Virus and Spyware Removal Guides, uninstall instructions

*.shit Ransomware

What is *.shit?

*.shit is a new variant of Locky ransomware that is distributed using spam emails. The emails contain malicious files (JS/WSF/HTA) that download an encrypted DLL file, decrypt, and execute it. The file downloads the ransomware. Once infiltrated, the virus will encrypt hundreds of file types.

Encrypted files will be renamed using the "[8_random_characters]-[4_random_characters]-[4_random_characters]-[4_random_characters]-[12_random_characters].shit" pattern. For example, "sample.jpg" might be renamed to "GPZ9PTN3-DJEU-DQ3M-7181-6BDB61A5F207.shit".

Following successful encryption, so-called "*.shit" ransomware creates two files (.html and .bmp) and places them on the desktop. The .bmp file is also set as the desktop wallpaper.

   
Complete a Quick Survey to Continue Virus

What is Complete a Quick Survey to Continue?

"Please complete a quick survey to continue" is a ransomware infection that locks computer users' desktops. This is an attempt to coerce users into completing online surveys in order to unlock their computers.

Ransomware infections of this type are relatively recent - previous variants exploited the names of authorities such as the FBI, Internet Crime Complaint Center, Interpol, etc. and demanded payment of bogus fines for supposed law violations. This variant, however, encourages users to complete online surveys.

Other known variants of this ransomware use similar tactics, including the message "Complete an offer below to unlock your desktop". PC users should not fall for such trickery or complete any offers.

   
Searchoko.com Redirect

What is searchoko.com?

searchoko.com is a fake Internet search engine identical to videobah.com, searchudak.com, worldonsearch.com, and many others. By falsely claiming to generate improved search results, searchoko.com often tricks users into believing that it is a legitimate and useful website.

Be aware, however, that this site is promoted using rogue software download/installation set-ups, which modify web browser settings without users' consent. Furthermore, searchoko.com records various information relating to users' Internet browsing activity.

   
CIA Election AntiCheat Control - 2016 Scam

What is CIA Election AntiCheat Control - 2016?

CIA Election AntiCheat Control - 2016 is ransomware-type malware that locks the computer screen and demands a payment. It is stated that the CIA (Central Intelligence Agency) and FBI (Federal Bureau of Investigation) is monitoring 2016 USA presidential election voting and that the victim must pay this ransom to avoid further fines.

   
Lock93 Ransomware

What is Lock93?

Lock93 is a ransomware-type virus that encrypts files and appends the name of each with a ".lock93" extension (e.g., "sample.jpg" is renamed to "sample.jpg.lock93"). Following encryption, Lock93 opens a pop-up window with a ransom-demand message.

   
ANGRY DUCK Ransomware

What is ANGRY DUCK?

ANGRY DUCK is a ransomware-type virus that encrypts files using AES-512 cryptography. During encryption, ANGRY DUCK appends the names of encrypted files with a ".adk" extension. For example, "sample.jpg" is renamed to "sample.jpg.adk". Following successful encryption, ANGRY DUCK also changes the desktop wallpaper.

   
Anubis Ransomware

What is Anubis?

Anubis is ransomware (based on EDA2) that infiltrates systems and encrypts files. During encryption, Anubis appends a ".coded" extension to the name of each encrypted file.

For example, "sample.jpg" is renamed to "sample.jpg.coded". Following successful encryption, Anubis modifies the desktop background and creates a text file ("Decryption Instructions.txt"), placing it on the desktop.

   
Search.conduit.com Redirect (Mac)

What is search.conduit.com?

search.conduit.com is a fake Internet search engine developed by ClientConnect Ltd. Developers claim that search.conduit.com significantly enhances the Internet browsing experience by generating improved search results. These false claims often trick users into believing that search.conduit.com is legitimate.

Be aware, however, that search.conduit.com is promoted using rogue applications download/installation set-ups that hijack web browsers and stealthily modify various options. Furthermore, search.conduit.com continually records information relating to users' Internet browsing activity.

   
Search.wharkike.com Redirect (Mac)

What is search.wharkike.com?

search.wharkike.com is a fake Internet search engine that falsely claims to the improve web browsing experience by generating the most relevant search results.

Many users believe that search.wharkike.com is legitimate and useful, however, this fake search engine monitor users' Internet browsing activity. In addition, developers promote it using deceptive software downloaders/installers that modify web browser settings without consent.

   
MegaBackup Unwanted Application

What is MegaBackup?

MegaBackup is a rogue application claiming to provide a data back-up facility. Initially, this functionality may appear legitimate and useful, however, this app infiltrates systems without users' consent. Therefore, MegaBackup is categorized as a potentially unwanted program (PUP).

   

Page 1999 of 2329

<< Start < Prev 1991 1992 1993 1994 1995 1996 1997 1998 1999 2000 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal