Lock2017 Ransomware Remove and Restore Files - How to, Technology and PC Security Forum | SensorsTechForum.com
THREAT REMOVAL

Lock2017 Ransomware Remove and Restore Files

OFFER

SCAN YOUR PC
with SpyHunter

Scan Your System for Malicious Files
Note! Your computer might be affected by Lock2017 and other threats.
Threats such as Lock2017 may be persistent on your system. They tend to re-appear if not fully deleted. A malware removal tool like SpyHunter will help you to remove malicious programs, saving you the time and the struggle of tracking down numerous malicious files.
SpyHunter’s scanner is free but the paid version is needed to remove the malware threats. Read SpyHunter’s EULA and Privacy Policy

Article created to help you remove Lock2017 ransomware infection from your computer and restore your files in the event they have been encrypted by it.

A virus from the file encryption type, using the e-mail [email protected] for contact with the victims has been detected by malware researchers at the end of February 2017. The ransomware is dubbed Lock2017 and it encodes the files on the computers it infects by using a combination of RSA and AES encryption algorithms. This combination makes the files on the compromised computers no longer able to be opened. In case you have become a victim of the Lock2017 ransomware infection, recommendations are to focus on reading this article carefully.

Threat Summary

Name

Lock2017

TypeRansomware
Short DescriptionThe malware encrypts users files using a strong encryption algorithm combination, making direct decryption possible only via a unique decryption key available to the cyber-criminals.
SymptomsThe user may witness ransom notes and “instructions” linking to a web page and a decryptor. Changed file names and the file-extension with the e-mail [email protected] has been used.
Distribution MethodVia an Exploit kit, Dll file attack, malicious JavaScript or a drive-by download of the malware itself in an obfuscated manner.
Detection Tool See If Your System Has Been Affected by Lock2017

Download

Malware Removal Tool

User ExperienceJoin our forum to Discuss Lock2017.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

Lock2017 Ransomware – How Does It Spread

In order for it to infect users, the creators of the virus may spread a malicious file extension via e-mail spam messages sent out. The messages may be sent via spam bots that send them from a pre-configured list of targeted e-mail addresses. The messages may be convincing and written to get the user to click on a web link or open an attachment.

Other methods of spreading this ransomware infection may be via fake installers, fake updates of programs and also fake patches or game cracks, all of which may be uploaded on shady websites.

Lock2017 Ransomware – What Happens When It Infects

After the user opens a malicious e-mail attachment, the Lock2017 virus begins to drop it’s malicious files, amongst which are it’s main executable which has a completely random name and is .exe type of file and alongside it is a README.TXT file with a ransom note in which there are demands.

In addition to dropping malicious files, the Lock2017 ransomware may also modify those files in a way that will make the executable or the ransom note run on system startup. This is usually achieved by adding a custom registry value string with the location of the file in the following Windows Registry Entries:

→ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

In addition to these activities the Lock2017 ransomware virus may also perform multiple other activities such as delete any backups from the infected computer and cut out any possibility of restoring backed up files. One way is to delete shadow volume copies via the vssadmin command in quiet mode:

Lock2017 Ransomware – Encryption Method

For the encryption, this ransomware virus uses two main algorithms:

  • RSA – Rivest-Shamir-Adleman encryption algorithm which generates unique keys for each file.
  • AES – Advanced Encryption Standard, also known as Rijndael. It is very stable and strong for file encryption.

These two, used in combination, make it practically impossible to factorize the AES decryption keys, because they are further encoded by the RSA algorithm. The Lock2017 ransomware may attack multiple widely used files that may be of importance to the victims:

  • Microsoft Office documents.
  • OpenOffice files.
  • PDF documents.
  • Text files.
  • Database files.
  • Photos.
  • Music files.
  • Image files.
  • Archive files.

These files are no longer able to be opened and the Lock2017 ransomware adds a unique file extension to them which appears relatively in the following format:

After the files have been encrypted, the virus makes sure that the victims knows of it’s presence by dropping a README.TXT file in which the situation and demands are explained:

Remove Lock2017 Ransomware Virus and Try Restoring Encoded Files

Before attempting any removal, we recommend backing up the encrypted files, just in case. Then, you can go ahead and follow the removal instructions below. In case you lack the experience in manually removing this ransomware virus, experts often advise victims of malware in general to remove viruses automatically with the aid of an anti-malware program. Such software in particular will ensure the full removal of all malware on your computer and make sure you are protected In the future too.

After having removed Lock2017 ransomware from your computer, recommendations are to focus on multiple different methods to try and get back the files. We have mentioned several alternative tools below in step “2. Restore files encrypted by Lock2017” but they are no guarantee you will get your files back. And if you are about to try the third-party decryptors, we recommend never to try them on the original files, but on copies instead.

Note! Your computer system may be affected by Lock2017 and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of threats such as Lock2017.
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove Lock2017 follow these steps:

1. Boot Your PC In Safe Mode to isolate and remove Lock2017 files and objects
2. Find files created by Lock2017 on your PC

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool
4. Try to Restore files encrypted by Lock2017

Ventsislav Krastev

Ventsislav has been covering the latest malware, software and newest tech developments at SensorsTechForum for 3 years now. He started out as a network administrator. Having graduated Marketing as well, Ventsislav also has passion for discovery of new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management and then Network Administration, he found his passion within cybersecrurity and is a strong believer in basic education of every user towards online safety.

More Posts - Website

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...