NoobCrypt Ransomware. How to remove NoobCrypt virus.

NoobCrypt Ransomware was discovered by security researcher Jakub Kroustek. What seems to be the case with this ransomware is that developer is low skilled (noob) and dubbed this virus NoobCrypt. The weakness of this ransomware allowed Jakub to reveal the password and provided it to victims to unlock files. Apparently the same encryption key was in use for every victim. If infected user try to enter random password will get an awkward massage “(random key) is not the code! You idiot. GO PAY IF U WANT UR PC BACK. NOOB HAH”. Anyway NoobCrypt ransomware will encrypt user files and set up encryption key, which supposedly victims have to pay for, however thanks to Jakub there is a list of keys that victims can use to decrypt files without paying.

Once user is infected with NoobCrypt ransomware a lock screen will be set up informing victims about current situation. The massage from the note is as follows:

Your personal files are encrypted
Made in R0MANIA

NoobCrypt ransomware threatens that vicitms have 48 hours to pay for the encryption key and that files will be deleted, increasing the demanded amount. This is a common ransom developers to scare victims into faster payment before they can find out about the free keys.

NoobCrypt ransomware

Each release of NoobCrypt ransomware has different bitcoin address and a different ransom fee.

  1. $299 – 1JrYNuMaE4VXKrod2gA9keBo6nzPvtaoZ6 – ZdZ8EcvP95ki6NWR2j
  2. $100 – 1MCLTT5qAqpabSSuKnYecRt1ZQyF6aaQFe – ZdZ8EcvP95ki6NWR2j
  3. $50 – 14YNpHUw3J2t6uhm2zcfQgrjVM5xR99iwE – lsakhBVLIKAHg

Once user determine the NoobCrypt variant can use the key provided above and enter it into the field to unlock files for free. If the key is correct, should be accepted, user will get a massage “Key correct. Decrypting! Wait.

Targeted extensions are as follows:

txt,doc,dot,docx,docm,dotx,dotm,docb,rtf,wpd,pdf,xls,xlt,xlm,xlsx,xlsm,xltx,xltm,xlsb,cdx,xla,
xlam,xll,xlw,ppt,pot,pps,pptx,pptm,potx,potm,ppam,ppsx,ppsm,sldx,sldm,accdb,db,dbf,mdb,pdb,sql,
jpg,jpeg,raw,tif,gif,png,bmp,wav,mp3,aif,iff,m3u,m4u,mid,mpa,wma,ra,avi,mov,mp4,3gp,3g2,asf,asx,
flv,wmv,vob,m3u8,ico

How to protect against ransomware is most frequently asked questions in the past year. Since ransomware has become the biggest threat among all viruses, people ask themselves if there’s a way to protect from such. It is already too late if you once suffered ransom attack and file has been locked. For some there is a solution but for others disappointment. Either way popularity of ransomware rises and new development are presented every day.

What can we do against the battle with ransomware?

  • If you are already infected do not pay the ransom! Remove the virus and look for other solutions rather than paying. Paying the ransom may be your only option if you have really valuable data. However we do not recommend doing this because you will support the work of criminals. The risk of losing money and still stuck with encrypted files since there is no guarantee in any way that you will recover what one is lost.
  • Security researcher are always working on recovery solutions. Not all ransomware are professionally developed and being cracked, but some are so good developed that there is no current way to be beaten at the current date. One of the solutions is system restore.
  • Best solution is if you have a backup, wipe your hard drive and perform system restore. If not, backup your data frequently. Store backup data in any removable storage device or use any online backup services.
  • Protect your computer with antivirus, internet security, anti-malware software or new developed applications like anti-ransomware. Highly recommended is to keep it up to date and use the paid surveys. We do not recommend free applications.

Now that you have been infected you have a few options:

Many suggest that you simply pay and hope that you will get all off your data back. However in this case you risk losing money and still being stuck with crypted files. We do not recommend this way simply because you will support the work of hackers and the more money thay get the stronger they will become.

The best option for you is if you have a backup, wipe your hard drive and perform system restore.

Use any type of anti malware software to remove NoobCrypt Ransomware.

NOTE: In this option the virus will be removed but the files will remain locked! You have to decrypt your files.

New research discovery shows how ransomware deletes files and substitute encrypted copy of them. It is not guaranteed, but it is a possibility that you may recover your files with data recovery software. Before trying to decrypt any files you can scan your computer for posible data loss.

Go here to find out how to recover deleted files.

Decrypt Noob Crypt Ransomware files.

Good news is that we can now use decryption programs. A lot of security companies like Kasperky lab, bitdefender and more has developed a program that is fully capable of decryption key for ransomware malware. You can find this programs anywhere on the internet but it is strongly suggested to download this programs from official websites. NOTE: It may take a long time for your files to be decrypted depending on your PC performance.

  • Name – NoobCrypt
  • Type Spamming – Malware, Ransomware, Trojan Horse
  • Danger Level – High
  • Brief Description – Encrypt files and demand ransom.
  • Symptoms – Poor pc performance or freezing, ransom massages.
  • Method – Via Trojan Horse or spam email.

Note: Removing NoobCrypt Ransomware manually could be very risky and unpredictable!

To remove this virus we suggest you follow the step by step instructions we provided. Since ransomware virus creates variety of malicious modified registry entries and different files, we strongly advise you to use anti-malware tool. Removing the virus manually requires high computer skills and knowledge.

Steps to remove “Noob Crypt Ransomware”