Virus and Spyware Removal Guides, uninstall instructions

RadianceChecked Adware (Mac)

What is RadianceChecked?

While investigating new submissions to VirusTotal, our research team discovered the RadianceChecked app. After analyzing this application, we determined that it is adware belonging to the AdLoad malware family.

   
Ocean Saver Browser Hijacker

What kind of application is Ocean Saver?

Upon conducting tests on the Ocean Saver browser extension, we determined that it is a browser hijacker developed to promote oceansaver.net, a fake search engine. This extension achieves this objective by modifying a web browser's settings. Typically, users download and install/add browser hijackers unintentionally.

   
Lilmoon Ransomware

What kind of malware is Lilmoon?

Lilmoon is ransomware belonging to the VoidCrypt family. We discovered Lilmoon while analyzing malware samples submitted to VirusTotal. In addition to encrypting data, Lilmoon appends the victim's ID, encrypt.ns@gmail.com email address, and the ".lilmoon" extension to filenames and creates a ransom note (the "Dectryption-guide.txt" file).

An example of how Lilmoon modifies filenames: it renames "1.jpg" to "1.jpg.[MJ-KN1806473259](encrypt.ns@gmail.com).lilmoon", "2.png" to "2.png.[MJ-KN1806473259](encrypt.ns@gmail.com).lilmoon", and so forth.

   
Ssaw Ransomware

What is Ssaw ransomware?

Our researchers discovered the Ssaw ransomware during a routine inspection of new submissions to VirusTotal. Ransomware is designed to encrypt data and demand payment for its decryption.

After we launched a sample of Ssaw on our test machine, it encrypted files and appended their filenames with a ".ssaw" extension. For example, a file originally named "1.jpg" appeared as "1.jpg.ssaw", "2.png" as "2.png.ssaw", etc. Once this process was finished, the ransomware changed the desktop wallpaper and created a file titled "как расшифровать файлы.txt". Both the wallpaper and text file contained identical ransom notes in Russian.

It is pertinent to mention that the wallpaper depicted the doll used by the Jigsaw Killer in the Saw movie franchise, and the ransom notes contained a play on a famous quote from this franchise – "I want to play a game". It must be stressed that the Ssaw ransomware is not associated with these films or any other related individuals or entities.

   
AssistiveBalance Adware (Mac)

What kind of application is AssistiveBalance?

During our testing of the AssistiveBalance application, our team identified that it displays aggressive and unwanted advertisements. Due to this behavior, we have classified AssistiveBalance as adware, which refers to software that is designed to generate revenue by displaying advertisements. Typically, users install adware without realizing it.

   
Qotr Ransomware

What kind of malware is Qotr?

Qotr, a variant belonging to the Djvu ransomware family, encrypts data and adds the ".qotr" extension to filenames. Qotr creates a "_readme.txt" file to provide contact and payment information. As an illustration of its file renaming method, Qotr changes "1.jpg" to "1.jpg.qotr", "2.png" to "2.png.qotr", and so forth.

Typically, Djvu ransomware is distributed alongside information stealers like RedLine or Vidar. Cybercriminals first steal sensitive data from compromised systems before proceeding to encrypt files. Our team found Qotr ransomware while examining malware samples submitted to VirusTotal.

   
Quick Video Find Adware

What is Quick Video Find?

Our research team discovered the Quick Video Find browser extension during a routine investigation of untrustworthy websites. Quick Video Find promises the functionality of providing easy access to free downloads of audio/video from browsed websites. However, after inspecting this extension, we determined that it operates as advertising-supported software (adware).

   
Hockey Start Browser Hijacker

What is Hockey Start?

While investigating suspicious websites, our researchers found one endorsing the Hockey Start browser extension. It is presented as a tool for quick access to hockey sports related online content.

However, after we analyzed this extension, we determined that it changes browser settings to promote the search.nstart.online fake search engine. Due to this behavior, Hockey Start is classified as a browser hijacker.

   
Music Adware

What kind of application is "Music"?

Our research team discovered the Music application while inspecting suspicious websites. After investigating this app, we determined that it is advertising-supported software (adware). In other words, Music operates by running intrusive advertisement campaigns.

   
Finder-search.com Redirect

What is finder-search.com?

Finder-search.com is the address of a fake search engine. Websites of this type usually cannot provide search results, and while finder-search.com can – they are likely to include unrelated and deceptive content. Illegitimate search engines are commonly promoted (through redirects) by browser hijackers. Additionally, these sites and software typically collect sensitive user data.

   

Page 588 of 2362

<< Start < Prev 581 582 583 584 585 586 587 588 589 590 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal