Do you know what Proticc Ransomware is?
There are some extremely harmful threats and some milder ones. Proticc Ransomware belongs to the latter group. Ransomware infections are used as hackers’ tools to obtain money from users, but this particular malicious application should not cause you many problems because it, simply, does not work as it should, which suggests us that it is still in development or it is just a school project. Even though this malicious application is not a typical ransomware infection, it does not mean that you can let it stay active on your computer because it might get an update from its C&C server and then lock all your personal files. To prevent this from happening, remove the launcher of the ransomware infection as soon as possible. If you cannot locate it, it would be best to remove all files downloaded recently from the web. The ransomware infection displays a window with a ransom note even though, technically, it does not encrypt any files, so you will have to close it first before you could erase Proticc Ransomware. No worries, it will not be something extremely challenging.
Specialists have found two versions of Proticc Ransomware. They look very similar, but they slightly differ from each other. The main differences are these: one of the versions has a countdown timer and both versions display different ransom notes. The first version of the ransomware infection claims that all files have been “safely encrypted,” and only a private key can unlock them, whereas the second one contains a similar message expressed in different words. The latter version also gives only 1 hour to get the decryptor and decrypt locked files. It is very likely that none of your files have been affected because this malicious application only targets .png, .jpg, and .jpeg files in one location – %USERPROFILE%\Desktop\lol. Most likely, you do not even have this folder on your Desktop. Even if you find your files with the added .lol extension, you could fix them by simply renaming them back. You should also try to click the Decrypt button if the version you have encountered has it. As mentioned at the beginning of this article, the ransomware infection does not really encrypt users’ files. As a consequence, there is no need to purchase a decryption tool. Unfortunately, we cannot promise that this infection will act the same in the future.
Proticc Ransomware screenshot
Scroll down for full removal instructions
The ransomware infection was not spread actively at the time of analysis, but this might change very soon, so you should know how ransomware infections are usually distributed so that you could prevent it from entering the system easier. This knowledge will also help you to protect the system against other (even more harmful) malicious applications. Specialists say that Proticc Ransomware should be mainly distributed via malicious spam email attachments, but it might be illegally dropped on the system by cyber criminals if a user’s RDP connection gets hacked. Last but not least, users might download malicious applications from P2P websites thinking that the program they have decided to download is legitimate and useful. Unfortunately, it is usually too late when they find out that they have downloaded malicious software. You must be more cautious yourself to prevent malware from entering your computer, but if you do not think that you could protect your system against bad software all alone, download a reliable antimalware scanner and install it on your PC.
Proticc Ransomware does not have a point of execution, i.e. it will not open a window on your Desktop again automatically after the system restart, but you will definitely find it on your screen if you open its launcher. Therefore, it would be best that you fully erase the ransomware infection. Feel free to use the manual removal guide you will find below this article if you have never deleted any malicious application in your life.
How to remove Proticc Ransomware
- Tap Ctrl+Shift+Esc.
- Click Processes.
- Locate the suspicious process that could belong to Proticc Ransomware and kill it to close the window opened on your Desktop.
- Remove all recently downloaded suspicious files.
- Empty Recycle Bin.
In non-techie terms:
Proticc Ransomware is known to be a ransomware infection, but it is not as dangerous as some other infections categorized as ransomware because it does not encrypt any files on victims’ computers. Instead, it only renames them and appends .lol. Consequently, specialists say that this infection does not work properly. There are no guarantees that it will not be updated by cyber criminals, so if you have encountered this threat, its removal is what you should do in the first place.
