Virus and Spyware Removal Guides, uninstall instructions
![Cleanmode.xyz Redirect](/images/thumbnails/th-26205-cleanmode-xyz-redirect.jpg)
What is cleanmode.xyz?
Cleanmode.xyz is the address of a fake search engine. Sites within this classification cannot provide search results and redirect to legitimate ones. Illegitimate search engines are typically promoted (via redirects) by browser hijackers. These sites and the software endorsing them tend to collect user information.
![STAR VS THE FORCES OF EVIL Ransomware](/images/thumbnails/th-26203-star-vs-the-forces-of-evil-ransomware.jpg)
What kind of malware is STAR VS THE FORCES OF EVIL?
STAR VS THE FORCES OF EVIL is ransomware we discovered while checking the VirusTotal page for recently submitted malware samples. STAR VS THE FORCES OF EVIL encrypts files, appends the ".STARVSTHEFORCESOFEVIL" extension to filenames, and drops the "how_to_back_files.html" file (a ransom note).
An example of how STAR VS THE FORCES OF EVIL renames files: it changes "1.jpg" to "1.jpg.STARVSTHEFORCESOFEVIL", "2.png" to "2.png.STAR VS THE FORCES OF EVIL", and so forth.
![eLiteSort Malware](/images/thumbnails/th-26197-elitesort-malware.jpg)
What is eLiteSort?
Our research team discovered the eLiteSort malicious program during a routine inspection of deceptive websites. The installer promoting this program also installed the Info adware on our test machine. Therefore, it is highly likely that if eLiteSort is detected on the system – other unwanted/harmful content is present as well.
![Info Adware](/images/thumbnails/th-26198-info-adware.jpg)
What kind of application is Info?
While checking out rogue websites, our research team found an installation setup containing an adware-type application named Info. It is pertinent to mention that said installer was also bundled with the eLiteSort malware.
![Nowcaptchahere.top Ads](/images/thumbnails/th-26202-nowcaptchahere-top-ads.jpg)
What kind of page is nowcaptchahere[.]top?
Our team has concluded that nowcaptchahere[.]top is an unreliable website that shows a deceptive message to trick visitors into consenting to receive notifications. It is common for individuals to access websites like nowcaptchahere[.]top accidentally. We found nowcaptchahere[.]top while examining other dubious pages.
![Coaq Ransomware](/images/thumbnails/th-26201-coaq-ransomware.jpg)
What kind of malware is Coaq?
During our examination of malware samples submitted to VirusTotal, we came across a variation of Djvu ransomware known as Coaq. This version encrypts files and adds the ".coaq" extension to their names. Moreover, Coaq also creates a ransom note file named "_readme.txt".
Since Coaq is associated with Djvu ransomware, it could be disseminated with other malware like RedLine, Vidar, or other types of data-stealing malware. An example of how Coaq alters file names: "1.jpg" becomes "1.jpg.coaq", "2.png" becomes "2.png.coaq", and so on.
![Cosw Ransomware](/images/thumbnails/th-26200-cosw-ransomware.jpg)
What kind of malware is Cosw?
Our investigation of malware samples uploaded to VirusTotal has uncovered a new version of the Djvu ransomware dubbed Cosw. Its primary aim is to encrypt files on the infected computer and rename them with by appending the ".cosw" extension. Cosw also creates a file named "_readme.txt", which contains instructions on how to pay a ransom to obtain a decryption tool.
It is worth noting that Cosw may be distributed alongside information stealers such as RedLine or Vidar. As an example of how Cosw renames files: it changes "1.jpg" to "1.jpg.cosw" "2.png" to "2.png.cosw" and so on.
![Carver Ransomware](/images/thumbnails/th-26199-carver-ransomware.jpg)
What is Carver ransomware?
While inspecting new submissions to VirusTotal, our researchers discovered Carver – a malicious program belonging to the Phobos ransomware family. Malware within this category is designed to encrypt data and demand ransoms for its decryption.
After we executed a sample of Carver on our test machine, it encrypted files and altered their filenames. To elaborate, original filenames were appended with a unique ID, the cyber criminals' email address, and a ".Carver" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.id[9ECFA84E-3455].[ineedatool@rape.lol].Carver".
Once the encryption was finished, Carver ransomware created two ransom notes "info.hta" (pop-up window) and "info.txt".
![ImBetter Stealer](/images/thumbnails/th-26196-imbetter-stealer.jpg)
What kind of malware is ImBetter?
ImBetter is the name of an information-stealing malware. Stealers can extract a wide variety of sensitive information from systems and installed applications. ImBetter has been actively spread via malicious websites disguised as ones relating to cryptocurrency and those offering online file format conversion services.
![CD Collection Malware](/images/thumbnails/th-26188-cd-collection-malware.jpg)
What is CD Collection?
While investigating rogue websites, our research team discovered an installer bundled with the CD Collection malicious program. If CD Collection is detected on the system, it is highly likely that adware and/or other unwanted/malicious content has infiltrated it as well.
More Articles...
Page 581 of 2362
<< Start < Prev 581 582 583 584 585 586 587 588 589 590 Next > End >>