The Cerber3 Ransomware a new updated version of the Cerber Ransomware
which has performed a 2.0 evolution in August 2016. The point different from
Cerber 2 is that the new variant appends the .cerber3 extension to encrypted
files. You will see your file of jpg picture turn into XXX.jpg.cerber3. The
encrypted files contains messages which demands you pay ransom about 0.7154
Bitcoins (nearly $410) for restoring your files. If the money is not sent out
within 96 hours the ransom will rise to 1.4308 Bitcoins.
Is it Possible to Decrypt Encoded Files without Ransom Payment?
No, unless pay ransom. However, it encourages more cyber crimes. Professionals are not able to break the 32-byte key which has a very long length.
Name:
|
Cerber3 Ransomware
|
Category:
|
Ransomware, Encrypted Files Malware
|
Family Members:
|
Cerber
Ransomware, Cerber2 Ransomware
|
Infected PCs:
|
82
|
encryption algorithm:
|
RSA-2048
key (AES CBC 256-bit)
|
Encryption
|
Use CryptGenRandom which is a Microsoft API to encrypt
the user's files
|
Targeted Files:
|
1CD, .3DM, .3DS,
.3FR, .3G2, .3GP, .3PR, .7Z, .7ZIP, .AAC, .AB4, .ABD, .ACC, .ACCDB, .ACCDE,
.ACCDR, .ACCDT, .ACH, .ACR, .ACT, .ADB, .ADP, .ADS, .AGDL, .AI, .AIFF, .AIT,
.AL, .AOI, .APJ, .APK, .ARW, .ASCX, .ASF, .ASM, .ASP, .ASPX, .ASSET, .ASX,
.ATB, .AVI, .AWG, .BACK, .BACKUP, .BACKUPDB, .BAK, .BANK, .BAY, .BDB, .BGT,
.BIK, .BIN, .BKP, .BLEND, .BMP, .BPW, .BSA, .C, .CASH, .CDB, .CDF, .CDR,
.CDR3, .CDR4, .CDR5, .CDR6, .CDRW, .CDX, .CE1, .CE2, .CER, .CFG, .CFN, .CGM,
.CIB, .CLASS, .CLS, .CMT, .CONFIG, .CONTACT, .CPI, .CPP, .CR2, .CRAW, .CRT,
.CRW, .CRY, .CS, .CSH, .CSL, .CSS, .CSV, .D3DBSP, .DAC, .DAS, .DAT, .DB,
.DB_JOURNAL, .DB3, .DBF, .DBX, .DC2, .DCR, .DCS, .DDD, .DDOC, .DDRW, .DDS,
.DEF, .DER, .DES, .DESIGN, .DGC, .DGN, .DIT, .DJVU, .DNG, .DOC, .DOCM, .DOCX,
.DOT, .DOTM, .DOTX, .DRF, .DRW, .DTD, .DWG, .DXB, .DXF, .DXG, .EDB, .EML,
.EPS, .ERBSQL, .ERF, .EXF, .FDB, .FFD, .FFF, .FH, .FHD, .FLA, .FLAC, .FLB, .FLF,
.FLV, .FLVV, .FORGE, .FPX, .FXG, .GBR, .GHO, .GIF, .GRAY, .GREY, .GROUPS,
.GRY, .H, .HBK, .HDD, .HPP, .HTML, .IBANK, .IBD, .IBZ, .IDX, .IIF, .IIQ,
.INCPAS, .INDD, .INFO, .INFO_, .INI, .IWI, .JAR, .JAVA, .JNT, .JPE, .JPEG,
.JPG, .JS, .JSON, .K2P, .KC2, .KDBX, .KDC, .KEY, .KPDX, .KWM, .LACCDB, .LBF,
.LCK, .LDF, .LIT, .LITEMOD, .LITESQL, .LOCK, .LOG, .LTX, .LUA, .M, .M2TS,
.M3U, .M4A, .M4P, .M4V, .MA, .MAB, .MAPIMAIL, .MAX, .MBX, .MD, .MDB, .MDC,
.MDF, .MEF, .MFW, .MID, .MKV, .MLB, .MMW, .MNY, .MONEY, .MONEYWELL, .MOS,
