What is Cerber3

Cerber3 ransomware is new version of notorious Cerber virus that infected hundreds of thousands computers. It uses the same algorithms to infect computer and encrypt user files. Now it appends .cerber3 to those files. Names of the files are changed to random 10 character sequence. Among other differences between Cerber3 and it predecessor are new ransomware note files (@__README__@.html, @__README__@.txt and @__README__@.url instead of #DECRYPT MY FILES#.txt, #DECRYPT MY FILES#.html, #DECRYPT MY FILES#.vbs). Text and html files contain identical instructions to pay the ransom, .url file opens Cerber3 website. Amount of ransom is less, than before – 0.7154 Bitcoin, but it doubles to 1.4308 if not paid in 5 days. We monitor all available resources for possible decryptors available, staying in contact with antivirus companies. Below you can find updated information on how to remove newest Cerber3 ransomware and decrypt .cerber3 files.

cerber3 virus

cerber3 files

How Cerber3 infected your PC

Cerber3 virus developers still use spam e-mails with malicious attachments for distribution. Usually short message offers to download archive with some document. This document contains built-in macros, that runs in the background when user opens the document. This macros downloads executable file of the virus and runs it. Since that moment Cerber3 starts encrypting your files. Antivirus may not catch this threat and we recommend you to use HitmanPro with Cryptoguard. This program can detect encryption process and stop it to prevent the loss of your files.

cerber3 decryptor page

Download Cerber3 Removal Tool

Download Removal Tool

To remove Cerber3 completely we recommend you to use SpyHunter 5 from EnigmaSoft Limited. It detects and removes all files, folders and registry keys of Cerber3.

Alternative remover

Download RakhniDecryptor

As a good free alternative to remove Cerber3 use Malwarebytes Anti-Malware. It will detect core files and processes of Cerber3 ransomware and eliminate them to allow you start decryption of your files.

How to remove Cerber3 manually

It is not recommended to remove Cerber3 manually, for safer solution use Removal Tools instead.

Cerber3 files:


Cerber3 reg keys:

no information

How to decrypt and restore .cerber3 files

trendmicro cerber3 decryptor

Use following tool from Trend Micro called Trend Micro Ransomware File Decryptor, that can decrypt files encrypted by Cerber3. Download it here:

There is no purpose to pay the ransom, because there is no guarantee you will receive the key, but you will put your bank credentials at risk.

If you are infected with Cerber3 ransomware and removed it from your computer you can try to decrypt your files. Antivirus vendors and individuals create free decryptors for some crypto-lockers. However, there is currently no automatic decryption tool for .Cerber3 files. To attempt to remove them you can do the following:

Using Windows Previous Versions option:

  1. Right-click on infected file and choose Properties.
  2. Select Previous Versions tab.
  3. Choose particular version of the file and click Copy.
  4. To restore the selected file and replace the existing one, click on the Restore button.
  5. In case there is no items in the list choose alternative method.

Using Shadow Explorer:

  1. Download Shadow Explorer program.
  2. Run it and you will see screen listing of all the drives and the dates that shadow copy was created.
  3. Select the drive and date that you want to restore from.
  4. Right-click on a folder name and select Export.
  5. In case there are no other dates in the list, choose alternative method.

If you are using Dropbox:

  1. Login to the DropBox website and go to the folder that contains encrypted files.
  2. Right-click on the encrypted file and select Previous Versions.
  3. Select the version of the file you wish to restore and click on the Restore button.

How to protect computer from viruses like Cerber3 in future

Use Malwarebytes Anti-Ransomware Beta

Famous anti-malware vendor Malwarebytes along with EasySync Solutions created tool that will help you with active anti-ransomware protection as additional shield to your current protection.


Use HitmanPro.Alert with CryptoGuard

Dutch vendor of legendary cloud-based scanner HitmanPro – Surfright released active antivirus solution HitmanPro.Alert with CryptoGuard feature that effectively protects from latest versions of cryptoviruses.

Download AdGuard
Previous articleHow to remove Searchgra.com
Next articleHow to remove Yourconnectivity.net
James Kramer
Hello, I'm James. My website Bugsfighter.com, a culmination of a decade's journey in the realms of computer troubleshooting, software testing, and development. My mission here is to offer you comprehensive, yet user-friendly guides across a spectrum of topics in this niche. Should you encounter any challenges with the software or the methodologies I endorse, please know that I am readily accessible for assistance. For any inquiries or further communication, feel free to reach out through the 'Contacts' page. Your journey towards seamless computing starts here


  1. i fucked too… all of my files are infected ..such as my wedding pictures , all of my e-books, all of my informations in pdf, power points , words, and etc.. i could remove all of trojans and viruses via eset nod32 version 9..but my files are encrypted yet..
    is there any software that can decrypt files??

  2. Hi, somebody he managed to decrypt data encrypted by cerber 3 with Trend Micro Ransomware File Decryptor ? Because cerber 3 is not available in the ransomware list.


Please enter your comment!
Please enter your name here