5.0.1 ransomware virus

The defining feature of almost all ransomware viruses are usually the extensions or prefixes they add to the encrypted files. A variety of extensions allow differentiating between different viruses and virus versions. This feature is a little more complicated with Cerber 5.0.1. This malware jumbles the file names AND the extension completely randomly, so if your files are marked with .adk extension, this does not mean that other victims’ computers are marked the same. However, after the file encryption is done, all of the virus versions will drop a .png image on the computer and replace the desktop with it. In this picture, the extortionist explain what data decryption steps should the victim take in order to regain his/her files. As we have already mentioned, you should only pay in the most critical situation and even then consider very carefully whether you want to support the evil-minded criminals in their further activities by sending them your money?

Prevention against ransomware techniques:

Protecting your computer from Cerber 5.0.1 full 100% is virtually impossible. Antivirus tools do not always detect the obfuscated .hta, .html or .htm files which the virus uses to deploy ransomware on the computer. Thus, to keep personal data secure it is necessary to keep and regularly update backup copies of the files. External storage devices, USB’s, CD’s and other devices that are disconnected from the computer. The devices that are plugged in can easily be infected with Cerber 5.0.1, so you should unplug these storage drives after the backup transfer. Keep in mind, though, that data recovery from these drives should only be attempted when the virus is eliminated from the computer.

Cerber 5.0.1 removal tips:

If you are a victim of Cerber 5.0.1 virus, don’t trust ransomers propositions to recover your files. There are no guarantees that the decrypter will be functional and unlock the access to your files. Instead, remove Cerber 5.0.1 and try to recover data from backups or using alternative data recovery instructions we present below the article. To recover the files securely, you need to take care of the Cerber 2.0 removal first. Since this virus tends to hide on the system, we recommend approaching its removal with some professional antivirus utility at hand. If you can’t get this utility running, check out the virus decontamination instructions below. These will help eliminate the harshest of the ransomware functionalities and allow you to proceed with the virus removal.

 

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.