Hey you,
BE IN THE KNOW!

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:


.Lockout Virus Files (Remove + Restore Data)

This article has been made to show you how to remove Lockout ransomware from your computer and provide ways restore .Lockout encrypted files.

A ransomware virus has been detected in the wild, leaving behind a “Payment-Instructions.txt” file and the .Lockout file extension which it adds to the files it encodes. The encoded files can no longer be opened and the virus demands from victims to pay a hefty ransom fee to restore the files encrypted by it. In case you have been infected by the .Lockout file virus, recommendations are to read this article thoroughly.

Threat Summary

Name

.Lockout virus

Type Ransomware
Short Description This ransomware encrypts files on the compromised computer and then demands a ransom payoff.
Symptoms Files are encrypted with an added .Lockout file extension and then a ransom note is dropped, named “Payment-Instructions.txt”.
Distribution Method Via an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by .Lockout virus

Download

Malware Removal Tool

User Experience Join our forum to Discuss .Lockout virus.
Data Recovery Tool Data Recovery Pro by ParetoLogic Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

.Lockout File Virus – How Does It Spread?

The primary method by which the .Lockout ransomware could be spread is via different forms of spammed e-mail messages. The usage of such e-mails may result in tricking users via deceptive tactics to either click on malicious web links or open malicious e-mail attachments. An example of such spam messages can be seen below.

Other methods of spreading such ransomware viruses, like the .Lockout infection include the usage of fake updates, fraudulent game patches, cracks or other fake setups uploaded on shady websites or via torrent sharing sites with weaker security.

.Lockout File Virus – Infection Activity

Once the .Lockout file virus compromises a computer, the virus may drop multiple files in different Windows folders, under different names, for example:

After this, the .Lockout file virus may perform modifications on different Windows sub-keys, meaning that it can add custom value strings to get the malicious executables to run on system start up.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

.Lockout Ransomware – Encryption Process

The encryption process of .Lockout file ransomware includes scanning the compromised computer for a set of important documents, videos, images and other files. The files which are encrypted by this virus may vary:

→ “PNG .PSD .PSPIMAGE .TGA .THM .TIF .TIFF .YUV .AI .EPS .PS .SVG .INDD .PCT .PDF .XLR .XLS .XLSX .ACCDB .DB .DBF .MDB .PDB .SQL .APK .APP .BAT .CGI .COM .EXE .GADGET .JAR .PIF .WSF .DEM .GAM .NES .ROM .SAV CAD Files .DWG .DXF GIS Files .GPX .KML .KMZ .ASP .ASPX .CER .CFM .CSR .CSS .HTM .HTML .JS .JSP .PHP .RSS .XHTML. DOC .DOCX .LOG .MSG .ODT .PAGES .RTF .TEX .TXT .WPD .WPS .CSV .DAT .GED .KEY .KEYCHAIN .PPS .PPT .PPTX ..INI .PRF Encoded Files .HQX .MIM .UUE .7Z .CBR .DEB .GZ .PKG .RAR .RPM .SITX .TAR.GZ .ZIP .ZIPX .BIN .CUE .DMG .ISO .MDF .TOAST .VCD SDF .TAR .TAX2014 .TAX2015 .VCF .XML Audio Files .AIF .IFF .M3U .M4A .MID .MP3 .MPA .WAV .WMA Video Files .3G2 .3GP .ASF .AVI .FLV .M4V .MOV .MP4 .MPG .RM .SRT .SWF .VOB .WMV 3D .3DM .3DS .MAX .OBJ R.BMP .DDS .GIF .JPG ..CRX .PLUGIN .FNT .FON .OTF .TTF .CAB .CPL .CUR .DESKTHEMEPACK .DLL .DMP .DRV .ICNS .ICO .LNK .SYS .CFG”Source:fileinfo.com

After files encrypted by this ransomware virus have been altered, they can no longer be opened and unique decryption keys are generated. These keys are sent to the servers of the cyber-criminals and then the files are appended the .Lockout file extension:

After the encryption, the Lockout ransomware drops it’s ransom note which has the following content:

Your Payment ID: {customID}
Contact bnd54@mail2tor.com with your Payment ID from above to
get price and payment details for unique decryption software.
Files are encrypted with RSA-2048 encryption so the only way to
recover your data is using our software. We will decrypt 1 file
for you to show you will get all data back using our unlocker.
Price will double in 3 days so don’t delay!

Remove Lockout Ransowmare and Restore .Lockout Encrypted Files

For the removal of Lockout ransomware, a good practice is to follow the instructions below. They will help you isolate the virus after which choose whether to look for each setting and file manually or if you do not have experience to perform the removal automatically (recommended).

After removing Serpent ransomware from your computer, it is time to think about the encrypted files. To restore files encoded by Serpent on your computer, we advise checking out the alternative file recovery methods in step “2. Restore files encrypted by .Lockout virus” below.

Manually delete .Lockout virus from your computer

Note! Substantial notification about the .Lockout virus threat: Manual removal of .Lockout virus requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove .Lockout virus files and objects
2.Find malicious files created by .Lockout virus on your PC

Automatically remove .Lockout virus by downloading an advanced anti-malware program

1. Remove .Lockout virus with SpyHunter Anti-Malware Tool and back up your data
2. Restore files encrypted by .Lockout virus
Optional: Using Alternative Anti-Malware Tools

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.