Step-by-Step Malware Removal Instructions

Decryption#1222 Ransomware
Ransomware

Decryption#1222 Ransomware

Decryption#1222 is ransomware that encrypts files and appends ".n53yb34tbb2" extension to filenames. It also creates the "HOW TO DEYCRYPT.txt" text file, a ransom note containing contact and payment information. We have discovered Decryption#1222 ransomware while checking the VirusTotal page for r

Check-pcsecurity.com Ads
Notification Spam

Check-pcsecurity.com Ads

Check-pcsecurity[.]com is an untrustworthy website running the "McAfee - Your PC is infected with 5 viruses!" scam. It is designed to trick visitors into believing that their computers are infected. Also, this site asks for permission to show notifications and may redirect to other shady pages.

ONYX Ransomware
Ransomware

ONYX Ransomware

ONYX is ransomware based on another ransomware called CONTI. It encrypts files and appends a randomly generated extension to filenames. Moreover, it deletes files larger than 200 megabytes in size and replaces them with random files. Like most ransomware variants, ONYX also creates a ransom note.

Your Viber Application Is Not Updated! POP-UP Scam
Phishing/Scam

Your Viber Application Is Not Updated! POP-UP Scam

It is a fake Viber warning displayed by a deceptive website. We have discovered this site while inspecting notifications displayed by other pages of this kind. Usually, the purpose of such scams is to trick visitors into downloading some software and (or) providing personal information. A

Play No Ads Adware
Adware

Play No Ads Adware

While inspecting suspicious download webpages, our researchers discovered the Play No Ads browser extension. According to its promotional material, this piece of software promises to block advertisements displayed on YouTube videos. However, after analyzing Play No Ads, we determined that it opera

News-relimo.cc Ads
Notification Spam

News-relimo.cc Ads

Our researchers discovered the news-relimo[.]cc rogue webpage while inspecting untrustworthy sites. It is designed to push browser notification spam and cause redirects to different (likely unreliable/malicious) websites. Most users access pages like news-relimo[.]cc via others that use rogue adve

Totalwownews.com Ads
Notification Spam

Totalwownews.com Ads

During a routine inspection of untrustworthy websites, our research team found the totalwownews[.]com page. This rogue site promotes spam browser notifications and redirects users to other (likely untrustworthy or malicious) webpages. Visitors to websites like totalwownews[.]com typically access

BestSportSearch Browser Hijacker
Browser Hijacker

BestSportSearch Browser Hijacker

After analyzing the BestSportSearch browser extension, our researchers determined that it is a browser hijacker. This piece of software makes alterations to browser settings in order to promote the bestsportsearch.com fake search engine. Following successful installation onto our test mach

GonnaCope Ransomware
Ransomware

GonnaCope Ransomware

Recently, a new ransomware called GonnaCope was discovered by Petrovic. It was found that GonnaCope not only encrypts files but also deletes files and replaces them with some random files (files with the ".cope" extension). Files encrypted by GonnaCope do not have a new extension. Also, GonnaCope

Deviceunder-shield.com Ads
Notification Spam

Deviceunder-shield.com Ads

While inspecting untrustworthy sites, our researchers found the deviceunder-shield[.]com rogue webpage. It is designed to load scams, push browser notification spam, and redirect visitors to other (likely dubious/malicious) websites. Most users enter deviceunder-shield[.]com and sites akin to it v