Virus and Spyware Removal Guides, uninstall instructions

Sorryitsjustbusiness Ransomware

What kind of malware is Sorryitsjustbusiness?

We have discovered the Sorryitsjustbusiness ransomware while examining malware samples submitted to VirusTotal. Our team has analyzed Sorryitsjustbusiness and found that this ransomware encrypts files and appends a string of four random characters to filenames as the file extension. For example, it renames "1.jpg" to "1.jpg.bjeq", "2.jpg" to "2.jpg.8i9g".

Like most ransomware variants, Sorryitsjustbusiness provides a ransom note. It creates the "read_it.txt" text file and changes the desktop wallpaper. Both of them contain are ransom notes containing contact and payment information.

   
Download All Your Blocked Email Messages Email Scam

What is "Download all your blocked email messages"?

After inspecting the "Download all your blocked email messages" letter, our researchers determined that it is a phishing scam. This email makes false claims about incoming messages having failed to reach the recipient's mailbox, and it instructs to update the account to retrieve the letters.

   
FlowSurplus Adware (Mac)

What kind of application is is FlowSurplus?

Our team has discovered the FlowSurplus application while inspecting the samples submitted to VirusTotal. After analyzing the application, it was found that FlowSurplus is an advertising-supported application that displays intrusive advertisements. As a rule, apps of this type are distributed using deceptive methods.

   
Xenomorph Malware (Android)

What is Xenomorph malware?

Discovered by the cybercrime prevention company ThreatFabric, Xenomorph is an Android malware that targets banking information.

According to our research, this malicious program is still in the development stages. However, it already has over fifty European banks on its target list. This malware's operations include multiple financial/banking institutions in Belgium, Italy, Portugal, and Spain.

At the time of writing, Xenomorph was heavily distributed through a system performance-enhancing app available on the Google Play Store.

   
LOCKFILE (Xorist) Ransomware

What kind of malware is LOCKFILE?

We have discovered the LOCKFILE ransomware while checking VirusTotal for recently submitted malware samples. After analyzing this ransomware, we learned that it encrypts files, appends ".LOCKFILE" extension to filenames, and generates three ransom notes: two pop-up windows and a text file named "ДЕБЛОКИРОВКА ФАЙЛОВ.txt".

Ransom notes are written in the Russian language. Thus, victims who do not have it installed see ransom notes written in gibberish. An example of how LOCKFILE modifies filenames: it renames "1.jpg" to "1.jpg.LOCKFILE", "2.exe" to "2.exe.LOCKFILE". Another detail about LOCKFILE is that it belongs to the Xorist ransomware family.

   
TaskCentral Adware (Mac)

What kind of software is TaskCentral?

Our team has discovered the TaskCentral application while checking the samples submitted to VirusTotal. After analysis, it was concluded that TaskCentral is typical adware - it bombards users with unwanted advertisements. Typically, adware is distributed using deceptive methods.

   
Cavallososo Ransomware

What is Cavallososo ransomware?

Cavallososo is a piece of malicious software belonging to the ZEPPELIN ransomware family. Our research team found a sample of this ransomware while inspecting new submissions to VirusTotal.

Once launched onto our test machine, Cavallososo encrypted files and appended their filenames with a ".Cavallososo.[victim's_ID]" extension. For example, a file originally titled "1.jpg" appeared as "1.jpg. Cavallososo.F19-784-369",a nd so on for all of the affected files.

Afterward, a ransom note named "!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT" was created on the desktop. Based on the message in this file, it is evident that this ransomware targets companies rather than home users.

   
TopMoviesLinks Default Search Browser Hijacker

What kind of application is TopMoviesLinks Default Search?

We have discovered the TopMoviesLinks Default Search app while doing our periodical research on shady advertising networks and deceptive pop-ups used to trick users into installing this extension. After testing the app, we have learned that it alters the settings of a browser - it hijacks a browser to promote a fake search engine.

   
Rtgf Ransomware

What kind of malware is Rtgf?

Our team has discovered the Rtgf ransomware while analyzing malware samples submitted for VirusTotal. Rtgf belongs to the Djvu ransomware family. It encrypts files and appends the ".rtgf" as their new extension. Also, it creates the "_readme.txt" file to provide victims with contact and payment information.

An example of how Rtgf modifies filenames: it renames "document.txt" to "document.txt.rtgf", "file.exe" to "file.exe.rtgf", and so on.

   
Pushnotstudio.com Ads

What kind of page is pushnotstudio[.]com?

Pushnotstudio[.]com is a rogue site, which our research team discovered while inspecting shady pages. It is designed to push spam browser notifications and cause redirects to other unreliable/malicious websites.

Visitors to pushnotstudio[.]com and similar sites primarily access them via redirects caused by webpages that use rogue advertising networks.

   

Page 642 of 2126

<< Start < Prev 641 642 643 644 645 646 647 648 649 650 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal