Locky ransomware: what it is and how to remove it
Locky virus is a dreadful data-encrypting parasite which managed to dangerously proliferate and infect thousands of computers since its first appearance at the beginning of 2016. Convinced by the success of the initial virus version, authors of this crypto-ransomware have created more differently named versions of it - Diablo6, Osiris, Aesir, Bart or Zepto virus.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Before you restore backups, a full scan can confirm the program that added .locky is gone.
Do it yourself · free Remove Locky ransomware yourself 6 steps, about 18 minutes, no software needed.
Start the steps
Locky ransomware: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Ransom note | _Locky_recover_instructions.txt; the text is quoted in full below |
| Contact | Not recorded in our earlier report |
| Encrypted file extension | .locky |
| Decryptor | No free decryptor is known for this variant; check No More Ransom (nomoreransom.org) for updates |
| Distribution | Not recorded in the old report |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Damage | Not recorded in the old report |
|---|---|
| Name | Locky ransomware |
| Type | File-encrypting ransomware |
| Symptoms | Files renamed with a new extension and a ransom note left in folders |
| Evidence | One write-up by a security site; no sample analysed yet |
| Encrypted files | .locky |
| Free decryptor | No free decryptor is known (checked 7 October 2026) |
| First seen | 16 August 2017 |
| Facts checked | 7 October 2026 |
What readers reported about Locky ransomware
Stay away from Locky ransomware!!. I want to warn all PC users about Locky!! Have you heard about it? It spreads as INVOICE, so stay away from emails with such attachments!! Thank you.
Locky virus removal problem. I am infected with Locky virus. It has affected my files, but I have already managed to face up that these files are doomed. However, I need to remove this ransomware from my computer and I don't know how could I do that. Could you help me with Locky removal? Thanks!
AutoLocky ransomware? Help me, please! Cannot open my files. Oh my god, my hands are shaking! I think I have just installed some malicious program on my computer! It's AutoLocky ransomware, I guess! Can you tell me how to decrypt my files?! is it even possible?! I cannot open them!!!
From the comments under our earlier guide; names and contact details removed.
- File extension:
.locky - Note file:
_Locky_recover_instructions.txt
From our report of Aug 2017 · not reviewed since
More from our earlier report on Locky ransomware
- Dear , Please see the attached invoice (Microsoft Word Document) and remit payment according to the terms listed at the bottom of the invoice.
- Let us know if you have any questions.
- We greatly appreciate your business!
- You can try to use one of these tools (they might help you to decrypt at least some of your files): Kaspersky virus-fighting utilities, R-Studio or Photorec;
- Update it as soon as the new version is available;
How Locky ransomware behaves
From our report of Aug 2017 · not reviewed since
Locky ransomware makes a comeback in August 2017
Locky virus is a dreadful data-encrypting parasite which managed to dangerously proliferate and infect thousands of computers since its first appearance at the beginning of 2016.
Convinced by the success of the initial virus version, authors of this crypto-ransomware have created more differently named versions of it - Diablo6, Osiris, Aesir, Bart or Zepto virus.
These viruses pose a serious threat to the computer system because Locky encryption algorithm can corrupt files not only on the compromised computer system and devices plugged into it, but also data on unmapped network shares. The reason why this virus encrypts victim's data is that it wants to receive a ransom payment, and this is why this virus is known as Locky ransomware.
After infecting the system, this Trojan-type pest uses an embedded encryption key (earlier, this ransomware used to connect to its Command & Control servers to get this key), then scans all system folders for particular file types and encrypts them with military-grade encryption, which securely detains victim's files as hostages.
The virus does not only encrypt files but also changes their filenames and adds .locky file extensions to them; this way, the virus seeks to confuse the victim and make it harder to decrypt particular data. If you are looking at suspicious file extensions added to your data, you are infected with this ransomware which will keep your files blocked until you pay a ransom.
To explain to the victim how to pay the ransom, the virus creates a ransom note called _Locky_recover_instructions.txt and saves a copy of it in every single folder that holds encrypted data. The ransom note contains the following message:
After that, virus changes desktop background with a _Locky_recover_instructions.bmp image, which displays the same information as the ransom note provides. The .onion links presented in both these files left by the virus lead to Locky payment website, which offers the Locker Decrypter for 0.5 or 1.0 BTC, (approximately 300-600 USD dollars at the time of writing this report).
You might think, "why I have to pay when I can use Volume Shadow Copies to restore my data?" Well, we have to disappoint you by saying that the virus runs the following function - vssadmin.exe Delete Shadows /All /Quiet , which carries out elimination of these copies. Therefore, there is no way to recover your precious files from these copies.
On top of that, malware researchers still cannot crack virus' source code and defeat this virus by creating a free Locky ransomware decryptor, so affected PC users have two options only:
If you decide to pay the ransom, you should note that security experts do NOT recommend doing so as there is no guarantee that hackers actually give their victims a key that they need. In this case, you have to remove Locky ransomware from your computer. You can use for that.
Update August 15, 2017. As summer 2017 draws to a close, Locky's developers presented their latest creation - Diablo6 ransomware virus. A relatively quiet summer season is usually known as a "holiday season" for cyber criminals; however, it seems that this doesn't apply for Locky's cybercrime gang. The malware developers are actively pushing this upgraded ransomware variant that uses .diablo6 file extension to mark victim's files once they're encoded.
The new ransomware wave was first noticed on August 9th, with a small test campaign the day before it. This time, virus' developers rely on spam again - they distribute the virus via email. The first spam campaign used archived VBS files to compromise victims' computers.
Criminals distributed emails with such subject lines -E (random numbers).docx. The attachment inside the email is named identically, except that its file format is different - it is a ZIP file. The archived file contains a VBS file that works as a ransomware downloader.
The second campaign used malicious DOCM files disguised as PDF files. Criminals distributed emails with such subject lines - IMG_ .PDF. The PDF file contains an embedded DOCM file with malicious Macro code. If the victim enables documents' contents, the code activates and connects to a remote domain to download the virus from it.
Opening these files guarantees instant data loss as the Diablo6 virus hidden in remote servers gets downloaded to the system by the malicious VBS or DOCM file instantly.
- Let crooks win and pay the ransom to them;
- Refuse to pay the ransom and restore them from backup or wait until a decryption tool gets released.

From our report of Aug 2017 · not reviewed since
The main Locky's attack vector
This computer threat spreads as a malicious Word document attached to spam emails that pretend to be delivering an invoice:
This email contains an attachment, which is named invoice J-[8 random numbers].doc. If the user opens this file using Word, Locky malware might start its malicious processes right away. It all depends on whether the user has Macros function enabled in Word or not.
If user does not have Macros turned on, Locky's document showcases a distorted text and then it asks to enable Macros to review it - "Enable macro if the data encoding is incorrect." You should NOT do as commanded! If the user enables Macros, a malicious code gets activated.
It downloads and runs an executive file of Locky virus, which immediately starts file encryption process. The ransomware runs its processes that scan system for personal files, including audio, video, image files, documents, and locks them using RSA-2048 and AES-128 encryption algorithms.
What is more, this virus can access and encrypt data stored on external drives that are plugged into your device. After the encryption process is done, this virus renames the affected files - it adds a .locky extension to the filenames.
Recently, authors of Locky and Zepto created a new crafty technique to deceive anti-virus programs from detecting the source of infection and allowing the virus to freely encrypt all files without being stopped. For that, the virus is distributed via an archived JavaScript attachment, aka downloader script.
Once executed, it downloads and decrypts malicious payload which arrives in the form of DLL file. This file is run with the help of rundll32.exe file. Typical antivirus programs consider the rundll32.exe file as safe one, so Locky and Zepto easily passes computer protection and steps into the system to wreak havoc there.
We also must add that people who tend to keep their computers unprotected risk to be attacked by JS.Nemucod Trojan horse, which can remain silently in the system for a while and then drop malware on the system. This Trojan horse is well-known conspirator involved in Locky's distribution scheme.
From our report of Aug 2017 · not reviewed since
Locky ransomware variations
Locky virus.
The first version of the malware has been spotted at the beginning of 2016. Since then it was updated several times, and now it is responsible for 50% of recognized ransomware attacks. The virus drops a three (some versions leaves two) files that include a ransom note. Hackers launched malicious email campaigns and spread infected Word documents.
When users activated macro command, virus infiltrated the system and encrypted files using AES-128 and RSA-2048 algorithms. Then it dropped a ransom note _Locky_recover_instructions.txt to each folder that stores encrypted files. The ransom note includes information about data encryption and decryption. Hackers explain that paying the ransom (0.5-1 BTC) is the only possibility to decrypt files.
Ransom note also provides information how to purchase Bitcoins, install Tor browser and use Locky Decrypter – a tool which is supposed to restore all damaged files. Unfortunately, malware researchers haven't created a free data decryption tool yet. However, we do not recommend using any data recovery solution suggested by the criminals. At the moment the only safe and free solution is to restore files from backups.
AutoLocky virus. Oppositely from Locky, AutoLocky was written not in C++ but in Autolt language; and this made malware the weakest version. Malware spreads via malicious spam emails.
Hackers attach an infected PDF file, and when users open it, the virus gets inside and starts encrypting files using the AES-128 cipher. It demands 0.75 Bitcoins for data recovery, but it's not necessary. There's a free AutoLocky decryption tool.
.locky file extension virus. Similarly to other malware variants, it encodes files using RSA-2048 and AES-128 ciphers and appends a .locky file extension to all corrupted documents, pictures, audio, video and other files. Following data encryption, it drops a ransom note where hackers demand 0.5 Bitcoins.
Unfortunately, malware researchers haven't created a free decryption tool yet, but it's not the reason to pay the ransom. If you have data backups, you can restore files after virus elimination. Another bad news is that .locky file extension virus has been updated in June 2016.
The newest version is called Diablo6 virus. For possibility to decrypt files with Locky Decryptor, criminals ask for 0.5 BTC . Please, do not transfer this enormous amount of money, because there's no guarantee that this tool will decrypts your files.
Bart virus. Instead of encrypting files with a sophisticated algorithm, this version of Locky virus adds files into a password-protected ZIP archive.
All archives have .bart file extensions and only Bart Decryptor can retrieve damaged files for 3 BTC. The payment website offers translation to several languages and looks similar to Locky's. The virus has another unique characteristic.
Before data encryption, it checks computer's default language settings. If targeted computer's language is Russian, Ukrainian or Belorussian, malware uninstalls itself. Malware researchers have created a free decryption tool and this fact motivated hackers to update the virus.
They have developed a Bart v2.0 ransomware virus that still adds targeted files to ZIP archive, but appends .bart2 extension to each of them. Unfortunately, this version is still undecryptable, unless you are willing to pay about 2 BTC for cyber criminals (NOT recommended).
ODIN virus. For data encryption virus use the same encryption method, but appends different file extension - .odin. The virus mostly targets Europe, but computers in Asia, Africa, and the USA suffered from it as well. The virus spreads via malicious email attachments.
It's already known that some emails have a subject line "Receipt "; however, there're hundreds of different infected emails. After successful file encryption, it drops a ransom note and tells that the only possibility to get back access to the files is to pay the ransom.
Thor virus. This variant appeared on October 2016.It encrypts for more than 400 different file extensions and encodes them using RSA and AES encryption. Following a successful file encryption, virus delivers two files _WHAT_is.html and _WHAT_is.bmp. These files include so-called ransom messages and explain to victims that they can restore their files using Locky Decryptor for 0.5 Bitcoins.
Shit virus. At the same time when Thor launched its first campaigns, computer users from France reported that their files were corrupted and had a .shit file extension. For file encryption virus uses a military grade AES CBC 256-bit encryption and, unfortunately, there's no way to decrypt them for free.
The virus leaves the same ransom note and demands the same amount of money like Thor. Unfortunately, victims can restore their files for free only from backups.
Hucky virus. It's a Hungarian version of the Locky which appends a .locky file extension to all affected files. It can only encrypt around 200 different file types. The virus uses an updated version of the _locky_recover_instructions.txt, and after file encryption malware drops a _Adatok_visszaallitasahoz_utasitasok.txt.
In this ransom message, victims learn that they have only 24 hours to contact cyber criminals via provided email. Hackers do not reveal the size of the ransom, but it might vary from 0.5 to 2 BTC.
Diablo6 virus. Diablo6 ransomware emerged in August 2017. The virus wreaks havoc on the computer system, turning all files into useless pieces and adding .diablo6 file extension to them. After a successful data encryption, malicious software drops diablo6.htm and diablo6.bmp files.
One of these is set as desktop's background, and the other one opens a message from cyber criminals. As usual, the victim gets instructions on how to access a payment site via Tor network and learns that files can be decrypted for a ransom worth half a Bitcoin.
The new Locky version is currently being pushed via two spam campaigns. One of them delivers a malicious ZIP attachment with a VBS file into it, and the other spreads malicious PDF files with embedded DOCM documents in them. The victim can get easily convinced to open these attachments because scammers spoof sender's email to make it appear legitimate.
Besides, the message body usually contains no suspicious details. The criminals may leave a short note such as "Files attached. Thanks." Opening attachments of such email can completely compromise your computer and make you lose your files for good.
The Locky ransomware note
! ! ! IMPORTANT INFORMATION ! ! !
All of your files are encrypted with RSA-2048 and AES-128 ciphers.
More information about the RSA and AES can be found here:
Decrypting of your files is only possible with the private key and decrypt program, which is on our secret server.
To receive your private key follow one of the links:
If all of this addresses are not available, follow these steps:
! ! ! Your personal identification ID: ! ! !
How to remove Locky ransomware
Tools you'll need
All of these are free except where noted. Download them on a clean device if the infected PC is offline.
- A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
- Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
- Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
- ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
- No More Ransom: the free decryptors from police and security companies; check it again every few months.
- Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.
How to remove Locky ransomware and get your files back
Work in this order.
Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.
Step 1: Disconnect the PC and unplug backup drives
Unplug the network cable or turn off Wi-Fi, and disconnect USB drives, external disks and network shares, so Locky ransomware cannot reach more files. Pause OneDrive, Google Drive or Dropbox sync, because synced folders upload the encrypted copies over the good ones.
Leave the PC on but offline while you read the next steps, since a restart can let the ransomware run again. This applies to Windows 11 and Windows 10 alike.

Windows 11: turn off Wi-Fi to take the PC offline. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 2: Save the ransom note and confirm the family
Your files now end in
.lockyand the instructions are in_Locky_recover_instructions.txt. Save both to a USB stick, a copy of the note and two small encrypted files, before anything else.On another device, check them with ID Ransomware or Crypto Sheriff: the family name decides which decryptor, if any, can help. Keep the note's ID and contact line for your report.

Windows 11: the ransom note and encrypted files to copy for identification. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 3: Check for a free decryptor
Our last check found that for Locky ransomware, no free decryptor is known (checked 7 October 2026). Look again yourself in the No More Ransom list and the free decryptor pages of Emsisoft, Avast and Kaspersky, which add new families every year.
A decryptor needs the ransomware gone first, or it encrypts the files again. Keep at least one copy of the encrypted files on an external drive, even if no tool works yet.
Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 4: Remove the ransomware before you restore or decrypt
Removing Locky ransomware does not bring the files back, but it has to come first. Start with Defender's Full scan, then the offline scan from the same Scan options page, which checks the disk before Windows loads.
If the scan cannot start, use Safe Mode with Networking. Delete the ransom notes only after you have saved a copy, because removal tools sometimes leave them behind on Windows 11 and Windows 10.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Look for shadow copies of the files
Windows keeps shadow copies for restore points and backups, and some ransomware fails to delete them.
vssadmin list shadowsin an administrator Command Prompt tells you at once whether any exist.If they do, right-click the folder that held your files, open Properties > Previous Versions, select a version from before the attack, and click Open to check it before you Restore or copy the files out. Windows 11 and Windows 10 both have the tab.

Windows 11: vssadmin list shadows shows whether shadow copies exist. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 6: Restore the files from a backup or recover deleted originals
A backup made before the attack is the surest way back. Connect it only once the PC is clean, then restore from File History, Windows Backup, OneDrive's Restore your OneDrive or your own external copies.
Without a backup, try file recovery: the originals that Locky ransomware deleted may still be on the disk until something overwrites them. Install nothing new on the drive you want to recover from on the Windows 11 or Windows 10 PC.
Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Manual removal using Safe Mode
Important! →
Manual removal guide might be too complicated for regular computer users. It requires advanced IT knowledge to be performed correctly (if vital system files are removed or damaged, it might result in full Windows compromise), and it also might take hours to complete. Therefore, we highly advise using the automatic method provided above instead.
Step 1. Access Safe Mode with Networking
Manual malware removal should be best performed in the Safe Mode environment.
Windows 7 / Vista / XP
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.

Windows 10 / Windows 8
- Right-click on Start button and select Settings.

- Scroll down to pick Update & Security.

- On the left side of the window, pick Recovery.
- Now scroll down to find Advanced Startup section.
- Click Restart now.

- Select Troubleshoot.
- Go to Advanced options.

- Select Startup Settings.

- Press Restart.
- Now press 5 or click 5) Enable Safe Mode with Networking.

Step 2. Shut down suspicious processes
Windows Task Manager is a useful tool that shows all the processes running in the background. If malware is running a process, you need to shut it down:
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Click on More details.

- Scroll down to Background processes section, and look for anything suspicious.
- Right-click and select Open file location.

- Go back to the process, right-click and pick End Task.

- Delete the contents of the malicious folder.
Step 3. Check program Startup
- Press Ctrl + Shift + Esc on your keyboard to open Windows Task Manager.
- Go to Startup tab.
- Right-click on the suspicious program and pick Disable.

Step 4. Delete virus files
Malware-related files can be found in various places within your computer. Here are instructions that could help you find them:
- Type in Disk Cleanup in Windows search and press Enter.

- Select the drive you want to clean (C: is your main drive by default and is likely to be the one that has malicious files in).
- Scroll through the Files to delete list and select the following:
Temporary Internet Files
Downloads
Recycle Bin
Temporary files - Pick Clean up system files.

- You can also look for other malicious files hidden in the following folders (type these entries in Windows Search and press Enter):
%AppData%
%LocalAppData%
%ProgramData%
%WinDir%
After you are finished, reboot the PC in normal mode.
From our report of Aug 2017 · not reviewed since
Steps to take if the system gets compromised by Locky virus
Speaking of ransomware, it is always better to secure yourself before it attacks you.
No matter how attentive and careful computer user you are, you can still be deceived by cyber-criminals, because they tend to spread malware like Trojan horses. In other words, malware comes as a safe-looking file that is infected. We strongly recommend to regularly create copies of your data and store them on an external hard drive.
Unfortunately, Locky is a disastrous virus, which can lock your personal files forever. As we have mentioned, you should not think that it lets its victims recover their files from Shadow Copies because this noxious virus simply deletes them.
Therefore, the only 100% working method to recover your files is to import them from an external drive. However, you must eliminate Locky malware before you do so, because as we have already stated before, it can encrypt records stored on external drives that are plugged into the infected machine, too.
If you do not have copies of your files xeroxed on an external drive, you have three options left:
Alternatively, you can try software. These three programs are professional malware removal tools that can completely terminate the virus.
NOTE. Anti-malware programs DO NOT decrypt the encrypted data. They are meant to eliminate malicious programs and their components.
- You can wait until someone creates a Locky decryption tool (this might take a long time);
- The last option is to pay the ransom, but we DO NOT recommend doing so. Not surprisingly, there is NO guarantee that cyber-criminals will give the decryption key for you. Plus, think about it - do you want to support cyber-criminals in such way?
From our report of Aug 2017 · not reviewed since
Avoid ransomware by following these rules
- Keep your computer security software up-to-date. Update it as soon as the version is available;
- Protect your PC with anti-malware software and make sure Windows Firewall is always turned on;
- Back up your files. We do not recommend using online data storage clouds because some viruses can reach them using your Internet connection;
- Do not wander through 'Spam' or 'Junk' email sections and make sure you do not open any suspicious emails or attachments that come with them;
- Update software frequently - make sure Java, Adobe Flash Player or other programs are up-to-date.
- Keep your computer security software up-to-date. Update it as soon as the version is available;
- Protect your PC with anti-malware software and make sure Windows Firewall is always turned on;
- Back up your files. We do not recommend using online data storage clouds because some viruses can reach them using your Internet connection;
- Do not wander through 'Spam' or 'Junk' email sections and make sure you do not open any suspicious emails or attachments that come with them;
- Update software frequently - make sure Java, Adobe Flash Player or other programs are up-to-date.
From our report of Aug 2017 · not reviewed since
Expert tips on Locky virus removal
Before you try to remove Locky virus from your computer, you have to realize that you are dealing with a seriously dangerous virus.
To remove this virus entirely, you have to get rid of each of its files because it can easily come back to your computer and encrypt NEW files right after rebooting it.
However, the virus can attempt to block these programs, so in order to launch them, or if you do not have one of these yet - download them, you have to reboot your PC into the Safe Mode first.
Please look at instructions provided below and carry them out carefully to run the malware removal program and complete Locky removal procedure.
Unfortunately, .locky file extension files can be recovered only with the help of the unique decryption key that is securely held by cyber criminals. If you are not willing to pay money for your own files, or simply if you do not want to give away your money for filthy scammers, you DO make the right choice.
We always encourage users not to pay up, because first of all, no one gives any guarantees that the decryption tool offered by criminals actually works, second, it might arrive in a package together with more malicious files. To recover your records, please use backup drives.
If you haven't created a data backup back in the day, then you can try to search for healthy files to replace the encrypted ones by looking through your USBs, files sent via social media or emails, CDs or DVDs. Make sure that you delete the virus first before trying to recover your files!
Otherwise, it will encrypt files in the data storage device as soon as you plug it in or encode files that you download to your computer system from the Internet.
Although there is no guarantee, it might help you to restore the encrypted data.
