Virus and Spyware Removal Guides, uninstall instructions

OriginalModule Adware (Mac)

What is OriginalModule?

People do not often download or install the OriginalModule app intentionally, since its installer is disguised as the Adobe Flash Player installer. Therefore, OriginalModule is categorized as a potentially unwanted application (PUA).

This app is designed to modify browser settings (to promote a fake search engine), generate advertisements, and collect browsing-related and possibly sensitive information. In this way, OriginalModule functions as adware and a browser hijacker.

   
Sn0wsLogger Malware

What is Sn0wsLogger?

Sn0wsLogger is malicious software, which is classified as a stealer. The primary purpose of this type of malware is to steal various sensitive and confidential information. Stealers have various capabilities, enabling them to carry out this purpose, however, in addition to being a serious privacy concern, these malicious programs also pose a threat to device safety.

   
VASA LOCKER Ransomware

What is VASA LOCKER?

VASA LOCKER is designed to prevent victims from accessing or using their files by employing SHA256 hashing, ChaCha8 encryption, ECDH key generation, and an algorithm to encrypt files and secure its keys.

VASA LOCKER also renames each encrypted file by appending the ".__NIST_K571__" extension to filenames. For example, "1.jpg" is renamed to "1.jpg.__NIST_K571__", "2.jpg" to "2.jpg.__NIST_K571__", and so on.

Malware of this type displays or creates ransom messages. This ransomware creates the "DECR.TXT" file, dropping it in all folders that contain encrypted data. Note that attackers behind VASA LOCKER target mainly companies and organizations, however, there is a high chance that regular users will also be targeted.

   
UpdaterSync Adware (Mac)

What is UpdaterSync?

UpdaterSync is an adware-type app with browser hijacker traits. It operates by running intrusive advertisement campaigns (i.e., delivering ads) and making modifications to browsers to promote fake search engines.

Due to the dubious methods used to proliferate UpdaterSync, it is also categorized as a Potentially Unwanted Application (PUA). Most PUAs have data tracking capabilities, which are employed to collect browsing-related information.

   
Cring Ransomware

What is Cring?

Cring encrypts files and appends the ".cring" extension to filenames. For example, "1.jpg" is renamed to "1.jpg.cring", "2.jpg" to "2.jpg.cring", and so on.

Cring also creates a ransom message within a text file named "!!!!deReadMe!!!.txt", dropoing this file into all folders that contain encrypted files. Note that there are two ransom message variants.

   
ProcessBrand Adware (Mac)

What is ProcessBrand?

Adware generates unwanted advertisements, however, ProcessBrand also functions as a browser hijacker, changing browser settings to promote a fake search engine address. It is likely that ProcessBrand also gathers browsing data and other information.

These apps are often downloaded and installed by users unintentionally and, therefore, they are classified as potentially unwanted applications (PUAs).

   
Aboutyoun.com Ads

What is aboutyoun[.]com?

Websites such as aboutyoun[.]com are promoted via deceptive advertisements, other untrusted pages, and potentially unwanted applications (PUAs). I.e., users do not often visit them intentionally. Many web pages are similar to aboutyoun[.]com including, for example, datingbasedspot[.]com, captchatopsource[.]com and continue-site[.]site.

Note that users do not often download or install PUAs intentionally. Apps of this type can be designed to promote untrusworthy pages, gather browsing data, and generate advertisements.

   
TheVideoSearch Browser Hijacker

What is TheVideoSearch?

TheVideoSearch browser hijacker promotes thevideosearch.com, the address of a fake search engine, by changing browser settings. It also collects browsing data. Typically, users download browser hijackers unintentionally and, for this reason, TheVideoSearch is categorized as a potentially unwanted application (PUA).

   
Datingbasedspot.com Ads

What is datingbasedspot[.]com?

Sharing many similarities with captchatopsource.com, holanews.biz, yourwownews.com, and countless others, datingbasedspot[.]com is an untrusted website. It operates by presenting visitors with dubious content and redirecting them to other dubious and possibly malicious pages.

Users rarely enter these sites intentionally - most are redirected to them by intrusive advertisements or Potentially Unwanted Applications (PUAs) already installed on their systems. These apps cause redirects, run intrusive ad campaigns, and collect browsing-related information.

   
FireMovieSearch Browser Hijacker

What is FireMovieSearch?

FireMovieSearch is a browser hijacker promoting firemoviesearch.com, a fake search engine. It operates by making modifications to browser settings, which result in redirects to firemoviesearch.com.

It is likely that FireMovieSearch also has data tracking capabilities, which are employed to monitor users' browsing activity. Since most users download/install browser hijackers inadvertently, these programs are also categorized as Potentially Unwanted Applications (PUAs).

   

Page 1157 of 2337

<< Start < Prev 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal