Netlock ransomware: what it is and how to remove it
Netlock is a Windows computer virus that operates by locking all files located on local and networked drives. Most commonly, users get infected with ransomware accidentally or when they open a spam email attachment or download an infected file that pretends to be a cracked program.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Make sure nothing will rename more files to .netlock: an automatic scan checks the PC first.
Do it yourself · free Remove Netlock ransomware yourself 6 steps, about 18 minutes, no software needed.
Start the steps
Netlock ransomware: summary
| Name | Netlock |
|---|---|
| Type | Ransomware, file-locking malware, cryptovirus |
| File extension | .netlock |
| Ransom note | how_to_back_files.html; the text of the note is not in our records |
| Encryption | AES + RSA |
| Data Recovery | If no backups are available, recovering data is almost impossible. However, we suggest you try the alternative methods that could help you in some cases – we list them below |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 12 more facts
| Detection names | No Microsoft detection name is known |
|---|---|
| Contact | Not recorded in our earlier report |
| Encrypted file extension | .netlock |
| Decryptor | No free decryptor is known for this variant; check No More Ransom (nomoreransom.org) for updates |
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Symptoms | Files renamed with a new extension and a ransom note left in folders |
| Evidence | 4 write-ups by security sites; no sample analysed yet |
| Encrypted files | .netlock |
| Free decryptor | No free decryptor is known (checked 7 October 2026) |
| First seen | 27 September 2022 |
| Facts checked | 7 October 2026 |
- File extension:
.netlock - Note file:
how_to_back_files.html
From our report of Sep 2022 · not reviewed since
More from our earlier report on Netlock
- Manual virus removal is not recommended, as it might be difficult for regular users.
- Instead, or other anti-malware tools should be used
- Malware can seriously impact a Windows computer's performance and stability after it is removed.
- Free Ransomware Decryptors by Kaspersky
How Netlock ransomware behaves
From our report of Sep 2022 · not reviewed since
Netlock ransomware is a money-extortion-based malware that shouldn't be underestimated
Netlock is a Windows computer virus that operates by locking all files located on local and networked drives.
Most commonly, users get infected with ransomware accidentally or when they open a spam email attachment or download an infected file that pretends to be a cracked program. Other distribution methods are also popular.
Netlock ransomware operates similarly to any other malware of this type:
- deletes Shadow Volume Copies
- disables Windows repair functions
- drops numerous malicious files on the system
This helps the malware to continue its operation at all times, making a recovery a particularly difficult task for users.
However, the main task of the virus is to ensure that all videos, pictures, documents, databases, and other files are thoroughly locked by a combination of sophisticated encryption algorithms AES and RSA.
The data would immediately become inaccessible to victims, and all the files would be appended with the .netlock extension. In the how_to_back_files.html ransom note, hackers would explain to users that they must pay a ransom to restore their files.

From our report of Sep 2022 · not reviewed since
What are MedusaLocker variants?
Instead of harming the system, ransomware's primary objective is to affect user files so that they are unrecoverable.
Through this method, hackers may then demand money from their victims. With hundreds of strains circulating online, ransomware has grown to be a very lucrative industry.
The Netlock virus stems from a relatively established family known as MedusaLocker, which has been active since at least 2019. We have previously discussed some variants of the strain, including Farlock, EMPg296LCK, and Revenlock. Instead of delivering a usual TXT file, malware versions usually employ a pop-up message which shows up as soon as the ransomware finishes the file encryption process.
In the note, cybercriminals typically explain what happened to users' files and then claim that they should not look for alternative solutions to recover their data. They offer a service of free decryption as proof that they indeed have a working decryption tool they are not going to give away for free.
As a result, you risk losing your funds as well.

