Virus and Spyware Removal Guides, uninstall instructions

IMI Ransomware

What is IMI?

Discovered by Jakub Kroustek, IMI belongs to a family of ransomware-type programs called Dharma. Like many other programs of this type, IMI is designed to encrypt data and keep it inaccessible unless victims pay a ransom. It renames all encrypted files by appending the victim's ID number, email address of its developers, and ".IMI" extension to their filenames.

For example, it renames "1.jpg" to "1.jpg.id-1E857D00.[imdecrypt@aol.com].IMI", and so on. IMI also displays a ransom message in a pop-up window and creates a text file named "FILES ENCRYPTED.txt".

   
Androidrecaptcha.info Ads

What is androidrecaptcha[.]info?

androidrecaptcha[.]info is similar to other websites, such as clicktube7[.]com, tatilyerlerim[.]com, orbetterpositiesa[.]info, and many more.

Generally, people who visit them are redirected to other dubious websites, or they load deceptive content. Most people do not visit these sites intentionally - typically, they are opened by potentially unwanted applications (PUAs) installed on browsers and/or operating systems. PUAs open rogue web pages, gather browsing data and serve dubious advertisements.

   
Landslide Search Browser Hijacker

What is Landslide Search?

Landslide Search is a rogue application advertised as a tool supposedly capable of providing improved search results. In fact, it operates as a browser hijacker and modifies browsers to promote a fake search engine (search.landslidesearch.com). Additionally, this app monitors users' browsing activity.

Most users install Landslide Search inadvertently, and therefore it is also classified as a Potentially Unwanted Application (PUA).

   
Clicktube7.com Ads

What is clicktube7[.]com?

clicktube7[.]com is a rogue website that is very similar to many other websites of this type, such as orbetterpositiesa[.]info, nlighttomayorw[.]info, new-incoming[.]email, and so on. When opened, it displays dubious content or causes redirects to other dubious websites.

In any case, few people visit clicktube7[.]com intentionally - redirects to untrustworthy websites are usually due to potentially unwanted applications (PUAs) installed on browsers. Most apps of this type also deliver intrusive ads and record browsing-related data.

   
Tatilyerlerim.com Ads

What is tatilyerlerim[.]com?

tatilyerlerim[.]com is a rogue website sharing many common traits with orbetterpositiesa.infoyourlifedate.comnew-incoming.email and countless others. It operates by presenting visitors with highly dubious content and causing redirects to other untrustworthy and malicious web pages.

Few users enter tatilyerlerim[.]com intentionally - typically they are redirected by intrusive ads or Potentially Unwanted Applications (PUAs) already present on the device. These apps generate redirects, run intrusive advertisement campaigns and monitor users' browsing activity.

   
Vpnshieldplus2.com POP-UP Scam (Mac)

What is vpnshieldplus2[.]com?

Like countless others available online, vpnshieldplus2[.]com is a deceptive/scam website. It endorses untrusted software through the use of scare tactics. Usually, these web pages operate by warning that devices are infected and offering products, allegedly capable of eliminating the threat.

No site can detect threats/issues present on systems. Any that make similar claims cannot be trusted, and the same applies to content promoted on them.

In fact, any such content is often bogus, nonoperational, and possibly harmful. Few users access these scam web pages intentionally - most are redirected by intrusive ads or by Potentially Unwanted Applications (PUAs) already infiltrated into the device.

   
Rooster865qqZ Ransomware

What is Rooster865qqZ?

Discovered by Raby, Rooster865qqZ belongs to the Maoloa ransomware family. It encrypts files and appends the ".Rooster865qqZ" extension to filenames. For example, "1.jpg" becomes "1.jpg.Rooster865qqZ", and so on.

Furthermore, Rooster865qqZ displays a pop-up window, a ransom message launched from the "HOW TO BACK YOUR FILES.exe" executable file.

   
Merl Ransomware

What is Merl?

Merl is malicious software belonging to the STOP/Djvu ransomware family. This malware operates by encrypting data and demanding ransom payments for decryption.

During the encryption process, all files are renamed with the ".merl" extension. For example, "1.jpg" would appear as "1.jpg.merl", and so on for all affected files. Once this process is finished, Merl creates a text file named "_readme.txt" and stores it on the desktop.

   
Orbetterpositiesa.info Ads

What is orbetterpositiesa[.]info?

orbetterpositiesa[.]info is a rogue website that causes redirects to other untrustworthy sites or displays dubious content. It is very similar to many other pages of this kind such as nlighttomayorw[.]info, new-incoming[.]email, and tirsmile[.]pro.

Few people visit orbetterpositiesa[.]info (or other, similar pages) intentionally - they are opened by potentially unwanted applications (PUAs) installed on the browser and/or operating system. Apps of this type usually gather browsing data and deliver advertisements.

   
Yourlifedate.com Ads

What is yourlifedate[.]com?

Similar to nlighttomayorw.infonew-incoming.emailritteddelibacyca.info and many others, yourlifedate[.]com is a rogue website. It presents users with dubious content and/or redirects them to other untrustworthy and malicious websites.

Few visitors enter yourlifedate[.]com willingly - most are redirected by intrusive ads or Potentially Unwanted Applications (PUAs) already present on the system.

Note that these apps do not require express permission to be installed onto devices. After successful infiltration, however, PUAs generate redirects, deliver intrusive advertisements and record browsing-related information.

   

Page 1303 of 2150

<< Start < Prev 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal