Virus and Spyware Removal Guides, uninstall instructions

Auto Ransomware

What kind of malware is Auto?

While examining malware samples submitted to the VirusTotal website, we discovered a ransomware variant dubbed Auto. This ransomware is identical to Septwolves, Wanqu, Axxes, and many other ransomware variants. Auto encrypts files and two ransom notes ("RESTORE_FILES_INFO.hta" and "RESTORE_FILES_INFO.txt" files).

Also, Auto ransomware appends the ".auto" extension to filenames. For instance, it renames "1.jpg" to "", "2.png" to "", and so forth.

Paid/Unpaid Invoice Email Scam

What kind of scam is "Paid/Unpaid Invoice"?

After reviewing the email, we have determined that it is a phishing attempt by scammers seeking to obtain sensitive information. The email appears to be about an invoice, but it is actually an elaborate hoax, complete with a bogus HTML file attachment. Recipients should not engage with this email and treat it as spam.

Ice Breaker Malware

What is Ice Breaker?

Ice Breaker is a backdoor-type malware written in Node.js. Campaigns involving this malicious program were first identified in 2022 by Security Joes. These attacks targeted the gaming and gambling industries and were particularly recognizable due to the social engineering techniques employed by the cyber criminals.

At the time of writing, the threat actors behind Ice Breaker campaigns are not identified as belonging to a specific hacker group or geographical region. However, there is evidence suggesting that these criminals are not native English speakers.

Foundation For Humanitarian Work Email Scam

What kind of scam is "Foundation For Humanitarian Work"?

We have examined this email and determined that it is a typical inheritance scam. Usually, scammers send such emails to trick recipients into parting with their money and (or) sharing their credit card details or other sensitive information. Emails of this type should be ignored. Ads

What kind of page is news-wemipo[.]cc?

While investigating dubious websites, our research team discovered the news-wemipo[.]cc rogue page. It pushes browser notification spam by using adult-themed clickbait. Additionally, news-wemipo[.]cc can redirect users to other (likely untrustworthy/malicious) sites.

Visitors to rogue webpages typically access them through redirects caused by sites that use questionable advertising networks.

Lottolore Email Scam

What kind of email is "Lottolore"?

After inspecting this "Lottolore" email, we determined that it is spam. It is presented as a notification regarding a lottery prize that the recipient has won. It must be emphasized that this email is fake and it is not associated with any legitimate lotteries.

DHL Express - AWB & Shipping Doc Email Virus

What kind of email is "DHL Express - AWB & Shipping Doc"?

After inspecting this "DHL Express - AWB & Shipping Doc" email – we determined that it is malspam (malicious spam). The scam letter is presented as a message regarding shipping documentation from DHL Express. It must be emphasized that this email is fake, and it is in no way associated with the actual DHL. The file attached to this mail is designed to infect recipients' systems with malware.

Images Switcher Adware

What kind of application is Images Switcher?

Our team found that the Images Switcher browser extension is an advertising-supported app after conducting a thorough examination. This extension displays intrusive advertisements. Our team discovered Images Switcher on a questionable website. Users often unknowingly download and install (or add) adware to their systems (or browsers).

NEVADA Ransomware

What kind of malware is NEVADA?

NEVADA is the name of ransomware targeting Windows and Linux operating systems. It is written in the Rust programming language. NEVADA encrypts files, appends the ".NEVADA" extension to filenames, and drops its ransom note (the "readme.txt" file) in folders containing encrypted files.

An example of how NEVADA ransomware modifies filenames: it changes "1.jpg" to "1.jpg.NEVADA", "2.doc" to "2.doc.NEVADA", and so forth. Cybercriminals who have developed NEVADA are selling it using the RaaS (Ransomware as a service) model.

Please Find Attached My CV Email Virus

What kind of email is "Please Find Attached My CV"?

After inspecting this "Please Find Attached My CV" email, we determined that it is malspam. This spam letter is presented as a CV submission from a party interested in working for the recipient's company. The file attached to this email is designed to infect devices with the Agent Tesla malware.


Page 2 of 1756

<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
About PCrisk

PCrisk logo

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal