Virus and Spyware Removal Guides, uninstall instructions

Iwantmyfiles Ransomware

What is iwantmyfiles?

Discovered by security researcher, Jakub Kroustek, iwantmyfiles is a ransomware-type virus that stealthily encrypts various data.

Unlike other ransomware, iwantmyfiles does not rename or append extensions to encrypted files. Following successful encryption, the virus opens a pop-up window and creates a text file ("READ_ME.txt"), placing it on the desktop. Both contain identical ransom-demand messages.

   
Lockify Ransomware

What is Lockify?

First discovered by malware security researcher, Michael Gillespie, Lockify is a virus based on an open source ransomware project called Hidden Tear.

Once infiltrated, Lockify encrypts various data using AES cryptography. This malware appends filenames with the ".lockify" extension (for example, "sample.jpg" is renamed to "sample.jpg.lockify"). After successfully encrypting files, Lockify places a "readme.HTA" file in each folder containing encrypted data.

   
DirectionsOnline Toolbar

What is hp.myway.com?

Developed by Mindspark Interactive Network, DirectionsOnline is a deceptive application that supposedly allows users to use GPS functions.

Judging on appearance alone, DirectionsOnline might seem legitimate and useful, however, this app is categorized as a potentially unwanted program (PUP) and a browser hijacker. There are three main reasons for these negative associations: 1) stealth installation without consent; 2) modification of web browser settings, and; 3) tracking of Internet browsing activity.

   
PEC 2017 Ransomware

What is PEC 2017?

Discovered by xXToffeeXx, PEC 2017 is a ransomware-type virus distributed via spam emails containing a fake CV attachment, which installs malware by employing a CVE-2017-0199 exploit. Once infiltrated, PEC 2017 encrypts various data using AES-256 cryptography.

During encryption, PEC 2017 appends the ".pec" extension to the name of each compromised file. The virus then creates an HTML file ("AIUTO_COME_DECIFRARE_FILE.html"), placing it in each folder containing encrypted files.

   
WiseFolderLock Adware

What is WiseFolderLock?

WiseFolderLock is a deceptive application that supposedly allows users to lock various folders. Judging on appearance alone, WiseFolderLock may appear legitimate and useful, however, this app infiltrates systems without consent.

Furthermore, it delivers intrusive online advertisements and records information relating to users' Internet browsing activity. For these reasons, WiseFolderLock is categorized as a potentially unwanted program (PUP) and a browser hijacker.

   
UpdateAdmin Adware

What is UpdateAdmin?

UpdateAdmin is a rogue application claiming to provide various useful features. Although this functionality may seem legitimate, UpdateAdmin is categorized as a potentially unwanted program (PUP) or adware.

One of the reasons for these negative associations is a deceptive software marketing method called 'bundling' used to install UpdateAdmin on systems without users' permission. Bundling is a way to stealthily distribute third party applications together with regular software.

Therefore, users often install this adware inadvertently with free software downloadable on freeware download websites. After infiltration, UpdateAdmin generates various intrusive online advertisements (banner, pop-up, etc.) that often redirect to bogus websites, thereby exposing your computer to risk of infection.

   
Googlescan.ru Redirect

What is googlescan.ru?

Developers present googlescan.ru as a 'high-experience' search engine that enhances the Internet browsing experience by generating improved results. Judging on appearance alone, googlescan.ru barely differs from Bing, Yahoo, Google, and other legitimate search engines.

Therefore, many users believe that this rogue website is legitimate. In fact, developers promote it by employing deceptive download/installation set-ups designed to modify browser settings without consent. Furthermore, googlescan.ru continually records various information relating to users' Internet browsing activity.

   
DownloadManagerNow Toolbar

What is hp.myway.com?

DownloadManagerNow is a deceptive application developed by Mindspark Interactive Network. By claiming to ease the data download process, DownloadManagerNow attempts to give the impression of legitimacy, however, this app is categorized as a potentially unwanted program (PUP) and a browser hijacker.

There are three main reasons for these negative associations: 1) installation without consent; 2) modification of web browser settings, and; 3) tracking of users' Internet browsing activity.

   
Mordor Ransomware

What is Mordor?

Mordor is a ransomware-type virus discovered by MalwareHunterTeam. This malware is a based on an open source ransomware project called Hidden Tear. Cyber criminals edit Hidden Tear source code and attempt to generate revenue by providing Mordor as a RaaS (Ransomware-as-a-Service).

Mordor is distributed using spam emails that contain malicious Javascript attachments designed to run the ransomware. Once infiltrated, Mordor encrypts various files and appends the ".mordor" extension to each of them. The virus then creates an HTML file ("READ_ME.html"), placing it on the desktop.

   
Restore@protonmail.ch Ransomware

What is restore@protonmail.ch?

Restore@protonmail.ch is an new version of Fantom ransomware. Once infiltrated, restore@protonmail.ch encrypts files using asymmetric cryptography. As with Fantom, restore@protonmail.ch also displays a fake Windows Update screen during file encryption.

Furthermore, this ransomware renames encrypted files using the "8_random_characters.locked" pattern (e.g., "sample.jpg" might be renamed to "MS5qcGc=.locked").

The desktop wallpaper is then modified and two files created: 1) an executable file ("READ_ME!.exe"), which opens a ransom-demand pop-up, and; 2) a random file ("16_random_characters.locked", content unknown). Both files are placed in every existing folder.

   

Page 1745 of 2134

<< Start < Prev 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal