May Ransomware – Remove It and Restore .locked Files

May Ransomware – Remove It and Restore .locked Files

This article will aid you to remove May ransomware fully. Follow the ransomware removal instructions at the bottom of the article.

May is a ransomware cryptovirus that displays a window with a ransom note. The message is written in English and you are being extorted to pay 1 Bitcoin in exchange of getting your files back to normal. This ransomware seeks to encrypt files while putting the extension .locked after the encryption process is done. Keep on reading below to see how you could try to potentially restore some of your files.

Threat Summary

Short DescriptionThe ransomware encrypts files on your computer and creates a ransom note afterward.
SymptomsThe ransomware will encrypt your files and put the extension .locked to them after it finishes with the encryption process.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by May


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss May.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

May Ransomware – Update

The virus has a new version, with a fe changes. The most noticeable difference is the ransom message, which will appear as a .html document called Restore_maysomware_files.html. You can see it below:

That ransom message reads the following:

All your files have been encrypted with May Ransomware. For encrypt we use AES256+RSA4096. You have 5 days for decrypt your files. Don`t try recover your files.
Decrypt Manual
1) Make your bitcoin wallet on or and buy 1,5 bitcoins on BTC Exchange Sites (
2) Send 1,5 bitcoin to adress 3Gw6b57A3E34nAph3mzGbKAj8sTSgD8GP9
3) Write to us on email In subject write this identificator [ID] 4) After receive bitcoins and your email, we contact with you.
— YOU MIGHT DECRYPT 2 FILES FOR FREE. Send it to email In Subject, write your UNIQUE Identificator.

Another thing which is worth to note is that the extension placed to encrypted files now is .maysomware.

May Ransomware – Infection

May ransomware might spread its infection with various methods. A payload dropper which initiates the malicious script for this ransomware is being spread around the world, and researchers have gotten their hands on a malware sample. If that file lands on your computer system and you somehow execute it – your computer will become infected. You can see the detections of such a file, called May_ransomware.exe, on the VirusTotal service right here:

May ransomware might also deliver its payload file on social media and file-sharing services. Freeware which is found on the Web can be presented as helpful also be hiding the malicious script for the cryptovirus. Refrain from opening files right after you have downloaded them. You should first scan them with a security tool, while also checking their size and signatures for anything that seems out of the ordinary. You should read the tips for preventing ransomware found in our forums.

May Ransomware – Description

May is a virus that will encrypt your files and try to extort you to pay a ransom to get them restored. Malware researchers have found it a few days ago in the middle of month May, so its name is appropriate.

May ransomware could make entries in the Windows Registry to achieve persistence, and probably launch or repress processes in a Windows environment. Such entries are typically designed in a way to launch the virus automatically with each start of the Windows operating system.

The note is written in English, and it will be inside a file called Restore_your_files.txt. You can view the ransom message that loads after the encryption process in this picture:

That ransom note stored in the Restore_your_files.txt file reads the following:

You have 5 days for decrypt your files.
All your files have been encrypted with May Ransomware.
For encrypt we use AES256+RSA4096.
Don`t try recover your files.
Decrypt instruction!
1) Make your bitcoin wallet on or and buy 1 bitcoins on BTC Exchange Sites (
2) Send 1 bitcoin to address 3Gw6b57A3E34nAph3mzGbKAj8sTSgD8GP9
3) Write to us on email . In subject write this identificator “81ff05bf2ab1406d8f11b866e804af37”
4) After receive bitcoins and your email , we contact with you.
YOU MIGHT DECRYPT 2 FILES FOR FREE. Send it to email .In Subject ,write your UNIQUE Identificator.

The ransomware gives you a period of 5 days to make the demanded payment of 1 Bitcoin. That amount equals to nearly 1.833 US dollars, at the moment of writing of this article.
You should NOT under any circumstances pay the ransom. Your files may not get restored, and nobody could give you any real guarantee. Moreover, giving money to cybercriminals will likely motivate them to create more ransomware viruses or even do different criminal activities.

May Ransomware – Encryption Process

Currently, the ransomware is still being researched, and some experts say that it might be a HiddenTear variant, while others don’t say such a thing. If that proves to be true, then the encryption algorithm will probably be AES. Although, the ransom note states that the encryption algorithms which are used are AES 256-bit and RSA 4096-bit ones. For now, there is no information about what extensions the cryptovirus seeks to encrypt. However, most probably extensions for the following file types are being encrypted:

  • Text
  • Image
  • Video
  • Music
  • Database

Those file types are still the most commonly-used ones today for nearly all Windows users, making the list quite viable. All of the files that get encrypted will receive the same extension appended to them, and that is the .locked extension.

The May cryptovirus might be tweaked to erase all the Shadow Volume Copies from the Windows operating system with the help of the following command:

→vssadmin.exe delete shadows /all /Quiet

In case the command stated above is executed that would make the encryption process more efficient as it will eliminate one of the ways for restoring your files. If your computer is infected with this ransomware, read on through to find out how you could potentially recover your files.

Remove May Ransomware and Restore .locked Files

If your computer got infected with the May ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.


Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share