Virus and Spyware Removal Guides, uninstall instructions

ZeRy Ransomware

What is ZeRy ransomware?

Our research team discovered the ZeRy ransomware-type program while inspecting new submissions to VirusTotal. ZeRy is part of the Xorist ransomware family.

On our testing system, this ransomware encrypted files and appended their filenames with a ".ZeRy" extension. To elaborate, a file initially named "1.jpg" appeared as "1.jpg.ZeRy", "2.png" as "2.png.ZeRy", etc.

Afterward, ZeRy displayed a pop-up window and created a text file titled "HOW TO DECRYPT FILES.txt", both of which contain identical ransom notes.

   
Basicnetworkpc.com Ads

What kind of page is basicnetworkpc[.]com?

Basicnetworkpc[.]com is a rogue page that promotes online scams, pushes spam browser notifications, and redirects visitors to different (likely unreliable/hazardous) websites.

Our researchers discovered this page while inspecting sites that use rogue advertising networks. In fact, most users enter webpages like basicnetworkpc[.]com through redirects caused by websites using such networks.

   
Globe Earth Browser Hijacker

What is Globe Earth?

Globe Earth is a rogue browser extension that our researchers discovered while looking through suspicious websites. The promotional material states that this extension displays Google Earth images on new browser windows and tabs. However, our analysis revealed that this piece of software operates as a browser hijacker.

   
Yourcommonblog.com Ads

What kind of page is yourcommonblog[.]com?

Our research team discovered the yourcommonblog[.]com rogue page while looking through dubious websites. It promotes browser notification spam and redirects visitors to different (likely untrustworthy/malicious) sites.

Most access webpages like yourcommonblog[.]com via redirects caused by sites using rogue advertising networks, spam notifications, intrusive ads, or installed adware.

   
PrimaryRotator Adware (Mac)

What is PrimaryRotator?

Our research team found the PrimaryRotator app while investigating new submissions to VirusTotal. After inspecting this piece of software, we determined that it operates as adware and is part of the AdLoad malware family.

   
Watch Movies Adware

What kind of application is Watch Movies?

Watch Movies is promoted as a browser extension allowing users to easily search for movies. We tested this app and found that it displays unwanted advertisements. Software that shows annoying ads is called adware. It is uncommon for adware to be downloaded and installed (or added to browsers) on purpose.

   
Faust Ransomware

What is Faust ransomware?

While inspecting new submissions to VirusTotal, our researchers discovered a new malicious program called Faust - which belongs to the Phobos ransomware family.

On our test machine, Faust ransomware encrypted files and changed their titles. Original filenames were appended with a unique ID, the cyber criminals' email address, and a ".faust" extension. For example, a file titled "1.jpg" appeared as "1.jpg.id[9ECFA84E-3421].[gardex_recofast@zohomail.eu].faust" following encryption.

Afterward, ransom notes were created/displayed in a pop-up window ("info.hta") and text file ("info.txt").

   
Fate Ransomware

What kind of malware is Fate?

Fate is ransomware (one of the Djvu ransomware variants) designed to encrypt files and change their extension to ".fate". It also creates the "_readme.txt" file that contains a ransom note. We discovered Fate while checking the VirusTotal page for recently submitted malware samples.

An example of how Fate renames files: it changes "1.jpg" to "1.jpg.fate", "2.png" to "2.png.fate", and so forth.

   
Fatp Ransomware

What kind of malware is Fatp?

Fatp is one of the ransomware variants belonging to the Djvu family. Our team discovered Fatp on VirusTotal (while inspecting submitted malware samples). Fatp encrypts files and appends the ".fatp" extension to their filenames. It also creates the "_readme.txt" file that contains a ransom note.

An example of how Fatp renames files: it changes "1.jpg" to "1.jpg.fatp", "2.png" to "2.png.fatp", and so forth.

   
Chainedprotol.com Ads

What kind of page is chainedprotol[.]com?

Our researchers discovered the chainedprotol[.]com rogue page while investigating suspicious websites. It promotes online scams, pushes browser notification spam, and redirects visitors to different (likely untrustworthy/dangerous) sites. Users typically access webpages like chainedprotol[.]com through redirects caused by sites using rogue advertising networks.

   

Page 442 of 2134

<< Start < Prev 441 442 443 444 445 446 447 448 449 450 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal