JUSTCRY.EXE ransomware is a virus that locks your computer, making it possible to recover them only if you pay a hefty ransom fee to the cyber-criminals who are behind this virus. The malware leaves behind a ransom note as a locked screen message and even if you boot the infected computer back in safe mode, JUSTCRY.EXE still manages to lock your screen. So, in order to remove this virus from your computer without paying a ransom, we advise you to read the following article.


Threat Summary
Name | JUSTCRY.EXE |
Type | Ransomware, Lockscreen |
Short Description | Aims to lock you out of your computer, restricting access to it, even if you boot it in Safe Mode. |
Symptoms | Your screen is dimmed down and a lockscreen, named JUSTCRY.EXE appears with instructions on how to pay ransom to unlock your PC. |
Distribution Method | Spam Emails, Email Attachments, Executable files |
Detection Tool | See If Your System Has Been Affected by JUSTCRY.EXE Download Malware Removal Tool | User Experience | Join Our Forum to Discuss JUSTCRY.EXE. |


JUSTCRY.EXE – How Does It Infect
The infection process of JUSTCRY.EXE ransomware is very similar to other malware like it. The virus aims to slither onto your computer via malicious e-mail attachments which are obfuscated, in other words, cannot be detected by updated antivirus programs.
The e-mails which may be sent spreading the JUSTCRY.EXE ransomware may contain different types of files, most of which pretend to be legitimate types of files, such as:
- Invoices.
- Fake receipts.
- Fraudulent banking statements.
- Account activity reports.
The messages attached to the e-mails may have deceptive content within them that aims to convince victims into opening the e-mails themselves.


JUSTCRY.EXE Ransomware – More Information
The JUSTCRY.EXE virus is associated with multiple malicious files which are it’s payload. They are dropped in multiple different Windows folders, such as:
- %AppData%
- %Temp%
- %Local%
- %Roaming%
- %LocalLow%
In addition to this, the JUSTCRY.EXE virus also heavily modifies the Windows Registry Editor, by adding registry entries in the following Registry sub-keys:
→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveActive
HKEY_CURRENT_USER\Control Panel\Desktop\
As soon as they are modified, the JUSTCRY.EXE ransomware locks the screen on your computer, displaying the following ransom note message:
In addition to this activity, the JUSTCRY.EXE ransomware may also obtain information regarding your computer’s IP address, your online accounts, information from your web browser (accounts you are registered in) and other data.


How to Remove JUSTCRY.EXE Ransomware
Since JUSTCRY.EXE ransomware is very difficult to remove manually, because it is still active, even after you boot your computer into Safe Mode, you can remove it using another trick up your sleeve. Here is how to remove JUSTCRY.EXE and unlock your PC.
1. Download a live operating system a safe computer which boots automaticallyfrom a flash drive. Make sure the live OS is Windows and has what is known as AntiWinLocker which unlocks folders of Windows if you boot from a live OS and bypasses user accounts. One of those live Windows OS’s is called Windows 7 LiveCD [Xemom1]. You can find it on many torrent sites.
2. Install the live OS on a flash drive via software, such as Rufus. If you are having difficulty using Rufus, you can follow the instructions on our forum. Use a safe PC, not the one you just turned off.
3.As soon as this is done, make sure to scan your hard drive from the Live OS you have previously installed with an advanced anti-malware software, to remove the malicious files of JUSTCRY.EXE ransomware virus. Below is one such tool which can help removing JUSTCRY.EXE automatically, without having to look for the files and registry objects created by this virus.