.xlsx, .odp, .xyp, .sr2, .asset, .zip, .bc7, .wp, .bc6, .bkf, .jpeg, .dng, .der, .forge, .xll, .wps, .lbf, .xld, .mdbackup, .iwd, .raf, .gdb, .x3f, .cas, .wn, .wmd, .wri, .wsd, .wire, .wmf, .rtf, .zw, .xmind, .dmp, .png, .ztmp, .map, .ff, .erf, .z, .xy3, .yml, .xdl, .t13, .x, .rgss3a, .wp5, .wdp, .x3d, .sum, .xxx, .xlgc, .xpm, .wpg, .accdb, .odb, .ntl, .srw, .hvpl, .epk, .sb, .cfr, .wpd, .esm, .xlsb, .pem, .vfs0, .wotreplay, .mpqge, .wp7, .psk, .hplg, .db0, .pst, .1st, .t12, .sidd, .mp4, .arw, .xls, .xlsm, .xls, .ltx, .pef, .avi, .m2, .odm, .zip, .zif, .cer, .rar, .wgz, .kdc, .pkpass, .ods, .pfx, .wbm, .zabw, .w3x, .wp6, .docx, .das, .pdd, .py, .m3u, .wma, .lvl, .rb, .css, .kdb, .mdb, .wpb, .zi, .ws, .pptx, .dxg, .wot, .wbc, .xlsx, .vdf, .mov, .itm, wallet, .fpk, .raw, .wbd, .bik, .rw2, .doc, .wpe, .3fr, .dwg, .csv, .wpt, .ibank, .d3dbsp, .dba, .psd, .zdc, .p7b, .wbz, .mlx, .pak, .wpw, .wma, .z3d, .mrwref, .xlsm, .wbmp, .mddata, .qic, .sidn, .ncf, .webp, .qdf, .wav, .xar, .indd, .sid, .webdoc, .bkp, .srf, .cr2, .blob, .ybk, .snx, .2bp, .bar, .r3d, .xdb, .hkdb, .rwl, .vpp_pc, .upk, .wmv, .wpa, .wcf, .iwi, .xlk, .xbdoc, .desc, .p7c, .nrw, .slm, .flv, .1, .orf, .wsc, .fos, .odt, .yal, .wdb, .dazip, .0, .vpk, .7z, .tax, .ai, .big, .svg, .sie, .sql, .lrf, .xml, .ppt, .wbk, .re4, .xbplate, .ysp, .jpg, .ptx, .wm
Threat Summary
Name | Derp |
Type | Ransomware, Crypto virus, File locker, Filecoder, Crypto malware |
Encrypted files extension | .derp |
Ransom note | _readme.txt |
Contact | gorentos@bitmessage.ch, salesrestoresoftware@firemail.cc, salesrestoresoftware@gmail.com |
Ransom amount | $490,$980 if paid after 72 hours |
Detection Names | Trojan/RansomWin32.Stop, Ransom.Win32.STOP, Trojan/TR.Crypt, W32Kryptik |
Symptoms | Files encrypted with .derp extension. Your photos, documents and music fail to open. Files named such as ‘_readme.txt’, or ‘_readme.txt” in every folder with an encrypted file. |
Distribution ways | Malicious spam , Torrents, Exploit kits, Adware, Social media, Cracks, RDP hacking. |
Removal | To remove Derp ransomware use the removal guide |
Decryption | free Derp decryptor |
You cannot start decryption or recovery of encrypted files without first making sure that the ransomware is completely removed. This is simply dangerous, as it can lead to the fact that the recovered or decrypted files will again become the target of ransomware attack and will be encrypted. Moreover, the contents of any drive connected to the infected computer will also be encrypted. To remove Derp, you need to identify and stop its active process, find and delete all its files and folders. Doing it manually is not always easy for the average user. Therefore, we recommend using malware removal tools. Below we list some of the most popular. You can find more free removal utilities here. Each of which has a fast scanner, can detect and remove various security threats, including ransomware, trojans, worms, adware, browser hijackers and other malware
How to remove Derp with Zemana
Remove Derp with HitmanPro
Remove Derp virus with Kaspersky virus removal tool
How to decrypt .derp files
- Open the page STOP Djvu decryptor.
- Scroll down to ‘New Djvu ransomware’ section.
- Click the download link and save the decrypt_STOPDjvu.exe file to your desktop.
- Run decrypt_STOPDjvu.exe, read the license terms and instructions.
- On the ‘Decryptor’ tab, using the ‘Add a folder’ button, add the directory or disk where the encrypted files are located.
- Click the ‘Decrypt’ button.