Identical to,,, and a number of other sites, is a fake Internet search engine that falsely claims to enhance the Internet browsing experience by generating improved search results.

Many users believe that this site is legitimate, however, is promoted using rogue download/installation set-ups that hijack Internet browsers and stealthily modify various options. In addition, gathers various data relating to users' Internet browsing activity. Redirect

What is is a rogue website claiming to be a legitimate Internet search engine. By falsely claiming to generate improved search results, attempts to trick users into believing that this site is legitimate.

In fact, developers promote via rogue software download and installation set-ups designed to stealthily modify web browser settings without users' consent. Furthermore, this site gathers various data types relating to Internet browsing activity.

Go Ransomware

What is Go?

Go is newly-discovered ransomware that infiltrates systems and encrypts files using AES cryptography. This malware is named after Go - a programming language used to design it. This is the first time a ransomware-type virus is seen in this programming language - most are written using C#, C++, and other professional object-oriented programming languages.

During encryption, Go renames all compromised files by generating a series of random characters and appending the ".enc" extension. For instance, an encrypted file might be renamed to "FBdfg8JKsdg2l11!km.enc", which makes it impossible to identify the original files.

Following successful encryption, Go creates an "Instructions.html" file and places it in each folder containing encrypted files.

Exotic Ransomware

What is Exotic?

Exotic is ransomware that encrypts and renames files using the "[several_random_characters].exotic" pattern. For instance, "sample.jpg" is renamed to "78!bk).exotic". Once files are encrypted, Exotic opens a pop-up message informing victims of the infection. A window is then displayed containing a ransom-demand message.

Windows Defender Has Detected Critically Corrupted File System! Scam

What is Windows Defender has detected Critically Corrupted File System!?

"Windows Defender has detected Critically Corrupted File System!" is a fake error message distributed using various adware-type applications.

This error locks the computer screen and claims that Windows Defender has detected corrupted files. Adware-type applications often infiltrate systems during installation of other programs. Furthermore, these apps continually gather various user/system information, cause unwanted browser redirects, and deliver intrusive online advertisements.

TVPlusNewtab Browser Hijacker

What is TVPlusNewtab?

TVPlusNewtab is a browser hijacker, endorsed as a tool for easy access to movie trailers, TV series and celebrity content. It is also supposedly capable of allowing users to quickly view PDF documents. TVPlusNewtab operates by making modifications to browser settings in order to promote - a fake search engine.

Additionally, this browser hijacker has data tracking abilities, which are used to record information relating to users' Internet browsing activity. Since most users install TVPlusNewtab inadvertently, it is also considered to be a PUA (Potentially Unwanted Application).

Ncrypt Ransomware

What is Ncrypt?

Ncrypt is a ransomware-type malware designed to encrypt victims' files. It was first discovered by a security researcher Michael Gillespie

During encryption, this malware appends a ".NCRYPT" extension to the name of each file. For instance, "sample.jpg" is renamed to "sample.jpg.NCRYPT". After encryption, Ncrypt creates a "_FILE_RETRIEVAL_INFORMATION.html" file (placed on the desktop) containing a ransom-demand message.

CryptoLocker 5.1 Ransomware

What is CryptoLocker 5.1?

CryptoLocker 5.1 is newly-discovered ransomware claiming to be the CryptoLocker virus. It is based on Hidden Tear - an open-source ransomware project. Following system infiltration, CryptoLocker 5.1 encrypts files using RSA-2048 cryptography and appends a ".locked" extension to the name of each encrypted file.

For example, "sample.jpg" is renamed to "sample.jpg.locked". Most ransomware appends unique extensions, however, recently, the ".locked" extension is popular amongst these viruses. Following encryption, CryptoLocker 5.1 opens a pop-up window and creates a "LEGGI.txt" file, placing it on the desktop. Both contain ransom-demand messages.

FunSafeTab Browser Hijacker

What is FunSafeTab?

FunSafeTab is a browser hijacker, endorsed as a tool to increase user security when browsing. It operates by modifying web browser settings in order to promote - a fake search engine. may appear legitimate and useful, however it is unable to provide search results.

Additionally, FunSafeTab tracks data, specifically information relating to Internet browsing activity. Due to its dubious proliferation methods, FunSafeTab is also considered to an unwanted application.

APT Ransomware

What is APT ransomware?

APT Ransomware v2.0 is a ransomware-type virus designed to encrypt files using RSA-4096 cryptography. This ransomware is based on a Hidden Tear project (so-called 'educational ransomware' that was released as Open Source in August 2015). APT appends a ".dll" extension to the name of each encrypted file.

For example, "sample.jpg" would be renamed to "sample.jpg.dll". In fact, ".dll" files are used by MS Windows (read more).

Therefore, we assume that by adding this extension to regular files, APT's developers attempt to confuse victims. Once the encryption is finished, APT creates a "DECRYPT_YOUR_FILES.html" file and places it in each folder that contains encrypted files.


