Remove Scarab-Red Ransomware and Restore .red Files

Remove Scarab-Red Ransomware and Restore .red Files

remove Scarab-Red ransomware .red extension sensorstechforum

Security researchers have spotted yet another version of Scarab ransomware that is associated with the .red extension. Combined this two traits lead to its alternative name Scarab-Red. The threat acts like a typical data locker ransomware. So once running on the system it plagues system settings, encrypts important files and demands ransom payment for decryption solution. Keep reading and find out how to remove this ransomware in full from the infected system. The steps presented in the guide at the end aid to the potential recovery of encrypted files as well.

Threat Summary

TypeRansomware, Cryptovirus
Short DescriptionA data locker ransomware that utilizes strond cihper algorithm to encrypt files on stored on the infected computer. Then it demands a ransom for decryption solution.
SymptomsImportant files are locked and renamed with .red extension. They remain unusable until a ransom is paid.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by Scarab-Red


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss Scarab-Red.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Scarab-Red Ransomware – Distribution

The infection process with this Scarab ransomware version Scarab-Red begins after its payload is running on the system. The distribution of this payload is implemented by various shady techniques all of which are designed to trick you into installing the malicious code. One of the most common ways of ransomware distribution is via email spam messages. Bad actors often mislead users by spoofing the emails by setting the names of legitimate services like your favorite website or your internet provider, any logistics company, your bank or even any governmental institution. As regards of the presented messages, they usually urge you to open an attached file as soon as possible or click a presented link as the information you will find there is very important or available for limited time.

Scarab-Red Ransomware – Overview

Another iteration of Scarab ransomware that appends the specific extension .red has been detected to harass online users. The threat is known to use sophisticated cipher algorithm to encrypt important files so it can then blackmail victims into paying a ransom for decryption solution.

However, before the encryption stage, a lot of modifications that plague essential system components are performed. In order to complete all these malicious activities Scarab-Red drops additional malicious files on the infected operating system. And with the help of the initial infection code it makes possible the automatic execution of all needed malicious files and objects.

One way to implement this is by adding malicious values under specific registry keys like Run and RunOnce. Afterward, the functionalities of these keys manage the process of files start. Additionally, some of the malicious values added there grant the ransomware persistent presence on the system as its files start on each Windows load.

At the end of the attack, a ransom message appears on the screen to inform you about the attack and its impacts. The message blackmails you to contact hackers at a given email so they can tell you the amount of the demanded ransom. Be advised to refrain from following their instructions before you try all you can do by yourself to resolve the problem.
Here is all that the message reads:

All your files have been encrypted!
Dont worry, you can return all your files!

Your ID:
[redacted] 61D75ECE06BBF06CC2BF91AA3D4F0F8E23D432FFB01C655FDE5A35CA627847B65B01296930619A3D03859C522E15BCAC5C60
[redacted] 614115848734ECC75DADEB2CCF3717FA0C0789A41CD0B29874DFFA4A88E588CFB3C9A3B2FEC08588E7A74A2AE6B71A3E41D3
[redacted] 9AE6996D70CC938C7BCBDBF5DD52968E1817C27046471F

If you want restore files write on e-mail:

Free decryption as guarantee!
Send me your ID and 1-2 small encrypted files(The total size of files must be less than 1Mb (non archived)) for free decryption.
After that, I’ll tell you the price for decryption all files.
After payment we will send you the decryption tool that will decrypt all your files.

* Do not rename encrypted files.
* Do not try to decrypt your data using third party software, it may cause permanent data loss.
* Decryption of your files with the help of third parties may cause increased price
(they add their fee to our) or you can become a victim of a scam.

How to obtain Bitcoins?
* The easiest way to buy bitcoins is LocalBitcoins site. You have to register, click
‘Buy bitcoins’, and select the seller by payment method and price:
* Also you can find other places to buy Bitcoins and beginners guide here:

Scarab-Walker Ransomware – Encryption Process

Similar to the previous Scarab ransomware iterations this one plagues computer systems with the main purpose to locate predefined target files and encrypt them with the strong RSA-2048 cipher. This process transforms all files that store sensitive information in a way that you cannot use them anymore.

So in case of infection it is likely that all of the following files will remain encrypted until an efficient recovery solution restores their original code:

  • Audio files
  • Video files
  • Document files
  • Image files
  • Text files
  • Backup files
  • Banking credentials, etc

After encryption, all corrupted files could be recognized by the extension .red that is appended at the end of their names.

Following encryption, Scarab-Red crypto virus deletes all Shadow Volume Copies stored by the Windows operating system which eliminates one of the possible data recovery options.

Remove Scarab-Red Ransomware and Restore .red Files

The removal of Scarab-Red ransomware demands a bit of technical experience and ability to recognize traits of malware files. And there is no doubt that you should remove this nasty threat from the infected PC as soon as you detect it. Otherwise, it has the chance to spread its infection files among the whole network. Below you could find how to remove it step by step. Beware that ransomware has highly complex code that could plague not only your files but your whole system. So as recommended by security researchers you need to utilize an advanced anti-malware tool for its complete removal. Such tool will keep your system protected against devastating threats like Scarab-Red and other kinds of malware that endanger your online security.

After you remove the ransomware make sure to check the “Restore Files” step listed in the guide below. But before you take any further actions, don’t forget to back up all encrypted files to an external drive in order to prevent their irreversible loss.

Gergana Ivanova

Gergana Ivanova

Gergana has completed a bachelor degree in Marketing from the University of National and World Economy. She has been with the STF team for three years, researching malware and reporting on the latest infections.

More Posts

Follow Me:
Google Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share