Lalaland ransomware – cryptomalware that doubles the price of the decryption tool after 48 hours

Lalaland virus belongs to a dangerous ransomware[1] family known as VoidCrypt. Since this computer infection is a cryptovirus, it immediately starts fulfilling its purpose as soon as it gains access to a computer system – data encryption[2] and money extortion. All essential data, except system files, on the targeted device is appended with a three-part extension and rendered useless because the victims can't access any of it. The aforementioned extensions consist of the following: criminals' contact email address in brackets, assigned unique user ID in brackets, and .lalaland extension.
When phase one is completed, the Lalaland virus moves on to phase two – money extortion. All affected folders receive a new !INFO.HTA file with the cybercriminals' instructions and demands. Also, an irritating pop-up window with the same message appears from time to time. In this ransom note, the cyberthieves are providing two emails to contact them (recover10@tutanota.com, recover1010@mail.ru) and providing their victims with a unique ID. To prove that they do have the decryption tool/key, they're offering the victims to send one file for test decryption. After the victims would transfer an unspecified amount of cryptocurrency Bitcoins,[3] they are promised to receive the decoding tool. As always, we strongly advise against contacting the criminals.
| Name | lalaland virus, Lalaland ransomware |
|---|---|
| type | Cryptoworm, Ransomware, File locker |
| family | Void/VoidCrypt |
| appended extension | Three-part extension appended: criminals' contact email address, a prescribed unique user ID and .lalaland extension. |
| ransom note | !INFO.HTA file found in contaminated folders. Abrupt pop-up window with same message. |
| criminals' contact details | Two emails provided – recover10@tutanota.com, recover1010@mail.ru |
| virus removal | Full system scan should be performed with a powerful anti-malware software and the virus eliminated complying with the given instructions |
| system fix | After lalaland virus removal, a system tune-up should be performed to check for any irregularities in the system files. Use the FortectIntego tool to fix issues caused by the virus automatically. |
Immediate eradication of malware from the computer system is critically important. A manual deletion might become a long and challenging process even for highly experienced computer users. To remove Lalaland ransomware, use apps like SpyHunterCombo Cleaner and MalwarebytesMalwarebytes to accomplish the task automatically. Keep software like this up-to-date, and it will protect devices for a long time.
VoidCrypt family members not only encrypt sensitive data but it also “plays” around with system settings and its files (victims wouldn't receive pop-up ransom messages otherwise). After Lalaland ransomware virus removal, use a trustworthy FortectIntego system tune-up tool to automatically find and fix whatever is wrong with the system files/settings.
Ransom note, in both the pop-up window and the newly created files in affected folders, reads:
!!! Your Files Has Been Encrypted !!!
♦ your files has been locked with highest secure cryptography algorithm ♦
♦ there is no way to decrypt your files without paying and buying Decryption tool♦
♦ but after 48 hour decryption price will be double♦
♦ you can send some little files for decryption test♦
♦ test file should not contain valuable data♦
♦ after payment you will get decryption tool ( payment Should be with Bitcoin)♦
♦ so if you want your files dont be shy feel free to contact us and do an agreement on price♦
♦ !!! or Delete you files if you dont need them !!!♦Your ID :-
our Email :recover10@tutanota.com
In Case Of No Answer :recover1010@mail.ru

Most common ways for cybercriminals to distribute the malware
There are two main methods for cybercriminals to spreads their creations: email spam and file-sharing platforms. Of course, there's plenty of other ways, but the main ones are these.
Email spam – we all receive it. There's even a folder for it. Within some of these emails – threats, like mischievous hyperlinks and malicious attachments, are hidden and waiting for unaware computer users to click on them. Once clicked on – infection is initiated. People, be conscious of what you're clicking on.
File-sharing platforms – Torrent sites, social media platforms are another suitable way for malware to spread. No one really knows who put what on the website. No-one knows what's really hiding under, e.g., GTA V crack.exe or Call of Duty cheat codes. We advise you not to be one to find out. Always use anti-malware software to safeguard your journeys on the internet.
Recommended software to remove Lalaland virus infection
Manual virus elimination might eventually do more harm than good. We advise leaving the dirty work to professionals. To remove Lalaland ransomware from infected device, use MalwarebytesMalwarebytes or SpyHunterCombo Cleaner. These reliable apps will erase the virus and all its allocated files. Furthermore, if constantly updated, they will protect user systems from future attacks.

Lalaland virus removal won't unlock your encrypted files. If you didn't have backups, tough news. Export all infected data to an external offline device, like a USB, and wait for a public decoding tool to be created. If you had backups – great! Run a system tune-up using FortectIntego to automatically find what the virus did to system files, restore the files and settings back to normal with a push of a button, get your files from backups and enjoy your computer system anew!
Was this guide helpful?
Be the first to comment