Virus and Spyware Removal Guides, uninstall instructions
What is ExploreTransaction?
During a routine inspection of new submissions to VirusTotal, our research team discovered the ExploreTransaction application. After analyzing this app, we determined that it operates as advertising-supported software (adware) and belongs to the AdLoad malware family.
What kind of malware is Yanluowang?
Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the "README.txt" file containing a ransom note. It appends the ".yanluowang" extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector.
Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
An example of how Yanluowang renames files: it changes "1.jpg" to "1.jpg.yanluowang", "2.png" to "2.png.yanluowang", and so forth. Yanluowang used the RSA-1024 asymmetric algorithm for encryption.
What kind of malware is Dkrf?
We found a new ransomware called Dkrf while examining malware samples submitted to VirusTotal. It was found that Dkrf is part of the Djvu ransomware family. The purpose of Dkrf is to encrypt files. Additionally, it renames files by appending the ".dkrf" extension to filenames and creates the "_readme.txt" file (a ransom note).
An example of how files encrypted by Dkrf are renamed: "1.jpg" is renamed to "1.jpg.dkrf", "2.png" to "2.png.dkrf", and so forth.
What kind of malware is Eiur?
Eiur is the name of ransomware belonging to a ransomware family called Djvu. We have discovered Eiur during our analysis of malicious installers distributed using deceptive pages. It was found that this ransomware encrypts files, appends the ".eiur" extension to filenames, and provides a ransom note (creates the "_readme.txt" file).
An example of how Eiur modifies filenames: it renames "1.jpg" to "1.jpg.eiur", "2.png" to "2.png.eiur", "3.exe" to "3.exe.eiur", and so forth.
What kind of page is resourceslatest[.]com?
We discovered the resourceslatest[.]com rogue webpage while inspecting unreliable sites. It operates by promoting scams, pushing browser notification spam, and redirecting visitors to different (likely dubious/malicious) sites.
Users typically enter resourceslatest[.]com and similar pages via redirects caused by websites using rogue advertising networks.
What is REVENLOCK ransomware?
REVENLOCK is a ransomware-type program we discovered while inspecting new submissions to VirusTotal. We determined that this program is part of the MedusaLocker ransomware family.
REVENLOCK encrypts files and appends their filenames with an extension. The variant we executed on our test system appended files with ".REVENLOCK7". For example, a file initially titled "1.jpg" appeared as "1.jpg.REVENLOCK7", "2.png" as "2.png.REVENLOCK7", etc. It is noteworthy that the number in the extension may vary depending on REVENLOCK's version.
Once the encryption was completed, a ransom note - "HOW_TO_RECOVER_DATA.html" - was dropped onto the desktop. Based on the message within, we can surmise that REVENLOCK targets companies rather than home users.
What is DeliteOutward?
DeliteOutward is a rogue app that our researchers found while checking out new submissions to VirusTotal. After analyzing this application, we discovered that it operates as advertising-supported software (adware) and belongs to the AdLoad malware family.
What kind of page is defendyourfiles[.]com?
Defendyourfiles[.]com is a rogue website that our researchers discovered while inspecting untrustworthy webpages. This page operates by hosting deceptive content, promoting browser notification spam, and redirecting visitors to other (likely dubious/malicious) sites.
Most users access defendyourfiles[.]com and webpages akin to it through redirects caused by sites using rogue advertising networks.
What kind of page is reserve-availability[.]cfd?
Reserve-availability[.]cfd is an untrustworthy page that runs a scam similar to "McAfee - Your PC is infected with 5 viruses!". Also, it asks visitors for permission to show notifications. Our team has discovered reserve-availability[.]cfd while examining other pages that use rogue advertising networks.
What kind of malware is DeadLocker?
DeadLocker is the name of ransomware discovered by MalwareHunterTeam. It was found that DeadLocker encrypts files, appends the ".deadlocked" extension to filenames, changes the desktop wallpaper, and displays a pop-up (a ransom note).
An example of how DeadLocker renames files: it changes "1.jpg" to "1.jpg.deadlocked", "2.png" to "2.png.deadlocked", and so forth.
More Articles...
Page 768 of 2357
<< Start < Prev 761 762 763 764 765 766 767 768 769 770 Next > End >>