Virus and Spyware Removal Guides, uninstall instructions

Nqix Ransomware

What is Nqix?

Discovered by Jakub Kroustek, Nqix is categorized as ransomware that locks (encrypts) files and displays a ransom message. Nqix is a part of the Dharma ransomware family. When encryption is complete, all encrypted files have a new extension. This ransomware adds the ".nqix" extension, and filenames of renamed files contain an email address plus the victim's ID.

For example, "1.jpg" might be renamed to a filename such as "1.jpg.id-1E857D00.[support@qbmail.biz].nqix". It also creates a text file called "RETURN FILES.txt" and displays a pop-up window.

   
Filerio.in Suspicious Website

What is filerio.in?

filerio[.]in offers a file hosting service. There is nothing wrong with services of this type, however, this particular web page contains rogue ads, causes redirects to other dubious pages, and is used to host software 'cracks' (illegal tools).

To avoid unwanted downloads, installations, redirects to dubious pages and other problems, we recommend that you avoid filerio[.]in and its file hosting service.

   
Clickworker.me Ads

What is clickworker[.]me?

Identical to viralupdatestoday.comcentral-messages.comchecking-in-progress.com, and many others, clickworker[.]me is a rogue site designed to display dubious content and redirect to other dubious websites.

Therefore, users end up visiting clickworker[.]me, since they are redirected by potentially unwanted applications (PUAs) and intrusive advertisements displayed on other rogue sites. PUAs typically infiltrate systems without users’ permission. In addition to causing redirects, they deploy intrusive advertisements and gather sensitive data.

   
.infected Ransomware

What is .infected?

.infected software is used by cyber criminals to blackmail people by forcing them to pay ransoms in return for decryption tools. Programs of this type are known as ransomware, since they encrypt files and make them unusable unless a decryption tool is purchased from cyber criminals (developers of the ransomware).

This ransomware is a part of the Aurora family and was discovered by MalwareHunterTeam. Like most ransomware-type programs, .infected changes the names of encrypted files, in this case, by adding the ".infected" extension. For example, "1.jpg" becomes "1.jpg.infected".

It also creates three ransom message in text files called "@@_FILES_ARE_ENCRYPTED_@@.txt", "@@_HOW_TO_RETURN_DATA_@@.txt", and "@@_RECOVERY_INSTRUCTIONS_@@.txt".

   
Nelasod Ransomware

What is Nelasod?

Nelasod belongs to the Djvu ransomware family and this new version was discovered by Michael Gillespie. Like many other programs that are categorized as ransomware, Nelasod encrypts files stored on the computer and prevents access unless victims decode them via a decryption tool that can only be purchased by the cyber criminals who developed the ransomware.

Nelasod changes filenames of encrypted files by adding the ".nelasod" extension. For example, "1.jpg" becomes "1.jpg.nelasod". It also stores the "_readme.txt" file (a ransom message) in all folders that contain encrypted data.

   
My Classifieds List Pro Browser Hijacker

What is My Classifieds List Pro?

My Classifieds List Pro is yet another rogue app that claims to enhance the browsing experience by allowing users to search directly from the homepage and providing quick access to various popular websites.

Judging on appearance alone, My Classifieds List Pro may seem to be a legitimate and useful application, however, it is categorized as a potentially unwanted application (PUA) and a browser hijacker.

The main reasons for these negative associations are: 1) installation without users' consent; 2) tracking of browsing activity, and; 3) promotion of the search.hmyclassifiedslistpro.com fake search engine.

   
Clickpush.biz Ads

What is clickpush[.]biz?

clickpush[.]biz is yet another rogue website that shares many similarities with allowpush.club, viralupdatestoday.com, central-messages.com, and a number of other rogue sites. The purpose of this website is to feed visitors with dubious content and redirect them to other rogue sites.

Many visitors arrive at clickpush[.]biz inadvertently - they are redirected by potentially unwanted applications (PUAs) or intrusive advertisements encountered on other sites. PUAs infiltrate computers without permission. As well as causing redirects, they deliver intrusive advertisements and gather information relating to browsing activity.

   
Get Maps Quick Browser Hijacker

What is Get Maps Quick?

Identical to Find My Route, Quick Audio Converter Pro, Find Forms Easy, and many others, Get Maps Quick is a deceptive application that supposedly provides access to maps, driving directions, and other similar features. Its appearance suggests that Get Maps Quick is a legitimate program.

In fact, it is categorized as a potentially unwanted application (PUA) and a browser hijacker. Get Maps Quick infiltrates computers without permission, promotes a fake search engine (search.hgetmapsquick.com), and tracks various sensitive data.

   
GozNym Trojan

What is GozNym?

GozNym is malicious software that operates as an online banking trojan. It is a combination of two malicious programs: Gozi ISFB (also known as Ursnif) and Nymaim. GozNym's developers use this malware to steal money from banks, e-commerce platforms, credit unions, and other business accounts.

Like many other trojans, GozNym is stealthy - it infects computers without being detected by installed anti-virus suites. Typically, people or companies who become victims of GozNym suffer financial loss. This and other trojans must be uninstalled immediately.

   
Coupon Club Browser Hijacker

What is Coupon Club?

Coupon Club is a deceptive application that, according to the developers, saves time and money by providing discount coupons for various online shops.

Judging on appearance alone, Coupon Club may seem legitimate and useful, however, it is categorized as a potentially unwanted application (PUA) and a browser hijacker. The reasons for these negative associations are installation without users' consent, promotion of a fake search engine, and tracking of browsing activity.

   

Page 1356 of 2105

<< Start < Prev 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal