Virus and Spyware Removal Guides, uninstall instructions

GoSportSearch Browser Hijacker

What is GoSportSearch?

GoSportSearch is a piece of rogue software categorized as a browser hijacker. It operates by promoting (i.e., causing redirects to) the gosportsearch.com fake search engine through alterations to browser settings.

Additionally, GoSportSearch likely spies on users' browsing habits, as such data tracking abilities are typical of browser hijackers. Since most users inadvertently download/install browser hijackers, they are also classified as PUAs (Potentially Unwanted Applications).

   
Mishmash Ransomware

What is Mishmash ransomware?

Mishmash is a ransomware-type program designed to encrypt data and demand payment for the decryption. In other words, victims cannot access/use the files affected by Mishmash, and they are asked to pay - to recover access/use of their data.

Typically, ransomware renames encrypted files, but that is not the case with this malicious program. After the encryption process is complete, a ransom note is displayed in a pop-up window.

At the time of research, Mishmash was a decryptable ransomware; the decryption password being "pass" (sans the quotation marks). Unless victims were infected with an updated version of the malware, this password will decrypt their data.

   
Babyk Ransomware

What is Babyk?

Babyk is a type of malware that encrypts files, appends the ".babyk" extension to their filenames, and creates ransom notes (text files named "How To Restore Your Files.txt") in all folders containing encrypted files. Its ransom notes contain payment information. Babyk modifies filenames like this: it renames a file named "1.jpg" to "1.jpg.babyk", "2.jpg" to "2.jpg.babyk", and so on. This ransomware is another variant of the Babuk Locker ransomware.

There are multiple variants of Babyk ransomware (".babuk", ".doydo", etc.), and some of them can be decrypted using a decrypted developed by Avast (more information below).

   
TabHelper Virus (Mac)

What is TabHelper?

Belonging to the Pirrit adware family, TabHelper is a rogue application. Following successful infiltration, it delivers intrusive advertisement campaigns.

Furthermore, most adware-type apps have data tracking abilities. Hence, TabHelper likely has such functionalities as well.

TabHelper may also display pop-up windows claiming that a piece of software is outdated/missing and requires updating/installation. This is important as fake software updaters/installers are used to distribute adware, browser hijackers, and other PUAs (Potentially Unwanted Applications). In some cases, this fraudulent content may even proliferate malware (e.g., ransomware, trojans, cryptocurrency miners, etc.).

   
Lootynews.com Ads

What is lootynews[.]com?

Lootynews[.]com is a website designed to check the IP address and then either display deceptive content or open two, three other shady pages. Lootynews[.]com is similar to kaba-zaba[.]com, stream-your-vids[.]com, scleriends[.]website, and hundreds of other pages of this type.

   
Romanticdating-day.com Ads

What is romanticdating-day[.]com?

Sharing many similarities with kaba-zaba.com, beastbuying.com, stream-your-vids.com, and thousands of others, romanticdating-day[.]com is a rogue page. This site operates by loading questionable content and/or redirecting visitors to different untrustworthy or malicious websites.

Users seldom access pages of this kind intentionally. Most get redirected to them by other rogue webpages, intrusive advertisements, or installed PUAs (Potentially Unwanted Applications).

This software can infiltrate systems without express permission; hence, users may be unaware of its presence. PUAs are designed to cause redirects, run intrusive advert campaigns, and collect browsing-related information.

   
COSCO Shipping Email Virus

What is the "COSCO Shipping email virus"?

"COSCO Shipping email virus" is the name of a spam campaign proliferating the Agent Tesla RAT (Remote Access Trojan). The term "spam campaign" defines a mass-scale operation during which thousands of deceptive emails are sent.

The letters spread through this campaign are disguised as business-related messages from COSCO Shipping Lines - a Chinese international container transportation and shipping company. It must be emphasized that these emails are in no way associated with the genuine COSCO company, nor is any information provided by them true.

This spam mail aims to infect recipients' systems with Agent Tesla malware. This malicious program is classified as a RAT since it can enable remote access and control over infected machines. Trojans of this type can have a wide variety of heinous abilities; hence, the threats posed by these programs are especially broad.

   
Kaba-zaba.com Ads

What is kaba-zaba[.]com?

Kaba-zaba[.]com is a page designed to promote other questionable pages and display deceptive content. There is a great number of websites like kaba-zaba[.]com on the Internet, for example, stream-your-vids[.]com, scleriends[.]website, and play-new-vids[.]com.

   
Beastbuying.com Ads

What is beastbuying[.]com?

Beastbuying[.]com is an untrustworthy site designed to present visitors with questionable content and/or redirect them to other unreliable and malicious webpages. The Internet is full of such dubious websites; stream-your-vids.comscleriends.website, and play-new-vids.com are but some examples.

Untrustworthy sites like beastbuying[.]com are rarely accessed intentionally. Most users enter them via redirects caused by rogue pages, intrusive advertisements, or installed PUAs (Potentially Unwanted Applications).

Unwanted apps can infiltrate systems without explicit user permission. PUAs operate by causing redirects, delivering intrusive advert campaigns, and collecting browsing-related data.

   
Lu0bot Malware

What kind of malware is Lu0bot?

Lu0bot is a piece of malicious software. The malware is lightweight, so its usage of system resources is low. This complicates Lu0bot's detection, as it does not cause significant symptoms, like a severe decline in system performance.

The malicious program operates as a telemetry harvester. However, such malware typically has additional heinous functionalities. Hence, it is likely that Lu0bot does as well.

   

Page 1041 of 2342

<< Start < Prev 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal