Virus and Spyware Removal Guides, uninstall instructions

Medusa Trojan (Android)

What is the Medusa trojan?

Medusa is the name of a banking trojan that we have researched and analyzed a sample obtained from VirusTotal. This malware targets Android operating systems; it enables remote access control over infected devices and can extract a wide variety of vulnerable data from them.

Initially, Medusa was leveraged against financial organizations based in Turkey; however, its operations have spread to the United States, Canada, and Europe.

   
Sncip Ransomware

What kind of malware is Sncip?

Sncip is the name of ransomware that we have discovered while checking the VirusTotal page for recently submitted malware samples. Our team has tested Sncip and learned that it encrypts files and appends a string of random characters and the ".sncip" extension to their filenames. Also, it creates the "eauk_HOW_TO_DECRYPT.txt" file.

An example of how Sncip renames files: it changes "1.jpg" to "1.jpg.ynTca1SK21D-LM1Vd9xbHtELRrRBnYVkXLwJynRsec__LAAAACwAAAA0.sncip", "2.jpg" to "2.jpg.ynTca1SK21D-LM1Vd9xbHtELRrRBnYVkXLwJynRsec__LAAAACwAAAA0.sncip". The text file that Sncip creates contains a ransom note.

   
TravelNow Adware

What is TravelNow?

Discovered by our researchers during a routine inspection of sites that use rogue advertising networks, TravelNow is a rogue application. After analyzing it, we determined that it operates as advertising-supported software (adware).

   
Aumcc Ransomware

What kind of malware is Aumcc?

We have examined the Aumcc ransomware and found that it encrypts files, appends a string of random characters and the ".aumcc" extension to filenames, and generates a ransom note (a text file named "3LUo_HOW_TO_DECRYPT.txt"). Our team has discovered Aumcc while checking the malware samples submitted to VirusTotal.

An example of how Aumcc modifies filenames: it renmaes "1.jpg" to "1.jpg.HlMZCanvyBm1DSYgKy2OX3soqeJnaJM2PR2j0FyWq5j_AAAAAAAAAAA0.aumcc", "document.txt" to "document.txt.HlMZCanvyBm1DSYgKy2OX3soqeJnaJM2PR2j0FyWq5j_AAAAAAAAAAA0.aumcc".

   
Thecred.info Ads

What kind of page is thecred[.]info?

Thecred[.]info is a deceptive website that we have discovered while testing illegal movie streaming, torrent, and similar sites that use questionable advertising networks. After examining thecred[.]info, we found that the purpose of this site is to get permission to show notifications and redirect visitors to similar pages.

   
GpCODE Ransomware

What is GpCODE ransomware?

GpCODE is a malicious program belonging to the Xorist ransomware family, which our researchers found when inspecting new submissions to VirusTotal.

On our test system, this ransomware encrypted files and appended the filenames with a ".GpCODE" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.GpCODE", "2.jpg" as "2.jpg.GpCODE", "3.jpg" as "3.jpg.GpCODE", and so on.

Once this process was completed, identical ransom notes were created/displayed in a pop-up window and "КАК РАСШИФРОВАТЬ ФАЙЛЫ.txt" text file. It is noteworthy that the message presented in the pop-up will appear as gibberish if the system is missing the Cyrillic alphabet.

   
OptionFlow Adware (Mac)

What kind of application is OptionFlow?

We have learned about the OptionFlow application while reading forums. Our researchers have concluded that OptionFlow functions as adware - it generates advertisements. We have also found that this app slows down the Safari web browser and can remove apps designed to block advertisements.

   
Kn33-m3dicin3.xyz Ads

What kind of page is kn33-m3dicin3[.]xyz?

We have discovered the kn33-m3dicin3[.]xyz site while examining other pages (various illegal streaming, torrent sites) that use questionable advertising networks. After analyzing this page, we have learned that it displays deceptive content (a fake security alert) and asks for permission to show untrustworthy notifications.

   
MapIt Adware

What kind of software is MapIt?

After downloading and launching the sample on our testing machine, we have noticed that MapIt displays unwanted advertisements. This program works as typical adware. It is very common for adware to be downloaded and installed mistakenly/unknowingly because it is promoted and distributed using questionable methods.

   
Click Togo Browser Hijacker

What is Click Togo?

After analyzing the Click Togo browser extension, our researchers have determined that it is a browser hijacker. This piece of software alters browser settings to promote the togosearching.com fake search engine, and it spies on users' browsing activity.

   

Page 660 of 2131

<< Start < Prev 651 652 653 654 655 656 657 658 659 660 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal