Virus and Spyware Removal Guides, uninstall instructions

Anonymous (Chaos) Ransomware

What kind of malware is Anonymous?

While inspecting malware samples submitted to the VirusTotal page, we discovered a ransomware variant based on Chaos ransomware dubbed Anonymous. This variant encrypts data, appends its extension (four random characters) to filenames, changes the desktop wallpaper, and the "for dencrypt" file that contains a ransom note.

An example of how Anonymous ransomware modifies filenames: it renames "1.jpg" to "1.jpg.4h9n", "2.doc" to "2.doc.nh54", and so forth.

   
Liffswithabr.com Ads

What kind of page is liffswithabr[.]com?

While researching suspicious websites, we discovered the liffswithabr[.]com rogue page. It operates by pushing browser notification spam and redirecting visitors to different (likely unreliable/harmful) sites. Most users access liffswithabr[.]com and similar pages through redirects caused by websites that use rogue advertising networks.

   
Dgnlwjw Ransomware

What is Dgnlwjw ransomware?

While inspecting new submissions to VirusTotal, our research team discovered yet another ransomware-type program from the Snatch family – called Dgnlwjw. Malware within this classification is designed to encrypt data for the purpose of making ransom demands for the decryption tools.

When we executed a sample of Dgnlwjw on our test machine, it encrypted files and appended their filenames with a ".dgnlwjw" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.dgnlwjw", "2.png" as "2.png.dgnlwjw", etc.

Once this process was concluded, a ransom-demanding message – "HOW TO RESTORE YOUR FILES.TXT" – was created.

   
Dark Theme For Chrome Adware

What kind of application is Dark Theme For Chrome?

Our team has examined Dark Theme For Chrome browser extension and found that it shows intrusive ads and can read browsing-related data. Apps that display ads are classified as adware. Users often download such software o purpose. We discovered Dark Theme For Chrome on a deceptive page.

   
AccessUnit Adware (Mac)

What is AccessUnit?

While investigating new submissions to VirusTotal, our research team discovered the AccessUnit app. This piece of rogue software operates as adware. Furthermore, we determined that this application is part of the AdLoad malware family.

   
Mekwyk Ransomware

What kind of malware is Mekwyk?

Mekwyk is ransomware that makes files inaccessible by encrypting them. Also, it appends the victim's ID and the ".mekwy" extension to filenames and creates the "RESTORE_FILES_INFO.txt" file that contains a ransom note. We discovered Mekwyk while inspecting samples submitted to the VirusTotal website.

An example of how Mekwyk renames files: it changes "1.jpg" to "1.jpg.[ID-9ECFA84E].mekwyk", "2.doc" to "2.doc.[ID-9ECFA84E].mekwyk", and so forth.

   
Honkai (Paradise) Ransomware

What is Honkai (Paradise) ransomware?

Our researchers discovered the Honkai ransomware while inspecting new submissions to VirusTotal. This malicious program is part of the Paradise ransomware family.

When we executed a sample of Honkai (Paradise) ransomware on our test system, it began encrypting files and modifying their titles.

Original filenames were appended with a unique ID assigned to the victim, the cyber criminals' email address, and a ".honkai" extension. For example, a file named "1.jpg" appeared as "1.jpg[id-f48tSVGB].[main@paradisenewgenshinimpact.top].honkai".

Afterwards, the ransomware dropped a ransom-demanding message titled "#DECRYPT MY FILES#.html" onto the desktop.

   
GonaCry Ransomware

What kind of malware is GonaCry?

GonaCry is ransomware that encrypts files, modifies filenames of the encrypted files, changes the desktop wallpaper, and provides a ransom note (creates the "read_it.txt" file). GonaCry is based on Chaos ransomware. Our team discovered it while examining samples submitted to the VirusTotal page.

GonaCry a random extension to filenames. For instance, it renames "1.jpg" to "1.jpg.h954", "2.doc" to "2.doc.i6as", and so forth.

   
Link2captcha.top Ads

What kind of page is link2captcha[.]top?

While checking out suspicious websites, our researchers discovered the link2captcha[.]top rogue webpage. It promotes browser notification spam by using fake CAPTCHA verification. Additionally, this page can redirect users to different (likely untrustworthy/harmful) websites.

Most users access webpages like link2captcha[.]top via redirects caused by sites using rogue advertising networks.

   
BTC (Azadi) Ransomware

What is BTC (Azadi) ransomware?

While investigating new submissions to VirusTotal, our researchers discovered the BTC (Azadi) ransomware. Malware within this classification operates by encrypting data and demanding payment for decryption.

Once we executed a sample of BTC (Azadi) on our test machine, it began encrypting files. The filenames of the affected files were modified, i.e., appended with the cyber criminals' email, a unique ID assigned to the victim, and the ".BTC" extension. For example, a file originally titled "1.jpg" appeared as "1.jpg.EMAIL=[azadi33@smime.ninja]ID=[4FC6718E700859F4].BTC". Afterward, this ransomware created a ransom note – "How To Restore Files.txt".

   

Page 3 of 1756

<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
About PCrisk

PCrisk logo

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal