Virus and Spyware Removal Guides, uninstall instructions

Worthyrid.com Ads

What kind of page is worthyrid[.]com?

During a routine inspection of rogue websites, our research team found the worthyrid.com site. It pushes browser notification spam and redirects visitors to other untrustworthy/harmful pages. Users typically access webpages like worthyrid[.]com via redirects caused by sites using deceptive advertising networks.

   
SpeedTestMe Adware

What is SpeedTestMe?

Discovered by our researchers while inspecting sites that use rogue advertising networks, SpeedTestMe is a browser extension endorsed as an Internet speed testing tool. It is supposedly capable of measuring webpage loading times, download speeds, etc. Having analyzed this extension, we can conclude that it operates as adware.

   
Qmam4 Ransomware

What is Qmam4 ransomware?

Qmam4 is a piece of malicious software categorized as ransomware. Our research team found this malware during a routine inspection of new submissions on VirusTotal.

While analyzing a sample of Qmam4, we learned that it renames the encrypted files by appending their filenames with a random character string and the ".qmam4" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.r8vPZRn3AswCHnMkuNqTujoCI0uaPEqooovazZCT1zD_FgAAABYAAAA0.qmam4" after encryption.

Once this process was completed, the ransomware created a ransom note - "C3QW_HOW_TO_DECRYPT.txt" - on our test machine's desktop.

   
Webpushworld.com Ads

What kind of website is webpushworld[.]com?

Webpushworld[.]com is a deceptive page designed to trick visitors into agreeing to receive its notifications. We have discovered it while visiting other shady websites and examining ads displayed on them. Webpushworld[.]com is promoted mainly through websites that use rogue advertising networks.

   
T800 Ransomware

What kind of malware is T800?

Our malware researchers have discovered T800 ransomware while checking malware samples submitted to VirusTotal. After analyzing the sample, we concluded that T800 encrypts files and keeps them inaccessible until a ransom is paid. Also, it renames files (appends the ".t800" extension to filenames) and creates the "!!!HOW_TO_DECRYPT!!!.txt" file.

An example of how T800 renames files: it changes "1.jpg" to "1.jpg.t800", "document.txt" to "document.txt.t800". The "!!!HOW_TO_DECRYPT!!!.txt" file is a ransom note containing contact and payment information.

   
Myjollyrudder.com Ads

What kind of page is myjollyrudder[.]com?

While analyzing untrustworthy websites, our researchers discovered the myjollyrudder[.]com page. It is designed to load deceptive content, push browser notification spam, and redirect visitors to other unreliable/harmful sites. Most users access webpages like myjollyrudder[.]com via redirects caused by sites that use rogue advertising networks.

   
Verifyisreal.com Ads

What kind of page is verifyisreal[.]com?

We have discovered the verifyisreal[.]com site while visiting illegal movie streaming, torrent, and similar sites. We found that it redirects visitors to other websites and uses a clickbait technique to trick visitors into allowing it to display notifications.

   
Remarksearch.com Redirect (Mac)

What is remarksearch.com?

Remarksearch.com is the address (URL) of an illegitimate search engine, which our researchers discovered while analyzing browser-hijacking software. Search engines of this type usually generate revenue by collecting information about their users. They are promoted by browser hijackers, which modify browser settings to cause redirects to these addresses.

   
NetMacro Adware (Mac)

What is NetMacro?

NetMacro is a rogue app that our researchers discovered while looking through new submissions to VirusTotal. After analyzing NetMacro, we determined that it is a piece of advertising-supported software (adware) that belongs to the AdLoad malware family.

   
ALBASA Ransomware

What kind of malware is ALBASA?

ALBASA is ransomware that encrypts and renames files and generates a ransom note. We have discovered it while examining the malware samples submitted to VirusTotal. ALBASA appends the ".ALBASA" extension to filenames (for example, it renames "1.jpg" to "1.jpg.ALBASA", "2.jpg" to "2.jpg.ALBASA"). Its ransom note is named "RESTORE_FILES_INFO.txt".

   

Page 650 of 2131

<< Start < Prev 641 642 643 644 645 646 647 648 649 650 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal