Virus and Spyware Removal Guides, uninstall instructions

TursiopsTruncatus Malicious Extension

What is TursiopsTruncatus?

While checking the TursiopsTruncatus browser extension, we found troubling activities like adding the "Managed by your organization" feature to Chrome settings and collecting data. Our encounter with TursiopsTruncatus occurred when we investigated a harmful installer downloaded from an unreliable page.

   
Product Request Email Scam

What kind of email is "Product Request"?

After examining the "Product Request" email, we determined that it is spam. This message claims to contain documentation regarding an urgent purchase. The attachment is a phishing file targeting email account log-in credentials.

   
Grounding Conductor Ransomware

What kind of malware is Grounding Conductor?

During our inspection of malware samples uploaded to VirusTotal, our team discovered a ransomware variant dubbed Grounding Conductor. The purpose of Grounding Conductor is to prevent victims from accessing their files by zipping and encrypting them. Additionally, this ransomware places a ransom note (named "readme.txt") within ZIP files.

Also, Grounding Conductor renames files. It leaves the original filename and appends the victim's ID, and ".Grounding Conductor.zip" to names. For instance, it renames "1.jpg" to "1.jpg.{B9A9FF03-F898-813E-2B13-9DA770161220}.Grounding Conductor.zip", "2.png" to "2.png.{B9A9FF03-F898-813E-2B13-9DA770161220}.Grounding Conductor.zip", etc.

   
S4b Ransomware

What kind of malware is S4b?

Our researchers found the S4b ransomware-type program while investigating new malware submissions to the VirusTotal website. This program is part of the Phobos ransomware family. S4b is designed to encrypt data and demand payment for its decryption.

On our test machine, this ransomware encrypted files and renamed them. Original titles were appended with a unique ID, the cyber criminals' email address, and a ".s4b" extension. For example, a file named "1.jpg" appeared as "1.jpg.id[9ECFA84E-3449].[submarine@cyberfear.com].s4b".

Once the encryption process was completed, ransom notes were created/displayed in a pop-up window ("info.hta") and text file ("info.txt").

   
MyWallPaper Browser Hijacker

What kind of application is MyWallPaper?

While assessing the MyWallPaper, it became apparent that its primary goal is to operate as a browser hijacker, with the objective of endorsing mywallpaper.co, a fraudulent search engine. This extension modifies web browser settings to establish control over it. To avoid potential damage, users with browsers hijacked by MyWallPaper should remove the app as soon as possible.

   
LavandulaAngustifolia Malicious Extension

What is LavandulaAngustifolia?

During our assessment of the LavandulaAngustifolia browser extension, we identified concerning actions, such as enabling the "Managed by your organization" feature in Chrome browsers, controlling specific browser components, and gathering data. Our interaction with LavandulaAngustifolia took place while probing a harmful installer obtained from an untrustworthy source.

   
Rzew Ransomware

What kind of malware is Rzew?

While reviewing malware samples on the VirusTotal platform, we encountered the Rzew ransomware, which belongs to the Djvu family. When this ransomware infects a computer, it encrypts files and adds the ".rzew" extension to their filenames. For example, "1.jpg" would be transformed into "1.jpg.rzew" and "2.png" would become "2.png.rzew".

In addition to encrypting files, Rzew creates a ransom note, a text file named "_readme.txt". Furthermore, the distribution of Rzew might involve information stealers such as Vidar and RedLine.

   
Release All Of Your Held Messages Email Scam

What is "Release All Of Your Held Messages"?

After careful analysis, our team has determined that the objective of this email is to deceive recipients into disclosing their personal information. These emails are classified as phishing attempts, where the senders, who are fraudulent actors, seek to trick recipients into sharing sensitive information on fraudulent websites.

   
Crystalchiseler.top Ads

What kind of page is crystalchiseler[.]top?

Crystalchiseler[.]top is a rogue webpage that our research team found while checking out untrustworthy sites. This page is designed to deceive visitors into allowing its spam browser notification delivery. It can also generate redirects to other (likely dubious/malicious) websites.

Users predominantly access webpages like crystalchiseler[.]top through redirects caused by sites employing rogue advertising networks.

   
ParameterLog Adware (Mac)

What kind of application is ParameterLog?

Our researchers discovered the ParameterLog app while investigating new submissions to the VirusTotal site. After inspecting this piece of software, we learned that it is adware belonging to the AdLoad malware family.

   

Page 444 of 2372

<< Start < Prev 441 442 443 444 445 446 447 448 449 450 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal