Severity scale:  
  (97/100)

Remove BigBobRoss ransomware (Virus Removal Guide) - Decryption Steps Included

removal by Ugnius Kiguolis - - | Type: Ransomware

BigBobRoss ransomware is the cryptovirus that requires a ransom in Bitcoin to return encrypted files marked with .obfuscated appendix

BigBobRoss ransomware

BigBobRoss ransomware is the cryptovirus that has a few versions actively spreading around the globe. It has also been named as Obfuscated ransomware, based on the file marker. The biggest damage caused by the virus is its encryption process which is launched against every file on the system. To inform the infected user about the damage made, malware also delivers a ransom note in the Read Me.txt file which requires using one of these emails:BigBobRoss@computer4u.com; Big8obRoss@protonmail.com; RobSmithMba@protonmail.com; support@robsmithmba.com. The virus was first spotted in January. However, more recent activity shows that the first variant was switched with other versions, including .djvu and .ecryptedALL. Remember that there is no need to pay the ransom or contact these people because it may lead you to data and money loss. Besides, keep in mind that most of the versions in this family can be decrypted, thanks to Emsisoft and Avast decrypters.[1]  

Name BigBobRoss ransomware
Type Cryptovirus
File marker [id=unique_victims'_number]original_filename.obfuscated, .djvu, .ecryptedALL
Executable files BigBobRoss.exe; bedoneupx.exe
Contact emails
  • BigBobRoss@computer4u.com;
  • info@bigbobross.website; 
  • Big8obRoss@protonmail.com; 
  • RobSmithMba@protonmail.com; 
  • support@robsmithmba.com
Encryption method AES-128 
Removal Employ Reimage Reimage Cleaner for BigBobRoss ransomware removal
Decryption You can find all the information on Emsisoft decrypter tool here

The initial BigBobRoss ransomware virus discovery was made on the second week of January, when malware researchers reported about the new ransomware sample. First two details about this threat were .obfuscated file extensions and ransom note file Read Me.txt.

At the time, BigBobRoss ransomware was called various names since developers haven't marked the name of their product as others do. Obfuscated was based on the file marker and BigBobRoss on the email shown in the ransom message. 

BigBobRoss ransomware ransom note reads the following:

Hello, dear friend!
=================================================
1- [All your files have been ENCRYPTED!]

Your files are NOT damaged! Your files are modified only.
The only way to decrypt your files is to receive the decryption program.
your files can not be decrypted without the special program we made it for your computer.

=================================================
2- [ HOW TO RETURN FILES? ]

To receive the decryption program Write to our email “BigBobRoss@computer4u.com”
and tell us your unique ID

=================================================
3- [ FREE DECRYPTION! ]

Free decryption as guarantee.
We guarantee the receipt of the decryption program after payment.
To believe, you can give us 1 file that must be less than 1MB and we decrypt it for free.
File should not be important to you! databases, backups, large excel sheets, etc.

=================================================
4- [ Instruction ]

the easiest way to buy bitcoins is LocalBitcoins site. you have to register, click “buy bitcoins”
and select the seller by payment method and price.

https://localbitcoins.com/buy_bitcoins

=================================================
CAUTION!
please do not change the name of files or file extension if your files are important to you!
Your unique ID :

There was no relation to other ransomware families at the time, so BigBobRoss ransomware gained a new name in the cybersecurity world. Developers were silent for a while, but in March the new version with the same marker but new email addresses came out. Following that, the decryption tool was released for this virus.

BigBobRoss ransomware virus
BigBobRoss ransomware is the cryptovirus that spreads around the world using spam email attachments. Fortunately, the virus can be decrypted.

When BigBobRoss ransomware developers released .encryptedALL and .djvu variants, researchers were expecting this reaction from cybercriminals.[2] Often after the decryptor developers make a new version to compensate. The notorious GandCrab is one of many examples.[3]

You should remove BigBobRoss ransomware from the machine as soon as possible. The best tip for the process from experts[4] is to get the anti-malware program and clean the system thoroughly. You should use Reimage Reimage Cleaner or a similar program and perform a system scan to delete all possible threats. 

Although there are a few methods of BigBobRoss ransomware removal or even a few decryption tools, the system should be entirely virus-free so that the user can work on the machine regularly. Remember that ransomware alters various system programs or functions to keep persistent.

For this reason that BigBobRoss ransomware alters system settings, we recommend rebooting the machine in Safe Mode with Networking before scanning the system with anti-malware program. This way all cyber threats can be found since the program is not disabled or blocked by the virus.

Email spam gets used to infect targeted computers with ransomware

The primary method used to spread ransomware is the email spam that delivers infected attachments on safe-looking emails named as financial notifications from known companies, services or even software providers. Emails may contain a direct link to downloading page or a document attachment. 

Spam emails often pose as sent from DHL, eBay or any other commonly used website that may send invoices or receipts. This way virus developers mask the real purpose of the message – delivering the malware. Once you download the file automatically or click on the Enable content button in the document, malicious macros lands on the system.

You should avoid clicking on emails with grammar mistakes or different suspicious content because those emails with red flags often contain malicious script or programs. Delete emails received out of nowhere and check the email box more often to clean unwanted material.

Terminate BigBobRoss ransomware and avoid infections in the feature

The best tip that security experts give to users is to keep their software updated and employing a reputable antivirus program. For the best BigBobRoss ransomware removal results, you should also employ the anti-malware tool and scan the system entirely.

This way you can remove BigBobRoss ransomware and get rid of all associated files or programs at the same time. The application indicates possibly dangerous programs and suggests removing them by following some simple steps. Use Reimage Reimage Cleaner , SpyHunter 5Combo Cleaner, or Malwarebytes for this job.

When BigBobRoss ransomware virus is terminated, you can get back to the safe and secure computer, browse online without risk and replace encrypted files using data backups. Also, you can find a decryption tool below.

Offer
do it now!
Download
Reimage Happiness
Guarantee
Download
Reimage Cleaner Happiness
Guarantee
Compatible with Microsoft Windows Supported versions Compatible with OS X Supported versions
What to do if failed?
If you failed to remove virus damage using Reimage Reimage Cleaner, submit a question to our support team and provide as much details as possible.
Reimage Reimage Cleaner has a free limited scanner. Reimage Reimage Cleaner offers more through scan when you purchase its full version. When free scanner detects issues, you can fix them using free manual repairs or you can decide to purchase the full version in order to fix them automatically.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage, try running SpyHunter 5.
Alternative Software
Different software has a different purpose. If you didn’t succeed in fixing corrupted files with Reimage Cleaner, try running Combo Cleaner.

To remove BigBobRoss virus, follow these steps:

Remove BigBobRoss using Safe Mode with Networking

Get rid of BigBobRoss ransomware by entering the Safe Mode with Networking and removing all potential threats:

  • Step 1: Reboot your computer to Safe Mode with Networking

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Safe Mode with Networking from the list Select 'Safe Mode with Networking'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Networking in Startup Settings window. Select 'Enable Safe Mode with Networking'
  • Step 2: Remove BigBobRoss

    Log in to your infected account and start the browser. Download Reimage Reimage Cleaner or other legitimate anti-spyware program. Update it before a full system scan and remove malicious files that belong to your ransomware and complete BigBobRoss removal.

If your ransomware is blocking Safe Mode with Networking, try further method.

Remove BigBobRoss using System Restore

System Restore is the feature helpful in virus removal when the whole system is affected:

  • Step 1: Reboot your computer to Safe Mode with Command Prompt

    Windows 7 / Vista / XP
    1. Click Start Shutdown Restart OK.
    2. When your computer becomes active, start pressing F8 multiple times until you see the Advanced Boot Options window.
    3. Select Command Prompt from the list Select 'Safe Mode with Command Prompt'

    Windows 10 / Windows 8
    1. Press the Power button at the Windows login screen. Now press and hold Shift, which is on your keyboard, and click Restart..
    2. Now select Troubleshoot Advanced options Startup Settings and finally press Restart.
    3. Once your computer becomes active, select Enable Safe Mode with Command Prompt in Startup Settings window. Select 'Enable Safe Mode with Command Prompt'
  • Step 2: Restore your system files and settings
    1. Once the Command Prompt window shows up, enter cd restore and click Enter. Enter 'cd restore' without quotes and press 'Enter'
    2. Now type rstrui.exe and press Enter again.. Enter 'rstrui.exe' without quotes and press 'Enter'
    3. When a new window shows up, click Next and select your restore point that is prior the infiltration of BigBobRoss. After doing that, click Next. When 'System Restore' window shows up, select 'Next' Select your restore point and click 'Next'
    4. Now click Yes to start system restore. Click 'Yes' and start system restore
    Once you restore your system to a previous date, download and scan your computer with Reimage Reimage Cleaner and make sure that BigBobRoss removal is performed successfully.

Bonus: Recover your data

Guide which is presented above is supposed to help you remove BigBobRoss from your computer. To recover your encrypted files, we recommend using a detailed guide prepared by 2-spyware.com security experts.

If your files are encrypted by BigBobRoss, you can use several methods to restore them:

Data Recovery Pro is the program designed to restore files after virus attack

This program is a great alternative for data backups since not everyone has the needed files backed up

  • Download Data Recovery Pro;
  • Follow the steps of Data Recovery Setup and install the program on your computer;
  • Launch it and scan your computer for files encrypted by BigBobRoss ransomware;
  • Restore them.

Windows Previous Versions is the method for file recovery

This is a useful solution when System Restore gets enabled

  • Find an encrypted file you need to restore and right-click on it;
  • Select “Properties” and go to “Previous versions” tab;
  • Here, check each of available copies of the file in “Folder versions”. You should select the version you want to recover and click “Restore”.

ShadowExplorer is the file restoring tool

If BigBobRoss ransomware affected Shadow Volume Copies, ShadowExplorer could not work

  • Download Shadow Explorer (http://shadowexplorer.com/);
  • Follow a Shadow Explorer Setup Wizard and install this application on your computer;
  • Launch the program and go through the drop down menu on the top left corner to select the disk of your encrypted data. Check what folders are there;
  • Right-click on the folder you want to restore and select “Export”. You can also select where you want it to be stored.

Decrypter for BigBobRoss ransomware

You can find all the information on Emsisoft decrypter tool here

Finally, you should always think about the protection of crypto-ransomwares. In order to protect your computer from BigBobRoss and other ransomwares, use a reputable anti-spyware, such as Reimage Reimage Cleaner , SpyHunter 5Combo Cleaner or Malwarebytes

About the author

Ugnius Kiguolis
Ugnius Kiguolis - The mastermind

If this free removal guide helped you and you are satisfied with our service, please consider making a donation to keep this service alive. Even a smallest amount will be appreciated.

Contact Ugnius Kiguolis
About the company Esolutions

References


Your opinion regarding BigBobRoss ransomware