Virus and Spyware Removal Guides, uninstall instructions
What is DASHA ransomware?
While investigating new malware submissions to VirusTotal, our research team discovered a variant of Eternity ransomware called DASHA.
After we launched a sample of DASHA ransomware on our test machine, it encrypted files and appended their filenames with a ".ecrp" extension. To elaborate, a file originally named "1.jpg" appeared as "1.jpg.ecrp", "2.png" as "2.png.ecrp", "3.exe" as "3.exe.ecrp", etc.
Once the encryption process was completed, this ransomware changed the desktop wallpaper and displayed a pop-up window. Both the wallpaper and pop-up contained DASHA's ransom notes.
What is VanillaRAT?
VanillaRAT is a piece of malicious software written in the C# programming language. It is categorized as a RAT (Remote Access Trojan). Malware within this category enables remote access and control over infected devices. These trojans tend to be particularly multifunctional, with features ranging from command execution to data extraction. Therefore, the threats posed by RATs are incredibly varied.
What is TotalResults?
While inspecting the contents of a fake Adobe Flash Player installer, our researchers discovered the TotalResults rogue application. After analyzing this app, we determined that it is adware belonging to the AdLoad malware family.
What is PremiumContinental?
PremiumContinental is an adware-type application that our research team discovered while inspecting new submissions to VirusTotal. It runs intrusive advertisement campaigns (displays ads) and likely collects private data. Additionally, PremiumContinental is part of the AdLoad malware family.
What kind of email is "Renewing The Domain"?
After inspecting the "Renewing The Domain" email, we determined that it is spam. The letter claims that a domain owned by the recipient is being renewed, and unless the email is backed up - disruptions in the mail service and data loss may occur. This email urges recipients to back up their email by following the provided link, which redirects to a phishing website that targets email account log-in credentials.
What is Mega Colors?
Our research team discovered the Mega Colors browser extension while inspecting questionable software-promoting webpages. This extension is endorsed as a tool capable of changing website background colors. Our analysis of Mega Colors revealed that it operates as advertising-supported software (adware) instead.
What is HIP1 ransomware?
HIP1 is a ransomware-type program that our researchers discovered while inspecting new submissions to VirusTotal. This malicious program belongs to the VoidCrypt ransomware family.
When we launched a sample of HIP1 on our test system, it encrypted files and appended their filenames with a unique ID, the cyber criminals' email address, and a ".HIP1" extension. For example, a file titled "1.jpg" appeared as "1.jpg[ID=J7rtO3-Mail=FreedomTeam@mail.ee].HIP1", etc. Afterward, this ransomware created a ransom note named "Read_Me!_.txt".
What is LevelNight?
During a routine investigation of new submissions to VirusTotal, our researchers discovered the LevelNight rogue application. After analyzing this app, we determined that it works as advertising-supported software (adware). Furthermore, it is noteworthy that LevelNight is part of the AdLoad malware family.
What is "Google Docs email scam"?
"Google Docs email scam" refers to scam campaigns that contain phishing attachments claiming to allow access to securely-stored files on Google Docs. The documents attached to these scam letters promote phishing websites, which typically target email account log-in credentials.
The invoice-related fake "Focke & Co" email (image below) is an example of "Google Docs email scam".
What kind of page is mytopwords[.]com?
While inspecting untrustworthy sites, our research team found the mytopwords[.]com rogue webpage. It is designed to deceive visitors into enabling spam browser notification delivery. Additionally, this site can lead users to other (likely unreliable/hazardous) websites.
Pages like mytopwords[.]com are typically accessed via redirects caused by websites that use rogue advertising networks.
More Articles...
Page 721 of 2358
<< Start < Prev 721 722 723 724 725 726 727 728 729 730 Next > End >>