How To Remove Lockme Ransomware and Decrypt .lockme exension

Lockme Ransomware Make Your Files Inaccessible And Demand Money

 

Lockme Ransomware is a recently found malware which can hold your files hostage and demands 0.03 Bitcoin which is $262 approx. as ransom. It affixes .lockme exension on encrypted files after modifying them. What more users will be threatened to pay the ransom amount on email [email protected] and [email protected]. Further it warns not to modify the file extension, else it will be damaged forever as it is written on ransom Text note in bold letters. It is a deadly ransomware that sneaks into computer silently to do their malicious activities to bother you and damage system completely. Once gets into your system then it start compromising your valuable files and folders by configuring your system storage and local storage drive. It start scanning to gather all the targeted files that take part into the encryption process. Normally files are like images, Microsoft Document files, videos, audios, html, pdfs or similar others as well. Once completed encryption process successfully then it locked all your files by appending a signature file name to the compromised files. Then all your files becomes inaccessible. After encryption it display or send a ransom note on victims system to notify them about the ransom encryption alert. The ransom note contains the information about decryption procedure and ransom payment information.

Lockme Ransomware : More Things You Should Know About Ransomware

Name Lockme Ransomware
Type Ransomware
Risk Level Severe
Ransom Demand 0.03 Bitcoins which is $262 approx
Distribution Suspicious downloads, awful websites, corrupted ads or links, spam emails etc.
Targets Windows OS
Extension .lockme

 

How Did My Computer Got Infected By Lockme Ransomware?

Most of the time malware hackers uses various methods to drop the infection files of Lockme Ransomware into your system. Generally they uses widely used infection distribution methods like sending infected files though an attachments using spam emails that is specially designed to look like a discounted deal offers or a mail from office with an attached doc file. When you download the file on system then it drop the infection file of ransom culprit and start executing on system automatically to spread on entire system. Some additional infecting methods are like accidental clicks on suspicious advertisements or infected links, sharing of files using peer to peer, third party freeware downloads and lots more.

Lockme Ransomware : Removal And Preventions

As you read above if your system got infected by the malware above mentioned then you should not make more late to remove Lockme Ransomware from infected system using a trusted anti-malware. You can also follow the below given manual removal but it is not an easily task and one should be really careful while eliminating manually. Follow the steps very carefully. 

Free Scan your Windows PC to detect Lockme Ransomware

rmv-notice

 

Remove Lockme Ransomware From Your PC

Step 1: Remove Lockme Ransomware in Safe Mode with Command Prompt

  • First of all disconnect your PC with network connection.
  • Click restart button and keep pressing F8 key regularly while system restart.

F8-keyboard

  • You will see “Windows Advanced Options Menu” on your computer screen.

Windows Advanced Options Menu

  • Select “Safe Mode with Command Prompt” and press Enter key.

safe mode with command promt

  • You must login your computer with Administrator account for full privilege.

daver

  • Once the Command Prompt appears then type rstrui.exe and press Enter

picture6

  • Now follow the prompts on your screen to complete system restore.

Step 2: Remove Lockme Ransomware using MSConfig in Safe Mode:

  • Power off your computer and restart again.
  • While booting press the “F8 key” continuously to open “Windows Advanced Options Menu”.

F8-keyboard

  • Use the arrow keys to select “Safe Mode” option and press Enter key.

Safe mode

  • Once system get started go to Start menu. Type “msconfig” in the search box and launch the application.

msconfig01

  • Go to the Startup tab and look for files from %AppData% or %Temp% folders using rundll32.exe. See an example below:

C:\Windows\System32\rundll32.exe C:\Users\username\appdata\local\temp\regepqzf.dll,H1N1

  • Disable all the malicious entries and save the changes.
  • Now restart your computer normally.

Step 3 : Kill Malicious Process Related To Lockme Ransomware

  • Press Alt+Ctrl+Del buttons together.

ctrl+alt+del

  • It will open the Task manager on your screen.
  • Go to Process Tab and find Lockme Ransomware related process.
  • Click the End Process Now button to stop the running process.

Step 4 : Remove Lockme Ransomware Virus From Registry Entry

  • Press “Windows + R” key together to open Run Box.

Win+R

  • Type “regedit” and click OK button.

Type-regedit-to-open-registry

  • Find and remove Lockme Ransomware related entries.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Now hopefully you have completely removed the Lockme Ransomware virus from your computer. If you are still get ransom message from the threat or unable to access your files, then it means that virus still remain into your computer. In such situation you don’t have any other option except removing this virus using any powerful malware removal tool.

Whereas if you have any backup of your infected or encrypted files, then you can also reinstall your Windows OS. This will erase all your files and data as along with the Lockme Ransomware infection. You will get a completely empty computer system with no files. Now you can use your backup to get your files. If you don’t have any backup then using malware removal tool is a better option for you.

freescan1

If you have any query or question regarding your computer, then you can easily ask your problem to our experts. Go to the Ask Any Question page and get the answer for your query directly from out experts.

footer-1

Skip to toolbar