Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Mar 2017

How to remove LLTP Locker ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

LLTP Locker ransomware in a nutshell

Spanish users should be extremely vigilant as they can be targeted with a new file-encrypting threat called LLTP Locker virus[1]. Specialists suspect that the malware was derived from well-known virus called VenusLocker. The current version encrypts data with an exquisite encryption algorithm, RSA-2048. Due to this fact, the cyber criminals enjoy terrifying users to comply with their demands. Interestingly, that the crypto-malware is set to operate even in the offline mode. This peculiarity resembles another troublesome ransomware, Spora virus[2]. If you suspect that this virtual menace has descended upon your device, it is high time you initiated LLTP Locker removal. FortectIntego or MalwarebytesMalwarebytes will help you get rid of the threat.

The original version of Venus Locker was based on EDA2 ransomware. It also prefers using RSA-2048 encryption technique. A while ago, it was “internationalized”: it appeared in the Korean language and targeted mainly South Korean residents. Similarly to Locky or Cerber, it asked users to enable macro settings by pressing a combination of keys. Current, LLTP ransomware seems to be an improved version of several viruses. The virus is able to function in both modes, online and offline. It connects to a remote Command & Control server to access http://moniestealer.co.nf. Later on, LLTP Locker malware transmits the technical information about an infected computer as well as user’s details.

The very encryption process is carried out with the help of AES-256 and RSA encryption technologies. AES encrypts the data, and the latter key is encoded with RSA-2048. Later on, it is placed in %UserProfile%\AppData\Local\Temp\tlltpl.tlltpl/. It appends two variations of file extensions: .ENCRYPTED_BY_LLTP and .ENCRYPTED_BY_LLTPp depending on the affected original file format[3]. Unfortunately, LTTP Locker ransomware targets a variety of documents, video and audio files. During the encryption process, it avoids certain folders. Some of them are Program Files, Program Files (x86), Windows, Windows Portable Devices, Windows Photo Viewer, Windows NT, Windows Media Player, Windows Mail, NVIDIA Corporation, Adobe, IObit, AVAST Software, CCleaner, AVG, and Mozilla Firefox.

The picture revealing LLTP Locker

LLTP Locker also creates an additional folder %Temp%\lltprwx86\which contains contains encp.exe file. An additional copy of all affected files with .encrypted_by_LLTPp is placed. Later on, the threat operates as an ordinary crypto-malware. It presents two versions of LEAME.txt, where the Spanish and English translations of the ransom note are displayed. It demands 200 USD in exchange for the data. The sum should be transmitted within 72 hours. It also communicates with victims via LLTP@mail2tor.com. Even though the malware deletes shadow volume copies and leaves fewer options for data recovery, we do not recommend remitting the payment. Instead, remove LLTP Locker right away.

How does this malware spread?

It is transmitted in the form of a trojan: Trojan.MSIL.Filecoder, Trojan-Ransom.Win32.Crypmod.yiz, Malware.Undefined!8.C (cloud:ccEuRwXLGlN), etc. LLTP.exe executes it[4]. In order for LLTP Locker hijack to complete successfully, the executable file might be placed in a .zip folder and named as “invoice” or another important document and attached to a spam message. Exploit kits, and less known forms of malware might also facilitate the attack. Usually, they dwell in poorly protected web pages. You can also lower the risk of getting infected with crypto-malware. Install an anti-spyware program to exterminate LLTP malware.

LLTP Locker elimination steps

Despite how destructive the malware might look, do not let the panic take over. Firstly, launch Task Manager with SHIFT+CTRL+ESC and end LLTP.exe task or another shady process[5]. Then turn on your malware elimination program to remove LLTP virus. If the program is forcefully shut down, use the below instructions to recover full control of the device. Though there is no LLTP Decrypter released yet, some of the below-suggested methods might come in handy. Note that data restore procedure should be completed only when you fully delete the infection.

5 comments

Read in your language

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.