JiangLocker ransomware holds files hostage, demanding a ransom in exchange for a decryption tool

The JiangLocker computer virus locks all data on both local and networked drives in order to have a pretense of money extortion. Most frequently, users install ransomware unintentionally when they open a spam email attachment or when they download a malicious file that masquerades as a cracked application. More sophisticated delivery methods, such as drive-by downloads, may also be used sometimes.
As soon as the virus is installed on Windows, it searches for documents, pictures, and other files to encrypt. In just a brief few moments, users would find their data inaccessible, and each of the files would be appended with a .jiang extension, making them lose their original icons as well.
Soon after that, JiangLocker ransomware would deliver a read.ini ransom note, which broadly explains to users what has happened to their files. In addition, a pop-up window would also show up and would include identical text to the one found in the text file. According to the message, users should transfer 0.05 BTC to1PdLyXQb2LpApw3e8DLLRu6vWyWLibaXtJ crypto-wallet (these parameters may vary from user to user) and then use a special button within the pop-up window to recover access to their files. Please ignore these requests and check the info below for a better solution.
| Name | JiangLocker |
|---|---|
| Type | Ransomware, file-locking malware, cryptovirus |
| File extension | .jiang |
| Ransom note | read.ini, “JiangLocker” pop-up window |
| Demands | 0.05 bitcoin |
| Data Recovery | Data recovery is nearly impossible if backups are not available. However, we advise you to try the alternate approaches listed below, which could be helpful to you in some circumstances |
| Malware removal | Manual virus removal is not recommended, as it might be difficult for regular users. Instead, SpyHunterCombo Cleaner or other anti-malware tools should be used |
| System fix | Malware can seriously impact a Windows computer's performance and stability after it is removed. We recommend scanning the system with FortectIntego to remedy it and avoid significant stability issues |
Questionable payment methods and decryptor retrieval
Cybercriminals are well aware of the new trends within their illegal line of business and constantly try new tricks to make victims pay ransoms. For example, attacks on corporate entities and organizations manifested as not only files being held hostage but also sensitive data being stolen from local networks. Crooks then have a pretense of blackmailing them, as they threaten to release this information to the public, which can cause tremendous damage.[1]
When it comes to ransomware which attacks regular computer users, hackers are well aware that most of them don't make proper data backups, abusing this fact to their favor. JiangLocker ransomware authors came up with a small program that would launch as soon as the virus finalizes the data locking process – it should make the payment process easier. Within the pop-up and the ransom note, read.ini lays the following information:
What Happened to My Computer?
Your important files are encrypted.
Many of your documents, photos, videos, databases and other files are no longer accessible because they have been encrypted. Maybe you are
busy looking for a way to recover your files, but do not waste your time. Nobody can recover your files without our decryption service.Can I Recover My Files?
Sure. We guarantee that you can recover all your files safely and easily. But you have not so enough time.
If you want to decrypt all your files, you need to pay.How Do I Pay?
Payment is accepted in Bitcoin only. For more information, click .
Please check the current price of Bitcoin and buy some bitcoins. For more information, click .
And send the correct amount to the address specified in this window.
After your payment, click button.
Once the payment is checked, you can start decrypting your files immediately. it may take a few hours.We strongly recommend you to not remove this software, and disable your anti-virus for a while, until you pay and the payment gets processed. If your anti-virus gets updated and removes this software automatically, it will not be able to recover your files even if you pay!
1. To pay us, you have to use Bitcoin currency. You can easily buy Bitcoins at following sites:
https://cex.io/
https://www.binance.com/
https://www.coinbase.com/2. After then, if you already have Bitcoins, pay our Bitcoin address.
3. Then, press the “Check Payment & Decrypt all Files” button. We will automatically decrypt your files, after bitcoin transfer.
Send 0.05 BTC to;
1PdLyXQb2LpApw3e8DLLRu6vWyWLibaXtJ
Contrary to what they may imply, it is not advisable to contact cybercriminals. The main goal of criminals is to appear approachable and friendly in order to increase the likelihood that victims would pay. This is a grievous mistake, though, since there have been countless instances when victims have paid attackers and yet not gotten the promised decryptor. Besides, there is no guarantee that the setup process of automatic decryption would work in the first place.

How to remove JiangLocker ransomware and recover files?
Many users who get infected with ransomware are shocked as soon as they realize that their files seem to be corrupted and unusable. While ransomware infection can be truly devastating, panicking would not solve the situation, and if you want to have at least a small chance of retrieving at least some of your files, you should perform remediation steps in the right order. Below you will find all you need to do just that.
1. Disconnect from the network
During the infection phase, ransomware often creates a link to a remote server known as Command & Control or C2[2] via the internet. This enables the attackers to carry out a variety of nefarious deeds, including upgrading malware or sending more commands. Therefore, you should isolate your computer from the network as follows before starting the JiangLocker ransomware removal process:
- Type in Control Panel in Windows search and press Enter
- Go to Network and Internet

- Click Network and Sharing Center

- On the left, pick Change adapter settings

- Right-click on your connection (for example, Ethernet), and select Disable

- Confirm with Yes.
2. Remove the infection
It is safe to start the ransomware eradication procedure once the infected machine has been disconnected from the network. It is well known that certain viruses of the ransomware family self-delete after the encryption process is complete, but this variant may not.
Malware can leave remnants of code in the background to continue performing other malicious activities, such as personal data theft or installation of additional payloads when the network connection is reimbursed. Ransomware is frequently found together with other malware, thus, there may be many infections on the system that need to be eradicated as well.
The only way to find out if this is true is by scanning the system with SpyHunterCombo Cleaner, MalwarebytesMalwarebytes, or another trustworthy anti-malware program. Security software can swiftly and effectively identify all harmful files and remove them. Besides, keeping an up-to-date anti-malware running on your system can save you from
3. Fix damaged system components
We advise repairing the operating system harm caused by ransomware. After entering the system, malware has the ability to change and damage certain components, which might subsequently cause system errors, crashes, or BSODs.[3] You may use the following potent PC repair tool to remedy that:
- Download FortectIntego
- Click on the ReimageRepair.exe

- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process

- The analysis of your machine will begin immediately

- Once complete, check the results – they will be listed in the Summary
- You can now click on each of the issues and fix them manually
- If you see many problems that you find difficult to fix, we recommend you purchase the license and fix them automatically.

4. Restore your files without paying
Although the FBI and security professionals strongly advise against paying ransoms or even getting in touch with cybercriminals, the decision is always up to the victim. But keep in mind that by paying the ransom, you're merely encouraging the attackers to produce more malware and infect other people – it's just evidence that the illegal business is profitable. The only way to fully prevent the devastating consequences of a ransomware attack is by keeping secure data backups – it can be done via reliable services such as Google Drive or OneDrive – we provide instructions for this below.
As for now, you should concentrate on restoring .Jiang files to their original form, where they could be opened and used once again. Before proceeding, make sure you copy all the encrypted files on your system onto a different medium, such as a USB flash drive or cloud service. Otherwise, files may be permanently corrupted, and even a working decryptor would no longer work.
Did this guide help?
Be the first to comment