Lockdown EXPOSED: .crypt_lock Files and a Lock Screen With No Inbox

You open Documents the way you did yesterday. The vacation photo should still be vacation.jpg. The invoice should still be invoice-2026.pdf. The tax sheet should still be taxes.xlsx. Instead every familiar name has a second ending tacked on. 1.jpg is now 1.jpg.crypt_lock. 2.png is now 2.png.crypt_lock.

Then the listing disappears behind a screen you did not open. It is not a text file in the folder. It is not a small portal in a corner. It covers the glass. The first line is ALL OF YOUR FILES ARE ENCRYPTED. Under that sits LOCKDOWN-RANSOMWARE. A field tells you to Enter the password provided. A button says Submit Password.

That is the trap, not a glitch.

Encrypted files after Lockdown. The .crypt_lock names are the tell.
Encrypted files after Lockdown. The .crypt_lock names are the tell.

Overview

Lockdown ransomware is a locker that brands the files, then covers the desktop, then leaves you with nothing to type. The lock is the extra ending .crypt_lock. The note is a full-screen overlay, not a README sitting in the folder. The squeeze is a password field with no password, and a restart warning written in all caps. There is no mail address on that screen. There is no Telegram handle. There is no wallet. There is no printed $ figure. The emptiness is the product.

If you are staring at a pile of .crypt_lock files and a lock screen that still wants a password it never gave you, you are in a ransom incident. You are not in a broken disk. You are not in a fake Windows security pop-up that only wants a phone call.

The costume is loud on purpose. A full-screen overlay feels like the machine itself is talking. It feels like a login you must finish before you can do anything else. That is how a locked photo folder starts to feel like a checkout. Stay with the folder. The overlay is intimidation. It is not a help desk, and it is not a door back into the files.

The .crypt_lock name is the first warning

After the lock, the old names stay. Then Lockdown hangs .crypt_lock on the end. A picture named 1.jpg becomes 1.jpg.crypt_lock. A second picture named 2.png becomes 2.png.crypt_lock. A vacation shot named vacation.jpg becomes vacation.jpg.crypt_lock. A scan named invoice-2026.pdf becomes invoice-2026.pdf.crypt_lock. A sheet named taxes.xlsx becomes taxes.xlsx.crypt_lock. A clip named family.mp4 becomes family.mp4.crypt_lock.

You can still read what the file used to be. You cannot open it. Windows may call the type a CRYPT_LOCK File and offer a useless “choose an app” box. An app cannot talk locked bytes back into a JPEG. The familiar words are still in the folder so you can inventory the damage in seconds. That readable name is advertising, not a repair.

Do not treat the extra letters as a typo. Do not strip .crypt_lock off the end and expect Photos or Excel to open the file. Do not run a bulk “extension fixer” you found in an ad. The name is a label. The lock is in the content. Editing the label can make a later trusted tool have a harder time matching the file to what it was. Leave the locked copies as they are until you have a clean machine and a plan that does not start inside that overlay.

The extra ending also does later work. Anyone who sees 1.jpg.crypt_lock can pretend they already have your case. A comment, a video, or a cold call can quote the extension back to you as if that were expertise. The extension is public. It is sitting in the folder. Quoting it proves nothing except that they can read a listing.

The lock screen is the whole note

Plenty of lockers drop a text file or an HTML page next to the damaged files. This one does the talking on the glass. The overlay is the ransom note. That matters because there is no second document in the folder that you can save, print, or hand to a responder as a neat flyer. The screen is the flyer. The files are the proof.

The wording on that screen is short. It does not need a long speech. It says ALL OF YOUR FILES ARE ENCRYPTED. It brands itself LOCKDOWN-RANSOMWARE. It puts a field on the glass: Enter the password provided. It puts a button next to that field: Submit Password. Then it shouts, in one run-on line, DO NOT RESTART YOUR COMPUTER THIS WILL RESULT IN ALL FILES BECOMING CORUPTED AND UNABLE TO BE RECOVERD!!!

Those are the lines on the overlay. There are no extra paragraphs hiding under them. There is no inbox under the button. There is no chat ID. There is no onion string. There is no Bitcoin address. The screen talks as if a password already exists somewhere else, then never says where. That missing “somewhere else” is the hook.

