Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Sep 2017

How to remove Nulltica ransomware virus

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Olivia Morelli · Ransomware analyst

Nulltica crypto-malware links to Polski ransomware?

The image of Nulltica GUI

Nulltica virus happens to be just another file-encrypting threat based on the infamous HiddenTear ransomware.[1] As common for this type of ransomware, it attaches .lock file extension and launches its GUI called as “Information.”

The ransom note instructs you to create a bitcoin wallet, pay 50 USD, and copy the code of the wallet in the indicated decryption box. Interestingly, after the supposed payment, the files will not revert to its original form but acquire another extension – .unlock.

However, there is no certainty that after this procedure, the data will be fully decoded. Therefore, this crypto-virus has hints to the malware released last year – Polski ransomware.[2]. The source code also refers that the malware aims to steal Facebook login data. While, there is no specific information about this malware detected on the social network, it would be better to stay vigilant.

The malware also tends to disguise under important.exe, though it is possible that it might disguise under alternative name. If you noticed its files, it would be better to reboot the system and remove Nulltica as soon as possible. FortectIntego or MalwarebytesMalwarebytes might be of assistance in this situation.

Facebook targeted again?

It seems that along with a new academic year, the season for spam season in Facebook has begun as well. Recently, it has suffered a several consecutive series of Facebook Message[3] and video virus assaults. Unfortunately, users still fall for the same trick by clicking on a video message containing their profile picture.

The ability to acquire Facebook login data makes sense as hijacked accounts are expected to be the main catalyst factor in conducting a malspam campaign. Therefore, it is another reason to perform Nulltica removal as soon as possible.The picture illustrating Nulltica virus

Transmission peculiarities

Since the crypto malware functions as Trojan.Ransom.Nulltica, Gen:Variant.Strictor.145532 (B),
Trojan-Ransom.Win32.Blocker.kgwu, etc, it is likely to make use of abandoned and faulty apps. Note that you might accelerate Nulltica hijack if you carelessly open a file attachment sent supposedly from an official institution. Be wary that the latest variation of Locky, Lukitus, has started its new campaign recently.

In addition, you should be cautious while surfing the Web as cyber criminals place exploit kits which facilitate the infection with ransomware process. Now let us discuss options how you can get rid of the malware from your Windows OS.

Delete Nulltica ransomware

When it comes to battling crypto-malware, you will need time and patience. Manual Nulltica removal might be futile unless you are an IT specialist.

Install an anti-spyware utility and start the elimination process. In case you are cannot launch the app, restart the system in safe mode and remove Nulltica virus. Below the instructions, you might find some useful tips how to recover the data with alternative tools.

Be the first to comment

Spyware news
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.