Use Windows Previous Versions feature
If your files have been corrupted by this filthy ransomware, you might want to restore some individual files. You can try to do that by carrying out the following commands:
Report it and recover your files
Report it
Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.
- United States
- FBI IC3 · FTC ReportFraud
- United Kingdom
- Report Fraud (formerly Action Fraud) · NCSC
- Australia
- ReportCyber (ASD)
- EU countries
- Europol: national reporting sites
Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.
Make the next attack harmless
Locky ransomware could only hurt the files that had no second copy, and the signs (files that end in .locky and no longer open) showed exactly which ones those were.
The 3-2-1 rule fixes that:
- three copies
- two media
- one disconnected
A practical version for a home PC: OneDrive or another cloud backup with version history, plus an external disk that you plug in once a week for File History and then unplug. Test a restore now and then by opening a few files from the backup on another device.
Details, schedules and what not to back up are in our 3-2-1 backup guide for Windows.
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
Questions about Locky ransomware
How do I open .locky files?
You cannot open them by renaming or with another program, because the content of files ending in .locky has been encrypted. The only ways back are a working decryptor for the family, or clean copies from elsewhere:
- OneDrive versions
- File History
- an offline backup drive
- Previous Versions if the ransomware did not delete them
Identify the family first by uploading the ransom note and one encrypted file to ID Ransomware or No More Ransom. Avoid websites and programs that promise to open any encrypted file; they do not work and some are scams.
Is there a free Locky ransomware decryptor?
We last checked on 7 October 2026, and for Locky ransomware no free decryptor is known. We check No More Ransom, which collects free tools from police and security companies, and the decryptor pages of the major antivirus vendors. A working decryptor exists only when the encryption has a flaw or the keys were leaked or seized.
Ignore sites and videos that offer a "Locky ransomware decryptor" for download or for a fee: these are usually scams or malware. Real decryptors are free and come from known security companies or law enforcement. Keep the encrypted files in case a tool appears later.
Are ransomware recovery services legitimate?
Some are, but read the offer carefully. Genuine data-recovery firms recover deleted originals from disks or rebuild damaged files, and they say so. Others promise to "decrypt any ransomware" for a fixed price, which is impossible without the key; they quietly pay the attackers and keep a margin, sometimes without telling the victim.
Be especially careful with services that contact you after you post about the attack online. Ask for references, a written method and a no-result-no-fee clause, and check the free tools on No More Ransom first.
Should I pay the ransom?
We advise against it, and so do the FBI, Europol and national cyber agencies. Payment does not guarantee a working tool: some attackers never reply, some tools damage files, and some variants have no decryptor at all. Paying also funds further attacks and can make you a target again.
Before considering payment, try every recovery option in this guide and report the attack. Companies must involve their legal adviser and insurer, because payments to sanctioned groups can be illegal. If files are truly irreplaceable, store the encrypted copies and wait; decryptors sometimes appear later.
How did Locky ransomware get on my computer?
The way Locky ransomware spreads has not been documented yet, so look at your own recent activity. On home PCs, ransomware most often comes with cracked programs, game cheats, key generators and fake updates, or with an e-mail attachment that was opened. On business networks, attackers usually log in through Remote Desktop with a stolen or guessed password.
Think back to what was downloaded or installed in the days before files that end in .locky and no longer open, and check the Downloads folder and Installed apps sorted by date. Keep anything suspicious for your report, but do not run it again.
Did Locky ransomware steal my files or passwords?
We do not know yet. Nothing published so far shows data theft by Locky ransomware, but the only confirmed sign is files that end in .locky and no longer open, which says nothing about what happened before. Many current ransomware attacks copy files or run a password stealer first, so it is wise to act as if they did.
From a clean device, change the passwords that were saved in the browsers on this PC, starting with e-mail and banking, sign out of all sessions and turn on two-step verification. Watch bank statements and account activity for the next few weeks.
Is Locky ransomware the same as other ransomware with a similar name?
Not necessarily. Ransomware names come from the file extension, the note or a word in the code, so unrelated families often end up with similar names, and one family can appear under several names. The difference matters: a decryptor or advice for one family does not fit another and can damage files.
Compare the ending added to your files and the exact name of the note with the summary table at the top of this guide, then upload the note and one encrypted file to ID Ransomware from a clean device. If the result names another family, follow the guide for that family instead.
Will Fortect remove Locky ransomware?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Locky ransomware, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- CISA: StopRansomware (read October 7, 2026)
- No More Ransom (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)