JNEC.a ransomware is a file locking malware that spreads with the help of WinRAR code execution vulnerability

JNEC.a ransomware is a new malware string that was recently discovered by security researchers at 360 Threat Intelligence Center.[1] Written in the .NET programming language, the malware takes advantage of a WinRAR vulnerability to spread.
The threat uses a sophisticated encryption algorithm to comprehensively lock personal pictures, databases, documents, spreadsheets, and other files and then appends a .Jnec extension, preventing users from operating any of the data located on the PC.
Afterward, the virus drops a pop-up window with basic information, such as the number of files encrypted, ransom size (0.05 BTC), the Bitcoin wallet, and a generated email address that the victim needs to create on Gmail web service, which will allow the attackers to send the alleged decryptor through. Nevertheless, excessive research of the virus showed that even the ransomware authors would not be able to decrypt locked files, so paying the ransom is completely pointless.
| Name | JNEC.a |
| Type | Ransomware |
| Related files | GoogleUpdate.exe, JNEC.A.exe, vk_4221345.rar, iku_m2VtkXA.jpg |
| Ransom note | JNEC.README.TXT |
| Distribution | 19-year old WinRAR vulnerability |
| Ransom demand | 0.05 BTC |
| Decryptabe? | No, but paying the ransom is useless as even the malware author would not be able to decrypt data |
| Removal | Use security software that can recognize and safely remove the malware |
| Recovery | Scan your PC with the FortectIntego system diagnostics tool to recover from virus damage |
In addition to a pop-up window, this infection also drops a text file called JNEC.README.TXT just so that users could properly comprehend what to do next. The message states:
Deposit amount: 0.05 BTC
BTC Address: 1JK1gnn4KEQRf8n7pHZiNvmV8WTXfq7kVa
Your ID: [redacted]
Your Email: [redacted] (Create a mail to get the decryption key)
Ransomware viruses generate the ID of the victim individually, which is ten consequently tied to a unique decryption key stored on a remote server. JNEC.a virus authors ask users to create the Gmail account using this ID, where they allegedly would receive the decryptor to.
At the time of the writing, 34 AV engines recognized this hazardous virus as:[2]
- Trojan.BTCWare – MalwarebytesMalwarebytes
- Trojan:Win32/Pynamer.B!ac – Microsoft
- Win32:Malware-gen – AVG
- Ransom.Win32.JNEC.A – Trend Micro
- UDS:DangerousObject.Multi.Generic – Kaspersky
Therefore, to remove this ransomware, you should download reliable anti-malware tools such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes. Afterward, we highly recommend scanning your device with the FortectIntego system optimizer to recover your system from the damage done by the virus.

The infection procedure and a 19-year old WinRAR vulnerability
Security researchers at Check Point recently unveiled a devastating vulnerability that has been affecting the file compressor software WinRAR for over 19 years – CVE-2018-20250.[3] The file archiver is one of the most popular software of such kind, available in 46 languages, so the discovery of vulnerability is huge.
According to researchers, the vulnerability can be exploited by at least 100 different exploits, which puts over 500 million users at risk. To stop the vulnerability in the unacev2.dll[4] library from being exploited, the developers had to stop the support for all ACE format versions from build 5.70.
The payload of JNEC.a ransomware is hidden inside a compressed .rar file called vk_4221345.rar, which users can download from anyone on the internet. When trying to open it, they are presented with a picture (iku_m2VtkXA.jpg) of a female, although the image seems o be corrupted. This might seem like a normal behavior due to failed decompression of the archive.
Victims who use vulnerable versions of WinRAR, who attempt to open the picture, will be automatically infected with this article's culprit. The vulnerability allows this malware to place the main executable GoogleUpdate.exe into the Windows Startup folder, which consequently lets the malicious program boot every time the operating system is launched.
The file encryption process takes much longer than usual, as all the files are encrypted fully – meaning that all the data in the binary file are encrypted instead of a part of it. Additionally, due to the bug in the encryption process, even the virus creators would not be able to decrypt it.
Instead, victims should focus on JNEC.a ransomware removal procedure. Those who had no backups are most likely doomed to lose their files forever, although third-party software might be helpful in some cases. Additionally, researchers might create an official decryptor, and then you could retrieve all the data encrypted by this cryptovirus for free.

Include software updates into your computer usage routine to avoid malware authors exploiting its vulnerabilities
Software vulnerabilities are bugs that allow attackers to use exploit kits to execute commands on the affected machine remotely. This means that if you have a piece of software installed that is not patched, hackers might abuse the flaw to install malware on your system. While the process still depends on users' activities (such as downloading a file or visiting a compromised website), the software flaw is what ultimately results in system compromise.
For that reason, you should apply software patches to all the installed applications as soon as possible. The best way to do so is by allowing the app to update itself – most developers implement an automatic update feature. However, those who have it turned off not only risk being exploited by malware authors but also running into fake update sites that host unwanted or even malicious programs.
The best example comes from Adobe Flash Player, as hackers have been exploiting the program for years now, despite numerous patches.[5] Additionally, having comprehensive security software installed is mandatory, as it can warn users of the incoming threats and prevent them from infecting the machine in the first place.
Remove JNEC.a ransomware by using a security tool that can detect the threat
Due to the nature of malware, manual ransomware removal is not recommended to anyone. Instead, you should make sure to install a security application such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes that can detect the malware and eliminate it promptly. However, before you can accomplish that, we recommend you enter Safe Mode with Networking, as the virus might prevent security anti-malware software from operating correctly.
Unfortunately, there are very few chances to retrieve files locked by this file-locking parasite if you had no backups ready. Nevertheless, do not lose hope, as a recovery of at least some of your data might be possible with the help of third-party software. Check out the instructions below.
Please remember that you need to remove JNEC.a ransomware before this, as all the recovered files will be repeatedly locked, rendering the recovery process useless. It is also recommended to perform system diagnostics with the FortectIntego software before proceeding with file recovery.
Did this guide help?
Be the first to comment