Step-by-Step Malware Removal Instructions

Two-step Verification Was Enabled Email Scam
Phishing/Scam

Two-step Verification Was Enabled Email Scam

We have inspected this email and determined that it is a phishing scam. The message falsely claims that two-step verification was recently enabled on the recipient's account and urges them to review their security settings immediately. It leads to a fake login page designed to steal email account

Damaged Package Email Virus
Phishing/Scam

Damaged Package Email Virus

After inspecting this email, we determined that it is malspam. The message is crafted to look like a routine customer complaint about a damaged shipment and contains a link that redirects to a malicious website. That site delivers a harmful file to the visitor's device. This email should be ignore

Canada Revenue Agency (CRA) Benefit Statement Email Scam
Phishing/Scam

Canada Revenue Agency (CRA) Benefit Statement Email Scam

We have examined this email and determined that it is a phishing scam. It impersonates the Canada Revenue Agency (CRA) and falsely claims that an official benefit statement is ready for download. The real goal is to trick recipients into surrendering their email login credentials on a fraudulent w

Email Migration Notice Scam
Phishing/Scam

Email Migration Notice Scam

We examined this email and determined it is a phishing scam. The message masquerades as an automated notice from the recipient's email service provider and tricks recipients into submitting their login credentials on a fake website. This email should be deleted without taking any action. T

Devill Ransomware
Ransomware

Devill Ransomware

Devill is ransomware that we discovered while examining new file submissions to the VirusTotal website. It encrypts files, appends a randomly generated five-character extension to their filenames, changes the desktop wallpaper, and creates a text-file ransom note named Readme.txt. On our test mac

InterServer Ransomware
Ransomware

InterServer Ransomware

InterServer is ransomware our research team identified during a routine inspection of samples submitted to VirusTotal. It encrypts files, appends a variant-specific extension (e.g., .interserver12), and creates an HTML ransom note named RANSOM_NOTE.html. The attackers also claim to have stolen sen

Dolphin X RAT
Trojan

Dolphin X RAT

Dolphin X RAT is a multi-purpose Windows malware sold as a subscription service to cybercriminals. It combines a Remote Access Trojan (RAT), information stealer, cryptocurrency clipper, and distributed denial-of-service (DDoS) tool in a single package. Research published by Varonis Threat Labs do

NoMatter Ransomware
Ransomware

NoMatter Ransomware

NoMatter is ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. It encrypts victims' files, changes the desktop wallpaper, and drops a ransom note in a text file named README.txt. Unlike most ransomware, NoMatter does not append any new extension

BlackWizard Ransomware
Ransomware

BlackWizard Ransomware

BlackWizard is ransomware that our researchers discovered during a routine inspection of new file submissions to VirusTotal. It encrypts victims' files and demands payment in exchange for a decryption key. The group behind it identifies themselves as "Ransomware Team" in the ransom message. On ou

FadeSEC Ransomware
Ransomware

FadeSEC Ransomware

FadeSEC is ransomware our research team discovered while examining malware samples submitted to VirusTotal. It encrypts victims' files and displays an interactive full-screen ransom message. Notably, restarting or re-logging into the system dismisses the screen lock, but files remain encrypted reg