Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2018

How to remove ScammerLocker ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Alice Woods · Likes to teach users about virus prevention

ScammerLocker – a malicious virus which locks up personal files

Image of ScammerLocker ransom note

ScammerLocker is a crypto-virus which is based on the HiddenTear open-source project. When it infiltrates victim's machines, it locks up a variety of personal files using AES[1] cipher and appending .jodis file extension. Then ransomware drops a FILES_ENCRYPTED.txt ransom note and demands a payment in cryptocurrency for data release. 

This deadly crypto-virus is named after a so-called tech support scammer, who’s picture is displayed on the main program window. It is currently unknown who the person is. Also, ScammerLocker virus was developed by hackers who are linked to “Jodis Hunter Team”; therefore, some security experts might refer to this malware as Jodis Hunter ransomware.

As soon as ScammerLocker infects the machine, it renders files like .jpg, .mpeg, .txt, .cab, .bin, .html, .exe completely useless. For example, a file called picture.jpg is turned into picture.jpg.jodis. The only way to decrypt files is by using a unique key which is stored on a remote server, closely guarded by hackers. Without it, recovering files is almost impossible.

However, authors of ScammerLocker suggest a data recovery solution which is not recommended to follow by security experts. The .txt file created by criminals states the following message:

You my friend, have been caught. Don't bother installing AntiVirus.
Because You're f**ked.
You can only decrypt your files with our decrypter, and a special key.
You must buy 10 IOTA and send it to [random characters]
[Click here for info on buying IOTA|HYPERLINK]
Or if you want to decrypt your files for free,
simply send an email to jodishunterteam@protonmail.com and then we can negotiate.
Good day, Jodis Hunter Team.

Hackers are asking for 10 IOTA, which is around 13.68 USD at the time of the writing. It might not seem like much and many users might consider contacting criminals to recover their precious files. However, we encourage you to restrain yourself from doing so. After all, there is always a chance you might not recover your data or you might be blackmailed into transferring more money.

Thus, you should remove ScammerLocker instead of communicating and having business with cyber criminals. Unfortunately, virus removal won't help to recover files, but you will be able to use your PC safely and try alternative data recovery methods. Our team has suggested several methods that might help to get back access to some of the locked files.

We want to discourage you from manual ScammerLocker removal. Instead, you have to employ robust security software for the job, such as FortectIntego or MalwarebytesMalwarebytes. These tools ensure that virus elimination is safe. Attempts to locate and delete ransomware-related components manually often end up with irreparable system damage.

Portraying ScammerLocker crypto-virus

Ways to protect yourself from a deadly crypto-virus

Developers of ransomware usually use numerous distribution methods to infect computers. Security experts from Faravirus[2] warn that users need to be careful when browsing the web and have backups of the most important data. Authors of file-encrypting malware use social engineering and other sophisticated techniques that trick even the advanced computer users.

The most prominent ransomware distribution method is spam emails. This method is often used by crooks because it is incredibly effective as many users carelessly open emails which they believe are coming from a legitimate source. However, email authors are not who they pretend to be.

Thus, whenever you open an email from an unknown source, you should first check what address is it coming from and look for other signs.[3] If you noticed that something does not feel right, DO NOT open the email, click on any links or download any attachments presented. Instead, delete the email immediately.

We must also warn you that using illegal software, keygens and similar can lead to serious infections, including ransomware infiltration. Thus, avoid questionable websites (such as torrents, crack sites, etc.) and pick legitimate software download sources.

Eliminate ScammerLocker ransomware correctly

To remove ScammerLocker virus, you do not need to contact cyber criminals and pay them a demanded sum of money. As we have mentioned in the beginning, it may lead to money loss or blackmailing. Additionally, keeping ransomware on the system might lead to encryption of new files and infiltration of other cyber threats. Hence, no matter how important your files are, you should focus on ransomware removal.

To ensure safe and correct ScammerLocker removal, you should employ a reputable anti-malware software, such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These programs are designed to deal even with the most stubborn viruses. Remember that ransomware might prevent the security application from starting. In that case, reboot your PC in Safe Mode with Networking as explained below:

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.