Remove LockeR Ransomware - Restore Files

Remove LockeR Ransomware – Restore Files

This article will aid you to remove LockeR ransomware completely. Follow the ransomware removal instructions given below in the article.

LockeR is a ransomware virus that encrypts your files. The LockeR virus displays a ransom note message stored in a file called [How_To_Decrypt_Files].txt. You are demanded to pay 10000 US dollars in the Bitcoin cryptocurrency as a ransom to supposedly restore your data. Continue to read below to see how you could try to potentially recover some of your files.

Threat Summary

TypeRansomware, Cryptovirus
Short DescriptionThe ransomware encrypts files on your computer and demands a ransom sum to be paid in the Bitcoin cryptocurrency.
SymptomsThe ransomware will encrypt your files, and also put up a ransom note called [How_To_Decrypt_Files].txt.
Distribution MethodSpam Emails, Email Attachments
Detection Tool See If Your System Has Been Affected by LockeR


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss LockeR.
Data Recovery ToolWindows Data Recovery by Stellar Phoenix Notice! This product scans your drive sectors to recover lost files and it may not recover 100% of the encrypted files, but only few of them, depending on the situation and whether or not you have reformatted your drive.

LockeR Ransomware – Infection Spread

LockeR ransomware might spread its infection with various methods. A payload dropper which initiates the malicious script for this ransomware is being spread around the World Wide Web, and researchers have gotten their hands on a malware sample. If that file lands on your computer system and you somehow execute it – your computer system will become infected.

LockeR ransomware might also distribute its payload file on social media and file-sharing services. Freeware which is found on the Web can be presented as helpful also be hiding the malicious script for the cryptovirus. Refrain from opening files right after you have downloaded them. You should first scan them with a security tool, while also checking their size and signatures for anything that seems out of the ordinary. You should read the tips for preventing ransomware found in the forum section.

LockeR Ransomware – In-Depth Analysis

LockeR is a virus that encrypts your files and extorts you to pay a ransom to supposedly recover them. The extortionists want you to pay in Bitcoin for the alleged restoration of your files.

The following pages which are hosted on the TOR network are all associated with the LockeR ransomware:

  • lockerrwhuaf2jjx.onion(.)link
  • lockerrwhuaf2jjx.onion(.)gq
  • lockerrwhuaf2jjx.onion(.)to
  • lockerrwhuaf2jjx.onion(.)top
  • lockerrwhuaf2jjx(.)onion
  • xk5perkqaaaoux2v(.)onion
  • wsg3wd4fepljpvwu(.)onion
  • i56bvhjey5gzakmd(.)onion

LockeR ransomware might make entries in the Windows Registry to achieve persistence, and could launch or repress processes in a Windows environment. Such entries are typically designed in a way to launch the virus automatically with each start of the Windows Operating System.

That ransom note message is displayed after the encryption of your files is complete. It is inside a file named [How_To_Decrypt_Files].txt and can be viewed from the following screenshot down here:

That note reads the following:

What happened to my files ?

All of your important files were encrypted using a combination of RSA-2048 and AES-256.

What does this mean ?

This means that your files were modified in a way that makes working with them impossible, unless you have the keys to decrypt them.

Is it possible to recover my files ?

Yes, it possible to get your files back, you’ll need a special program (decryptor) and the private key of the key pair used to encrypt them.

How can I get the decryptor and the private key ?

You can buy both of them in any of the links below. Just visit one of them and follow the instructions.
If you cannot access the site from any of the addresses above, you can follow the instructions below to access the site using the Tor Browser.

Download the Tor Browser Bundle here:
Execute the file you downloaded to extract the Tor Browser into a folder on your computer.
Then simply open the folder and click on “Start Tor Browser”.
Copy and paste the onion address into the address bar: http://lockerrwhuaf2jjx.onion/1820-LOANER_4F28C903F6E96F5D6522DF69/


The note of the LockeR ransomware states that your files are encrypted. You are demanded to pay 1.76565830 Bitcoin. That sum equates to 10000 US dollars as stated in the note. However, you should NOT under any circumstances pay any ransom. Your files may not get recovered, and nobody could give you a guarantee for that. Moreover, giving money to cybercriminals will most likely motivate them to create more ransomware viruses or commit different criminal acts.

The screenshot below shows the payment page hosted on the TOR network:

Negotiation Support Free Decryption (1)


Your files have been encrypted, to recover them you need the private key of the key pair used to encrypt them and the decryptor. You can buy both of them for $10000.00. However, if the payment is not made until 2017-10-22 14:05 UTC, the price for the decryptor and private key will increase to $20000.00.
03days 00hours 44minutes 23seconds

Register a bitcoin wallet.

Easiest online wallet or other wallets.

Purchase the required amount of bitcoins.

There are several ways you can buy bitcoins, you can use bitcoin exchanges, buy directly from people selling near you or using a bitcoin ATM.

Send exactly 1.76565830 BTC ($10000.00) to the address:

1LcbBzkgBVRq3NywSrqHEFCymXcUnrnwrH The confirmation may take several minutes, please be patient.

Status: Awaiting payment…
Expires in: 57:17

1 BTC ≈ 5663.61 USD

The private key is stored in our server for two months.

From that same page you can find the Help page which is shown down here:

Here is what that Help page reads:

What is the KEY file ?

It is a storage for the information regarding the infection of your computer, it contains the private key of the key pair used to encrypt your files, along with information to identify your computer.
I don’t have a KEY file, how can I synchronize my computer ?

If you don’t have a KEY file, your machine is already synchronized, you just need to follow any of the links in the HTML note.
How long does it take for my payment to be confirmed ?

It depends on how much you paid for the transaction fee and how much the network is congested. You can check the average confirmation time clicking here.
I paid a lower value and/or to a different address. What should I do ?

In your personal page, click the “Support” option and open a new ticket. You must say in the message which address you paid to and how many bitcoins you sent.

The 4 domains listed in the beginning of this section are the known ones that host these pages, but there might be more. Your ID should work on all such pages if they are related to the LockeR virus.

LockeR Ransomware – Encryption Process

There is not much known for the encryption process of the LockeR ransomware, except that the encryption algorithms used by the virus are AES and RSA.

The targeted extensions of files which are sought to get encrypted are currently unknown and if a list is discovered, it will be posted here as the article gets updated. The files used most by users and which are probably encrypted are from the following categories:

  • Audio files
  • Video files
  • Document files
  • Image files
  • Backup files
  • Banking credentials, etc

The LockeR cryptovirus could be set to erase all the Shadow Volume Copies from the Windows operating system with the help of the following command:

→vssadmin.exe delete shadows /all /Quiet

If the above-stated command is executed that will make the encryption process more efficient. That is due to the fact that the command eliminates one of the prominent ways to restore your data. If your computer device was infected with this ransomware and your files are locked, read on through to find out how you could potentially restore your files back to normal.

Remove LockeR Ransomware and Restore Files

If your computer got infected with the LockeR ransomware virus, you should have a bit of experience in removing malware. You should get rid of this ransomware as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the ransomware and follow the step-by-step instructions guide provided below.

Berta Bilbao

Berta is a dedicated malware researcher, dreaming for a more secure cyber space. Her fascination with IT security began a few years ago when a malware locked her out of her own computer.

More Posts

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share