Virus and Spyware Removal Guides, uninstall instructions

Internal-scanning.com Ads

What kind of page is internal-scanning[.]com?

Internal-scanning[.]com is a rogue page that runs scams, promotes browser notification spam, and redirects visitors to other (likely unreliable/dangerous) sites.

Our researchers discovered this untrustworthy webpage while inspecting websites that use rogue advertising networks. Typically, pages like internal-scanning[.]com are accessed via redirects caused by sites that are monetized through said networks.

   
CMLOCKER Ransomware

What is CMLOCKER ransomware?

Our researchers discovered the CMLOCKER ransomware-type program while investigating new submissions to VirusTotal. It operates by encrypting data and demanding ransoms for the decryption keys/tools.

After we executed a sample of CMLOCKER on our test machine, it encrypted files and appended their filenames with a ".CMLOCKER" extension. For example, a file titled "1.jpg" appeared as "1.jpg.CMLOCKER", "2.png" as "2.png.CMLOCKER", and so on.

Once this process was finished, a ransom-demanding message named "HELP_DECRYPT_YOUR_FILES.txt" was created.

   
AMERICAN GLOBAL TRADE Email Scam

What kind of email is "AMERICAN GLOBAL TRADE"?

While investigating this email, we found that it is a scam email written by scammers who aim to lure unsuspecting recipients into opening the attached file. Scammers disguised this email as a letter from a company called AMERICAN GLOBAL TRADE regarding a new purchase order. It is strongly recommended to ignore such emails and, more importantly, leave files in them unopened.

   
Powersoftwarepc.com Ads

What kind of website is powersoftwarepc[.]com?

We examined powersoftwarepc[.]com and learned that it is a deceptive page running the "McAfee - Your PC is infected with 5 viruses!" scam. Additionally, this website wants to show notifications. Our team discovered powersoftwarepc[.]com while analyzing shady web pages that use rogue advertising networks.

   
RONALDIHNO ENCRYPTER Ransomware

What kind of malware is RONALDIHNO ENCRYPTER?

RONALDIHNO ENCRYPTER is ransomware - a type of malware that uses cryptography to encrypt files (to make them inaccessible). Also, this particular ransomware appends the ".r7" extension to filenames, changes the desktop wallpaper, and creates the "READ_THIS.txt" (a ransom note). We discovered RONALDIHNO ENCRYPTER while inspecting malware samples submitted to VirusTotal.

An example of how RONALDIHNO ENCRYPTER ransomware modifies filenames: it renames "1.jpg" to "1.jpg.r7", "2.png" to "2.png.r7", "3.exe" to "3.exe.r7", and so forth.

   
Power-stability.com Ads

What kind of page is power-stability[.]com?

While checking out suspicious websites, our researchers discovered the power-stability[.]com rogue page. It promotes deceptive material, pushes spam browser notifications, and redirects users elsewhere (likely untrustworthy/malicious sites).

Most visitors to power-stability[.]com and similar webpages enter them through redirects caused by sites using rogue advertising networks.

   
Webprotectionsurveys.live Ads

What kind of page is webprotectionsurveys[.]live?

Webprotectionsurveys[.]live is a rogue site that our researchers found while inspecting dubious webpages. It operates by running scams, promoting spam browser notifications, and redirecting visitors to other (likely untrustworthy/harmful) websites.

Users typically enter pages like webprotectionsurveys[.]live through redirects caused by websites that use rogue advertising networks.

   
New Order Email Scam

What kind of scam is "New Order"?

While investigating this email, we found that it is a scam email. Scammers behind it aim to trick recipients into opening a phishing website and providing information on it. The email is disguised as an inquiry letter regarding some order. This email should be ignored, and its hyperlink should be left unopened.

   
Text to Google Maps Adware

What kind of application is Text to Google Maps?

Text to Google Maps is described as a tool allowing users to send the selected text to Google Maps (search for selected location/address in Google Maps). However, while testing this browser extension, we found that unwanted advertisements appear while it is added to a browser. Thus, we classified Text to Google Maps as adware.

   
Tuow Ransomware

What kind of malware is Tuow?

Tuow is a Djvu ransomware that encrypts files, appends its extension (".tuow") to filenames, and creates a text file ("_readme.txt") containing a ransom note. Victims cannot access/use encrypted files until they are decrypted. Our malware researchers discovered Tuow ransomware while inspecting malware samples submitted to VirusTotal.

An example of how Tuow ransomware modifies filenames: it renames "1.jpg" to "1.jpg.tuow", "2.png" to "2.png.tuow", "3.exe" to "3.exe.tuow", and so forth. It is important to mention that some threat actors distribute Djvu ransomware alongside information stealers (e.g., Vidar and RedLine).

   

Page 685 of 2359

<< Start < Prev 681 682 683 684 685 686 687 688 689 690 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal