Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2019

How to remove JCry ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Gabriel E. Hall · Passionate web researcher

JCry ransomware is a crypto-virus that was meant  to be delivered to Israeli website visitors in the #OpJerusalem campaign

JCry ransomware

JCry ransomware is a data locking virus that was spotted in early March 2019, when the malware authors tried to attack thousands of Israeli websites by utilizing Nagich plugin that is used by multiple site developers.[1] However, the scheme failed due to a bug in the code, although the payload could have been distributed with the help of fake Flash Player updates by using flashplayer_install.exe executable. JCry virus takes advantage of AES and RSA encryption algorithms to encrypt data and adds a .jcry marker, denying them access to it after the modifications are performed. The malware drops ransom note JCRY_Note.html, which explains to users that their important files have been encrypted, and they need a decryption key to regain access to them. Hackers ask for $500 worth of Bitcoin to be paid in a provided wallet. Additionally, JCry ransomware spawns a pop-up window Dec.exe which serves the #OpJerusalem message.

Name JCry
Type Ransomware
Related files flashplayer_install.exe, Dec.exe, Enc.exe
Campaign #OpJerusalem #OpIsrael
Cipher AES + RSA
Ransom note  JCRY_Note.html
Ransom size  $500 in Bitcoin
Removal Use reputable security software that can recognize the threat.[2] We recommend using FortectIntego or SpyHunterCombo Cleaner

#OpJerusalem #OpIsrael is an annual cyber-attack campaign used to enforce the Israel-Palestine conflict in the Middle-East against Israel. The attackers who organize the criminal activity are fueled by the goal of “erasing Israel from the Internet” due to political struggle in Gaza strip. This year, on March 2nd, hackers tried to utilize JCry ransomware as a primary attack vector to infect Israeli website users with the malicious code.

However, due to the bug in the code, the payload of JCry ransomware failed to deploy and instead showed “Jerusalem is the capital of Palestine #OpJerusalem” message instead of the original site. The defaced page was intended to be shown to users who are not utilizing the Windows operating system. The flaw in the code made the message to pop-up to every user, however, failing the infection procedure of JCry ransomware entirely.

Nevertheless, JCry virus might be used in other campaigns and distributed by using such methods as spam email attachments or hyperlinks, brute-force attacks, exploit kits, fake updates, etc. Speaking of the latter, the #OpJerusalem attack was meant to be performed with the help of fake Flash updates, so malware authors might use this tactic in the future.

JCry ransomware virus

The flashplayer_install.exe file drops another two executables – Dec.exe and Enc.exe. The latter is the main executable that generates AES and RSA keys for the encryption. After that, JCry ransomware contacts C&C server[3] to send the relevant information and uploads ransom note JCRY_Note.html, which states:

All Your Important Files have been Encrypted
1- Send 500$ worth of Bitcoin to this Address : 1FKWhzAeNhsZ2JQuWjWsEeryR6TqLkKFUt
2- Download Tor Browser and Open the following Link : Recovery Link
3- Enter the Address used in Payement
4- We'll check your Payement and upload your Decryption Key
5- Open the same link again (after a while) and enter your Unique ID to get your Decryption Key
Your Unique Key :

Additionally, the Dec.exe delivers another note with ASCII Text Art “#OpJerusalem,” in addition to “Jerusalem is the capital of Palestine” message.

While it is obvious that the authors of the virus are active participants of the movement against Israel, the fact that they are asking for payment indicates that money might be a motivator as well. Which means that infection rate might be increased rapidly, and users all over the world could be targeted.

In case your device got infected with the virus, you should perform JCry ransomware removal using reputable security software that can detect the threat (we recommend using FortectIntego or SpyHunterCombo Cleaner). Entering Safe Mode with Networking is advised, although it might not be needed in every instance.

Once you remove JCry ransomware from your Windows machine, you can start file recovery procedure. Note that no decryptor is yet available, so ways of recovering data are limited to backups, third-party software or ransom payment. Researchers do not recommend paying or contacting criminals, as chances of being scammed are quite high.

Adobe Flash is an unsafe plugin that is often used by fake update malware delivery tactic

Adobe Flash Player has been a major focus of cybercriminals to infect users with malware. Since the plugin is so widely used, fake updates, which claim that the software is outdated, is a popular tactic used among hackers. Additionally, Flash Player is known to have multiple security flaws that render users vulnerable to malware attacks. These bugs are often patched by Adobe, although many people fail to update software on a regular basis.

Due to significant security flaws and plugins' outdated technology, Adobe plans to shut it down by the end of 2020, discontinuing its support.[4] However, the software is not that needed currently, as newer technology and built-in plugins exist in most modern browsers.

JCry virus

Therefore, it is time to disable Adobe Flash altogether, or at least set it to click-to-run function. Once you stop using the plugin, the danger of installing fake updates will disappear as well. Aside from this, experts also recommend using general safety practices:

  • Employ reputable security software;
  • Use Firewall, VPN, password manager, ad-blocker, and similar tools that can help you increase online safety;
  • Patch your system and software with the latest security updates upon their release;
  • Beware of spam emails – malicious attachments and hyperlinks might lead to malware infection;
  • Avoid using high-risk sites, such as torrent, porn, gambling, etc.;
  • When installing freeware or shareware, always opt for Advanced/Custom installation settings instead of Recommended/Quick ones to avoid optional programs.

Terminate JCry ransomware and only then proceed with file recovery procedure

Before you attempt file recovery, you must remove JCry ransomware from your device. Otherwise, all your backups or recovered files will be encrypted repeatedly.

For complete JCry ransomware removal, you should use anti-malware software that can detect all the malicious entries and remove them. While manual elimination is possible, it requires extensive IT knowledge. Thus, regular users should stay away from tampering with system files, and leave the job to automatic removal tools.

Once JCry virus is terminated, you can connect your backup device or load files from a remote server. If you did not have backups prepared, do not lose hope, as decryption tools are developed by cyberthreat researchers regularly. Additionally, you can also try third-party recovery software that might help you to recover at least some of your files locked by .jcry file virus.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.