Nusm Virus (. Nusm File) — Removal & Decrypt Data
The Nusm Virus Is a Stop/Djvu Family of Ransomware-Type Infections. This Virus Encrypts Your Files (Video, Photos, Documents) That Can Be Tracked by a Specific...
The Nusm virus is a STOP/DJVU family of ransomware-type infections. This virus encrypts your files (video, photos, documents) that can be tracked by a specific “.nusm” extension. It using a strong encryption method, which makes it impossible to calculate the key in any way.
Nusm uses a unique key for each victim, with one exception:
- If Nusm is unable to establish a connection to its command and control server (C&C Server) before starting the encryption process, it uses the offline key. This key is the same for all victims, which makes it possible in some cases to decrypt files encrypted during a ransomware attack.
There are several universal methods for recovering encrypted .nusm files, which will be demonstrated below. It is very important to read the entire instruction manual carefully and make sure to understand it all. Do not skip any steps, each of these steps is very important and must be completed by you.
Nusm virus
Nusm
🤔 Nusm virus is ransomware that originates from the DJVU/STOP family. Its primary purpose is to encrypt files that are important for you. After that ransomware virus asks its victims for a ransom fee ($490 – $980) in BitCoin.
The Nusm ransomware is a kind of threat that encrypted your documents and then forced you to pay to restore them. Note that Djvu/STOP ransomware family was first revealed and analyzed by virus analyst Michael Gillespie.
Nusm virus is similar to other representatives of DJVU ransomware like: PAHD, Ehiz, Igvm, Pcqq, Rejg. This virus encrypt all common file types and adds its own “.nusm” extension into all files. For example, the file “1.jpg”, will be amended into “1.jpg.nusm“. As soon as the encryption is accomplished, virus creates a specific message file “_readme.txt” and adds it into all folders that contain the modified files.
| Name | Nusm Virus |
| Ransomware family1 | DJVU/STOP2 ransomware |
| Extension | .nusm |
| Ransomware note | _readme.txt |
| Ransom | From $490 to $980 (in Bitcoins) |
| Contact | , |
| Detection3 | Ransom:Win32/Avaddon.A!MTB, Win32/LockScreen.BQ, ATK/Shellter-AF |
| Symptoms |
|
| Fix Tool | To remove possible malware infections, scan your PC: 6-day free trial available. |
The image below gives a clear vision of how the files with the “.nusm” extension look like:
This _readme.txt file asking payment is for restore files via decryption key:
_readme.txt (STOP/DJVU Ransomware) – The scary alert demanding from users to pay the ransom to decrypt the encoded data contains these frustrating warnings
The cryptography algorithm used by DJVU/STOP virus is AES-256. So, if your files got encrypted with an online decryption key, which is unique. The sad reality is that it is impossible to decrypt the files without the unique key.
In case if Nusm worked in online mode, it is impossible for you to gain access to the AES-256 key. It is stored on a distant server owned by the criminals who distribute the Nusm ransomware.
For receiving decryption key the payment should be $980. To obtain the payment details, the victims are encouraged by the message to contact the frauds by email ().
The message by the ransomware states the following information:
ATTENTION! Don't worry, and you can return all your files! All your files like photos, databases, documents, and other important are encrypted with the strongest encryption and unique key. The only method of recovering files is to purchase a decrypt tool and unique key for you. This software will decrypt all your encrypted files. What guarantees you have? You can send one of your encrypted files from your PC, and we decrypt it for free. But we can decrypt only 1 file for free. The file must not contain valuable information. You can get and look video overview decrypt tool: The price of private keys and decrypt software is $980. Discount 50% available if you contact us first 72 hours, that's the price for you is $490. Please note that you'll never restore your data without payment. Check your e-mail "Spam" or "Junk" folder if you don't get an answer in more than 6 hours. To get this software you need writes on our e-mail: Reserve an e-mail address to contact us: Your personal ID: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
How did Nusm infect my computer?
Typically, ransomware developers distribute malware through untrustworthy software downloads, fake (unofficial) software updates, email spam, and system vulnerabilities (exploits).
Some examples of unreliable software download sources are peer-to-peer networks (for example, uTorrent, eMule, Deluge, BitTorrent, and others), so-called “free download sites” or sites for sharing files.
Using these sources, cybercriminals present their malware as legitimate and trick people into downloading and installing malware (or other unwanted applications).
Often, unofficial software update tools (fake updaters) are used to download and install malware instead of promised software updates. These tools are capable of exploiting vulnerabilities in legacy software.