Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Feb 2020

How to remove Cezar ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Linas Kiguolis · Expert in social media

Cezar ransomware is a file-locking infection that compromises Run and RunOnce keys to execute during Windows boot

Cezar malware

Cezar ransomware is a file-encrypting virus that can cause the loss of all files on the targeted machine. It is the continuation of the infamous Dharma ransomware[1] and has emerged in August 2017. The malicious program[2] encrypts all data by adding a specific file extension that includes the victim’s ID number, cybercriminals' email address, and either .cezar or .cesar file extension. Cezar virus encrypts all the data that is found on the infected Windows computer system, including pdfs, Microsoft Office documents, images, audios, videos, virtual drive files, and more.

It then drops the ransom note called HELP.txt which urges users to contact the cybercriminals via email gladius_rectus@aol.com or gladius_rectus@india.com. Users must pay the ransom in Bitcoin to get their data back, otherwise, it will be left blocked forever. At least this is what the cybercriminals want you to believe. However, staying away from ransom payments would be a wiser choice than accepting them as the crooks might try to scam you.

Users on Reddit have been complaining about Cezar ransomware virus rooting in their systems and supposedly compromising the RDP configuration to get in.[3] Also, security researchers have already noticed that the ransomware virus is delivered via Necurs botnet through phishing email messages and their infectious attachments. Nevertheless, some people have seen this ransomware provided as RaaS on the Dark Web's market where anyone who wants to play with the malware and infect potential victims can purchase it for a specific price.

SUMMARY
Name Cezar
Type Ransomware virus/malware 
Family Dharma ransomware
First discovered This cyber threat was first spotted in August 2017 and has emerged again in 2020
Encryption The ransomware virus employs a unique encryption cipher such as AES to lock up all files, folders, and documents found on the Windows computer system. Afterward, the .cezar or .cesar appendix is added to each filename
Ransom note The malware provides the HELP.txt ransom note, after the encryption, that includes crooks' email addresses: gladius_rectus@aol.com or gladius_rectus@india.com
Related files When the malware infiltration process happens, Cezar virus can bring files such as notepad.exe, svchost.exe, setup.exe, patch.exe, update.exe, and software-update.exe and install them in the system
Modules The newly-updated version of Cezar ransomware might be capable of tracking user activity, harvesting private details, etc.
Distribution Spreading of this parasite relies on various different techniques such as phishing email messages and their malicious attachments, botnets and other malware, cracked software such as key generators or fake setups from torrenting networks, vulnerable RDP settings
Removal If you have been dealing with this malware lately, you should take action against it ASAP. Our recommendation would be to employ a reliable antimalware product that will be capable of dealing with the ransomware virus
Data recovery There is no official decrypter released for .cezar or .cesar files at the moment. However, our security experts have provided some alternative data recovery tools that you can find at the end of this article
Fixing tool If your computer system has experienced some type of damage, you can try fixing things with the help of software such as FortectIntego 

When Cezar ransomware appears on the targeted Windows computer, it heads for the Run and RunOnce keys that allow the payload to execute every time when the machine is turned on. Furthermore, the malware might include some files in the system, for example, notepad.exe, svchost.exe, setup.exe, patch.exe, update.exe, and software-update.exe. Following a successful computer infiltration and data encryption, Cezar ransomware drops a ransom note that contains a short message from criminals to the victim:

To decrypt files, write to my email gladius_rectus@aol.com

This short Cesar ransomware ransom note is provided in a simple .txt file named “HELP.txt.” However, it’s quite an unusual ransom message because it does not include any information about data recovery possibilities and how it may cost for the victims. It is clear why cybercriminals do not want to reveal the final price of the ransom – they might be open to negotiations with potential victims. In addition, different versions of Cesar malware might be adding one of the following file extensions to encrypted files:

  • .id-.[JasonStewem@aolonline.top].cesar;
  • .id-.[btc2017@india.com].cesar;
  • id-.[bonum_malum@aol.com].

However, even though Cezar ransomware developers do not provide any particular information about the ransom price, most of the demands vary from $100 to $2000 or even more and need to be transferred during a particular time period. Also, criminals are very likely to urge for some type of digital currency such as Bitcoin as this type of cryptocurrency allows the hackers to stay safe from tracking and keep their identities a secret.

Cezar ransomware

A big problem with .cesar ransomware is that it is capable of deleting Shadow Volume Copies by executing specific PowerShell command. Sadly, the Shadow Copies are necessary for recovering files using third-party software and criminals seek to make this data recovery method not work for the victims. Currently, the official decryptor for .cezar and .cesar files is not released yet. However, some versions of Dharma are already decryptable.[4] Thus, there’s hope.

If this ransomware has hit your computer, we strongly recommend using a decent antispyware product to remove Cezar ransomware from the system. Once you eliminate the ransomware virus and all the malicious payload that was brought to the computer as a result of the dangerous infection, you might be interested in tools such as FortectIntego or SpyHunterCombo Cleaner if there are any corrupted areas on the Windows device as this type of software might help to fix them. 

You should not put Cezar ransomware removal aside because it is a highly important task that you must complete. Only after deleting the virus from the system you will be able to use it again securely. The reason why we recommend using the automatic spyware/malware removal tool is that some viruses spread in tandem with other severe malware variants such as Trojans or keyloggers and you will need strong software to deal with all these potential cyber threats.

Update 2020: Cezar (Dharma) ransomware searching for targets in Italy

According to security researchers, Cezar ransomware that was first discovered in 2017, decided to renew its activities in 2020. This time malicious actors are targetting people who live in Italy by delivering them malware-laden payload through email spam that contains VBS (Visual Basic Scripts).

Furthermore, investigations have provided results that Cezar virus includes improved functionality but uses the same operating principle as earlier. The ransomware virus employs a cipher such as AES and locks up all the components that are found on the infected Windows PC. However, researchers have found out that the malware was added with some complex modules and now might be capable of these activities:

  • Cybercriminals can have the ability to track victims and their computers.
  • The malware might be programmed to hijack the users' activities.
  • The virus can include harvesting of personally-identifiable information from the infected device.

Cesar virus

Methods used for malware distribution

According to LesVirus.fr experts,[5]Dharma ransomware variants usually employ traditional malware distribution techniques for proliferation. Most of the time it arrives as a malicious email attachment[6] that needs to be opened by the computer user in order to be run. To convince the victim to open the document, criminals spoof the sender’s address and rename the malicious file as invoice, a message from courier, receipt, or another important document that might interest the potential victim.

Furthermore, ransomware viruses can also get spread through other malware forms such as trojans and botnets and be downloaded as a regular file at first until the embedded macros are enabled. However, this is still not all about the possible distribution techniques of file-encrypting viruses. These malicious threats can get infiltrated through hacked RDPs. Hackers usually steal the password or search for unlocked configuration and connect to the computer system remotely.

In addition, ransomware is often uploaded on torrenting websites that are filled with game cracks, key generators, fake setups, and various questionable files that look harmless only from the first view. Since you have learned about the distribution tactics of ransomware viruses, it would be recommendable to also learn about their prevention:

  • Always investigate your received email. Check the sender, view the content for possible grammar mistakes, and measure the expectancy of such message. Also, do not open any questionable attachments without scanning them with an antimalware program.
  • Avoid visiting peer-to-peer networks. Make sure that you get all of your products and services from official sources. It is better to pay more than to deal with malware and its consequences later.
  • Install reliable antivirus protection. If you do not already have antimalware software on your Windows computer, you should get one ASAP. Make sure that you keep this tool regularly updated.

Steps to take after Cesar virus attack

Cezar ransomware virus

Cezar ransomware removal is the first thing you should do when you discover that you are infected with this malware. Postponing the elimination might relate in more damage to your Windows computer system. Besides, you will not be able to recover your files properly with additional software until the parasite is residing on your device.

If you want to remove Cezar ransomware, you should rely on automatical software that would be able to delete with this parasite. However, if your antivirus tool is being blocked by the malware, you can try diminishing malicious processes on your Windows computer system by rebooting it in Safe Mode with Networking.

Furthermore, Cezar ransomware virus can have posed some type of harm on your device during the infection process or might have infiltrated additional malware to the system. To check for possible damage, use SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. If these tools find any compromised areas on the machine, you might have a chance of repairing them with software such as FortectIntego.

Video clip displaying Cesar ransomware removal

Cezar ransomware virus is a complex malware form that can be hard to eliminate if you have no understandings of how to complete the process and what tools to use for it. Our cybersecurity experts understand the struggle and decided to create some visual material that would be very easy for all users to understand. Look below and you will find the Youtube video:

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.