Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteFiles ending in .locked alongside notes such as README1.html, READ_ME4.html or READ_ME10.html are consistent with TellYouThePass ransomware, but the extension alone does not prove it. Isolate the affected systems, preserve the note and logs, and identify the strain with a reputable service before attempting recovery or paying anyone.
This guide covers the 2024 TellYouThePass reports, safe identification, containment, rebuilding and recovery. A dedicated BleepingComputer support topic was opened on June 8, 2024: TellYouThePass Ransomware support topic.
At a glance
- Suggestive indicators: a
.lockedsuffix, numberedREADME*.htmlorREAD_ME*.htmlnotes, a long alphanumeric victim ID, Bitcoin instructions and an attacker email address. - Not proof: many unrelated ransomware families also use
.locked. Do not run a decryptor selected only by that suffix. - First actions: disconnect networks and shares, preserve evidence, then verify the family with ID Ransomware, No More Ransom or a qualified responder.
How to recognize TellYouThePass
Reports associated with TellYouThePass include encrypted websites, databases, archives, images and documents. Notes may be named README.html, README1.html, READ_ME4.html, READ_ME9.html or READ_ME10.html; naming differs between samples. A long personal identifier is commonly embedded in the note. These clues are documented in the 2024 support discussion and an older README.html support topic.
Timeline and server clues
Security reporting linked a June 2024 campaign to exploitation of CVE-2024-4577, a CVSS 9.8 PHP CGI argument-injection flaw capable of unauthenticated code execution on affected deployments. This is especially relevant when an exposed PHP or web server was encrypted around June 8–9, 2024. Earlier TellYouThePass reporting also discussed Apache ActiveMQ and other possible entry points. A timeline is a clue, not proof of exploitation in an individual case.
#1 Best Overall
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
Why .locked is not a diagnosis
The suffix is shared by multiple ransomware families. A different ransom note, multiple extensions, or no note at all may indicate another strain, a deleted note or more than one incident. Treat the result from an identification service as evidence rather than an absolute verdict.
Evidence to collect
- Save the complete ransom note and its text without opening links or contacting the criminals.
- Copy one or two benign encrypted files; retain their original names and extensions if known.
- Record the exact suffix and capitalization, victim ID, first encryption time and last known clean backup.
- Note the operating system, web/PHP software, hosting arrangement and any recent alerts.
- Preserve firewall, web-server, PHP, Windows, antivirus, EDR, VPN, RDP and authentication logs.
What to do immediately
Contain the spread
- Disconnect affected computers and servers from wired and wireless networks.
- Disconnect mapped drives, NAS devices, network shares and removable backup media.
- Follow your incident-response plan if several systems are involved.
- Do not reconnect a restored machine until it has been assessed and cleaned.
- Avoid shutting down a live system when memory or forensic evidence matters, unless continued operation is causing damage or a qualified responder directs it.
Preserve ransom notes, encrypted files and logs. The CISA/FBI guidance identifies notes, wallet information, decryptors, benign samples, timing and the initial attack vector as useful evidence.
Rank #2
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Protect credentials
From a known-clean device, prepare to reset exposed administrator, VPN, RDP, hosting-panel and service credentials. Do not reset accounts in a way that destroys needed evidence; coordinate with responders where possible.
Identify the variant safely
- Submit the ransom note or a small, non-sensitive encrypted sample to ID Ransomware.
- Check the identified family at No More Ransom for a current decryptor.
- Use an incident-response or malware-analysis provider for business-critical, confidential or multi-server cases.
Never upload confidential documents to an unknown “unlocker” site. If a service identifies a different family, do not force a TellYouThePass tool onto the files.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Can TellYouThePass files be decrypted?
A BleepingComputer responder wrote that recovery for the discussed samples required a session RSA-1024 private key held by the attackers and that no alternative solution was then available (forum page 2). A 2024 PCRisk overview likewise reported no free public decryptor for its samples.
Those are dated findings, not a permanent impossibility claim. Keys may later be recovered, infrastructure may be seized or implementation weaknesses may be discovered. Check No More Ransom and ID Ransomware immediately before recovery work. Do not assume payment supplies a working key: the FBI and Microsoft both state that payment does not guarantee restoration or removal of attacker access.
Rank #4
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Removal, eradication and rebuilding
- Isolate systems and preserve evidence.
- Identify the family and likely entry point.
- Patch or disable exposed PHP CGI and other vulnerable internet-facing services; investigate ActiveMQ, RDP, VPN and stolen credentials where relevant.
- Reset compromised credentials from a clean device and remove unauthorized accounts, web shells and persistence.
- Rebuild a server from trusted media when compromise cannot be confidently eradicated.
- Restore only after the root cause is fixed, then monitor for reinfection.
- Reconnect production systems in stages.
Antivirus removal and file decryption are separate problems. A consumer scan is not a complete response to a compromised web host.
Recovery options, from safest to riskiest
| Option | How to use it safely | Main limitation |
|---|---|---|
| Known-good backup | Use offline, immutable or versioned copies that predate encryption. | Online backups may have been encrypted or deleted. |
| Snapshots or previous versions | Verify their date and that attackers could not alter them. | Accessible snapshots may be compromised. |
| Cloud or SaaS restore | Check retention and immutability; treat synchronization as separate from backup. | Sync can propagate encrypted files. |
| Original copies | Re-download trusted installers, media, public documents or source data. | Unique data may not exist elsewhere. |
| Forensic recovery | Ask a specialist whether deleted originals or shadow copies may remain. | Expensive and uncertain. |
| Verified decryptor | Use only a tool matched to the exact family and test on copies. | An incorrect tool can damage recoverable files. |
| Negotiation or payment | Consider only after legal, insurance, sanctions and data-theft review. | No guaranteed key, complete recovery or removal. |
What not to do
- Do not pay immediately or email criminals from a company account before consulting responders and counsel.
- Do not rename every
.lockedfile or run multiple unverified decryptors on originals. - Do not delete notes, logs or encrypted files.
- Do not restore onto an infected or still-vulnerable server.
- Do not reconnect shares before confirming that the threat and stolen credentials are contained.
- Do not trust recovery services that demand unexplained upfront payment or cannot explain evidence handling.
Reporting and legal issues
U.S. victims can report through the FBI Internet Crime Complaint Center. The FBI asks for the known variant, extension, wallet address, attacker email or URL, demand, payment status and timestamps. Businesses should involve legal counsel, cyber-insurance representatives, privacy officers and applicable regulators. Reporting, breach-notification duties, insurance conditions and sanctions screening vary by jurisdiction.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Preventing a repeat incident
- Maintain offline, immutable and regularly tested backups.
- Patch PHP, web servers, ActiveMQ and other exposed software quickly; restrict internet exposure.
- Use MFA, least privilege, segmented networks and controlled RDP/VPN access.
- Monitor web roots, administrator accounts, authentication logs and unusual encryption activity.
- Test restoration and document who can isolate systems during an incident.
The Bottom Line
If .locked files appear with numbered READ_ME*.html notes, TellYouThePass is a credible possibility—not a certainty. Isolate first, preserve evidence, verify the family, fix the entry point and restore from protected backups. Treat any decryptor or payment promise as unverified until independently confirmed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




