Lmas ransomware infection: it may cost you your files

Lmas ransomware is malicious software that encrypts all personal data and demands a ransom through a generated ransom note. When this cryptovirus infects your Windows device, all non-system files, such as documents, databases, archives, pics, etc., are locked within minutes. Then a ransom note titled _readme.txt appears on the desktop so victims could find cybercriminal demands with ease.
During the encryption, original filenames are appended with a .lmas extension. Their contents aren't changed, but access to them is blocked. The criminals behind this malware demand to contact them through two given emails (helpteam@mail.ch, helpmanager@airmail.cc) and pay either $980 or $490 (depends on whether the victims establish contact within 72 hours of the attack) to get the data back.
This particular file-locking parasite belongs to the infamous Djvu ransomware family who first struck the world in late 2018 and has been terrorizing innocent people around the world since. Due to its prevalence, companies like Emsisoft are constantly upgrading their free decryption software to help ransomware victims regain access to their files without paying a dime to the criminals.
There's no guarantee that such tools will work in your case. We've included alternative data recovery options at the bottom of the article. We'll also explain how to remove this malicious software, inform you of its most popular spreading techniques, and tell you how to restore altered system settings and files.
| name | Lmas ransomware |
|---|---|
| Type | Malware, file-locking parasite, cryptovirus |
| Family | Djvu/STOP ransomware |
| Appended file marker | .lmas extension is appointed to all original file names when data is encoded |
| Ransom note | _readme.txt is found on the desktop after the encryption is done |
| Ransom amount | $980/$490 – differs for victims that contact criminals within 72 hours |
| Criminal contact details | helpteam@mail.ch, helpmanager@airmail.cc |
| Distribution | Mainly file-sharing platforms, but could also travel with fake Flash Player updates, software bundles, deceptive ads, spam emails |
| Elimination | You must use a reliable security tool to remove this cryptovirus or any other hazardous cyber infection |
| System health check | As a rule, this cryptovirus modifies the Registry and other core system settings to establish persistence. Use powerful time-proven system diagnostics tools such as the FortectIntego software to repair any system irregularities |
The operation of ransomware
The latest variants of Djvu family ransomware use military-grade coding algorithms to lock files on the infected computer, making it really hard to decrypt them without the necessary decryption key. New variations from this lineage appear at least once a week or even more frequently. Here are a few examples of its latest cryptoviruses:
When such file-locking parasites bypass your computer's security, they immediately scan for the most frequently used files and begin encrypting them. The whole process takes no more than 5 minutes before victims are locked out of their data. Ransomware doesn't encrypt system files, although it modifies them.
When the encryption is completed, a _readme.txt file appears on the desktop with instructions and demands of the criminals behind .Lmas virus. They try to persuade victims into succumbing to their demands by using various scaring and convincing techniques.

First, they state that only they have the power to unlock encrypted data. Then they offer free decryption of one file from the infected machine. They continue by providing a link to a video where the supposed decryption tool is seen in action and finish by offering a 50% discount on the ransom amount for victims that reach out to them within 71 hours of the attack.
All these methods are used to push you into making rash decisions and paying the criminals. Here's the full message within the ransomware note:
ATTENTION!
Don't worry, you can return all your files!
All your files like pictures, databases, documents and other important are encrypted with strongest encryption and unique key.
The only method of recovering files is to purchase decrypt tool and unique key for you.
This software will decrypt all your encrypted files.
What guarantees you have?
You can send one of your encrypted file from your PC and we decrypt it for free.
But we can decrypt only 1 file for free. File must not contain valuable information.
You can get and look video overview decrypt tool:
hxxps://we.tl/t-9CYW99VhUR
Price of private key and decrypt software is $980.
Discount 50% available if you contact us first 72 hours, that's price for you is $490.
Please note that you'll never restore your data without payment.
Check your e-mail “Spam” or “Junk” folder if you don't get answer more than 6 hours.To get this software you need write on our e-mail:
helpteam@mail.chReserve e-mail address to contact us:
helpmanager@airmail.ccYour personal ID:
No matter how precious your encrypted data is to you, paying the criminals is the least reasonable thing you could do. Hackers could use that money to increase their attacks, research more effective infection methods, and develop more sophisticated malware. This malware can be extremely persistent and dangerous.
That's why you should remove the ransomware from your infected device. But first, try to recover your files with our suggested tools (if you didn't keep backups). Then download free but trustworthy anti-malware software such as MalwarebytesMalwarebytes or SpyHunterCombo Cleaner and perform a full system scan. Proper security tools will detect, isolate, and remove the infection with all residual files automatically.
Since Lmas ransomware virus makes modifications to the Registry, host files, and other key system settings, you have to scan your device with the time-proven FortectIntego system repair tool to restore these alterations. Otherwise, crashing, freezing, severe lag, or even malware renewal is possible. Only after completing all these steps, it's safe to recover data from backups.

The most popular method of Djvu family ransomware distribution
From fake Flash Player updates to drive-by downloads,[1] hackers can use various techniques to infect your computer with hazardous malware.[2] But Djvu family ransomware is mainly spread through file-sharing platforms, especially the most popular torrent websites.
These portals are exploited due to the lack of end-to-end security, meaning no one is checking whether the uploaded files are malicious or not. Cybercriminals upload their evil creations camouflaged as unlocked expensive commercial software, cracks for the latest games, and alike.
A proper anti-malware tool would detect the virus payload files no matter how they're named, but to be safe, we recommend our readers refrain from using torrent sites. Download your desired software directly from its developers or official distributors.
Remove Lmas virus by performing a full system scan with reliable security tools
If a ransomware infection bypasses your security system and encrypts your precious files, the main thing is not to panic and don't make any rash decisions. There are always alternatives to paying the criminals for the decryption key. Please check out our suggestions below for file recovery options.
To ensure that such malware doesn't infect your computer in the future, you have to upgrade your cybersecurity. Free but reliable security software such as SpyHunterCombo Cleaner or MalwarebytesMalwarebytes will do the trick and can be used to remove Lmas ransomware. After installing it, perform a full system scan and let the anti-malware tool do the dirty work for you.
In some cases, Djvu family ransomware prevents victims from launching their AV tools by editing the Registry and other system files and settings. If that happens to you, reboot your Windows PC in Safe Mode with Networking. If you don't know how to do that, please see our instructions posted below.
To repair all system-related issues that the cryptovirus has made to establish persistence, security experts from LesVirus.fr[3] highly recommend using the FortectIntego system diagnostics tool. It will automatically restore all system values to normal so you could enjoy your device anew.
Was this guide helpful?
Be the first to comment