.MOV, .MP3, .MP4, .MPEG, .MPG, .MRW, .MSF, .MSG, .MYD, .ND, .NDD, .NDF, .NEF,
.NK2, .NOP, .NRW, .NS2, .NS3, .NS4, .NSD, .NSF, .NSG, .NSH, .NVRAM, .NWB,
.NX2, .NXL, .NYF, .OAB, .OBJ, .ODB, .ODC, .ODF, .ODG, .ODM, .ODP, .ODS, .ODT,
.OGG, .OIL, .OMG, .ONE, .ORF, .OST, .OTG, .OTH, .OTP, .OTS, .OTT, .P12, .P7B,
.P7C, .PAB, .PAGES, .PAS, .PAT, .PBF, .PCD, .PCT, .PDB, .PDD, .PDF, .PEF,
.PEM, .PFX, .PHP, .PIF, .PL, .PLC, .PLUS_MUHD, .PM!, .PM, .PMI, .PMJ, .PML,
.PMM, .PMO, .PMR, .PNC, .PND, .PNG, .PNX, .POT, .POTM, .POTX, .PPAM, .PPS,
.PPSM, .PPSX,.PPT, .PPTM, .PPTX, .PRF, .PRIVATE, .PS, .PSAFE3, .PSD,
.PSPIMAGE, .PST, .PTX, .PUB, .PWM, .PY, .QBA, .QBB, .QBM, .QBR, .QBW, .QBX,
.QBY, .QCOW, .QCOW2, .QED, .QTB, .R3D, .RAF, .RAR, .RAT, .RAW, .RDB, .RE4, .RM,
.RTF, .RVT, .RW2, .RWL, .RWZ, .S3DB, .SAFE, .SAS7BDAT, .SAV, .SAVE, .SAY,
.SD0, .SDA, .SDB, .SDF, .SH, .SLDM, .SLDX, .SLM, .SQL, .SQLITE, .SQLITE3,
.SQLITEDB, .SQLITE-SHM, .SQLITE-WAL, .SR2, .SRB, .SRF, .SRS, .SRT, .SRW,
.ST4, .ST5, .ST6, .ST7, .ST8, .STC, .STD, .STI, .STL, .STM, .STW, .STX, .SVG,
.SWF, .SXC, .SXD, .SXG, .SXI, .SXM, .SXW, .TAX, .TBB, .TBK, .TBN, .TEX, .TGA,
.THM, .TIF, .TIFF, .TLG, .TLX, .TXT, .UPK, .USR, .VBOX, .VDI, .VHD, .VHDX,
.VMDK, .VMSD, .VMX, .VMXF, .VOB, .VPD, .VSD, .WAB, .WAD, .WALLET, .WAR, .WAV,
.WB2, .WMA, .WMF, .WMV, .WPD, .WPS, .X11, .X3F, .XIS, .XLA, .XLAM, .XLK,
.XLM, .XLR, .XLS, .XLSB, .XLSM, .XLSX, .XLT, .XLTM, .XLTX, .XLW, .XML, .XPS,
.XXX, .YCBCRA, .YUV, .ZIP.
|
Files created:
|
“# HELP DECRYPT #.html”, “# HELP DECRYPT #.txt” and
“# HELP DECRYPT #.url”
|
New Function:
|
Code optimization,
new obfuscation layer and packing procedure; new “Command and Control” servers
|
Method: RemoveCerber3 Ransomware with SpyHunter and RegCure
Step 1 Download and Install SpyHunter
1. Click the below link and then click on Run button to download SpyHutner.
2. Have a full scan for your computer now and remove all suspicious processes.
Step 2 Download and Install RegCure
1. Click the below link and then click on Save File button to download RegCure.
2. Have a full scan for your computer now and clean all unnecessary items.
Note: You can enjoy the free scan of SpyHunter and RegCure firstly. If you have questions when downloading, you can consult customer service staff.
Please beware the spam emails and fake software updates which promote that the Cerber3 Ransomware invades into your computer. The Cerber3 is so malicious that it can sneak its process in the background and block UAC prompts as well as normal registry items of Windows.
No comments:
Post a Comment