Virus and Spyware Removal Guides, uninstall instructions

ESCANOR Ransomware

What is ESCANOR ransomware?

While investigating new submissions to VirusTotal, our researchers discovered the ESCANOR ransomware. It is designed to encrypt data and demand ransoms for the decryption.

When we executed a sample of this ransomware on our test machine, it began encrypting files and changed their filenames. To elaborate, the names were appended with a ".ESCANOR" extension, e.g., a file initially titled "1.jpg" appeared as "1.jpg.ESCANOR", "2.jpg" as "2.png.ESCANOR", etc.

Afterward this process was completed, ESCANOR ransomware dropped a ransom-demanding message - "HELP_DECRYPT_YOUR_FILES.txt" - onto the desktop.

   
MicroStrategy Crypto Giveaway Scam

What is "MicroStrategy Crypto Giveaway"?

While inspecting suspicious websites, we discovered the "MicroStrategy Crypto Giveaway" scam. It promises to double the amount of BTC (Bitcoin cryptocurrency) or ETH (Ethereum cryptocurrency) that participants contribute to the event. It must be emphasized that this giveaway is fake; not only will victims receive no return, but they will lose all the cryptocurrency that they transfer to this scam.

   
The Wise Guys Ransomware

What kind of malware is The Wise Guys?

The Wise Guys is the name of a data wiper disguised as ransomware. It deletes all files (it does not encrypt them). Also, it generates three files ("readme.txt", "readme.hta", and "readme.html") containing identical ransom notes. Our team discovered The Wise Guys malware while checking the VirusTotal website for recently submitted malware samples.

   
Border Colors Adware

What kind of application is border colors?

border colors is the name of a browser extension that supposedly puts border colors on layouts of websites. Our team discovered this app while inspecting various deceptive pages (it is promoted on several shady pages). During the examination, we found that border colors shows annoying advertisements. Thus, we classified border colors as adware.

   
Protectionsurveys.online Ads

What kind of page is protectionsurveys[.]online?

Protectionsurveys[.]online is a rogue webpage that our research team discovered while inspecting dubious sites. It is designed to promote deceptive content, push spam browser notifications, and redirect visitors to different (likely untrustworthy/harmful) websites. Users typically enter these pages via redirects caused by sites that use rogue advertising networks.

   
Posto.click Ads

What kind of page is posto[.]click?

While examining posto[.]click, our team found that this page runs the "McAfee - Your PC is infected with 5 viruses!" scam and wants to deliver its notifications. It uses deceptive marketing to trick visitors into purchasing legitimate computer security software. We discovered posto[.]click while investigating pages that use rogue advertising networks.

   
Elon Musk Twitter Giveaway Scam

What kind of scam is "Elon Musk Twitter Giveaway"?

After examining this website, we concluded that it is a fake crypto giveaway scam page that offers to send cryptocurrency to a specified wallet and get twice as much back. Scammers behind this scam impersonate Elon Musk (use a fake Twitter page) to d deceive users. It is a complete scam that should be ignored.

   
Chromnius Adware

What is Chromnius?

Chromnius is a rogue browser based on the Chromium open-source project. Our research team discovered this piece of software while inspecting suspicious software-promoting websites.

After installing this application on our test machine, we determined that it operates as adware and has qualities that are typical for browser hijackers. Furthermore, it is highly likely that Chromnius collects private information. Due to the fact that most users download/install this untrustworthy browser unintentionally, it is also classified as a PUA (Potentially Unwanted Application).

   
Tuis Ransomware

What kind of malware is Tuis?

Tuis is one of the ransomware variants belonging to the Djvu family. Cybercriminals use it to encrypt files. Tuis not only encrypt files but also appends the ".tuis" extension to filenames and creates a ransom note (the "_readme.txt" file). We discovered this ransomware while checking the VirusTotal website for recently submitted malware samples.

An example of how Tuis renames files: it changes "1.jpg" to "1.jpg.tuis", "2.png" to "2.png.tuis", "3.exe" to "3.exe.tuis", and so forth. It is important to mention that before encrypting files, threat actors behind Djvu ransomware attacks often use information stealers (like Vidar and RedLine) to gain sensitive information.

   
Tury Ransomware

What kind of malware is Tury?

Tury is one of the Djvu ransomware variants. It encrypts files and appends its extension to filenames. We discovered Tury inspecting malware samples submitted to the VirusTotal site. It appends the ".tury" extension to filenames and drops the "_readme.txt" file (a ransom note) on the desktop.

An example of how Tury modifies filenames: it renames "1.jpg" to "1.jpg.tury", "2.png" to "2.png.tury", "3.exe" to "3.exe.tury", and so forth. It is known that Djvu ransomware is often distributed alongside information stealers such as Vidar and RedLine.

   

Page 463 of 2136

<< Start < Prev 461 462 463 464 465 466 467 468 469 470 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal