Virus and Spyware Removal Guides, uninstall instructions

Problem Ransomware

What kind of malware is Problem?

We have found a new ransomware variant called Problem while inspecting ransomware samples submitted to VirusTotal. During analysis, we discovered that Problem encrypts files, appends the ".problem" extension to filenames, and creates the "readme.txt" file (a ransom note).

An example of how this ransomware renamed files: it changed the "1.jpg" file to "1.jpg.problem", "document.txt" to "document.txt.problem".

   
Universal-current.com Ads

What kind of page is universal-current[.]com?

Universal-current[.]com is a shady website that displays deceptive content and asks for permission to show notifications. We have discovered it while testing pages that are using questionable advertising networks. More precisely, we ended up on universal-current[.]com after visiting various illegal movie streaming, torrent, and similar sites.

   
KUKANOS Ransomware

What is KUKANOS ransomware?

During a routine inspection into new submissions on VirusTotal, our researchers detected a new addition to the ZEPPELIN ransomware family - called KUKANOS.

When we tested this malware, it encrypted files and appended their filename with this extension - ".@KUKANOSSOSANOS.[victim's_ID]" (the IDs are unique and very between infections). For example, a file that was initially titled "1.jpg" appeared as "1.jpg.@KUKANOSSOSANOS.199-BDC-9E1".

Afterward, a ransom note - "!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT" was dropped onto the desktop. Judging from the message within this text file, it is evident that KUKANOS targets companies rather than home users.

   
InitiatorIntegrate Adware (Mac)

What kind of software is InitiatorIntegrate?

Our team has analyzed the InitiatorIntegrate application and discovered that it generates advertisements and hijacks a web browser to promote a fake search engine. Knowing this, we can state that InitiatorIntegrate functions as adware and a browser-hijacking application.

   
Sync Wallets Scam

What is "Sync Wallets"?

"Sync Wallets" is a phishing scam, which our researchers found when inspecting shady websites. Schemes of this type can be promoted on many rogue pages simultaneously; we found it on fixedvalidity[.]online website, but it may be encountered on others as well.

"Sync Wallets" is presented as a dApp (decentralized application) capable of linking up with various iOS and Android cryptocurrency wallets. However, we discovered that this fake service aims to extract cryptowallet log-in credentials. Therefore, through "Sync Wallets" scammers can gain access to digital wallets and control the cryptocurrency stored therein.

   
Color Darker Browser Hijacker

What kind of application is color darker?

We have found the installer for the color darker application on multiple deceptive websites. While analyzing the color darker application, we learned that it hijacks a web browser by changing some of its settings to wwmnnl.com (a fake search engine).

   
Facebookteens.com Ads

What kind of page is facebookteens[.]com?

We discovered facebookteens[.]com whilst researching other questionable websites. The page in question is designed to load dubious content, promote browser notification spam, and redirect visitors to various unreliable/dangerous sites. Most visits to facebookteens[.]com are unintentional as they are caused by redirects from rogue advertising networks used by other webpages.

   
Webdefencesupprot.com Ads

What kind of page is webdefencesupprot[.]com?

Detected by our researchers when inspecting untrustworthy webpages, webdefencesupprot[.]com is a site designed to load deceptive content, promote its browser notifications, and redirect visitors to other unreliable/harmful pages. During our observation, this website ran the "McAfee - Your PC is infected with 5 viruses!" scam.

It is noteworthy that most visitors to webdefencesupprot[.]com access it via other websites that employ rogue advertising networks.

   
WaspLocker Ransomware

What is WaspLocker ransomware?

While searching VirusTotal for new malware submissions, our researchers found a new ransomware called WaspLocker. On our test system, this ransomware-type program encrypted files and appended them with the ".locked" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.locked", "2.jpg" as "2.jpg.locked", etc.

It is noteworthy that there another variant of WaspLocker, which adds ".0.locked" to filenames (e.g., "1.jpg" would look like "1.jpg.0.locked", etc.).

Once the encryption was completed, the ransomware changed the desktop wallpaper, displayed a pop-up window, and created "How to restore your files.txt" text file.

   
Wholewowblog.com Ads

What kind of page is wholewowblog[.]com?

Wholewowblog[.]com is a deceptive website that has been discovered by our team while testing sites that use questionable advertising networks. We examined wholewowblog[.]com and found that it uses a clickbait technique to trick visitors into agreeing to receive notifications that promote other untrustworthy websites.

   

Page 679 of 2134

<< Start < Prev 671 672 673 674 675 676 677 678 679 680 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal