Virus and Spyware Removal Guides, uninstall instructions

Beijing Ransomware

What is Beijing ransomware?

Beijing is typical ransomware, which encrypts files, appends its extension to the filenames of all encrypted files, and creates a ransom message with instructions about how to contact the developers. Beijing renames encrypted files by appending the ".beijing" extension to filenames.

For example, "1.jpg" is renamed to "1.jpg.beijing", "2.jpg" to "2.jpg.beijing", and so on. Beijing creates a ransom message (within the "!RECOVER.txt" text file) in all folders that contain encrypted files. This ransomware is another variant of LeakTheMall ransomware.

   
Montana Ransomware

What is the Montana ransomware?

Montana is a variant of LeakTheMall ransomware. This malicious program is designed to encrypt data and demand payment for decryption. During the encryption process, all affected files are appended with the ".montana" extension. For example, a file originally named something like "1.jpg" would appear as "1.jpg.montana" following encryption.

Once this process is complete, ransom messages in "!HELP!.txt" files are dropped into compromised folders.

   
Alltopposts.com Ads

What is alltopposts[.]com?

alltopposts[.]com and similar web pages should never be trusted. Typically, they are opened by browsers that have potentially unwanted applications (PUAs) installed on them, through deceptive ads, or other untrusted pages. In any case, users do not often open/visit these sites intentionally.

Some examples of other web pages similar to alltopposts[.]com are reightpainf[.]top, content4you[.]net and mylot[.]com. Note that PUAs promote dubious websites, serve ads, and collect data.

   
PDF Mighty Unwanted Application

What is PDF Mighty?

PDF Mighty is rogue software endorsed as a tool capable of converting files (e.g. Microsoft Office documents) into the PDF format, however, due to the dubious methods used to proliferate this application, it is classified as a Potentially Unwanted Application (PUA).

One of the primary purposes of PDF Mighty is to promote the SearchMighty browser hijacker. Furthermore, PUAs often have undisclosed, dangerous capabilities and the advertised features are rarely operational.

   
FileConvertGiant Unwated Application

What is FileConvertGiant?

FileConvertGiant is advertised as the most comprehensive file converter that works with a wide range of file types including various documents, archive files, spreadsheets, and audio and video files. In fact, this app is categorized as potentially unwanted application (PUA) because of the method that is used to distribute the software.

The installer for FileConvertGiant also includes an offer to install MySearchGiant, a browser hijacker (another PUA). You are advised not to download or install FileConvertGiant, MySearchGiant, or any other PUAs.

   
LeakTheMall Ransomware

What is LeakTheMall ransomware?

Discovered by Amigo-A, LeakTheMall is a ransomware-type malicious program. Systems infected with this malware have their data encrypted and users receive ransom demands for decryption tools. During the encryption process, files are appended with the ".crypt" extension.

For example, a file originally named something like "1.jpg" would appear as "1.jpg.crypt", "2.jpg" as "2.jpg.crypt", and so on. After this process is complete, ransom-demand messages in "ReadMe.txt" files are dropped into affected folders.

   
Clay Ransomware

What is Clay?

Discovered by xiaopao, Clay encrypts files and provides instructions about how to pay a ransom, contact the developers, and various other details. Unlike other malware of this type, Clay does not rename encrypted files or append any extension to the compromised filenames, however, it displays a ransom message in a pop-up window.

   
PromoteQueue Adware (Mac)

What is PromoteQueue?

PromoteQueue is a rogue application classified as adware and also possessing browser hijacker traits. Following successful infiltration, PromoteQueue runs intrusive ad campaigns and makes modifications to browser settings to promote fake search engines.

Most adware-type apps and browser hijackers monitor users' browsing activity, and it is likely that this app does so as well. Due to the dubious techniques used to proliferate PromoteQueue, it is also classified as a Potentially Unwanted Application (PUA).

   
LiveSportSearch Browser Hijacker

What is LiveSportSearch?

LiveSportSearch hijacks browsers by changing certain settings to livesportsearch.com (the address of a fake search engine). This browser hijacker also collects browsing-related information. Frequently, users download and install apps such as LiveSportSearch inadvertently and, therefore, they are categorized as potentially unwanted applications (PUAs).

   
TG33 Ransomware

What is TG33 ransomware?

TG33 is malicious software belonging to the Matrix ransomware family. It is designed to encrypt data and demand ransoms for decryption.

During the encryption process, all affected files are renamed following this pattern: "[TomGate33@criptext.com].[random_string].TG33", which consists of the cyber criminals' email address, a random character string, and the ".TG33" extension.

For example, a file originally named "1.jpg" would appear as something similar to "[TomGate33@criptext.com].nMN9Poie-CaWYsbTD.TG33" following encryption. After this process is complete, ransom messages within "TG33_INFO.rtf" files are dropped into compromised folders.

   

Page 1025 of 2126

<< Start < Prev 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal