Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Nov 2017

How to remove LOL ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Julie Splinters · Anti-malware specialist

Hackers have created an unusual name for a ransomware — LOL

Image of .LOL! ransomware

LOL virus is a malicious program designed to encrypt valuable data on the targeted computer. It is easily recognized by the extension mark .LOL! appended at the end of the file-name. Immediately after the virus finishes data encryption, get data.txt file is dropped on the desktop and victim is asked to pay 1 Bitcoin as a ransom. According to the research, malware is a variation of another highly aggressive virtual threat – GPCode ransomware (also known as GPCoder).

Several weeks ago, cybersecurity experts from NoVirus.uk[1] warned users about the similar version of this ransomware. It appends .lol file extension and demands a significantly lower amount of money for a decryption tool — 0.1 BTC. However, the risk of getting infected with this threat seems to be much higher as it was found spreading as a keygen[2] on highly unreliable websites. Therefore, you should not only remove .LOL virus but also be cautions of similar malware infections. 

The most peculiar features of .LOL! ransomware serves the get data.txt message. It is divided into two sections named “JOKE” and “SERIOUS”. In the former part, the hackers address their victims in a mocking way by addressing them “Boys and Girls.” Later on, it preaches them of not being cautious about their cyber security.

Moving on to the latter part, .LOL! developers threaten the community that all their data has been locked by the strongest encryption techniques, standard AES and RSA algorithms[3]. Therefore, there is no supposed decryption tool except their own. They assure the victims that they are not scammers and encourage to contact via gpcode@gp2mail.com e-mail address.

Illustration of .LOL! ransomware virus

The cybercriminals try to earn the trust of their victims by allowing to decrypt files up to 5 MB for free. To increase the rate of successful transactions, attackers urge to pay the ransom or the files will be permanently deleted within a month. At this point we want to calm you and offer another solution that will protect you from financial losses and recover some parts of your data.

We recommend you to start LOL ransomware removal right now with the help of FortectIntego or any other security software of your choice and try to retrieve your files from backups. It is the best alternative way to fight ransomware attacks and minimize illegal profits used to finance the development of other types of high-risk computer infections. 

Spam messages are the major cause of the ransomware infection

Analysts have spotted LOL virus spreading via malspam campaigns that send e-mail messages with malicious attachments worldwide. In order to delude as many users as possible, developers wrap their viruses in the fake package of financial reports, invoices, and customs declaration forms.

Unfortunately, credulous users who are unaware of the hidden danger, open the attachment and activate the threat. Needless to say, you should be extremely cautious if you want to avoid ransomware attack. Even if the message is sent from the local police or tax institution, double-check the sender in order to escape the severe consequences of the file-encrypting virus.

Learn how to safely terminate LOL virus

We always recommend to use a reputable anti-malware program to remove LOL ransomware from your system. It is the safest way since it is designed to not only detect ransomware but other computer threats as well. As a result, you will get rid of the malware and increase your computer's security in future.

Be aware that .LOL virus removal won't decrypt your files. After the elimination, you can concentrate on the file recovery. Below this article you will find the instructions on how to retrieve your files using verified decryption tools.

3 comments

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.