Virus and Spyware Removal Guides, uninstall instructions

Your Apple iPhone Is Severely Damaged by (6) Viruses! POP-UP Scam (Mac)

What is "Your Apple iPhone is severely damaged by (6) viruses!"?

This scam website tricks visitors into downloading and installing various dubious applications such as fake VPN (Virtual Private Network) clients and other app types. The site claims that the device (iPhone) is infected with viruses and encourages visitors to remove them with an application.

At the time of research, it offered download of an app called "Free App". We advise against downloading or installing software that is advertised on web pages such as this, or other deceptive, unofficial sites.

   
DMR64 Ransomware

What is DMR64?

Discovered by MalwareHunterTeam, DMR64 is a malicious program categorized as ransomware. It operates by encrypting the data of infected devices and demanding ransom payments for decryption. During the encryption process, all affected files are renamed using the following pattern: "[id=victim's_ID]original_filename.DMR64".

The pattern comprises a string of characters with the unique ID, original filename and ".DMR64" extension. For example, "1.jpg" might appear as something similar to "[id=1E857D00]1.jpg.DMR64", and so on for all compromised files. After this process is complete, DMR64 creates an HTML application ("!!! READ THIS !!!.hta"), which contains the ransom message.

   
MessengerDeck Adware

What is MessengerDeck?

MessengerDeck is software classified as adware. It is promoted as an application for easy access to Facebook Messenger on a PC desktop.

In fact, it operates by running intrusive advertisement campaigns. Therefore, MessengerDeck simply delivers various unwanted and even harmful ads. Since most users install this app inadvertently, it is also categorized as a Potentially Unwanted Application (PUA).

   
Mainsiteofupgradenow.best POP-UP Scam (Mac)

What is mainsiteofupgradenow[.]best?

mainsiteofupgradenow[.]best is a scam website and practically identical to mainsourceofupdate[.]best. It is designed to endorse a fake Adobe Flash Player updater. Visitors to this site are warned that the aforementioned plug-in is outdated and recommends an update.

Content promoted on deceptive webpages is often untrustworthy and malicious. Rogue updaters are commonly used to spread Potentially Unwanted Applications (PUAs) such as fake system cleaners and optimizers, browser hijackers, adware, and even malware.

Most users enter mainsiteofupgradenow[.]best unintentionally, since they are redirected by intrusive advertisements or PUAs already infiltrated into the device.

   
Free-girls-vids.com Ads

What is free-girls-vids[.]com?

free-girls-vids[.]com is a dubious website, which is usually opened by browsers that have potentially unwanted applications (PUAs) installed on them. This web page redirects visitors to other untrustworthy sites or loads dubious content. It is very similar to horny-vid[.]com, rex-news1[.]club, pushpush[.]net and many other web pages.

Generally, people download and install apps that open these sites unintentionally. When installed, they usually gather information relating to users' browsing activities and/or display intrusive advertisements.

   
Horny-vid.com Ads

What is horny-vid[.]com?

horny-vid[.]com is a rogue website. Like many other web pages of this type (such as rex-news1[.]club, pushpush[.]net, nerdailingcurv[.]com, etc.), horny-vid[.]com redirects people to various other untrustworthy sites, or loads dubious content.

Visitors do not generally open this site intentionally - in most cases, they are opened by Potentially Unwanted Applications (PUAs) installed on browsers and/or computers. Furthermore, apps of this type usually gather browsing data and display intrusive ads.

   
Ultimate-captcha.com Ads

What is ultimate-captcha[.]com?

If visited, ultimate-captcha[.]com loads dubious content or leads to other untrustworthy websites. Many other websites have identical behavior. Some examples are rex-news1[.]club, pushpush[.]net and nerdailingcurv[.]com. In most cases, they are opened by browsers with Potentially Unwanted Applications (PUAs) installed on them.

I.e., people do not usually visit these web pages intentionally. Furthermore, PUAs force browsers to open untrustworthy sites such as ultimate-captcha[.]com, serve advertisements and collect information relating to browsing habits of their users.

   
Mainsourceofupdate.best POP-UP Scam (Mac)

What is mainsourceofupdate[.]best?

mainsourceofupdate[.]best is a deceptive/scam web page, which claims that the visitor's Adobe Flash Player is outdated. It also endorses a fake Flash updater. These rogue updaters are used to proliferate a wide variety of untrustworthy and malicious content.

Few users access mainsourceofupdate[.]best intentionally, since most are redirected to this site by intrusive advertisements or Potentially Unwanted Applications (PUAs) already infiltrated into the system.

   
ConvertMyFile Search Browser Hijacker

What is ConvertMyFile Search?

ConvertMyFile Search is a browser hijacker, which is advertised as a tool for quick access to online file format conversion services. It operates by modifying browsers to promote a fake search engine (services.convertmyfile-svc.org). The updated variant of this browser hijacker promotes search.convertmyfiletab-nt.org fake search engine.

Note that ConvertMyFile Search also monitors browsing activity and gathers personal data. Since most users install this program inadvertently, it is additionally classified as a Potentially Unwanted Application (PUA).

   
Anchor_DNS Malware

What is Anchor_DNS?

Anchor_DNS is a malicious program associated with another malware infection called TrickBot. It operates as a 'backdoor', which is used on high-profile targets. Anchor_DNS communicates with Command-and-Control (C2) servers over DNS using the DNS Tunneling technique.

In this way, Anchor_DNS can receive commands, transfer data and download additional malware or other unwanted software. It can also avoid detection by certain security suites.

   

Page 1288 of 2139

<< Start < Prev 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal