The latest news about Cyber SpLiTTer Vbs virus
Cyber SpLiTTer Vbs virus appeared in September 2016, but it did not succeed. Malware does not behave like an ordinary ransomware[1] virus. It does not encrypt files on the attacked computer and only delivers a lock screen. However, it seems that the first failure was a motivation for the hackers to learn from the mistakes and updated the virus. A few months later, malware researchers spotted CyberSplitter 2.0 ransomware that can actually encrypt files using strong encryption algorithm. However, it is not the only one attempt to update Cyber SpLiTTer Vbs ransomware. On February 2017, malware researchers have noticed two new variants of the virus. The one version pretends to be from the FBI and delivers a fake message that victim’s computer has been locked. Another variant is known under Blue Eagle name and informs people that their computer has been hacked. It seems that hackers try their best to finally create a powerful cyber threat and swindle as much money as possible[2] from the computer users. However, we highly recommend not paying the ransom and concentrating on Cyber SpLiTTer Vbs removal. It doesn’t matter which variant has attacked your machine, install reputable antivirus program or malware removal tool and run a full system scan. If you need advice, choose FortectIntego for ransomware removal.

As we mentioned at the beginning, SpLiTTer Vbs virus does not behave as typical ransomware. It does not encrypt targeted files; it only delivers a lock screen. What is interesting that Cyber SpLiTTer Vbs ransomware tries to copy the techniques of infamous Cerber virus[3]. For example, after the attack, the virus plays an audio message saying “your pictures, videos, and databases have been encrypted.” Apart from hearing the scary message, victims also see the lock screen message informing about encrypted files and demanding 1 Bitcoin for data decryption:
Your files have been encrypted
Send $ 1 BTC amount of the account is decrypted your files
“Cyber SpLiTTer Vbs”
Send to Account Bitcoin ->
As you can see, crooks are not very educated, and the information on the ransomware lock screen is full of mistakes. However, the virus is not precisely developed, and it seems that its authors are low-level programmers who haven’t mastered software development skills well enough to create a code that could corrupt victim’s files. Obviously, you should not pay the ransom because your data is free – you just need to remove Cyber SpLiTTer Vbs ransomware from the system.
Variants of Cyber SpLiTTer Vbs ransomware
CyberSplitter 2.0 ransomware. Developers updated the virus, and now it can actually encrypt targeted files. After infiltration, malware encrypts files using AES and RSA encryption algorithms and appends .cyber splitter vbs file extension. Following data encryption malware also leaves a ransom note called Read_Me.txt which includes all necessary information about date decryption. Developers of the ransomware also demand 1 Bitcoins for data recovery. What is more, the second version of the Cyber SpLiTTer Vbs virus also plays the same audio file scare and convince victims to pay the ransom.
Your Computer Has Been Locked. On February 2017 malware researchers noticed a new version of the virus that pretends to be from FBI. Malware delivers a lock screen that informs that attacked computer was suspended because its owner visited pornographic websites, violate the intellectual property right, published malware or commit other crimes. The lock screen also includes what punishment victim can expect if he or she won’t pay the ransom of 0,5 Bitcoin.
Blue Eagle Ransomware. On February 2017, another variant of Cyber SpLiTTer Vbs ransomware has been noticed attacking home computer users and informing that their files have been Crypted by Saher Blue Eagle. Malware appends the .blueeagle file extension to the targeted data and demands to pay 0,5 Bitcoins for the decryption.
How does ransomware spread?
Ransomware is a computer pest that is mainly distributed using Trojan horse[4] technique. It means that cyber criminals create a file that looks entirely safe and inject malicious codes into it. Such file can be a document, PDF file, archive, or a different type of file as well. The most popular way to deceive victims is to send a phony email message[5] to them, stating that relevant files have been attached to the letter, and the victim must open them to see the information they provide. Of course, once the victim opens such malicious attachments, malware roots into the system and wreaks havoc there. Be careful because criminals can pretend that they are sending invoices, speeding tickets, health test results, and the like. It is highly recommended to delete emails that come from unknown senders; besides, it is also advisable to keep all your software up-to-date and protect the system with anti-malware software because there are numerous other malware distribution techniques that crooks use.
The safe way to Cyber SpLiTTer Vbs virus from the computer
If you have been attacked by Cyber SpLiTTer Vbs virus, you will need to clean the computer using anti-malware software such FortectIntego or SpyHunterCombo Cleaner. Firstly, you will have to reboot the PC into Safe Mode and download anti-malware tool (if you do not have one yet). If you have never attempted to start your PC in such mode, please follow Cyber SpLiTTer Vbs removal instructions provided below this post. When you remove Cyber SpLiTTer Vbs ransomware, do not forget to take security measurements and protect your data in advance – back up most important files and move them to a safe removable storage drive so that you can use it in the future. It is the most efficient way to protect your important files because typically when a really powerful ransomware attacks the computer, data cannot be restored in any way.
Was this guide helpful?
6 comments