Jianglocker Virus 🔐 (. Jiang Files) — How to Remove?

What is Jianglocker virus?

Jianglocker will append its extra .jiang extension to every file’s name. For instance, an image entitled “photo.jpg” will be turned into “photo.jpg.jiang”. Likewise, the Excel sheet with the name “table.xlsx” will end up as “table.xlsx.jiang”, and so on.

In every directory that contains the encrypted files, a read.ini text file will appear. It is a ransom money note. Therein you can find information on the ways of paying the ransom and some other information. The ransom note usually contains instructions on how to purchase the decryption tool from the tamperers. That is basically the scheme of the crime.

NameJianglocker Virus
Extension.jiang
Ransomware noteread.ini
Detection1TrojanDownloader:Win32/Nitedrem.A, Backdoor:Win32/Koceg!B, Win32/GenKryptik.DCUC
SymptomsYour files (photos, videos, documents) have a .jiang extension and you can’t open them.
Fix ToolSee If Your System Has Been Affected by Jianglocker virus

In the screenshot below, you can see what a folder with files encrypted by the Jianglocker looks like. Each filename has the “.jiang” extension added to it.

An example of encrypted .jiang files.

How did my machine catch Jianglocker ransomware?

There are currently three most popular methods for hackers to have ransomware acting in your system. These are email spam, Trojan injection and peer-to-peer file transfer.

If you open your mailbox and see emails that look like familiar notifications from utility services providers, postal agencies like FedEx, web-access providers, and whatnot, but whose sender is strange to you, beware of opening those letters. They are most likely to have a ransomware file enclosed in them. So it is even more dangerous to download any attachments that come with letters like these.

Another option for ransom hunters is a Trojan virus scheme2. A Trojan is a program that infiltrates into your machine pretending to be something legal. For instance, you download an installer of some program you want or an update for some service. However, what is unboxed reveals itself a harmful agent that compromises your data. Since the installation wizard can have any name and any icon, you’d better be sure that you can trust the source of the things you’re downloading. The best thing is to use the software developers’ official websites.

As for the peer networks like BitTorrent or eMule, the threat is that they are even more trust-based than the rest of the Web. You can never guess what you download until you get it. Our suggestion is that you use trustworthy resources. Also, it is reasonable to scan the directory containing the downloaded files with the anti-malware utility as soon as the downloading is finished.

Robert Thorne

Robert Thorne

Automotive & Future Transportation Editor

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.

Share this article
Twitter Facebook Pinterest