Keep a photo of the overlay from a phone if you can do it without typing into the field. The wording is evidence. The typos are evidence too. The screen spells CORUPTED and RECOVERD. A later stranger who “already has your ticket” should be able to quote that exact line, including the missing letters, if they actually saw the overlay. Most of them will clean the spelling. That cleanup is a tell.

Enter the password provided, with nothing provided

Read the field again. Enter the password provided. Provided by whom. Provided where. Provided in what mail, what chat, what envelope. The overlay never answers. It speaks as if you already received a string through some other channel, and the only job left is to paste it and press Submit Password.

That sentence does more work than a printed $ amount would do. A printed amount can be argued with. A missing password cannot. You cannot haggle with a blank. You sit with the feeling of being one string away from the vacation photo. The overlay taught your hands where to put that string before anyone else had to sell it to you.

People waste the first hour on that field. They type the filename 1.jpg.crypt_lock. They type LOCKDOWN-RANSOMWARE. They type a birthday. They press Submit Password with nothing in the box, just to see. None of those guesses is a key. Closing the overlay is fine for your nerves if you can still reach the machine underneath. It is not a repair. The lock lives in every .crypt_lock file, not in the glass in front of you.

If you already typed something before you stopped, do not keep going. Do not try a second guess. Do not try a third. A password box with no operator behind it will not suddenly become a decryptor because you were persistent. Persistence here is how a second scam times its pitch.

Do not restart is a freeze, not a repair

The last line on the overlay is the panic button. DO NOT RESTART YOUR COMPUTER THIS WILL RESULT IN ALL FILES BECOMING CORUPTED AND UNABLE TO BE RECOVERD!!! It is spelled in a rush. It is punctuated like a siren. It wants you glued to the chair with the password field still in front of you, because a person who is afraid to reboot is a person who will keep staring at Submit Password.

Treat that line as intimidation, not as a technician’s memo. The people who locked 1.jpg.crypt_lock have a reason to keep you on their screen. They do not have a reason to protect your bytes. A restart warning that arrives with no inbox, no wallet, and no password is not a recovery policy. It is a way to own the next ten minutes.

Do not take the overlay as a runbook either the other way. This page will not walk you through killing the locker or bypassing the glass. Isolation still comes first. Unplug. Take Wi-Fi down. Keep extra disks out. The overlay is trying to make those slow, correct moves feel dangerous. They are not more dangerous than sitting in the password field until a stranger offers to fill it.

If this is a company machine, the restart line is also a way to keep you off the phone with the person who handles incidents. A full-screen warning feels like a system crash that only you can prevent. It is not. Tell someone from a phone, not from the infected box. The files are already renamed. Another hour of obedience will not unsay .crypt_lock.

The empty inbox is the product

Most ransom notes want a conversation. They print a mail address. They print a Telegram name. They print a wallet. This overlay prints none of that. The public facts on this strain are blunt about the gap. The lock screen does not provide contact information. It does not provide payment information. That emptiness is not mercy. It is the hook.

A screen that says the password was “provided” sends you hunting for the missing provider. You search LOCKDOWN-RANSOMWARE. You search .crypt_lock password. You search the restart line. Each of those searches can plant a string, a chat, or a “recovery” shop. The overlay already taught you where to paste whatever comes back. Scare, blank, hunt, paste. That is the whole funnel, and it never needed an inbox of its own.

Do not invent the missing channel to finish their sentence. Do not open a fresh mail account because you assume the password will arrive there. Do not join a Telegram group that uses the same brand. Do not type a wallet a comment thread supplied. Those doors were not on the overlay. Adding them is how a locked folder becomes a second crime.

The CISA StopRansomware Guide is blunt about payment even when a crew does print a price. Paying does not ensure the files come back, does not ensure the systems are clean, and does not ensure anything stays unpublished. A locker that never even printed a $ figure is not a special case. It is the same squeeze with the checkout hidden off-screen.

This is not the old locked-PC pop-up

The word lockdown has been on this blog before, attached to different costumes. A 2012 write-up covered a “Your computer has been locked” screen locker. A later page covered a “Your System Is Locked Due To Detected Threats” pop-up. Those stories wanted a phone call, a scare page, or a fake police overlay. They did not append .crypt_lock to 1.jpg. They did not brand a file type CRYPT_LOCK. They did not put LOCKDOWN-RANSOMWARE over a password field that never gives a password.

