Virus and Spyware Removal Guides, uninstall instructions

Browec Ransomware

What is Browec?

Discovered by Michael Gillespie, Browec is yet another ransomware virus that belongs to the Djvu malware family. As with its predecessor, Browec encrypts stored data (thereby making it unusable) and adds the ".browec" extension to each filename. For example, "1.jpg" is renamed to "1.jpg.browec". Browec also stores a text file ("_readme.txt") in each folder.

   
Apple.com-clear.live POP-UP Scam (Mac)

What is "apple.com-clear[.]live"?

apple.com-clear[.]live is a scam website that is used to promote the Cleanup My-Mac application. This website displays a fake virus alert and encourages users to remove 'computer infections' by downloading and installing the aforementioned potentially unwanted application (PUA).

Generally, people do not visit apple.com-clear.live intentionally - they are redirected to it by PUAs that are already installed on their computers or web browsers. Most PUAs cause redirects to scams or other dubious sites, feed users with advertisements, and gather data relating to browsing habits.

   
Vercallactont.com POP-UP Redirect

What is vercallactont[.]com?

vercallactont[.]com is one of many, virtually identical, rogue websites. Other examples are butitereventwil[.]info, refrebrepheon[.]info, and ketintontrat[.]info. This site causes redirects to other dubious, deceptive websites or displays dubious content.

Generally, users arrive at vercallactont[.]com unintentionally - potentially unwanted applications (PUAs) installed on their systems force redirects to it. Typically, people install PUAs inadvertently. Furthermore, when installed, they deliver intrusive ads and gather data relating to users' browsing habits.

   
Youtubnow.com Virus

What is youtubnow[.]com?

The youtubnow[.]com websites allows users to download videos from YouTube in the .mp4 video format, or audio only in .mp3 or .webm formats. This service can be used via the website and a desktop application. Note that youtubnow[.]com is not malicious, however, downloading videos from YouTube is illegal.

Furthermore, this page uses advertising networks. Therefore, it displays pop-up and other ads, opens dubious web pages, and causes redirects that might lead to download or installation of various potentially unwanted applications (PUAs).

   
Hiding Taxes Email Scam

What is "Hiding Taxes"?

The "Hiding Taxes" scam is proliferated by sending emails to many people. Scammers behind it attempt to trick people into sending money (cryptocurrency). They threaten to proliferate information about the supposed recipient's tax evasion activity. In fact, all statements in this scam are false. Never trust these emails.

   
LOVE Ransomware

What is LOVE?

Discovered by Jakub Kroustek and Belonging to the Dharma malware family, LOVE is a malicious program that cyber criminals (developers) use to block access to data. This ransomware-type program is used to encrypt files and prevent access to them unless a ransom is paid.

 This ransomware renames encrypted files by adding an extension which contains the victim's ID, an email address for contacting cyber criminals, and the name of the ransomware.

For example, "1.jpg" might be renamed to a filename such as "1.jpg.id-1E857D00.[seeyoubro@tutanota.com].LOVE". It also creates a short ransom message with the "FILES ENCRYPTED.txt" text file and displays an extended version of this in a pop-up window.

   
Guvara Ransomware

What is Guvara?

Discovered by Michael Gillespie, Guvara is a malicious program that belongs to the Djvu ransomware family. As with most ransomware, Guvara encrypts data and keeps it that state until a ransom is paid. Guvara renames each encrypted file by adding the ".guvara" extension.

For example, "1.jpg" becomes "1.jpg.guvara". It also stores a text file ("_readme.txt") containing a ransom message in every folder that contains encrypted files.

   
French101 Ransomware

What is French101?

Discovered by security researcher Petrovic, French101 is malicious software categorized as ransomware. Developers use it to block access to users' files by encryption. To regain access to their data, victims are encouraged to pay a ransom. Like most ransomware-type programs, it renames encrypted files by adding its own extension.

In this case, it changes the name of the file to a random string and adds the ".french101" extension. For example, "1.jpg" might be renamed to a filename such as "bvMqp5yz0AL98A.french101". French101 also creates a ransom message within the "HOW TO RECOVER ENCRYPTED FILES.TXT" text file.

   
Spi Virus (Mac)

What is Spi?

Spi is an adware-type app that injects various advertisements into legitimate websites such as Google. In summary, it serves unsuspecting users with advertisements when they search. When installed, Spi also displays a number of pop-up windows asking people to provide a Mac user-account username and password.

   
Searchmedia.online Redirect

What is searchmedia.online?

searchmedia.online is a fake search engine that is promoted useful and capable of providing fast searches, accurate results, and so on.

In fact, this site is promoted using a browser hijacker, a potentially unwanted application (PUA) called Movie Browsing. This app promotes a number of other URLS including movies.searchmedia.online and music.searchmedia.online. Note that PUAs usually gather browsing-related data and change browser settings.

   

Page 1417 of 2106

<< Start < Prev 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal