THREAT REMOVAL

JUSTCRY.EXE Ransomware – Remove Virus and Unlock Your PC

This article aims to help you remove JUSTCRY.EXE ransomware virus from your computer and show you how to restore files that have been encrypted by this virus.

JUSTCRY.EXE ransomware is a virus that locks your computer, making it possible to recover them only if you pay a hefty ransom fee to the cyber-criminals who are behind this virus. The malware leaves behind a ransom note as a locked screen message and even if you boot the infected computer back in safe mode, JUSTCRY.EXE still manages to lock your screen. So, in order to remove this virus from your computer without paying a ransom, we advise you to read the following article.

Threat Summary

Name JUSTCRY.EXE
Type Ransomware, Lockscreen
Short Description Aims to lock you out of your computer, restricting access to it, even if you boot it in Safe Mode.
Symptoms Your screen is dimmed down and a lockscreen, named JUSTCRY.EXE appears with instructions on how to pay ransom to unlock your PC.
Distribution Method Spam Emails, Email Attachments, Executable files
Detection Tool See If Your System Has Been Affected by malware

Download

Malware Removal Tool

User Experience Join Our Forum to Discuss JUSTCRY.EXE.

JUSTCRY.EXE – How Does It Infect

The infection process of JUSTCRY.EXE ransomware is very similar to other malware like it. The virus aims to slither onto your computer via malicious e-mail attachments which are obfuscated, in other words, cannot be detected by updated antivirus programs.

The e-mails which may be sent spreading the JUSTCRY.EXE ransomware may contain different types of files, most of which pretend to be legitimate types of files, such as:

  • Invoices.
  • Fake receipts.
  • Fraudulent banking statements.
  • Account activity reports.

The messages attached to the e-mails may have deceptive content within them that aims to convince victims into opening the e-mails themselves.

JUSTCRY.EXE Ransomware – More Information

The JUSTCRY.EXE virus is associated with multiple malicious files which are it’s payload. They are dropped in multiple different Windows folders, such as:

  • %AppData%
  • %Temp%
  • %Local%
  • %Roaming%
  • %LocalLow%

In addition to this, the JUSTCRY.EXE virus also heavily modifies the Windows Registry Editor, by adding registry entries in the following Registry sub-keys:

→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Control Panel\Desktop\ScreenSaveActive
HKEY_CURRENT_USER\Control Panel\Desktop\

As soon as they are modified, the JUSTCRY.EXE ransomware locks the screen on your computer, displaying the following ransom note message:

In addition to this activity, the JUSTCRY.EXE ransomware may also obtain information regarding your computer’s IP address, your online accounts, information from your web browser (accounts you are registered in) and other data.

How to Remove JUSTCRY.EXE Ransomware

Since JUSTCRY.EXE ransomware is very difficult to remove manually, because it is still active, even after you boot your computer into Safe Mode, you can remove it using another trick up your sleeve. Here is how to remove JUSTCRY.EXE and unlock your PC.

1. Download a live operating system a safe computer which boots automaticallyfrom a flash drive. Make sure the live OS is Windows and has what is known as AntiWinLocker which unlocks folders of Windows if you boot from a live OS and bypasses user accounts. One of those live Windows OS’s is called Windows 7 LiveCD [Xemom1]. You can find it on many torrent sites.

2. Install the live OS on a flash drive via software, such as Rufus. If you are having difficulty using Rufus, you can follow the instructions on our forum. Use a safe PC, not the one you just turned off.

3.As soon as this is done, make sure to scan your hard drive from the Live OS you have previously installed with an advanced anti-malware software, to remove the malicious files of JUSTCRY.EXE ransomware virus. Below is one such tool which can help removing JUSTCRY.EXE automatically, without having to look for the files and registry objects created by this virus.

Automatically remove JUSTCRY.EXE by downloading an advanced anti-malware program

1. Remove JUSTCRY.EXE with SpyHunter Anti-Malware Tool

Remove JUSTCRY.EXE with SpyHunter Anti-Malware Tool

1. Install SpyHunter to scan for and remove JUSTCRY.EXE.2. Scan with SpyHunter to Detect and Remove JUSTCRY.EXE.
Step 1:Click on the “Download” button to proceed to SpyHunter’s download page.

It is highly recommended to run a scan before purchasing the full version of the software to make sure that the current version of the malware can be detected by SpyHunter.

Step 2: Guide yourself by the download instructions provided for each browser.
Step 3: After you have installed SpyHunter, wait for it to automatically update.

pets-by-myway-ads-virus

Step1: After the update process has finished, click on the ‘Scan Computer Now’ button.
pets-by-myway-ads-virus
Step2: After SpyHunter has finished scanning your PC for any JUSTCRY.EXE files, click on the ‘Fix Threats’ button to remove them automatically and permanently.
pets-by-myway-ads-virus
Step3: Once the intrusions on your PC have been removed, it is highly recommended to restart it.

Avatar

Ventsislav Krastev

Ventsislav is a cybersecurity expert at SensorsTechForum since 2015. He has been researching, covering, helping victims with the latest malware infections plus testing and reviewing software and the newest tech developments. Having graduated Marketing as well, Ventsislav also has passion for learning new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management, Network Administration and Computer Administration of System Applications, he found his true calling within the cybersecrurity industry and is a strong believer in the education of every user towards online safety and security.

More Posts - Website

Follow Me:
Twitter

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...