ScammerLocker – a malicious virus which locks up personal files

ScammerLocker is a crypto-virus which is based on the HiddenTear open-source project. When it infiltrates victim's machines, it locks up a variety of personal files using AES[1] cipher and appending .jodis file extension. Then ransomware drops a FILES_ENCRYPTED.txt ransom note and demands a payment in cryptocurrency for data release.
This deadly crypto-virus is named after a so-called tech support scammer, who’s picture is displayed on the main program window. It is currently unknown who the person is. Also, ScammerLocker virus was developed by hackers who are linked to “Jodis Hunter Team”; therefore, some security experts might refer to this malware as Jodis Hunter ransomware.
As soon as ScammerLocker infects the machine, it renders files like .jpg, .mpeg, .txt, .cab, .bin, .html, .exe completely useless. For example, a file called picture.jpg is turned into picture.jpg.jodis. The only way to decrypt files is by using a unique key which is stored on a remote server, closely guarded by hackers. Without it, recovering files is almost impossible.
However, authors of ScammerLocker suggest a data recovery solution which is not recommended to follow by security experts. The .txt file created by criminals states the following message:
You my friend, have been caught. Don't bother installing AntiVirus.
Because You're f**ked.
You can only decrypt your files with our decrypter, and a special key.
You must buy 10 IOTA and send it to [random characters]
[Click here for info on buying IOTA|HYPERLINK]
Or if you want to decrypt your files for free,
simply send an email to jodishunterteam@protonmail.com and then we can negotiate.
Good day, Jodis Hunter Team.
Hackers are asking for 10 IOTA, which is around 13.68 USD at the time of the writing. It might not seem like much and many users might consider contacting criminals to recover their precious files. However, we encourage you to restrain yourself from doing so. After all, there is always a chance you might not recover your data or you might be blackmailed into transferring more money.
Thus, you should remove ScammerLocker instead of communicating and having business with cyber criminals. Unfortunately, virus removal won't help to recover files, but you will be able to use your PC safely and try alternative data recovery methods. Our team has suggested several methods that might help to get back access to some of the locked files.
We want to discourage you from manual ScammerLocker removal. Instead, you have to employ robust security software for the job, such as FortectIntego or MalwarebytesMalwarebytes. These tools ensure that virus elimination is safe. Attempts to locate and delete ransomware-related components manually often end up with irreparable system damage.

Ways to protect yourself from a deadly crypto-virus
Developers of ransomware usually use numerous distribution methods to infect computers. Security experts from Faravirus[2] warn that users need to be careful when browsing the web and have backups of the most important data. Authors of file-encrypting malware use social engineering and other sophisticated techniques that trick even the advanced computer users.
The most prominent ransomware distribution method is spam emails. This method is often used by crooks because it is incredibly effective as many users carelessly open emails which they believe are coming from a legitimate source. However, email authors are not who they pretend to be.
Thus, whenever you open an email from an unknown source, you should first check what address is it coming from and look for other signs.[3] If you noticed that something does not feel right, DO NOT open the email, click on any links or download any attachments presented. Instead, delete the email immediately.
We must also warn you that using illegal software, keygens and similar can lead to serious infections, including ransomware infiltration. Thus, avoid questionable websites (such as torrents, crack sites, etc.) and pick legitimate software download sources.
Eliminate ScammerLocker ransomware correctly
To remove ScammerLocker virus, you do not need to contact cyber criminals and pay them a demanded sum of money. As we have mentioned in the beginning, it may lead to money loss or blackmailing. Additionally, keeping ransomware on the system might lead to encryption of new files and infiltration of other cyber threats. Hence, no matter how important your files are, you should focus on ransomware removal.
To ensure safe and correct ScammerLocker removal, you should employ a reputable anti-malware software, such as FortectIntego, SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. These programs are designed to deal even with the most stubborn viruses. Remember that ransomware might prevent the security application from starting. In that case, reboot your PC in Safe Mode with Networking as explained below:
Was this guide helpful?
Be the first to comment