The Netlock ransomware note
The note is called how_to_back_files.html.
We did not record the full text of the ransom note in our report.
How to remove Netlock ransomware
Tools you'll need
All of these are free except where noted. Download them on a clean device if the infected PC is offline.
- A USB stick: to keep the ransom note, two or three encrypted files and screenshots off the infected PC.
- Microsoft Defender Offline: built into Windows 11 and Windows 10; scans before Windows starts, so running malware cannot hide.
- Microsoft Safety Scanner: a second, portable scanner with current signatures; each download works for 10 days.
- ID Ransomware: identifies the family from the note and one encrypted file and says whether a decryptor exists.
- No More Ransom: the free decryptors from police and security companies; check it again every few months.
- Fortect (optional): scans Windows for malware and repairs the system files and settings it damaged. The free scan is in the box above.
How to remove Netlock and get your files back
Work in this order.
Disconnecting comes first, removal comes before any restore, and nothing here asks you to contact the attackers.
Step 1: Disconnect the PC and unplug backup drives
Unplug the network cable or turn off Wi-Fi, and disconnect USB drives, external disks and network shares, so Netlock cannot reach more files. Pause OneDrive, Google Drive or Dropbox sync, because synced folders upload the encrypted copies over the good ones.
Leave the PC on but offline while you read the next steps, since a restart can let the ransomware run again. This applies to Windows 11 and Windows 10 alike.

Windows 11: turn off Wi-Fi to take the PC offline. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 2: Save the ransom note and confirm the family
Your files now end in
.netlockand the instructions are inhow_to_back_files.html. Save both to a USB stick, a copy of the note and two small encrypted files, before anything else.On another device, check them with ID Ransomware or Crypto Sheriff: the family name decides which decryptor, if any, can help. Keep the note's ID and contact line for your report.

Windows 11: the ransom note and encrypted files to copy for identification. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 3: Check for a free decryptor
Our last check found that for Netlock, no free decryptor is known (checked 7 October 2026). Look again yourself in the No More Ransom list and the free decryptor pages of Emsisoft, Avast and Kaspersky, which add new families every year.
A decryptor needs the ransomware gone first, or it encrypts the files again. Keep at least one copy of the encrypted files on an external drive, even if no tool works yet.
Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 4: Remove the ransomware before you restore or decrypt
Removing Netlock does not bring the files back, but it has to come first. Start with Defender's Full scan, then the offline scan from the same Scan options page, which checks the disk before Windows loads.
If the scan cannot start, use Safe Mode with Networking. Delete the ransom notes only after you have saved a copy, because removal tools sometimes leave them behind on Windows 11 and Windows 10.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Look for shadow copies of the files
Windows keeps shadow copies for restore points and backups, and some ransomware fails to delete them.
vssadmin list shadowsin an administrator Command Prompt tells you at once whether any exist.If they do, right-click the folder that held your files, open Properties > Previous Versions, select a version from before the attack, and click Open to check it before you Restore or copy the files out. Windows 11 and Windows 10 both have the tab.

Windows 11: vssadmin list shadows shows whether shadow copies exist. Full procedure with screenshots: Ransomware: first steps, finding a decryptor and recovering files
Step 6: Restore the files from a backup or recover deleted originals
A backup made before the attack is the surest way back. Connect it only once the PC is clean, then restore from File History, Windows Backup, OneDrive's Restore your OneDrive or your own external copies.
Without a backup, try file recovery: the originals that Netlock deleted may still be on the disk until something overwrites them. Install nothing new on the drive you want to recover from on the Windows 11 or Windows 10 PC.
Full procedure with screenshots: Recover deleted files (Recycle Bin, backups, OneDrive) On uGetFix
From our report of Sep 2022 · not reviewed since
Remove malware from your device to prevent further data locking
You should unplug the computer(s) from the network to stop the attackers from exchanging ransomware communications over it.
Through it, malware developers may distribute further payloads or upgrade ransomware with fresh code. While it is possible just to unplug the internet wire, this may not always be practical. Instead, you should do the following actions:
Although it is feasible, manual virus removal is not advised; security software is the best choice. You can use or to automatically detect and eliminate all harmful components from your system. Your primary line of defense against malware attacks should be security software, however, it's always preferable to attempt to prevent infection in the first place.
Windows 7 / Vista / XP
Windows 10 / Windows 8
- Type in Control Panel in Windows search and press Enter
- Go to Network and Internet
- Click Network and Sharing Center
- On the left, pick Change adapter settings
- Right-click on your connection (for example, Ethernet), and select Disable
- Confirm with Yes.
- Click Start > Shutdown > Restart > OK.
- When your computer becomes active, start pressing the F8 button (if that does not work, try F2, F12, Del, etc. - it all depends on your motherboard model) multiple times until you see the Advanced Boot Options window.
- Select Safe Mode with Networking from the list.
- Right-click on the Start button and select Settings.
- On the left side of the window, pick Recovery.
- Click Restart now.
- Select Troubleshoot.
- Go to Advanced options.
- Select Startup Settings.
- Click Restart.
- Press 5 or click 5) Enable Safe Mode with Networking.


From our report of Sep 2022 · not reviewed since
Fix damaged system files
When a computer becomes infected with malware, the way its operating system functions is altered.
For instance, an infection may remove crucial DLL files or harm essential bootup and other registry database parts. Users may face speed or stability issues, as well as usability concerns, as soon as system components are infected by malware. Antivirus software cannot remedy these issues, and users may need to completely reinstall Windows.
The program may also assist with a number of technical difficulties unrelated to malware attacks and clear the computer of junk and third-party trackers.
- Download
- Click on the ReimageRepair.exe
- If User Account Control (UAC) shows up, select Yes
- Press Install and wait till the program finishes the installation process
- The analysis of your machine will begin immediately
- Once complete, check the results - they will be listed in the Summary
- You can now click on each of the issues and fix them manually


From our report of Sep 2022 · not reviewed since
How to recover .netlock files?
Files that have been encrypted cannot be read without a key, which is frequently kept on a server that hackers run.
They can then determine which key decrypts which victim's data using the user ID. Since each victim is given a unique key, there is no universal password in this scenario.
Both data encryption and virus infection are independent occurrences that should be treated separately. This means that by using antivirus software to check your computer, you will be able to delete any harmful files that would otherwise be operating on your system and, for example, encrypt any incoming documents.
Files would stay locked, and this would not be able to restore them. This is among the most hazardous characteristics of ransomware.
Although it is likely that hackers have the password to decrypt data encrypted by the Netlock ransomware, paying the ransom is never worth the risk since you might lose both your money and your contents. As a result, even if taking the other path might not always be effective, we advise doing so.
Once the virus has been removed from your device, you can recover your data if you have data backups. To avoid irreparable data corruption, you should first make copies of encrypted files if you don't have them before moving on to the next step. After that, you may begin using data recovery software as follows:
Waiting for a functional decryption tool, which may or may not be created by security experts, is another option for file restoration. Malware researchers successfully developed a large number of decryptors that allow users to retrieve ransomware-encrypted data without paying a fee. The key here is patience because it can be weeks, months, or even years before this happens. We advise visiting the following links while seeking a decryptor tool:
- Download .
- Double-click the installer to launch it.
- Follow on-screen instructions to install the software.
- As soon as you press Finish, you can use the app.
- Select Everything or pick individual folders where you want the files to be recovered from.
- Press Next.
- At the bottom, enable Deep scan and pick which Disks you want to be scanned.
- Press Scan and wait till it is complete.
- You can now pick which folders/files to recover - don't forget you also have the option to search by the file name!
- Press Recover to retrieve your files.
- No More Ransom Project
- Free Ransomware Decryption Tools from Emsisoft


