Virus and Spyware Removal Guides, uninstall instructions

WanaCray2023+ Ransomware

What kind of malware is WanaCray2023+?

WanaCray2023+ is ransomware that belongs to the Xorist ransomware family. We have discovered this variant while examining malware samples submitted to the VirusTotal website. It was found that WanaCray2023+ encrypts files and appends the ".WanaCray2023+" extension to their filenames.

Also, WanaCray2023+ changes the desktop wallpaper, displays a pop-up window and creates the "HOW TO DECRYPT FILES.txt" file (both contain a ransom note). An example of how WanaCray2023+ renames files: it changes "1.jpg" to "1.jpg.WanaCray2023+", "2.png" to "2.png.WanaCray2023+", and so forth.

   
Live-Secure Browser Hijacker

What kind of application is Live-Secure?

Live-Secure is a browser hijacker that our team has discovered while examining questionable web pages. After installing this application, we found out that it hijacks a web browser by changing some of its settings to live-secure.xyz - it promotes a fake search engine.

   
News-jivuka.cc Ads

What kind of page is news-jivuka[.]cc?

News-jivuka[.]cc is a rogue site designed to promote browser notification spam and redirect visitors to other (likely untrustworthy/malicious) webpages. Our research team discovered this page while inspecting websites using rogue advertising networks. Most users enter news-jivuka[.]cc and similar sites via redirects caused by webpages employing such advertising networks.

   
StreamTopSearch Browser Hijacker

What is StreamTopSearch?

StreamTopSearch is a rogue browser extension. After analyzing it, our researchers determined that it operates as a browser hijacker. StreamTopSearch modifies browser settings to promote the streamtopsearch.com fake search engine.

   
Scanandclean.xyz Ads

What kind of page is scanandclean[.]xyz?

Our research team found the scanandclean[.]xyz rogue webpage during a routine inspection of untrustworthy sites. This page is designed to load deceptive content (scams), push spam browser notifications, and redirect visitors to different (likely untrustworthy/harmful) webpages.

Most users enter websites of this kind through redirects caused by pages using rogue advertising networks.

   
Myauto.site Ads

What kind of page is myauto[.]site?

We have discovered the myauto[.]site website while inspecting other pages that use rogue advertising networks. Myauto[.]site asks for permission to show notifications (it uses a clickbait technique to trick visitors into clicking the "Allow" button). Also, it redirects to an identical page.

   
Salvation Army Email Scam

What kind of scam is the "Salvation Army" email scam?

We have examined this email and concluded that it is used to steal credentials. It contains an attachment designed to open a page asking to provide email, phone or Skype, and password. This site is disguised as a letter from The Salvation Army, an evangelical protestant Christian church in Australia.

   
Email Shutdown In Progress Email Scam

What is "Email Shutdown In Progress" email scam?

After inspecting the "Email Shutdown In Progress" email, we determined that it is spam. This fake letter threatens that the recipient's email account is pending deactivation. The goal of this mail is to trick users onto providing their email account's log-in credentials to a phishing website.

   
Japan Ransomware

What is Japan ransomware?

Japan is the name of a malicious program that our researchers found while inspecting new malware submissions to VirusTotal. We determined that the Japan program is ransomware.

After launching a sample on our test machine, we learned that it encrypts files and appends their filenames with a ".japan" extension. For example, a file initially titled "1.jpg" appeared as "1.jpg.japan", "2.png" as "2.png.japan", and so forth.

Once this process was finished, the ransomware changed the desktop wallpaper and created a text file named "how to decrypt.txt". Both the wallpaper and text file contain ransom notes, although the former is in English while the latter is in Vietnamese.

   
Takecontent.net Ads

What kind of website is takecontent[.]net?

Takecontent[.]net is a deceptive website designed to trick visitors into allowing it to show notifications. It also redirects to other untrustworthy pages. We have discovered takecontent[.]net while examining torrent sites, illegal movie streaming pages, and other pages that use shady advertising networks.

   

Page 808 of 2356

<< Start < Prev 801 802 803 804 805 806 807 808 809 810 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal