Virus and Spyware Removal Guides, uninstall instructions

Nullbyte Ransomware

What is Nullbyte?

Nullbyte is a ransomware-type virus (previous variants: DetoxCrypto, Serpico) that infiltrates the system and encrypts a variety of stored files.

During encryption, Nullbyte appends names of encrypted files with the "_nullbyte" extension (for example, "sample.jpg" is renamed to "sample.jpg_nullbyte"). Following successful encryption, Nullbyte displays a pop-up window that contains a ransom-demand message. This ransomware is distributed via a fake Pokemon Go bot application called NecroBot.

   
Safe-web.tk Redirect

What is safe-web.tk?

safe-web.tk is a rogue website claiming to be a legitimate search engine that supposedly generates improved search results, and provides a 'result-filtering' feature allowing users to search within certain websites only.

This functionality may seem legitimate and useful, however, developers promote safe-web.tk using a deceptive marketing method called "bundling". Furthermore, safe-web.tk continually monitors users' Internet browsing activity.

   
Chromestart4.ru Redirect

What is chromestart4.ru?

According to the developers, chromestart4.ru/i/rt4.html is a legitimate Internet search engine that greatly improves Internet browsing by generating the most relevant search results. These claims often trick users into believing that chromestart4.ru is legitimate, however, this website records various information regarding users' web browsing activity.

In addition, developers promote chromestart4.ru using deceptive software download/installation set-ups that hijack web browsers and stealthily modify various options (the bundling method).

   
Ustarts.xyz Redirect

What is ustarts.xyz?

ustarts.xyz is a fake Internet search engine. By claiming to generate improved search results, ustarts.xyz attempts to give the impression of legitimacy.

Be aware, however, that developers promote this rogue site using deceptive software downloaders/installers that hijack Internet browsers and stealthily modify various options. In addition, ustarts.xyz gathers various data relating to web browsing activity.

   
Blankpage3.ru Redirect

What is blackpage3.ru?

Identical to ttczmd.com, mystartpage1.ru, wzscnet.com, and a number of other rogue sites, blackpage3.ru/i/start.html is fake Internet search engine that falsely claims to enhance the web browsing experience by generating improved search results. 

These claims often trick users into believing that blackpage3.ru is legitimate, however, this site gathers various information relating to users' web browsing activity. Furthermore, developers promote it using deceptive software download/installation set-ups that hijack web browsers and modify various options without consent.

   
Cerber3 Ransomware

What is Cerber3?

Cerber3 is an updated version of Cerber - high-risk ransomware-type malware. Following successful infiltration, Cerber3 encrypts files, generates random file names (10 characters), and appends the ".cerber3" extension to the name of each encrypted file. For example, "sample.jpg" might be renamed to "G0s-4kha_J.cerber3".

The desktop wallpaper is then modified and three files created: "# HELP DECRYPT #.html", "# HELP DECRYPT #.txt", and "# HELP DECRYPT #.url". Newer variants of this ransomware use "@__README__@.html", "@__README__@.txt" and "@__README__@.url".

While the ".txt" and ".html" files contain identical ransom-demand messages, the ".url" file redirects victims to the Cerber3 payment website. To restore their files, victims must pay a ransom.

   
Tab4you.com Redirect

What is tab4you.com?

tab4you.com is a deceptive website that claims to be a legitimate Internet search engine generating improved search results and displaying local weather forecasts, current time, and allowing creation of 'to-do' lists.

Some users believe that tab4you.com is a legitimate and useful website, however, developers promote this website via deceptive software downloaders/installers that hijack Internet browsers and modify various options. In addition, tab4you.com continually monitors users' Internet browsing activity by gathering various user/system data.

   
JohnyCryptor Ransomware [Updated]

What is JohnyCryptor?

JohnyCryptor is another ransomware-type virus that stealthily infiltrates systems and encrypts stored files. During encryption, JohnyCryptor generates a "How to decrypt your files.txt" file, placing it on the desktop. It also changes the desktop background. This behavior is common to ransomware-type malware.

   
Serpico Ransomware

What is Serpico?

Serpico is a new variant of DetoxCrypto ransomware. Unlike DetoxCrypto, however, Serpico does not use PokemonGo video game images to trick users into running malicious files. Following infiltration, Serpico encrypts various data types (for example, .jpg, .docx, .ppt, .psd, etc.) stored on the computer.

Unlike many other ransomware-type viruses, Serpico does not change names of encrypted files in any way. Thus, it is often difficult to determine which files are encrypted. Following successful encryption, Serpico opens a window that contains a ransom-demand message.

   
Ads by TribalAd PPC Ad Network

What is TribalAd PPC Ad Network?

TribalAd PPC Ad Network is a legitimate advertising network, however, research shows that associated advertisements are often displayed by various potentially unwanted adware-type programs (PUPs). By falsely claiming to provide 'useful functions' PUPs often attempt to give the impression of legitimacy.

In fact, these apps often infiltrate systems without users' permission. Furthermore, adware continually monitors users' Internet browsing activity and delivers various intrusive online advertisements.

   

Page 2013 of 2329

<< Start < Prev 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal