What is Lock93

Lock93 is a new ransomware that have been discovered by MalwareHunterTeam expert last Saturday. We still don't have enough information to tell you about its complexity, but for now we can say that it has almost no differences from other ransomware in its structure and encryption methods. It uses AES-256 method of encryption, that can't be decrypted without a key. It penetrates user's system with help of fraud e-mails, and encrypts all types of files. The ransom note says that any operation with ransomware files might cause the removal of encrypted files, but this is just a trick. if you want to keeep your files safe, you need to follow the instructions, given in this article, and perform the removal of Lock93 ransomware in Safe Mode, where all its features will be useless.

The structure of this ransomware is pretty plain, but its behavior isn't. First of all, the instructions on payment come in two languages: English and Russian. The ransom price is 1000 RUR ($16), which is extremely low for ransomware. The ransom message and the currnecy in which the scammers want to receive their money are pointing directly on Russia, but this fact isnt' helpful for the specialists which are trying to break the code of this ransomware.As we said earlier, the price of decryption is veru low, and this might be a sign of weakness. Hackers just want to get as much money as they can before the code of their product will be broken. So, even if $16 is nothing for you, it is wiser to wait until the decryption tool will be released, to decrypt your files for free. Remember, that each time when ransomware victim pays for decryption, web-scammers are getting money that will be used for criminal purposes, or for the creation of new virus. The right decision would be to remove Lock93 from your computer and wait few weeks until MalwareHunterTeam will give us news about the decryption of files.

Step 1. Boot into Safe mode

Safe mode

Start -> Msconfig.exe

Safe mode. Step 1

On the tab Boot select Safe boot

Safe mode. Step 2

Step 2. Check Startup folder

Start -> Msconfig.exe ->Disable unknown programs in the Startup tab

Startup

Step 3. Check hosts file

Modify hosts file, that located in C:\Windows\System32\drivers\etc\ .

Hosts file.Step 1

Open the file with Notepad and delete suspicious strings.

Hosts file.Step 2

It has to look like this:

Hosts file.Step 3

Step 4. Scan the system with antiviral scanner

 

Antivirus scanner

Why we recommend SpyHunter antimalware as removal tool

Removes virus fully: all files and even registry keys of malware will be deleted

Protects your system in the future

24/7 free support team

bwd  Instructions 1/2  fwd

Step 5. Disable Safe mode

Start -> Msconfig.exe ->Disable Safe boot in the Boot tab

Deactivate Safe mode

Add comment

Security code
Refresh

This website uses cookies to improve your experience. If you continue using the site, we will assume that you accept our cookies policy.