Virus and Spyware Removal Guides, uninstall instructions

KratosCrypt Ransomware

What is KratosCrypt?

KratosCrypt is a ransomware virus that stealthily infiltrates computers, encrypting files using an asymmetric AES encryption algorithm.

This virus appends the name of each encrypted file with a .kratos extension. Following successful encryption, KratosCrypt creates a README_ALL.html file and places it in each folder containing encrypted files. This file contains a ransom-demand message.

   
NegozI Ransomware

What is NegozI?

NegozI is a ransomware-type virus similar to Sanction and RemindMe. Once infiltrated, NegozI encrypts various files and adds .evil as an extension to the name of each encrypted file. The following files are then created: decrypt_your_files.txt and decrypt_your_files.html. These are placed in each folder containing encrypted files.

   
Urban-search.com Redirect

What is urban-search.com?

urban-search.com is a fake Internet search engine identical to searchonlineusa.com. Judging on appearance alone, urban-search.com may seem legitimate, however, developers promote this bogus website using dubious software 'installers' that modify Internet browser settings without users' permission.

Furthermore, this bogus site continually gathers various user/system information relating to users' web browsing activity.

   
Music Player Ads

What is Music Player?

Music Player is a potentially unwanted program (PUP) that supposedly allows users to play various audio formats. Initially, this app may seem legitimate and useful, however, research shows that Music Player often infiltrates systems without users’ permission.

Furthermore, this app continually gathers information regarding users' web browsing activity and delivers various intrusive online advertisements. For these reasons, Music Player is classed as adware.

   
Searchonlineusa.com Redirect

What is searchonlineusa.com?

Searchonlineusa.com is a deceptive website that claims to improve the web browsing experience by generating the most relevant search results.

On initial inspection, searchonlineusa.com may seem to be a legitimate site, however, developers promote it using bogus software 'installers' that hijack Internet browsers and stealthily modify their settings. In addition, searchonlineusa.com records various user/system information relating to users' web browsing activity.

   
Dozensearch.com Redirect

What is dozensearch.com?

Dozensearch.com is another fake Internet search engine identical to walasearch.com, newsearch123.com, yessearches.com, and a number of other dubious websites.

On initial inspection, dozensearch.com may seem legitimate, however, dozensearch.com is promoted using rogue software 'installers' designed to modify web browser settings without users' consent. In addition, this fake Internet search engine continually tracks Internet browsing activity.

   
Search.yourspeedtestcenter.com Redirect

What is search.yourspeedtestcenter.com?

Your Speed Test Center is a dubious program that supposedly allows users to test their connection Internet speeds. On initial inspection, Your Speed Test Center may seem to be a legitimate application, however, it is classed as a potentially unwanted program (PUP) and adware.

One of the main reasons for these negative associations is stealth infiltration - Your Speed Test Center often installs without users' permission. In addition, this PUP generates intrusive online advertisements, causes unwanted browser redirects, and gathers various user/system information.

   
UltraCrypter Ransomware [Updated]

What kind of malware is UltraCrypter?

UltraCrypter is an updated version of CryptXXX ransomware. As with CryptXXX, UltraCrypter is distributed using the Angler Exploit Kit. In fact, these viruses are practically identical. UltraCrypter uses an asymmetric RSA-4096 algorithm to encrypt many files stored on the infiltrated system.

Therefore, public (encryption) and private (decryption) keys are generated and stored on remote servers. Decryption without the private key is impossible. Furthermore, UltraCrypter adds a .cryp1, .crypz, or .crypt extension (some newer variants add 5 random symbols or doesn't add any extension) to the name of each encrypted file.

Following successful encryption, UltraCrypter generates three different files: .bmp (which is also set as the desktop wallpaper); .txt, and; .html. These files have an identical naming format - [Victim’s personal ID].

   
Kozy.Jozy Ransomware

What is Kozy.Jozy?

Kozy.Jozy is a ransomware-type virus that encrypts files using the RSA-2048 algorithm. During encryption, Kozy.Jozy appends the name of each encrypted file with the .31392E30362E32303136_(number from 0 to 20)_(4 or 5 random numbers) extension.

Following successful encryption, Kozy.Jozy opens a .jpg file that contains a message encouraging users to contact developers of Kozy.Jozy.

   
Incosic.com Redirect

What is incosic.com?

incosic.com is another fake Internet search engine identical to yessearches.com, maniihome.com, searchvvay.com, and many other websites. By falsely claiming to enhance users' web browsing experience by generating the most relevant search results, incosic.com often tricks users into believing that this site is legitimate.

Be aware, however, that this site is promoted using dubious software 'installers'. Furthermore, incosic.com continually records various information relating to users' web browsing activity.

   

Page 1841 of 2132

<< Start < Prev 1841 1842 1843 1844 1845 1846 1847 1848 1849 1850 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal