Nulltica crypto-malware links to Polski ransomware?

Nulltica virus happens to be just another file-encrypting threat based on the infamous HiddenTear ransomware.[1] As common for this type of ransomware, it attaches .lock file extension and launches its GUI called as “Information.”
The ransom note instructs you to create a bitcoin wallet, pay 50 USD, and copy the code of the wallet in the indicated decryption box. Interestingly, after the supposed payment, the files will not revert to its original form but acquire another extension – .unlock.
However, there is no certainty that after this procedure, the data will be fully decoded. Therefore, this crypto-virus has hints to the malware released last year – Polski ransomware.[2]. The source code also refers that the malware aims to steal Facebook login data. While, there is no specific information about this malware detected on the social network, it would be better to stay vigilant.
The malware also tends to disguise under important.exe, though it is possible that it might disguise under alternative name. If you noticed its files, it would be better to reboot the system and remove Nulltica as soon as possible. FortectIntego or MalwarebytesMalwarebytes might be of assistance in this situation.
Facebook targeted again?
It seems that along with a new academic year, the season for spam season in Facebook has begun as well. Recently, it has suffered a several consecutive series of Facebook Message[3] and video virus assaults. Unfortunately, users still fall for the same trick by clicking on a video message containing their profile picture.
The ability to acquire Facebook login data makes sense as hijacked accounts are expected to be the main catalyst factor in conducting a malspam campaign. Therefore, it is another reason to perform Nulltica removal as soon as possible.
Transmission peculiarities
Since the crypto malware functions as Trojan.Ransom.Nulltica, Gen:Variant.Strictor.145532 (B),
Trojan-Ransom.Win32.Blocker.kgwu, etc, it is likely to make use of abandoned and faulty apps. Note that you might accelerate Nulltica hijack if you carelessly open a file attachment sent supposedly from an official institution. Be wary that the latest variation of Locky, Lukitus, has started its new campaign recently.
In addition, you should be cautious while surfing the Web as cyber criminals place exploit kits which facilitate the infection with ransomware process. Now let us discuss options how you can get rid of the malware from your Windows OS.
Delete Nulltica ransomware
When it comes to battling crypto-malware, you will need time and patience. Manual Nulltica removal might be futile unless you are an IT specialist.
Install an anti-spyware utility and start the elimination process. In case you are cannot launch the app, restart the system in safe mode and remove Nulltica virus. Below the instructions, you might find some useful tips how to recover the data with alternative tools.
Was this guide helpful?
Be the first to comment