Scroboscope ransomware is a crypto-malware that executes several malicious processes on the infected system

Scroboscope ransomware is a dangerous cyber threat that was first spotted by security experts in early November 2018. It infects computers with the help of typical ransomware distribution techniques, such as brute-force[1] attacks, spam emails, fake updates, and other methods. The malware then encrypts all the personal files on the machine with the help of RC2[2] encryption algorithm and adds .N0JJC appendix to each of the affected files. Scroboscope virus also contacts a remote server and sends the decryption key together with the personal ID to the attackers. It also drops a ransom note (a text file) that asks users to pay ransom in Bitcoin for file recovery.
| Summary | |
| Name | Scroboscope |
| Type | Ransomware |
| Encryption algorithm | RC2 |
| File extension | .N0JJC |
| First spotted | November 2018 |
| Demands ransom | Bitcoins |
| Decryptable? | No |
| Elimination | Use Fortect |
Scroboscope is a ransomware virus, so its operation is advanced. Once installed, the performs multiple changes to the machine, including:
- Spawns KashperovskyInternetSecurity12.0.dub.b.4.exe. thankyou.exe, several instances of cmd.exe, and other processes;
- Writes data to a remote process;
- Deletes Shadow Volume Copies;
- Modifies Windows Registry;
- Elevates permission rights to admin and system;
After these modifications are made, Scroboscope virus starts a PC scan and looks for files to encrypt. It usually targets most commonly used file extensions, like .jpg, .png, .doc, .dat, .html, .txt, ,mp4, and many others. Once the encryption process is complete, the virus appends an extension which denies the access to computer users (for example, a picture.jpg is turned into picture.jpg.N0JJC and becomes unreadable by the system).
To regain control of data, victims are asked to contact crooks and pay them a specified amount of money in Bitcoin cryptocurrency. However, we highly advise users to ignore hackers as these individuals cannot be trusted. While there is a chance that Scroboscope authors will send the key, they can also choose to ignore the victim. Therefore, we advise users not to rush, remove Scroboscope ransomware and try to regain data with the help of third-party software.
Nevertheless, those who are aware of ransomware risks and keep backups of their files will not have any troubles, as long as Scroboscope ransomware removal is performed first. If the remote backup device is connected to the infected machine before the virus is eliminated, however, all the data located in the backup will be lost as well.
Therefore, you should first get rid of the virus with the help of security software, such as FortectIntego, or any other anti-malware application that can detect[3] Scroboscope virus. Once you are sure that the malware is gone, try to recover your data.

Being careful online can prevent you from trouble
Users are usually not that aware of the peculiarities of ransomware infection. Most heard news about such infections like WannaCry or NotPetya – just because these viruses were highly publicized and made a significant impact on the economy, healthcare system, and other aspects. However, there are thousands of ransomware viruses created every month, as well as Ransomware-as-a-service is employed to modify the original script and propagate the threat to as many victims as possible.
For that reason, we suggest you be careful when browsing the internet. Experts[4] advise the following:
- Use comprehensive security application that could prevent malware from entering;
- Patch your system as soon as new updates become available;
- Do not open attachments or click on links inside a spam email, even if it looks legitimate;
- Backup your files regularly;
- Use strong passwords for RDP and all personal accounts (use a reliable password manager and 2-step verification);
- Avoid downloading torrent files and stay away from suspicious websites.
Terminate Scroboscope ransomware virus
Scroboscope ransomware removal should be the first step to the recovery from the infection. Manual elimination should be out of the question, as various modifications to the system and spawned processes can make that procedure almost impossible. To remove Scroboscope virus without much trouble, you should enter Safe Mode with Networking as explained below and perform a full system scan with Fortect, or other software that can recognize and get rid of the threat.
Ransomware infection does not only mean that your computer is compromised, but your files are also affected, even after Scroboscope removal is performed. To recover data affected by .N0JJC file extension virus, use backups that you prepared previously. Alternatively, you should try third-party software that we offer below. If nothing works, you should keep the copies of your files and wait till security researchers crack the malicious code and release the decryptor that works for Scroboscope ransomware encrypted files
Did this guide help?
Be the first to comment