Nusm Virus (. Nusm File) — Removal & Decrypt Data

The Nusm virus is a STOP/DJVU family of ransomware-type infections. This virus encrypts your files (video, photos, documents) that can be tracked by a specific “.nusm” extension. It using a strong encryption method, which makes it impossible to calculate the key in any way.

Nusm uses a unique key for each victim, with one exception:

  • If Nusm is unable to establish a connection to its command and control server (C&C Server) before starting the encryption process, it uses the offline key. This key is the same for all victims, which makes it possible in some cases to decrypt files encrypted during a ransomware attack.
Brendan Smith
IT Security Expert

First, scan your PC with antivirus tool!

I will try to help you remove Nusm virus and will assist you to decrypt or restore encrypted files. The is an excellent way to deal with recognizing and removing threats - using Gridinsoft Anti-Malware. This program will scan your PC, find and neutralize all suspicious processes.
Gridinsoft Anti-Malware 6-day trial available.
EULA | Privacy Policy | Gridinsoft

There are several universal methods for recovering encrypted .nusm files, which will be demonstrated below. It is very important to read the entire instruction manual carefully and make sure to understand it all. Do not skip any steps, each of these steps is very important and must be completed by you.

Nusm virus

Nusm

🤔 Nusm virus is ransomware that originates from the DJVU/STOP family. Its primary purpose is to encrypt files that are important for you. After that ransomware virus asks its victims for a ransom fee ($490 – $980) in BitCoin.

The Nusm ransomware is a kind of threat that encrypted your documents and then forced you to pay to restore them. Note that Djvu/STOP ransomware family was first revealed and analyzed by virus analyst Michael Gillespie.

Nusm virus is similar to other representatives of DJVU ransomware like: PAHD, Ehiz, Igvm, Pcqq, Rejg. This virus encrypt all common file types and adds its own “.nusm” extension into all files. For example, the file “1.jpg”, will be amended into “1.jpg.nusm“. As soon as the encryption is accomplished, virus creates a specific message file “_readme.txt” and adds it into all folders that contain the modified files.

NameNusm Virus
Ransomware family1DJVU/STOP2 ransomware
Extension.nusm
Ransomware note_readme.txt
RansomFrom $490 to $980 (in Bitcoins)
Contact,
Detection3Ransom:Win32/Avaddon.A!MTB, Win32/LockScreen.BQ, ATK/Shellter-AF
Symptoms
  • Encrypted most of your files (photos, videos, documents) and adds a particular “.nusm” extension;
  • Can delete Volume Shadow copies to make victim’s attempts to restore data impossible;
  • Adds a list of domains to HOSTS file to block access to certain security-related sites;
  • Installs password-stealing Trojan on the system, like Azorult Spyware;
Fix Tool To remove possible malware infections, scan your PC:
6-day free trial available.

The image below gives a clear vision of how the files with the “.nusm” extension look like:

Encrypted files by NUSM Ransomware

This _readme.txt file asking payment is for restore files via decryption key:

_readme.txt (STOP/DJVU Ransomware) – The scary alert demanding from users to pay the ransom to decrypt the encoded data contains these frustrating warnings

The cryptography algorithm used by DJVU/STOP virus is AES-256. So, if your files got encrypted with an online decryption key, which is unique. The sad reality is that it is impossible to decrypt the files without the unique key.

In case if Nusm worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a distant server owned by the criminals who distribute the Nusm ransomware.

For receiving decryption key the payment should be $980. To obtain the payment details, the victims are encouraged by the message to contact the frauds by email ().

The message by the ransomware states the following information:

ATTENTION!

Don't worry, and you can return all your files!

All your files like photos, databases, documents, and other important are encrypted with the strongest encryption and unique key.
The only method of recovering files is to purchase a decrypt tool and unique key for you.
This software will decrypt all your encrypted files.

What guarantees you have?

You can send one of your encrypted files from your PC, and we decrypt it for free.
But we can decrypt only 1 file for free. The file must not contain valuable information.

You can get and look video overview decrypt tool:



The price of private keys and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's the price for you is $490.

Please note that you'll never restore your data without payment.

Check your e-mail "Spam" or "Junk" folder if you don't get an answer in more than 6 hours.

To get this software you need writes on our e-mail:



Reserve an e-mail address to contact us:



Your personal ID:
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

How did Nusm infect my computer?

Typically, ransomware developers distribute malware through untrustworthy software downloads, fake (unofficial) software updates, email spam, and system vulnerabilities (exploits).

Some examples of unreliable software download sources are peer-to-peer networks (for example, uTorrent, eMule, Deluge, BitTorrent, and others), so-called “free download sites” or sites for sharing files.

Using these sources, cybercriminals present their malware as legitimate and trick people into downloading and installing malware (or other unwanted applications).

Often, unofficial software update tools (fake updaters) are used to download and install malware instead of promised software updates. These tools are capable of exploiting vulnerabilities in legacy software.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest