Virus and Spyware Removal Guides, uninstall instructions
![NoMercy Stealer](/images/thumbnails/th-24291-nomercy-stealer.jpg)
What is NoMercy Stealer?
NoMercy is a piece of malicious software classified as a stealer. Malware within this classification operates by extracting a wide variety of sensitive information from infected machines. These programs can have a broad range of abilities for stealing data.
![Brute Ratel Malware](/images/thumbnails/th-24281-brute-ratel-malware.jpg)
What is Brute Ratel?
Brute Ratel is a penetration testing tool created after reverse engineering multiple highest quality Endpoint Detection and Response (EDR) and antivirus dynamic-link libraries (DLLs). It is a post-exploitation toolkit designed to avoid detection by EDR and antivirus capabilities. Its license costs $2500 per year for one user.
![HelperProtocol Adware (Mac)](/images/thumbnails/th-24290-helperprotocol-adware-mac.jpg)
What is HelperProtocol?
While inspecting new submissions to VirusTotal, we discovered the HelperProtocol rogue application. After analyzing this piece of software, we learned that it operates as adware and belongs to the AdLoad malware family.
![Now-scan.com Ads](/images/thumbnails/th-24288-now-scan-com-ads.jpg)
What kind of page is now-scan[.]com?
While examining websites that use rogue advertising networks, our team came across the now-scan[.]com website. It is a deceptive page running the "McAfee - Your PC is infected with 5 viruses!" scam. Also, now-scan[.]com asks for permission to show notifications. It is an untrustworthy page that should be ignored.
![Remindexpert.xyz Ads](/images/thumbnails/th-24289-remindexpert-xyz-ads.jpg)
What kind of page is remindexpert[.]xyz?
Remindexpert[.]xyz is a rogue page that our researchers found while inspecting untrustworthy websites. This webpage operates by hosting scams, promoting spam browser notifications, and redirecting visitors to other (likely dubious/malicious) sites.
Most users enter websites like remindexpert[.]xyz through redirects caused by pages that use rogue advertising networks.
![Quick Site Browser Hijacker](/images/thumbnails/th-24286-quick-site-browser-hijacker.jpg)
What kind of application is Quick Site?
While examining deceptive pages, our team has discovered a browser extension called Quick Site. After adding it to a browser, we found that it makes certain changes in the settings. Quick Site hijacks a web browser to promote quicknewtab.com, a fake search engine.
![Pcprotect.name Ads](/images/thumbnails/th-24287-pcprotect-name-ads.jpg)
What kind of page is pcprotect[.]name?
While looking through dubious webpages, our research team found the pcprotect[.]name rogue site. It promotes scams, pushes browser notification spam, and redirects visitors to other (potentially unreliable/harmful) pages.
Users typically enter sites like pcprotect[.]name through redirects caused by webpages that use rogue advertising networks.
![Video Player Adware](/images/thumbnails/th-24284-video-player-adware.jpg)
What kind of application is Video Player?
While inspecting a shady page, our team discovered a browser extension called Video Player. After testing the app, we found that it generates advertisements (it is an advertising-supported application). It is not recommended to have any adware added to a browser, especially if it was downloaded from an untrustworthy source.
![Washedback Ransomware](/images/thumbnails/th-24285-washedback-ransomware.jpg)
What is Washedback ransomware?
Washedback is a piece of malicious software categorized as ransomware. Malware within this category encrypts data and demands ransoms for the decryption. Washedback is part of the Sojusz ransomware family.
On our test system, the Washedback program encrypted files and altered their filenames. To elaborate, the filenames were appended with a unique ID assigned to the victim, the cyber criminals' contact name, and a ".Washedback" extension. For example, a file initially named "1.jpg" appeared as "1.jpg.[a3470ab7d0].[RicardoMilos].Washedback".
Once this process was finished, a text file titled "#HOW_TO_DECRYPT#.txt" was dropped onto the desktop. This file contained the ransom-demanding message.
![DARKY LOCK Ransomware](/images/thumbnails/th-24283-darky-lock-ransomware.jpg)
What kind of malware is DARKY LOCK?
While analyzing the recently submitted samples to the VirusTotal site, our team discovered DARKY LOCK, which is ransomware. DARKY LOCK encrypts files, appends the ".darky" extension to filenames, and creates a ransom note (the "Restore-My-Files.txt" file). We also found that this ransomware is part of the Babuk family.
An example of how files encrypted by DARKY LOCK are renamed: "1.jpg" is renamed to "1.jpg.darky", "2.png" is renamed to "2.png.darky", "3.exe" is renamed to "3.exe.darky", and so forth.
More Articles...
Page 762 of 2357
<< Start < Prev 761 762 763 764 765 766 767 768 769 770 Next > End >>