Virus and Spyware Removal Guides, uninstall instructions
What is Black Feather?
Black Feather is ransomware that claims to be an Adobe PDF document. Once the file is opened, victims are presented with an error message stating that the file is damaged and cannot be opened. In fact, Black Feather encrypts files using AES cryptography.
During encryption, Black Feather appends the ".blackfeather" extension to the name of each encrypted file. For instance, encrypted "sample.jpg" is renamed to "sample.jpg.blackfeather". Following successful encryption, Black Feather displays a pop-up and creates a text file ("BLACK_FEATHER.txt", placed on the desktop), containing a ransom-demand message.
Updated variant of this ransomware uses .cryptolocker extension for encrypted files and stores a ransom demanding message in CRYPTOLOCKER.txt file.
What is Dev-Nightmare?
Dev-Nightmare is ransomware-type virus based on Hidden Tear. Following infiltration, Dev-Nightmare encrypts various files and appends the ".2xx9" extension to the name of each encrypted file (for example, encrypted "sample.jpg" is renamed to "sample.jpg.2xx9").
Following successful encryption, Dev-Nightmare generates a text file ("READ_ME.TXT", placed on the desktop) containing a ransom-demand message.
What is tavanero.info?
Identical to chromestart4.ru, searchboro.com, ttczmd.com, and a number of other rogue sites, tavanero.info is a fake Internet search engine claiming to enhance the Internet browsing experience by generating improved search results.
Judging on appearance alone, tavanero.information may seem legitimate, however, this rogue site is promoted using deceptive software download/installation tools that hijack Internet browsers and stealthily modify various options. In addition, tavanero.information continually tracks users' Internet browsing activity by gathering various user/system data.
What is JokeFromMars?
JokeFromMars is ransomware-type malware similar to CTB-Locker (potentially, a new variant). Following infiltration, JokeFromMars encrypts various files stored on the system.
Following successful encryption, JokeFromMars changes the desktop wallpaper, creates a text file ("ReadMeFilesDecrypt!!!.txt") placing it on the desktop, and displays a pop-up window. All contain a ransom-demand message.
What is 'Your personal files are encrypted by CTB-Locker'?
CTB-Locker ransomware virus infiltrates operating systems via infected email messages and fake downloads (for example, rogue video players or fake Flash updates).
After successful infiltration, this malicious program encrypts various files (*.doc, *.docx, *.xls, *.ppt, *.psd, *.pdf, *.eps, *.ai, *.cdr, *.jpg, etc.) stored on computers and demands a ransom payment of $300 (in Bitcoins) to decrypt them (encrypted documents receive the .ctbl files extension).
Cyber criminals responsible for releasing this rogue program ensure that it executes on all Windows operating system versions (Windows XP, Windows Vista, Windows 7, and Windows 8). CTB-Locker ransomware creates AllFilesAreLocked.bmp DecryptAllFiles.txt and [seven random letters].html files within each folder containing the encrypted files.
What is BestCleaner?
BestCleaner is a deceptive application that supposedly improves computer performance by cleaning various junk files. Initially, this functionality may seem legitimate and useful, however, BestCleaner often infiltrates systems without users' permission.
Furthermore, it is likely to gather information relating to Internet browsing activity. For these reasons, this app is categorized as a potentially unwanted program (PUP).
What is workno.ru?
Developers present workno.ru as a legitimate Internet search engine that enhances the Internet browsing experience by generating improved Internet search results.
These claims often trick users into believing that workno.ru is a legitimate and useful site, however, developers promote it via rogue software download and installation set-ups that hijack Internet browsers and modify various options. In addition, workno.ru gathers various information relating to users' Internet browsing activity.
What is searchvvay.com?
Searchvvay.com is a fake Internet search engine identical to walasearch.com, yessearches.com, yoursearching.com, and a number of other bogus sites.
On initial inspection, searchvvay.com may seem legitimate, however, developers promote this site using rogue installation set-ups designed to hijack web browsers and modify their settings. In addition, searchvvay.com continually collects various information about users' web browsing habits.
What is tech-connect.biz?
tech-connect.biz is a rogue site claiming to be a legitimate Internet search engine that enhances the Internet browsing experience by generating improved search results.
These claims often trick users into believing that tech-connect.biz is legitimate, however, this site continually gathers information relating to users' Internet browsing activity. Furthermore, developers promote this site using deceptive software download/installation tools that hijack web browsers and stealthily modify various options.
What is FenixLocker?
FenixLocker is another ransomware-type virus that encrypts files using AES cryptography. During encryption, FenixLocker appends the names of compromised files with the ".centrumfr@india.com" extension (e.g., "sample.jpg" is renamed to "sample.jpg.centrumfr@india.com").
Following successful encryption, FenixLocker creates a text file ("Help to decrypt.txt" or "Cryptolocker.txt"), which contains a ransom-demand message and is placed on the desktop. Updated variants of this ransomware use ".[help24decrypt@cock.li]" and ".help24decrypt@qq.com!!" extensions for encrypted files.
More Articles...
Page 2007 of 2329
<< Start < Prev 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 Next > End >>