Hackers have created an unusual name for a ransomware — LOL

LOL virus is a malicious program designed to encrypt valuable data on the targeted computer. It is easily recognized by the extension mark .LOL! appended at the end of the file-name. Immediately after the virus finishes data encryption, get data.txt file is dropped on the desktop and victim is asked to pay 1 Bitcoin as a ransom. According to the research, malware is a variation of another highly aggressive virtual threat – GPCode ransomware (also known as GPCoder).
Several weeks ago, cybersecurity experts from NoVirus.uk[1] warned users about the similar version of this ransomware. It appends .lol file extension and demands a significantly lower amount of money for a decryption tool — 0.1 BTC. However, the risk of getting infected with this threat seems to be much higher as it was found spreading as a keygen[2] on highly unreliable websites. Therefore, you should not only remove .LOL virus but also be cautions of similar malware infections.
The most peculiar features of .LOL! ransomware serves the get data.txt message. It is divided into two sections named “JOKE” and “SERIOUS”. In the former part, the hackers address their victims in a mocking way by addressing them “Boys and Girls.” Later on, it preaches them of not being cautious about their cyber security.
Moving on to the latter part, .LOL! developers threaten the community that all their data has been locked by the strongest encryption techniques, standard AES and RSA algorithms[3]. Therefore, there is no supposed decryption tool except their own. They assure the victims that they are not scammers and encourage to contact via gpcode@gp2mail.com e-mail address.

The cybercriminals try to earn the trust of their victims by allowing to decrypt files up to 5 MB for free. To increase the rate of successful transactions, attackers urge to pay the ransom or the files will be permanently deleted within a month. At this point we want to calm you and offer another solution that will protect you from financial losses and recover some parts of your data.
We recommend you to start LOL ransomware removal right now with the help of FortectIntego or any other security software of your choice and try to retrieve your files from backups. It is the best alternative way to fight ransomware attacks and minimize illegal profits used to finance the development of other types of high-risk computer infections.
Spam messages are the major cause of the ransomware infection
Analysts have spotted LOL virus spreading via malspam campaigns that send e-mail messages with malicious attachments worldwide. In order to delude as many users as possible, developers wrap their viruses in the fake package of financial reports, invoices, and customs declaration forms.
Unfortunately, credulous users who are unaware of the hidden danger, open the attachment and activate the threat. Needless to say, you should be extremely cautious if you want to avoid ransomware attack. Even if the message is sent from the local police or tax institution, double-check the sender in order to escape the severe consequences of the file-encrypting virus.
Learn how to safely terminate LOL virus
We always recommend to use a reputable anti-malware program to remove LOL ransomware from your system. It is the safest way since it is designed to not only detect ransomware but other computer threats as well. As a result, you will get rid of the malware and increase your computer's security in future.
Be aware that .LOL virus removal won't decrypt your files. After the elimination, you can concentrate on the file recovery. Below this article you will find the instructions on how to retrieve your files using verified decryption tools.
Was this guide helpful?
3 comments