If your only symptom is a browser pop-up, a fake support number, or an old lock screen with no renamed files, you are in that older story. If documents, photos, and shares now end in .crypt_lock, and a full-screen overlay is sitting on top of the listing, you are not in the pop-up story. Mixing the two wastes the first hour. The old pages wanted a call. This locker already has the files. Treat them as different files with a shared scrap of branding.

Public scanners can add another layer of confusion. Microsoft has logged a detection as Ransom:Win64/LockDownCrypt.PA!MTB. ESET has logged Win64/Filecoder.AIL. Kaspersky has logged Trojan-Ransom.Win64.Agent.een. Those labels are useful when you talk to an incident-response shop. They are not a second article sitting on this blog, and they are not a decryptor. An AV name that contains LockDownCrypt is not proof you should hunt a different family. Match the files in front of you. The ending is .crypt_lock. The overlay is the note.

A detection can remove the active locker. It cannot roll back files that already grew the new ending. That is why a green scan after cleanup can still sit next to a dead photo folder. Cleanup and recovery are different jobs. Do the first so the second is not undone overnight. There is no public free decryptor known for this strain. Anyone who greets you by .crypt_lock and offers the missing password is still selling the lock.

How The Ransomware Works

The shop is simple once you stop reading the overlay as a rescue. Lock the files. Brand the names with .crypt_lock. Cover the desktop. Ask for a password that was never provided. Warn you not to restart. Leave no inbox. Then wait for someone else to sell the missing string.

1. One reachable account is enough

Someone on the machine still has a session the attackers can use. That can be a stolen remote-desktop login, a phishing mail from last month, a cracked installer, or a share that was never meant to be open. This page will not walk through those paths. The part you can see is the aftermath: one account was enough, and the overlay now speaks as if the whole computer is already theirs.

From the chair in front of the screen, it feels sudden. From the other side, the lock screen is the last page of a longer stay. CISA warns that a ransomware event can be the noisy end of an earlier compromise. That is why “reboot and hope” is a poor first move on a business network, and why the overlay’s restart line is so useful to the people who wrote it. The locker may be the only thing you can see. It may not be the only thing that is there.

2. Files pick up .crypt_lock and stop opening

The locker walks the folders it can reach and rewrites the files it cares about. Documents, images, archives, and exports are the usual targets because those are the files people miss first. When it finishes a file, it leaves the old name in place and hangs .crypt_lock on the end. That is why 1.jpg is still readable as 1.jpg.crypt_lock, and why 2.png is still readable as 2.png.crypt_lock.

Shared folders make the scene look bigger than one PC. A mapped drive, a NAS share, or a user profile that syncs to a server can carry the new ending across the office in one pass. A USB stick you forgot was plugged in can pick it up too. If only one folder looks wrong, do not assume the rest of the disk is safe. Unplug extra disks. Do not plug in the backup drive “just to check.” Checking is how the backup gets the same .crypt_lock ending.

Double-clicking a renamed file does not bring the photo back. The thumbnail may already look broken. Spreadsheet software may ask for a workbook that is still sitting in the same folder, only the bytes inside are no longer a workbook. That broken open is the first proof. The second proof is the extra ending. Together they are enough. You do not need the overlay to confirm what you are looking at.

3. The lock screen covers the desktop

A renamed file can be ignored for a minute if you are busy trying to open the photo. A full-screen overlay cannot. It sits on top of Explorer, on top of the taskbar, on top of the instinct to unplug the cable. ALL OF YOUR FILES ARE ENCRYPTED is the first thing you are allowed to read. LOCKDOWN-RANSOMWARE is the brand. The rest of the computer is costume furniture behind the glass.

That coverage is the product. A text file can be closed. A small window can be moved. A full-screen note makes every other action feel like a violation of the warning at the bottom. People freeze. They screenshot. They search every word. They wait for a password that the same screen promised was already provided. The overlay does not have to name a $ amount to own that hour. It only has to keep you from isolating the machine.

Do not keep the overlay up “so you do not lose the password box.” The box has nothing in it. Do not screenshot the window and send it to a stranger who offered to read the password from the image. The image will show a blank field and a restart threat. The stranger already knows that. They are selling a fill-in, not a reading.

