Virus and Spyware Removal Guides, uninstall instructions

Dev-Nightmare Ransomware

What is Dev-Nightmare?

Dev-Nightmare is ransomware-type virus based on Hidden Tear. Following infiltration, Dev-Nightmare encrypts various files and appends the ".2xx9" extension to the name of each encrypted file (for example, encrypted "sample.jpg" is renamed to "sample.jpg.2xx9").

Following successful encryption, Dev-Nightmare generates a text file ("READ_ME.TXT", placed on the desktop) containing a ransom-demand message.

   
Tavanero.info Redirect

What is tavanero.info?

Identical to chromestart4.ru, searchboro.com, ttczmd.com, and a number of other rogue sites, tavanero.info is a fake Internet search engine claiming to enhance the Internet browsing experience by generating improved search results.

Judging on appearance alone, tavanero.information may seem legitimate, however, this rogue site is promoted using deceptive software download/installation tools that hijack Internet browsers and stealthily modify various options. In addition, tavanero.information continually tracks users' Internet browsing activity by gathering various user/system data.

   
JokeFromMars Ransomware

What is JokeFromMars?

JokeFromMars is ransomware-type malware similar to CTB-Locker (potentially, a new variant). Following infiltration, JokeFromMars encrypts various files stored on the system.

Following successful encryption, JokeFromMars changes the desktop wallpaper, creates a text file ("ReadMeFilesDecrypt!!!.txt") placing it on the desktop, and displays a pop-up window. All contain a ransom-demand message.

   
CTB-Locker Ransomware [Updated]

What is 'Your personal files are encrypted by CTB-Locker'?

CTB-Locker ransomware virus infiltrates operating systems via infected email messages and fake downloads (for example, rogue video players or fake Flash updates).

After successful infiltration, this malicious program encrypts various files (*.doc, *.docx, *.xls, *.ppt, *.psd, *.pdf, *.eps, *.ai, *.cdr, *.jpg, etc.) stored on computers and demands a ransom payment of $300 (in Bitcoins) to decrypt them (encrypted documents receive the .ctbl files extension).

Cyber criminals responsible for releasing this rogue program ensure that it executes on all Windows operating system versions (Windows XP, Windows Vista, Windows 7, and Windows 8). CTB-Locker ransomware creates AllFilesAreLocked.bmp DecryptAllFiles.txt and [seven random letters].html files within each folder containing the encrypted files.

   
BestCleaner Unwanted Application

What is BestCleaner?

BestCleaner is a deceptive application that supposedly improves computer performance by cleaning various junk files. Initially, this functionality may seem legitimate and useful, however, BestCleaner often infiltrates systems without users' permission.

Furthermore, it is likely to gather information relating to Internet browsing activity. For these reasons, this app is categorized as a potentially unwanted program (PUP).

   
Workno.ru Redirect

What is workno.ru?

Developers present workno.ru as a legitimate Internet search engine that enhances the Internet browsing experience by generating improved Internet search results.

These claims often trick users into believing that workno.ru is a legitimate and useful site, however, developers promote it via rogue software download and installation set-ups that hijack Internet browsers and modify various options. In addition, workno.ru gathers various information relating to users' Internet browsing activity.

   
Searchvvay.com Redirect

What is searchvvay.com?

Searchvvay.com is a fake Internet search engine identical to walasearch.com, yessearches.com, yoursearching.com, and a number of other bogus sites.

On initial inspection, searchvvay.com may seem legitimate, however, developers promote this site using rogue installation set-ups designed to hijack web browsers and modify their settings. In addition, searchvvay.com continually collects various information about users' web browsing habits.

   
Tech-connect.biz Redirect

What is tech-connect.biz?

tech-connect.biz is a rogue site claiming to be a legitimate Internet search engine that enhances the Internet browsing experience by generating improved search results.

These claims often trick users into believing that tech-connect.biz is legitimate, however, this site continually gathers information relating to users' Internet browsing activity. Furthermore, developers promote this site using deceptive software download/installation tools that hijack web browsers and stealthily modify various options.

   
FenixLocker Ransomware

What is FenixLocker?

FenixLocker is another ransomware-type virus that encrypts files using AES cryptography. During encryption, FenixLocker appends the names of compromised files with the ".centrumfr@india.com" extension (e.g., "sample.jpg" is renamed to "sample.jpg.centrumfr@india.com").

Following successful encryption, FenixLocker creates a text file ("Help to decrypt.txt" or "Cryptolocker.txt"), which contains a ransom-demand message and is placed on the desktop. Updated variants of this ransomware use ".[help24decrypt@cock.li]" and ".help24decrypt@qq.com!!" extensions for encrypted files.

   
Save Serp Now Adware [Updated]

What is Save Serp Now?

Save Serp Now claims to be a legitimate application designed to help users keep track of their Internet search history. This functionality may seem legitimate and useful, however, Save Serp Now is considered to be a potentially unwanted program (PUP).

This application is distributed using a deceptive free software marketing method called 'bundling' - stealth installation of additional programs together with the chosen software without users' consent. Bundling is often employed by freeware download websites, and therefore, you should always express caution when downloading free software.

   

Page 1933 of 2255

<< Start < Prev 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal