Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Oct 2016

How to remove JokeFromMars ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

JokeFromMars (MarsJoke) virus is a poor knockoff of CTB-Locker virus

According to the latest researches, JokeFromMars virus spreads using even three different names – the previously mentioned one, also MarsJoke and Polyglot. If any of these names look familiar, you should know that you are dealing with ransomware-type infection which mimics an infamous CTB Locker. It is believed that current versions of JokeFromMars malware pose as CTB-Locker in order to confuse malware researchers, however, research shows that these two viruses share no code, but operate in a very similar way. The lock screen that these viruses display is almost identical, besides, both of them allow the victim to test the decryption tool by decrypting 5 selected files. The virus triggers “Request failed” message in case the compromised computer loses Internet connection during attempt to test the decryption tool. It is apparent that the developer of this virus precisely copied modus operandi of CTB-Locker, however, the JokeFromMars virus does not append file extensions to encrypted data. Besides, despite that two years already passed since CTB-Locker first showed up, it is still an undefeated computer threat and nobody can decrypt their files for free. Speaking of MarsJoke ransomware, the developer of it wasn’t precise enough, and malware researchers managed to create a free JokeFromMars decryption tool using a flaw in virus’ source code. You can decrypt your files for free using Data Recovery guide provided below the text. Do not forget to remove JokeFromMars virus first!

How does this virus operate?

MarsJoke ransomware may appear less powerful than other file-encrypting threats, but don’t make a severe mistake by underestimating it. It gets into the system or network as a file_6.exe executable that is used to install a malicious code and launch the ransomware virus. As soon as it becomes active, it encrypts all your files with a strong encryption algorithm (known as AES-256 cipher) and demands ransom in exchange for them. In this sense, it does not stand out much from other samples of ransomware. Nonetheless, it is interesting that MarsJoke virus is spread using the Kelihos botnet which has tripled in size within 24 hours after the virus was released. It only suggests that the cyber criminals have been preparing for the mischief quite some time before the ransomware itself was even launched. And this broad network of “zombie” computers has been accumulated for a very specific reason — to target computers of located in schools, state and local governmental institutions. Unfortunately, this does not mean that your personal computer is safe from this infection. You still might get infected, so you must learn the basic aspects of the JokeFromMars removal. We discuss them later in the article. But if you do not have time for that, obtaining a proper malware elimination utility, such as FortectIntego, should solve this problem automatically.

The example of JokeFromMars virus

What is more, the ransomware changes your background picture after the invasion. When the cyber threat succeeds in taking control of the computer, the virus makes sure you get acquainted with the current situation by opening ReadMeFilesDecrypt!!!.txt message which looks like that:

 the ransom message of MarsJoke virus

It is clear that MarsJoke virus operates in the same manner as the vast of other ransomware threats. It sets a certain time period within which you should transmit the payment of 0.7 Bitcoin, which currently equals around 421 USD. Of course, the criminals clearly indicate that if the ransom money is not transferred until the deadline, the sum demanded for the files will double or the victim might lose any chance of recovering his/her files entirely. Terror is a common practice the hackers use to convince victims into remitting the payment. Besides, looking at the common practices, there are no guarantees that you will retrieve the files even after paying the ransom. Instead, we offer you to remove MarsJoke and focus on other methods of data recovery.

Distribution methods

Less known viruses tend to employ the proof-check technique of placing the infected executables in the spam messages. In order to occupy as many PCs as possible, they present such malicious miles as fake invoices, package delivery reports or tax refund files. Therefore, this distribution method is still highly profitable. JokeFromMars also employs the same techniques. As mentioned previously, it employs a botnet of computers to distribute spam emails with a malicious software attached to them. Usually, the MarsJoke emails its victims a fake flight confirmation document with a malicious executable hidden within. Let us suggest you not to open unknown emails unless you can verify the sender. Even if the email is sent from the governmental institution, keep in mind the possibility of a fraud and always double-check the facts. In addition, you can reduce the amount of received commercial spam or infectious emails by installing a reliable anti-spyware application.

JokeFromMars removal guide

Since this threat is still a highly damaging threat, you should not postpone its removal. Each minute counts because this ransomware can continue the encryption of your files. We want to encourage you to take care of MarsJoke removal carefully by using reputable security software. We used FortectIntego, SpyHunterCombo Cleaner and MalwarebytesMalwarebytes when tested this virus. You may try to remove JokeFromMars manually unless you specialize in the IT sphere. Keep in mind that ordinary users are not advised to waste time on this method since the malware might have scattered its files on the entire system. In case you cannot remove JokeFromMars virus because it locked your screen, feel free to use the below-indicated guidelines. We should also add that anti-spyware, anti-virus and similar security software can only ensure elimination of malicious files. Such programs cannot decrypt your affected files, so you need to follow “Data recovery” guide as well to get your files back. 

Did this guide help?

4 comments

  1. Robbie

    This is no joke at all...

  2. grudge547

    And they continue making fun of us.

  3. willa

    When is it going to stop?

  4. cyber-jam*

    Does anybody know when the decrypter is released?

Read in your language

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.