4. The password field trains you to hunt a secret

Enter the password provided is the most important line on the overlay, and it is empty on purpose. An empty required field is how a form tells you that you are not done. The word “provided” does extra cruelty. It implies the secret already exists. It implies you misplaced it. It implies the failure is yours, not theirs.

Watch what that line does to the next hour. You search for a Lockdown password. You search for a Lockdown inbox. You open comment threads. You watch a video that promises the string in the description. Each of those places can plant a value. The overlay already taught your hands where to paste it and which button to press. Scare, blank, hunt, Submit Password.

There is no password printed on the screen. There is no password printed in the folder. Inventing one so the costume feels complete is how the second shop gets paid. If a later message quotes your .crypt_lock files and says the password was “in the first mail,” look at the overlay again. The overlay never named a mail. The missing inbox is not a clue you failed to notice. It is the design.

5. The restart line tries to keep you in the chair

Urgency is the cheapest tool in this trade. A restart warning sounds technical, so it feels real. It is specific the way a fake shipping countdown is specific. The people who set it can wait, raise the fear, or vanish. Your job in that first hour is not to protect a lock they already finished. Your job is to stop the spread and to keep a clean copy of what you still have.

The line also does social work. If a relative walks in and says unplug the box, the overlay has already told you that adult is a threat. If IT says isolate the share, the overlay has already told you that move will “CORUPT” the files. The spelling is sloppy. The psychology is not. A freeze that arrives with no contact channel is still a freeze.

Put the siren down. The files are already locked. Another hour of staring at Submit Password will not unlock them, and it will not make a missing inbox appear. Isolation is still the first useful move. The overlay’s job is to make that move feel like vandalism. It is not.

6. Searching for an inbox becomes the next trap

Because the overlay never printed a way to write back, the search bar becomes the contact form. That is the dangerous hour. Results fill up with pages that already know the brand, the extension, and the restart line. Some of those pages are ordinary write-ups. Plenty are a second storefront. They need you to believe the password was provided somewhere, and that they are the somewhere.

Do not write an address a stranger supplies “for Lockdown support.” Do not open a Telegram chat that uses the same name. Do not send a sample file to prove you are a real victim. A sample can still hold a client line, a path, or a photo you did not mean to share. You do not owe anyone a test. You do not need their proof. If a trusted decryptor ever appears, it will come from a project like No More Ransom, not from a mailbox that had to be invented after the fact.

Silence is not rude here. Silence is how you stay out of a queue that was never printed on the glass. The overlay already has what it wanted from the first half of the job. The second half is getting you to go find a cashier.

7. Third parties will sell a password for that empty field

After a ransomware incident, search results fill up with companies that say they can decrypt Lockdown or “all .crypt_lock files.” Some of those shops are ordinary overpriced consultants. Plenty are a second scam. The original overlay never named a price. The second crew will. They want a deposit, a remote-access session, or the same password field filled with a string they dictate.

A real public decryptor, when one exists, shows up on an official project page that already existed before your incident. It does not need a deposit in cryptocurrency. It does not need you to press Submit Password while someone watches. It does not need a Telegram handle that was missing from the overlay. If the pitch is “we have the Lockdown password, pay us first,” you are still paying the lock.

There is no public free decryptor known for this strain, and there is no honest way to claim the files came back through a paid inbox that the lock screen never printed. Anyone who can quote LOCKDOWN-RANSOMWARE has read the same overlay you did. That is not a credential.

8. Payment and guessing close nothing

Everything on the glass points to one action: produce a password. The brand, the field, the button, and the restart siren all serve that action. Guessing is how a locked folder becomes a longer incident. Paying a stranger for the guess is how the next victim is funded. Neither step restores a machine you can trust.

The No More Ransom project puts the rule in plain language. Paying is not guaranteed to bring the files back, and you should not pay. That is not a slogan from a blog. It is the line on the official landing page run with Europol and the project partners. Use that page. Do not use the overlay as a vendor, and do not use a comment thread as the missing inbox.

A blank password field is not a reason to skip a report. It is a reason to stop typing. The files are already locked. Another night of guesses will not change the bytes. The overlay’s emptiness does not make this locker experimental in a way that helps you. It makes the second shop’s job easier.

What To Do If Your Files End in .crypt_lock

The first useful hour is quiet. You are not looking for the password the overlay claimed was already provided. You are stopping the spread, keeping evidence, and moving the incident onto official rails. The house steps below cover the generic work every ransomware victim needs. After that block, stay with the Lockdown details a generic page cannot name for you. There is no inbox to write. The lock screen is intimidation.

STEP 1: Use Rkill to terminate suspicious programs.

In this first step, we will download and run Rkill to terminate suspicious programs that may be running on your computer.

RKill is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then removes incorrect executable associations and fixes policies that stop us from using certain tools.

  1. Download Rkill.

    You can download RKill to your computer from the below link. When at the download page, click on the Download Now button labeled iExplore.exe. We are downloading a renamed version of Rkill (iExplore.exe) because some malware will not allow processes to run unless they have a certain filename.

    RKILL DOWNLOAD LINK

    (The above link will open a new page from where you can download Rkill)
  2. Run RKill.

    After downloading, double-click the iExplore.exe icon to kill malicious processes. In most cases, downloaded files are saved to the Downloads folder.
    The program may take some time to search for and end various malware programs.

    RKILL Window

    When it is finished, the black window will close automatically and a log file will open. Do not restart your computer. Proceed to the next step in this guide.

STEP 2: Use Malwarebytes to remove Ransomware and Unwanted Programs

In this second step, we will install Malwarebytes to scan and remove any infections, adware, or potentially unwanted programs that may be present on your computer.

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

STEP 3: Use HitmanPro to remove Rootkits and other Malware

In this third step, while the computer is in normal back, we will download and run a scan with HitmanPro to remove Trojans, rootkits, and other malicious programs.

HitmanPro is a second-opinion scanner — it’s designed to catch what your main antivirus might have missed. Instead of relying on a single detection engine, it checks the behavior of files in the locations where malware usually hides. Anything suspicious gets sent to the cloud, where it’s analyzed by two of the best antivirus engines available: Bitdefender and Kaspersky.

Good news: scanning is completely free, with no limits. You only need a license when it’s time to remove what was found — and even then, you can activate a free one-time 30-day trial to clean your PC at no cost. (A full license is $24.95 per year for 1 PC.)

  1. Download HitmanPro

    Click the button below to download HitmanPro. Remember — the scan is free, so you have nothing to lose by checking your PC.

    DOWNLOAD HITMANPRO (FREE SCAN)
    (The link opens in a new page where your download will start)
  2. Install HitmanPro

    When the download finishes, open your Downloads folder and double-click the file: “hitmanpro.exe” on 32-bit Windows, or “hitmanpro_x64.exe” on 64-bit Windows.

    Double-click on the HitmanPro file

    If a User Account Control pop-up asks whether HitmanPro can make changes to your device, click “Yes” to continue.

    Windows asking for permissions to run the HitmanPro setup

  3. Follow the On-Screen Prompts

    On the HitmanPro start screen, click “Next” to begin the system scan. No lengthy setup required — it goes straight to work.

    Click Next to install HitmanPro on your PC

    HitmanPro final installer screen

  4. Wait for the Scan to Finish

    HitmanPro will now check your computer for malicious programs. This usually takes just a few minutes thanks to its cloud-based scanning.
    HitmanPro scans your computer for any infections, adware, or potentially unwanted programs that may be present

  5. Review the Results and Click “Next”

    When the scan is done, HitmanPro will show you everything it found. Click “Next” to remove the detected threats.

    HitmanPro scan summary. Click Next to remove malware

  6. Click “Activate Free License”

    To remove the malicious files, click the “Activate free license” button. This starts your free 30-day trial — no payment details needed — and unlocks the full cleanup.
    Click on the Activate free license button

    When the removal is complete, HitmanPro will show a summary of everything it cleaned. Click Next, then click Reboot if prompted. If there’s no reboot prompt, just click Close — your PC is clean.

STEP 4: Use AdwCleaner to remove Malicious Browser Extensions and Adware

In this next step, we will use AdwCleaner to remove malicious browser policies and unwanted browser extensions from your computer.

AdwCleaner is a free on-demand scanner that specializes in adware, browser hijackers, and unwanted toolbars — the exact threats that mainstream antivirus programs often miss. It also includes tools that repair the damage malware leaves behind, like hijacked browser settings and malicious policies. It’s a quick scan that’s well worth running.

