Hey you,
BE IN THE KNOW!

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:


Remove LataRebo Locker Ransomware and Unlock Your PC

This article will help you to remove LataRebo Locker ransomware totally. Follow the ransomware removal instructions at the end of the article.

LataRebo Locker is the name of a ransomware, which is also a screenlocker. After infection, the LataRebo Locker locks your Desktop and displays a window with a ransom message. The message contains instructions for payment, while the sum of the ransom is 10 Euros. Continue to read and see what you can do to unlock your computer.

Threat Summary

NameLataRebo Locker
TypeRansomware
Short DescriptionThe ransomware has a lockscreen function which it uses to lock your desktop.
SymptomsThe ransomware will display a window containing instructions about payment. The demanded sum is 10 Euros.
Distribution MethodStill unknown.
Detection Tool See If Your System Has Been Affected by LataRebo Locker

Download

Malware Removal Tool

User ExperienceJoin Our Forum to Discuss LataRebo Locker.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

LataRebo Locker Ransomware – Delivery

LataRebo Locker might be using different tactics for delivery. The ransomware features a screenlock function and usually that means that an executable/binary file will be involved. That .exe file can be distributed across the Internet as a useful program. The delivery ways may use social media networks, services for file-sharing, spam email campaigns with attached files, and other things, too. The executable file has been spotted by malware researchers in the wild and has been uploaded for analysis over at VirusTotal as you can see below:

All of the above scenarios are possible, and could be used for the delivery of the screenlocker. Check the ransomware prevention tips written in the forum to see how you can best protect yourself from similar infections.

LataRebo Locker Ransomware – Analysis

LataRebo Locker is the name of a ransomware, which also features the function of a screenlocker. The name is on the window that locks your screen after you are infected with this malware. A possibility exists for the threat to still be under development, so future functions might be developed for it.

LataRebo Locker ransomware could make entries in the Windows Registry aiming to achieve persistence. Those registry entries are typically designed in a way that will start the virus automatically with each boot of the Windows Operating System and make it harder for security software to detect the virus.

The ransom message screen will appear after your computer system gets locked. The message provides the demands of the cybercriminals, such as the ransom price, along with how to make the payment. LataRebo Locker ransomware loads the following screen:

The message reads the following:

Your computer has been locked by LataRebo Locker!
INSERT KEY HERE Insert Key
Buy unlock key for 10EURO paysafe card pin and send
it to this facebook page via pm : facebook.com/TheDarkJoJo.
Im gonna check if it’s working and then your key will be given
in 24 hours. After using the correct unlock key,
you should open task manager and close this program, explorer
will work too. Good luck

The above ransom message of LataRebo Locker seems like a bad joke, especially with the sign “Water Bottle Flip Challenge”, but the ransomware is out there. You should NOT in any circumstance pay these crooks. Nobody could guarantee you that your files will be restored. The unlock code for the screenlocker is Rebatsa, and was found by a couple of malware researchers on their own.

The LataRebo Locker cryptovirus could be modified to erase the Shadow Volume Copies from the Windows operating system with the help of the following command:

→vssadmin.exe delete shadows /all /Quiet

In case the password no longer works or your files get encrypted and your PC remains locked, try closing the malicious program from the Task Manager. Afterward, check the removal instructions below to entirely remove the threat.

Remove LataRebo Locker Ransomware Completely

If your computer got infected with the LataRebo Locker ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.

Manually delete LataRebo Locker from your computer

Note! Substantial notification about the LataRebo Locker threat: Manual removal of LataRebo Locker requires interference with system files and registries. Thus, it can cause damage to your PC. Even if your computer skills are not at a professional level, don’t worry. You can do the removal yourself just in 5 minutes, using a malware removal tool.

1. Boot Your PC In Safe Mode to isolate and remove LataRebo Locker files and objects
2.Find malicious files created by LataRebo Locker on your PC

Automatically remove LataRebo Locker by downloading an advanced anti-malware program

1. Remove LataRebo Locker with SpyHunter Anti-Malware Tool and back up your data
2. Restore files encrypted by LataRebo Locker
Optional: Using Alternative Anti-Malware Tools

Berta Bilbao

Berta is the Editor-in-Chief of SensorsTechForum. She is a dedicated malware researcher, dreaming for a more secure cyber space.

More Posts - Website

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.