Report it and recover your files
Report it
Report the attack even if you do not expect the files back: insurers and banks ask for the report number, and police use the contacts in the note to link cases.
- United States
- FBI IC3 · FTC ReportFraud
- United Kingdom
- Report Fraud (formerly Action Fraud) · NCSC
- Australia
- ReportCyber (ASD)
- EU countries
- Europol: national reporting sites
Give the victim ID, the note and the date the files were encrypted. A business that holds personal data may also have to notify its data protection authority, in the EU within 72 hours.
Backups: the 3-2-1 rule
Keep three copies of files that matter, on two kinds of storage, with one copy offline or off-site.
A disk that stays plugged in is reached by malware like Netlock together with the PC; one you connect only for the backup is not.
On Windows 11, File History keeps versions on an external drive, and OneDrive keeps earlier versions of synced files. Before restoring anything, make sure the PC no longer shows files that end in .netlock and no longer open.
Setting it up step by step: 3-2-1 backups on Windows 11 and 10.
Choose a proper web browser and improve your safety with a VPN tool
Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.
One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.
However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.
Lost your files? Use data recovery software
While some files located on any computer are replaceable or useless, others can be extremely valuable.
Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:
- power cuts
- Blue Screen of Death errors
- hardware failures
- crypto-malware attack
- even accidental deletion
To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.
Questions about Netlock ransomware
How do I open .netlock files?
You cannot open them by renaming or with another program, because the content of files ending in .netlock has been encrypted. The only ways back are a working decryptor for the family, or clean copies from elsewhere:
- OneDrive versions
- File History
- an offline backup drive
- Previous Versions if the ransomware did not delete them
Identify the family first by uploading the ransom note and one encrypted file to ID Ransomware or No More Ransom. Avoid websites and programs that promise to open any encrypted file; they do not work and some are scams.
Is there a free Netlock decryptor?
We last checked on 7 October 2026, and for Netlock no free decryptor is known. We check No More Ransom, which collects free tools from police and security companies, and the decryptor pages of the major antivirus vendors. A working decryptor exists only when the encryption has a flaw or the keys were leaked or seized.
Ignore sites and videos that offer a "Netlock decryptor" for download or for a fee: these are usually scams or malware. Real decryptors are free and come from known security companies or law enforcement. Keep the encrypted files in case a tool appears later.
How did Netlock get on my computer?
The way Netlock spreads has not been documented yet, so look at your own recent activity. On home PCs, ransomware most often comes with cracked programs, game cheats, key generators and fake updates, or with an e-mail attachment that was opened. On business networks, attackers usually log in through Remote Desktop with a stolen or guessed password.
Think back to what was downloaded or installed in the days before files that end in .netlock and no longer open, and check the Downloads folder and Installed apps sorted by date. Keep anything suspicious for your report, but do not run it again.
Are ransomware recovery services legitimate?
Some are, but read the offer carefully. Genuine data-recovery firms recover deleted originals from disks or rebuild damaged files, and they say so. Others promise to "decrypt any ransomware" for a fixed price, which is impossible without the key; they quietly pay the attackers and keep a margin, sometimes without telling the victim.
Be especially careful with services that contact you after you post about the attack online. Ask for references, a written method and a no-result-no-fee clause, and check the free tools on No More Ransom first.
Should I pay the ransom?
We advise against it, and so do the FBI, Europol and national cyber agencies. Payment does not guarantee a working tool: some attackers never reply, some tools damage files, and some variants have no decryptor at all. Paying also funds further attacks and can make you a target again.
Before considering payment, try every recovery option in this guide and report the attack. Companies must involve their legal adviser and insurer, because payments to sanctioned groups can be illegal. If files are truly irreplaceable, store the encrypted copies and wait; decryptors sometimes appear later.
Did Netlock steal my files or passwords?
We do not know yet. Nothing published so far shows data theft by Netlock, but the only confirmed sign is files that end in .netlock and no longer open, which says nothing about what happened before. Many current ransomware attacks copy files or run a password stealer first, so it is wise to act as if they did.
From a clean device, change the passwords that were saved in the browsers on this PC, starting with e-mail and banking, sign out of all sessions and turn on two-step verification. Watch bank statements and account activity for the next few weeks.
Is Netlock the same as other ransomware with a similar name?
Not necessarily. Ransomware names come from the file extension, the note or a word in the code, so unrelated families often end up with similar names, and one family can appear under several names. The difference matters: a decryptor or advice for one family does not fit another and can damage files.
Compare the ending added to your files and the exact name of the note with the summary table at the top of this guide, then upload the note and one encrypted file to ID Ransomware from a clean device. If the result names another family, follow the guide for that family instead.
What does how_to_back_files.html tell me about the ransomware?
Quite a lot. The file name how_to_back_files.html, the wording, the contact addresses and the format of the personal ID are typical for each family. Uploading the note together with one encrypted file to ID Ransomware or No More Ransom's Crypto Sheriff usually names the family within seconds.
That name decides your options: some families have free decryptors, some can be partially recovered, and some cannot be decrypted at all. The note's claims about stolen data should be taken seriously but not at face value.
Will .netlock spread to my other drives?
It can. Ransomware encrypts every drive and network share it can reach while it runs, so external disks, USB sticks and shared folders connected during the attack may also have files ending in .netlock. Disconnect everything now, then check each device from a clean computer.
Do not plug a backup drive into the infected PC until the ransomware has been removed with an offline scan. Cloud folders such as OneDrive sync the encrypted versions, but they keep earlier versions you can usually restore.
Will Fortect remove Netlock?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Netlock, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia: Shadow Copy (read October 7, 2026)
- Precisely: AES vs. RSA Encryption: What Are the Differences? (read October 7, 2026)
- CISA: StopRansomware (read October 7, 2026)
- No More Ransom (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)