  1. Download AdwCleaner

    Click the button below to download AdwCleaner — it’s free, portable, and requires no installation.

    DOWNLOAD ADWCLEANER (FREE)

    (The link opens in a new page where your download will start)
  2. Run AdwCleaner

    Open your Downloads folder and double-click the file named “adwcleaner_x.x.x.exe“. There’s no installation — the program starts right away.
    Download AdwCleaner on your computer

    If Windows asks whether you want to allow AdwCleaner to run, click “Yes“. When the license agreement appears, click I agree to continue.

    Windows ask if you want to run AdwCleaner

  3. Enable “Reset Chrome policies”

    This setting removes malicious browser policies — a trick malware uses to lock your browser settings so you can’t change them back. Click “Settings” on the left side of the window, then turn on “Reset Chrome policies“.

    Enable Reset Chrome policies to remove malicious browser policies

  4. Start the Scan

    Click “Dashboard” on the left side of the window, then click the “Scan” button.

    Click on Scan to start a AdwCleaner scan

  5. Wait for the Scan to Finish

    AdwCleaner will now check your computer for adware and other malware. This usually takes only a few minutes — it’s one of the fastest scanners around.

    AdwCleaner scanning for adware and other malware

  6. Quarantine the Detected Threats

    When the scan finishes, AdwCleaner will list everything it found. Click the “Quarantine” button to remove all the malicious items at once.

    Click on Quarantine to remove malware

  7. Click “Continue” to Finish the Cleanup

    Save any open work first — AdwCleaner needs to close your open programs before it can clean. When you’re ready, click the “Continue” button.
    Click Continue to remove malicious files

    AdwCleaner will now delete all detected malware from your computer. If it asks you to restart your PC, allow it — your computer will be clean when you log back in.

STEP 5: Perform a final check with ESET Online Scanner

This final step involves installing and running a scan with ESET Online Scanner to check for any additional malicious programs that may be installed on the computer..

ESET Online Scanner is a free second-opinion scanner that performs a deep, full-system check for viruses, trojans, rootkits, and other malware. We use it as the final step because it’s thorough — if anything slipped past the previous scans, ESET will find it. A clean result here means your computer is malware-free.

  1. Download ESET Online Scanner

    Click the button below to download ESET Online Scanner.

    DOWNLOAD ESET ONLINE SCANNER (FREE)

    (The link opens in a new page where your download will start)
  2. Run the Installer

    When the download finishes, open your Downloads folder and double-click “esetonlinescanner.exe“.
    Image - Double-click on the ESET Online Scanner setup file

  3. Install ESET Online Scanner

    On the start screen, select your language from the drop-down menu and click Get started.

    Image - Click Get Started to install ESET Online Scanner

    On the Terms of use screen, click Accept.
    Image - Accept Terms to Install ESET Online Scanner

    Choose your preferences for the Customer Experience Improvement Program and the Detection feedback system (either choice is fine), then click Continue.
    Image - Follow the on-screen prompts

  4. Start a Full Scan

    Click Full Scan — this checks your entire computer, not just the common hiding spots.

    Start a Full Scan with ESET Online Scanner

    Select Enable for Detection of Potentially Unwanted Applications — this lets ESET catch adware and bundled junk programs, not just viruses. Then click Start scan.

    Image - Enable PUA Detection and Start Scan

  5. Wait for the Scan to Finish

    ESET will now check every file on your computer. Because it’s a full scan, this can take a while — often an hour or more, depending on how much data you have. Leave it running in the background and check on it from time to time.

    Image- Wait for the ESET Online Scanner scan to finish

  6. Review the Results

    When the scan completes, the Found and resolved detections screen appears. Any threats found were automatically cleaned and quarantined — there’s nothing extra you need to do. Click View detailed results if you want to see exactly what was removed.
    Image - ESET Online Scanner malware removal

    If ESET found nothing — congratulations, your computer has passed the final check and is malware-free.

STEP 6: Restore the files encrypted by ransomware

Unfortunately, in most cases, it’s not possible to recover the files encrypted by this ransomware virus because the private key which is needed to unlock the encrypted files is only available through the attackers. However, below we’ve listed three options you can use to try and recover your files.

