Virus and Spyware Removal Guides, uninstall instructions
![Editortrip.com Ads](/images/thumbnails/th-26809-editortrip-com-ads.jpg)
What kind of page is editortrip[.]com?
Editortrip[.]com is a rogue page that our research team discovered while inspecting questionable websites. It operates by promoting browser notification spam and redirecting visitors to other (likely untrustworthy/hazardous) sites. Most users enter webpages like editortrip[.]com via redirects generated by sites using rogue advertising networks.
![Mediatesupervis.com Ads](/images/thumbnails/th-26808-mediatesupervis-com-ads.jpg)
What kind of page is mediatesupervis[.]com?
After analyzing mediatesupervis[.]com, we discovered that the page employs a deceitful tactic to entice visitors into granting permission for notifications. We also observed that mediatesupervis[.]com redirects users to other questionable websites. As a result, it is strongly recommended to refrain from visiting mediatesupervis[.]com or any sites accessed through it.
![Your Account Is Successfully Debited POP-UP Scam](/images/thumbnails/th-26807-your-account-is-successfully-debited-pop-up-scam.jpg)
What kind of scam is "Your Account Is Successfully Debited"?
Our analysis of this page revealed that it presents a fabricated system scan and employs deceptive tactics to coerce users into contacting a fraudulent technical support number. These scams, known as pop-up scams, often masquerade as legitimate websites and are utilized by scammers to engage in malicious activities.
![OBSIDIAN ORB Ransomware](/images/thumbnails/th-26806-obsidian-orb-ransomware.jpg)
What kind of malware is OBSIDIAN ORB?
While reviewing new submissions to VirusTotal, our researchers discovered yet another malicious program based on the Chaos ransomware – called OBSIDIAN ORB. Malware within this classification is designed to encrypt data and demand ransoms for its decryption.
On our testing system, OBSIDIAN ORB ransomware encrypted files and appended their filenames with an extension consisting of four random characters. For example, a file initially titled "1.jpg" appeared as "1.jpg.q3uk". Afterwards, OBSIDIAN ORB changed the desktop wallpaper and created a ransom note named "read_It.txt".
![Guerilla Malware (Android)](/images/thumbnails/th-26799-guerilla-malware-android.jpg)
What kind of malware is Guerilla?
Guerilla is the name of a malware that targets Android devices. Previous iterations of this malicious software operated predominantly as adware. Specifically, the program functioned by stealthily clicking advertisements – thus generating revenue for its developers via affiliate programs and similar mechanisms.
However, in the latest activity, Guerilla expanded to encompass stealer and backdoor/loader capabilities. The most alarming facet of this new activity is that this malware arrives pre-installed on Android devices.
At the time of writing, the exact distribution chain of the infected devices is uncertain. The number of compromised machines could exceed nine million and range from Android smartphones to smartwatches. The activity is global, with the most affected countries including the USA, Mexico, Indonesia, Thailand, and Russia.
Evidence links Guerilla malware with a threat actor dubbed Lemon Group (currently rebranded as "Durian Cloud SMS"). This group is connected to a variety of businesses relating to advertising and marketing.
![Newsfeedhome.com Ads](/images/thumbnails/th-26805-newsfeedhome-com-ads.jpg)
What kind of page is newsfeedhome[.]com?
After analyzing newsfeedhome[.]com, our team discovered that the website employs a deceptive tactic by displaying a misleading message to manipulate visitors into granting permission for notifications. Additionally, newsfeedhome[.]com redirects users to other websites that employ clickbait techniques in order to obtain consent for displaying notifications.
![Sembilme.com Ads](/images/thumbnails/th-26804-sembilme-com-ads.jpg)
What kind of pag is sembilme[.]com?
In our examination of websites employing deceitful advertising networks, we encountered sembilme[.]com, a deceptive website. Users who visit this site are confronted with misleading information (a fake CAPTCHA), aiming to deceive them into accepting notifications. Moreover, accessing sembilme[.]com may lead to other dubious websites.
![Itlock (MedusaLocker) Ransomware](/images/thumbnails/th-26803-itlock-medusalocker-ransomware.jpg)
What kind of malware is Itlock?
Itlock is one of the ransomware variants belonging to the MedusaLocker family. Our malware researchers discovered it while checking the VirusTotal page for recently submitted samples. Itlock encrypts files, appends the ".itlock20" extension to filenames (the number in the extension can vary), and provides its ransom note ("How_to_back_files.html").
An example of how Itlock modifies filenames: it changes "1.jpg" to "1.jpg.itlock20", "2.png" to "2.png.itlock20", and so forth.
![Post And Search Browser Hijacker](/images/thumbnails/th-26802-post-and-search-browser-hijacker.jpg)
What kind of software is Post and Search?
Our research team discovered the Post and Search browser extension during a routine investigation of dubious websites. After we analyzed this extension, we determined that it is a browser hijacker. Post and Search makes modifications to browser settings in order to cause redirects to the find.tnav-now.com fake search engine.
![Galaxy Search Browser Hijacker](/images/thumbnails/th-26801-galaxy-search-browser-hijacker.jpg)
What kind of software is Galaxy Search?
While investigating suspicious sites, our research team discovered the Galaxy Search browser extension. It is endorsed as an extension that displays galaxy/space themed browser wallpapers. However, Galaxy Search operates as a browser hijacker, i.e., it alters browser settings to promote (via redirects) the find.nseeknow.com fake search engine.
More Articles...
Page 524 of 2364
<< Start < Prev 521 522 523 524 525 526 527 528 529 530 Next > End >>