Derp ransomware – the 176th version of the Djvu ransomware that is currently undecryptable

Derp ransomware, discovered by Michael Gillespie,[1] is one of the latest variants of the Djvu ransomware family that promotes file decryption by using a unique algorithm. Emsisoft reported[2] that they have released the STOP/Djvu decryption software that works for Djvu ransomware variants that have been released earlier than August 2019, so Derp virus still remains undecryptable as it uses a different decryption tool than its previous ancestors that were released before August. However, the activity principle is the same – alterings of the Windows Registry/Task Manager, encryption by adding a specific appendix (.derp in this case), ransom demands from $490 to $980 via the _readme.txt message.
| Name | Derp ransomware |
|---|---|
| Type | Ransomware |
| Family | Djvu ransomware (STOP virus) |
| Version number | Research shows that this malware is the 176th variant of the Djvu category |
| Appendix | Once files are locked with a unique cipher, they end up with the .derp appendix |
| Ransom message | The malware displays the _readme.txt message where crooks urge for $490 as a starter price if the money is transferred in 3 days and $980 if the victim goes over the time limit |
| File location | Malicious executables might be found in the %LocalAppData% or %AppData% directories. Additionally, the Windows Task Manager and Registry might also be filled with suspicious entries/files |
| Additional malware | STOP ransomware variants (this includes Derp virus) are known for distributing AZORult trojan |
| Discoverer | Michael Gillespie has announced his findings on Twitter social network |
| Elimination tip | Delete the ransomware virus automatically (find instructions at the end of this article). Afterward, try using FortectIntego to scan the computer for damage |
During installation, Derp ransomware will supposedly drop a malicious executable in the %LocalAppData% or %AppData% folder that is responsible for finding decryptable files on your Windows computer. Additionally, the malware can delete the Windows hosts file to prevent the user from accessing security-related forums and networks.
Nevertheless, you will supposedly find malicious entries and files in the Task Manager and Windows Registry added by Derp ransomware. This way the malware ensures that it will be automatically booted within every computer startup process. Additionally, some dropped entries might allow the malware to avoid being detected by security software.

If you have taken a good look to the _readme.txt ransom note, you will see that Derp ransomware developers are trying to threaten you that there is no other option of recovering your files instead of paying the demanded price:
ATTENTION!
Don’t worry, you can return all your files!
All your files like photos, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
https://we.tl/t-sTWdbjk1AY
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that’s price for you is $490.
Please note that you’ll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don’t get answer more than 6 hours.To get this software you need write on our e-mail:
gorentos@bitmessage.chReserve e-mail address to contact us:
gerentoshelp@firemail.ccYour personal ID:
The criminals urge for $490 if the ransom price is transferred in a three-day time period. However, if the victim is too late and decides to pay after 72 hours, he has to now transfer a doubled price. Derp ransomware urges a pretty big price here and our experts say that it is not worth paying such amount of money while there is a big risk of scamming.
The crooks also provide gorentos@bitmessage.ch, gorentoshelp@firemail.cc email addresses as a way to contact them. We suggest avoiding any contact possible and going straight for Derp ransomware removal. If you get scammed, it would be almost impossible to recover your money as hackers often urge prices in Bitcoin or another cryptocurrency that guarantees full anonymity.

After Derp ransomware is gone, you can try fixing the damage with software such as FortectIntego. However, note that the tool does not decrypt data. For that, travel to the end of the article and choose a method to try. Also, you can purchase DrWeb's Rescue Pack for $150 that includes decryption software that might be capable of recovering some data and also two full years of antimalware protection.
Vulnerable RDP configuration allows malware installation
Security experts from LosVirus.es[3] state that RDPs which include weak passwords or no password security at all are a very nice target for bad actors. These people hack the RDP[4] (for example, TCP port 3389) and connect to the targeted computer system by remote technique.
Even though this ransomware distribution method is a very popular one, there are other techniques that are not less popular. Criminals often drop questionable email messages to the user's inbox or spam sections. Sometimes, the crooks pretend to be from official shipping companies such as FedEx/DHL, banking firms, or healthcare organizations in order to give the look of a trustworthy email.
Afterward, users are encouraged to click on a particular hyperlink or open an infectious attachment where ransomware is hiding. Nevertheless, this still is not it. Hackers are capable of distributing malware via many other different sources! Unsecured p2p networks, outdated software, exploit kits, fake Flash Player updates, infectious downloading links and ads, gambling networks, porn sources – all these places are potential ransomware holders.
Avoiding ransomware and preventing system damage
Once you have learned about ransomware distribution techniques, it is about time to learn how to avoid these dangerous cyber threats. First of all, you should purchase reliable antivirus protection. You can find various user and expert reviews in forums and security pages where you might be able to choose the right tool for you. When you have the program, do not forget to update it when official upgrades are released.
Continuously, learn how to manage your email box. Delete all messages that fall to your spam section but also be careful with letters that appear in the inbox. Evaluate the expectancy of the email, check out the sender, and search the entire content for grammar/style mistakes. If you have a questionable feeling of the email, better delete it as any reputable company would manage to contact you in other ways, e.g. mobile phone.
Furthermore, avoid downloading movies and video clips from sources such as The Pirate Bay, eMule, and other torrenting networks as these websites provide software cracks that might be filled with dangerous viruses, including ransomware. Also, do not perform any software updates you are not aware of, keep all of your programs regularly upgraded, and keep a fair distance from all questionable online sources.
Derp ransomware removal guidelines
Derp ransomware removal needs to be performed as soon as you find .derp files on your computer system. Eliminating the virus on your own is not a possibility here. Keep in mind that reputable antimalware software is necessary if you are looking forward to a safety elimination process.
After you remove Derp ransomware, you can try downloading one of these tools: FortectIntego, SpyHunterCombo Cleaner, or MalwarebytesMalwarebytes. This software might help you to fix the damage that has been brought by the malware. Additionally, below you will find some data recovery techniques that might help you with file restoring.
When Derp virus is gone, you should start taking care of your future data. Purchase and USB flash drive and keep your data or at least copies of important files stored on the remote device in case of a repeated malware attack in the future.
Did this guide help?
Be the first to comment