Make sure you remove the malware from your computer first, otherwise, it will repeatedly lock your system or encrypt files. If you suspect that your computer is still infected with malware, you can run a free scan with Emsisoft Emergency Kit.

Option 1: Search a decryption tool for this ransomware

The cybersecurity community is constantly working to create ransomware decryption tools, so you can try to search these sites for updates:

Option 2: Use EaseUS Data Recovery Wizard Free to recover the encrypted files

EaseUS Data Recovery Wizard Free can restore files and repair corrupted files with simple clicks. Its powerful scanning algorithms can identify and retrieve huge file type library, including all of the popular video files, audio files, photos, and document formats.
While the free version only allows you to recover 2 GB of data, this can be helpful to see if the recovery is possible and restore back the most important files from your computer.

  1. Download EaseUS Data Recovery Wizard Free.

    You can download EaseUS Data Recovery Wizard Free by clicking the link below.

    EASEUS DATA RECOVERY WIZARD FREE DOWNLOAD LINK

    (The above link will open a new page from where you can download EaseUS Data Recovery Wizard)
  2. Double-click on the EaseUS Data Recovery Wizard Free setup file.

    When EaseUS Data Recovery Wizard Free has finished downloading, double-click on the setup file to install EaseUS Data Recovery Wizard on your computer. In most cases, downloaded files are saved to the Downloads folder.

    Image: EaseUS Data Recovery Wizard Free Installer

    You may be presented with a User Account Control pop-up asking if you want to allow EaseUS to make changes to your device. If this happens, you should click “Yes” to continue with the EaseUS Data Recovery Wizard Free installation.

  3. Follow the on-screen prompts to install EaseUS Data Recovery Wizard.

    When the EaseUS Data Recovery Wizard installation begins, click on the “Install Now” as seen in the image below.
    EaseUS Data Recovery Wizard Free Install Now

    When your EaseUS Data Recovery Wizard installation completes, click the “Start Now” button to start the program.
    Image: Click Start Now

  4. Select a location to start recovering the encrypted files.

    Choose the drive or folder where you are the encrypted files that you want to recover and click “Scan“.
    Select a location to start recovering the encrypted files

  5. Wait for the EaseUS Data Recovery Wizard scan to complete.

    EaseUS Data Recovery Wizard will now scan your computer files that can be restored. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Image: Wait for the EaseUS Data Recovery Wizard scan to complete.

  6. Find the files you want to recover.

    When the EaseUS Data Recovery Wizard scan is finished scanning it will show a screen that displays the files that can be recovered. This tool can recover a lot of data, use the “Filter” button to quickly filter specific file types and find the files that you want to recover.
    Filter the Files by Type

    Click the “Preview” button or double-click on a file for a full preview.
    Image: Click Preview to view the file

  7. Select your files and click “Recover”.

    Finally, select the the files you want to recover and click “Recover“.
    Select your files and click Recover
    Choose a safe location to save all the files.
    Select a safe location
    The free version only allow you to recover 2 GB of data, however, this will allow you to recover the most important files and see if EaseUS Data Recovery Wizard can correctly recover them.
    Image: View Recovered Files

Option 3: Try to restore your files with ShadowExplorer

This ransomware will attempt to delete all shadow copies when you first start any executable on your computer after becoming infected. Thankfully, the infection is not always able to remove the shadow copies, so you should continue to try restoring your files using this method.

  1. Download ShadowExplorer.

    You can download ShadowExplorer from the below link.

    SHADOW EXPLORER DOWNLOAD LINK
    (This link will open a new web page from where you can download “ShadowExplorer”)
  2. Install ShadowExplorer.

    Double-click on the ShadowExplorer-x.x-setup file to start the installation process, then follow the on-screen promts to install this program.
    Install Shadow Defender

  3. Select snapshot date.

    Open ShadowExplorer and then from the top bar select the drive where the files that you want to save are located, then select from the snapshot available one previous to this infection.

    Select drive and date to recover the files encrypted by this ransomware

  4. Export the files that you want to recover.

    Once you have found a copy of the original file or folder, right-click on it and the select “Export”. A window will prompt you where you want to save the file or folder.
    Find copy then click on Expor to recover the files encrypted by this ransomware

Do not type a string into Enter the password provided. Do not press Submit Password to see what happens. Do not hunt the internet for an inbox, a Telegram handle, a wallet, or a $ figure the overlay never printed. Do not invent a mail address to finish their flyer. The empty field is not a key waiting for you. If you already opened the overlay before you stopped, do not send a sample file to a stranger who offered to fill the field.

Do not obey DO NOT RESTART YOUR COMPUTER THIS WILL RESULT IN ALL FILES BECOMING CORUPTED AND UNABLE TO BE RECOVERD!!! as if it were a support policy. That line is there to keep you in the chair with the password box still on the glass. This page will not walk you through killing the overlay. It will tell you the overlay is not in charge of the incident.

Keep every .crypt_lock name exactly as it is. Do not bulk-rename 1.jpg.crypt_lock back to 1.jpg, or 2.png.crypt_lock back to 2.png, or vacation.jpg.crypt_lock back to a normal JPEG, or invoice-2026.pdf.crypt_lock back to a normal PDF. Stripping the extra ending is not a repair. It can make a later trusted tool worse, not better. The original name is already sitting in front of .crypt_lock.

Keep a photo of the overlay if you have one. The brand LOCKDOWN-RANSOMWARE, the password field, the Submit Password button, and the misspelled restart line are how you prove this was this strain and not an older locked-PC pop-up. The overlay is evidence. It is not a set of steps you should carry out. There is no note file in the folder to “clean up,” and you should not create one by copying the wording into a new document on the infected machine.

Treat the empty password field as a slot, not a lock. Do not paste a “universal Lockdown password” from a comment. Do not pay anyone to dictate digits into that box. Do not run a third-party decryptor you found in an ad, a YouTube description, or a chat “recovery” channel because it promised to fill the overlay. Leave the locked copies alone until a trusted project publishes a tool for this family. None is public now.

When you talk to a responder, use the names that already exist. The file ending is .crypt_lock. The overlay brand is LOCKDOWN-RANSOMWARE. Microsoft: Ransom:Win64/LockDownCrypt.PA!MTB. ESET: Win64/Filecoder.AIL. Kaspersky: Trojan-Ransom.Win64.Agent.een. Add that the screen asks for a password it never provides, and that it prints no contact and no payment details. That is enough to match the strain without handing anyone a sample.

A blank overlay is not a reason to skip a report. File the incident through the CISA ransomware reporting page or the FBI IC3 desk if those are the right doors for you.

If a stranger later greets you by .crypt_lock, by LOCKDOWN-RANSOMWARE, or by the misspelled restart line, they read the same overlay you did. A password that was “provided” in a mail you never received is not a reason to skip the report. The clock is theirs. The files are already locked. Another night of typing into an empty box will not change the bytes.

The Bottom Line

Lockdown ransomware is a locker with a readable filename and a lock screen that asks for a password it never gives. It keeps the old name and appends .crypt_lock. 1.jpg becomes 1.jpg.crypt_lock. 2.png becomes 2.png.crypt_lock. The note is not a text file in the folder. It is a full-screen overlay branded LOCKDOWN-RANSOMWARE. It says ALL OF YOUR FILES ARE ENCRYPTED. It tells you to Enter the password provided. It offers Submit Password. It warns you not to restart, with CORUPTED and RECOVERD spelled that way. It prints no inbox, no Telegram, no wallet, and no $ figure. The emptiness is the hook.

This is not the old “Your computer has been locked” pop-up, and it is not the later “Your System Is Locked Due To Detected Threats” scare. Public antivirus talks about it as Microsoft Ransom:Win64/LockDownCrypt.PA!MTB, ESET Win64/Filecoder.AIL, and Kaspersky Trojan-Ransom.Win64.Agent.een. Those labels are identifiers. They are not a decryptor. There is no public free decryptor known for this strain.

Do not pay. Do not type into that field. Do not hunt a missing inbox. Do not invent a contact. Do not rename the pile in bulk. If you take one sentence with you, take this. A folder of names ending in .crypt_lock, plus a lock screen with no inbox, is ransomware on the first sighting. Treat it that way before anyone offers to provide the password the overlay only pretended you already had.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Hnx911 EXPOSED: .hnx911 Files, HOW TO DECRYPT FILES.txt, and hnx911@yahoo.com

Next

Prinz Eugen EXPOSED: .prinzeugen Files and No Note on the Desktop