Virus and Spyware Removal Guides, uninstall instructions

Pay Ransomware

What is Pay ransomware?

Pay is the name of a ransomware-type program that our research team discovered while inspecting new submissions to VirusTotal. We determined that this program is part of the Xorist ransomware family.

After we executed a sample of Pay ransomware on our test system, it encrypted files and appended their filenames with a ".Pay" extension. For example, a file originally named "1.jpg" appeared as "1.jpg.Pay", "2.png" as "2.png.Pay", and so on.

Once the encryption process was completed, this ransomware displayed a pop-up window and created a text file titled "HOW TO DECRYPT FILES.txt". Both of these messages contain identical ransom notes.

   
Shieldproblocker.xyz POP-UP Scam (Mac)

What kind of page is shieldproblocker[.]xyz?

Shieldproblocker[.]xyz is a deceptive website that uses a scare tactic to trick visitors into downloading an application. It displays a fake system notification claiming that a device has been compromised. Our team has discovered shieldproblocker[.]xyz while inspecting other sites that use rogue advertising networks.

   
Hacker Crypt2020 Ransomware

What is Hacker Crypt2020 ransomware?

During a routine inspection of new malware submissions, our researchers found a new ransomware-type program from the Xorist family - called Hacker Crypt2020.

After a sample of this ransomware was launched on our test machine, it encrypted files and appended their filenames with a ".hacker crypt2020.data" extension. For example, a file initially named "1.jpg" appeared as "1.jpg.hacker crypt2020.data", "2.png" appeared as "2.png.hacker crypt2020.data", etc.

Once this process was completed, Hacker Crypt2020 changed the desktop wallpaper, created a text file named - "HOW TO DECRYPT FILES.txt", and displayed a pop-up window. All three contained identical ransom notes in the Czech language. It is notable that these messages had elements of a sextortion scam.

   
Coca Cola Lottery Email Scam

What is kind of email is "Coca Cola Lottery"?

The "Coca Cola Lottery" email is spam. Our inspection revealed that this letter operates as a phishing scam. It attempts to trick recipients into disclosing private information by claiming that they have won a large sum of money - hence, providing personal details is necessary to claim the prize.

It must be emphasized that these scam emails are in no way associated with The Coca-Cola Company.

   
Greenspecialmyline.com Ads

What kind of page is greenspecialmyline[.]com?

Our researchers discovered the greenspecialmyline[.]com rogue webpage while inspecting untrustworthy websites. It is designed to promote browser notification spam and redirect visitors to other (likely unreliable/malicious) sites. Most users enter pages of this type via redirects caused by websites using rogue advertising networks.

   
Ontario UK Lottery Email Scam

What is the "Ontario UK Lottery" email scam?

After inspecting the "Ontario UK Lottery" email, we determined that it is spam. The scam letter claims that the recipient has been chosen as a lottery winner. This fake email mentions several legitimate entities, and it must be emphasized that none of them are associated with this scam.

   
IntegerLocator Adware (Mac)

What is IntegerLocator?

IntegerLocator is a rogue app that our researchers discovered while inspecting new submissions to VirusTotal. After analyzing this piece of software, we determined that IntegerLocator operates as advertising-supported software (adware) and belongs to the AdLoad malware family.

   
Industrial Spy Market Ransomware

What is Industrial Spy Market ransomware?

Industrial Spy Market is a piece of malicious software classified as ransomware. Malware within this classification operates by encrypting files to demand payment for the decryption.

Typically, ransomware renames the encrypted files, but Industrial Spy Market does not alter filenames. Once the encryption process is completed, this ransomware drops a ransom-demanding titled - "readme.html" - onto the desktop.

   
Frame Order Adware

What is frame order?

While inspecting deceptive download webpages, our researchers found the frame order browser extension. After analyzing this piece of software, we determined that it operates as adware.

   
CAETANO FORMULA Email Virus

What is "CAETANO FORMULA" email virus?

Our team has examined this email and found that it contains a malicious attachment. The file attached to it infects computers with Agent Tesla - a remote administration Trojan (RAT). This file is disguised as a purchase order document.

   

Page 796 of 2356

<< Start < Prev 791 792 793 794 795 796 797 798 799 800 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal