Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · May 2017

How to remove Lockout ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Ugnius Kiguolis · The mastermind

Lockout ransomware urges users to remit ransom within 3 days

Lockout virus operates as a file-encrypting threat encrypting files with RSA-2048 algorithm and attaches .lockout file extension. It has a preference for Windows 7 users. After infiltration, and during next reboot, the malware changes regular startup screen with its ransom note entitled as cUrHj2m7C, etc. Certainly, the title might be differ depending on each user’s IP. On the startup screen, it suggests contacting the penetrators via bnd54@mail2tor.com and provide an identification number. It urges affected users to pay the money within three days. When you log into the computer, Payment-isntructions.txt opens up with the same information[1]. Otherwise, the amount of money will double. They also offer to decrypt one file for free to earn users’ trust. Even in that case, it does not mean that the cyber criminals will return all files undamaged. Thus, instead, we recommend you to proceed to Lockout removal. For that purpose, FortectIntego or MalwarebytesMalwarebytes might be of use.The picture illustrating Lockout virus

One of the peculiar features of the virus is its ability to modify boot settings. Thus, this function enables the malware to present its message at startup. Furthermore, the malware behaves like ordinary malware. It connects to Command and Control server to coordinate the malware and its traffic. Due to this ability recovering private, decryption, the key is not an easy task as well. Interestingly, that the definitions by which Lockout malware is detected, relate to a notorious Win32Heur trojan, which was active three years ago, HEUR:Trojan.Win32.Generic. Interestingly, that another recently emerged threat, XData virus[2], which rampaged in Ukraine and managed to occupy four times more computers than WannaCry during the same period of time, also contains references to HEUR trojan. Thus, there is a probability that the scale of the inflicted damage by this malware might rocket. Therefore, the ransomware tends to behave as a screen locker malware as well. Though at the moment, there is no free decryption tool released of the malware yet, you should remove Lockout virus as soon as possible.

Distribution tendencies of the malware

The distribution techniques of Lockout ransomware hardly differ from the other samples of the ransomware family. The fact, that its executable trojan, which might be detected as
W32.eHeur.Malware08, hides in c.exe executable suggests that it may target users in disguise of fake updates, questionable scanners, browser add-ons as well as spam emails. Note that such emails may contain alerting information, such as urgent messages alarming user to review attached files. Such emails may contain typos or grammar mistakes which suggest the origin of the email. Thus, in order to limit the risk of Lockout hijack, install and keep updated anti-malware programs. Besides, it is crucial to retain vigilance while browsing the Web and installing new applications or enabling new features.Lockout  startup screen note

Lockout elimination guide

Regarding the fact that this malware might be related to menacing XData virus, it is crucial to remove Lockout virus right away. For that purpose, security applications come in handy. Taking into account that this malware may block your computer screen, you may face Lockout removal problems. In that case, below guide will come in handy. Thus, below indicated guide would be of use. You may also disturb its process by ending its c.exe task in Task Manager.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.