Virus and Spyware Removal Guides, uninstall instructions

CommandImprovement Adware (Mac)

What is CommandImprovement adware?

CommandImprovement is designed to generate advertisements and hijack a web browser by changing its settings. This app has the qualities of both adware and a browser hijacker. Apps of this kind are distributed using questionable methods. Thus, most users download and install them inadvertently.

   
Aclientirethe.xyz Ads

What is the aclientirethe[.]xyz website?

Aclientirethe[.]xyz is a rogue webpage, similar to captchafilter.top, onestoreblog.com, watch-this-viral.video, and thousands of others. It operates by presenting visitors with dubious content, pushing its browser notifications, and/or redirecting users to various (likely untrustworthy and malicious) websites.

Rogue sites are usually accessed via redirects caused by suspect pages, intrusive adverts, or installed PUAs (Potentially Unwanted Applications).

   
Domain Quality Adware

What is Domain Quality?

Domain Quality is a rogue browser extension promoted as a tool for quickly checking a website's reputation. This piece of software operates as adware, i.e., runs intrusive advertisement campaigns. Additionally, since most users download/install adware-type products inadvertently, they are also categorized as PUAs (Potentially Unwanted Applications).

   
Alkhal Ransomware

What is Alkhal ransomware?

Alkhal encrypts files and creates two ransom notes ("ReadMe.txt" and "Recovery.bmp") containing identical text. The purpose of Alkhal ransomware is to keep files inaccessible until a ransom is paid. Its ransom notes provide instructions on how to contact cybercriminals for payment information.

   
Yourhotfeed.com Ads

What is yourhotfeed[.]com site?

Yourhotfeed[.]com opens shady websites and asks for permission to show notifications. Users do not open yourhotfeed[.]com intentionally. Most likely, it is promoted via potentially unwanted applications (PUAs), shady ads, or other dubious pages. Yourhotfeed[.]com is similar to eruthoxup[.]com, onestoreblog[.]com, and lots of other sites.

   
VICE SOCIETY Ransomware

What is VICE SOCIETY ransomware?

VICE SOCIETY is a ransomware-type program. It encrypts data (renders files inaccessible) and demands ransoms for the decryption (access recovery).

Encrypted files are appended with a ".v-society.[victim's_ID]" extension. For example, a file initially titled "1.jpg" would appear as something similar to "1.jpg.v-society.923-C3D-30D". Once this process is complete, a ransom note named "!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT" is created.

Another variant of VICE SOCIETY ransomware appends ".v1cesO0ciety" extension (e.g., "1.jpg.v1cesO0ciety"). The ransom note delivered by this variant is named "AllYFilesAE!" (the content is identical) and the changed desktop wallpaper is also changed. Additional variants of VICE SOCIATY ransomware may also be released in future.

   
Keq4p Ransomware

What is Keq4p ransomware?

Keq4p is a malicious program categorized as ransomware. It operates by encrypting data (rendering files unusable) and demanding ransoms for the decryption.

Affected files are appended with the ".[random_string].keq4p" extension, e.g., a file like "1.jpg" would appear as something similar to "1.jpg.T112tM5obZYOoP4QFkev4kSFA1OPjfHsqNza12hxEMj_uCNVPRWni8s0.keq4p", and so on. Afterwards, a ransom note - "zB6F_HOW_TO_DECRYPT.txt" - is created.

   
Nicyaboyenan.com POP-UP Scam (Mac)

What is nicyaboyenan[.]com scam?

Nicyaboyenan[.]com is a website that uses scare tactics to trick visitors into installing some potentially unwanted application (PUA). Usually, websites of this type display fake virus notifications claiming that a device is infected and offer to remove detected malware with some app.

   
Secure-support.space POP-UP Scam (Mac)

What is the secure-support[.]space site?

Secure-support[.]space is a deceptive website running various scams. At the of research, this page ran a scheme targeting iPhone users. The scam claims that visitors' iPhones have been infected and recommends installing a free protection tool.

Typically, such schemes push untrustworthy software, e.g., fake anti-viruses, adware, browser hijackers, and other PUAs (Potentially Unwanted Applications). In seldom cases, scams of this kind are used to proliferate malware (e.g., trojans, ransomware, cryptominers, etc.).

Sites like secure-support[.]space are usually accessed via mistyped URLs or redirects caused by rogue webpages, intrusive ads, or installed PUAs.

   
Zvw5k Ransomware

What is Zvw5k ransomware?

Zvw5k encrypts files and modifies their filenames. It adds a string of random characters and the ".zvw5k" extension to filenames. For instance, Zvw5k renames "1.jpg" to "1.jpg.NZ4g08eQk3TfLo_4PSAQQ7ff0o9pcKspQmt1rhxGnTj_IAC1NfcI0680.zvw5k", "2.jpg" to "2.jpg.NZ4g08eQk3TfLo_4PSAQQ7ff0o9pcKspQmt1rhxGnTj_IAC1NfcI0680.zvw5k".

Also, Zvw5k creates a text file named "Hw44_HOW_TO_DECRYPT.txt". This file contains instructions on how to contact the attackers for data decryption and some other details.

   

Page 982 of 2353

<< Start < Prev 981 982 983 984 985 986 987 988 989 990 Next > End >>
About PCrisk

PCrisk is a cyber security portal, informing Internet users about the latest digital threats. Our content is provided by security experts and professional malware researchers. Read more about us.

Malware activity

Global malware activity level today:

Medium threat activity

Increased attack rate of infections detected within the last 24 hours.

Virus and malware removal

This page provides information on how to avoid infections by malware or viruses and is useful if your system suffers from common spyware and malware attacks.

Learn about malware removal