Step-by-Step Malware Removal Instructions

Vanta Stealer
Trojan

Vanta Stealer

Vanta Stealer is an information stealer written in Python and designed to harvest credentials, session tokens, gaming account data, and cryptocurrency wallet details from infected computers. Once executed, the malware targets saved browser passwords and cookies, Discord and Telegram session files

Golden Gh0st RAT
Trojan

Golden Gh0st RAT

Golden Gh0st RAT is a Remote Access Trojan (RAT) operated by CylindricalCanine, a subgroup of the Chinese cybercrime group GoldenEyeDog (also tracked as APT-Q-27). The malware is based on the Gh0st RAT codebase, which was publicly released in 2008 and has been adapted for attacks ever since. Acco

AI Detected That Your Email Account Requires Email Scam
Phishing/Scam

AI Detected That Your Email Account Requires Email Scam

We have inspected this email and determined it is a phishing scam. The message falsely claims that an AI system detected a verification requirement for the recipient's email account, then directs them to a counterfeit login page to capture their credentials. This email should be ignored and delete

Email Address Re-verification Scam
Phishing/Scam

Email Address Re-verification Scam

We examined this email and determined it is a phishing scam. The message falsely claims that recipients must re-verify their email address to prevent their account from going dormant. It is designed to steal webmail login credentials and should be ignored. The email presents itself as an u

Set Your Password To Avoid Database Loss Email Scam
Phishing/Scam

Set Your Password To Avoid Database Loss Email Scam

We have examined this email and determined that it is a phishing scam. The message falsely claims the recipient must set a new password to prevent database loss, and contains a link to a fraudulent login page designed to steal email account credentials. This email should be deleted without clickin

UMBRA Ransomware
Ransomware

UMBRA Ransomware

UMBRA is ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. It encrypts files on the victim's computer, appends the ".umbra" extension to their filenames, drops a ransom note named "README_[victim_ID].txt", and replaces the desktop wallpaper with

Bank Of America Account Update Email Virus
Phishing/Scam

Bank Of America Account Update Email Virus

We have analyzed this email and determined it is malspam. It impersonates Bank of America and falsely warns recipients that their account will be restricted unless they download and install a program called "Account Guard." That program is actually a remote access tool installed without the victim

WeedHack Malware
Trojan

WeedHack Malware

WeedHack malware is a Malware-as-a-Service (MaaS) campaign that combines an information stealer with Remote Access Trojan (RAT) features, and distributes both through fake Minecraft mods and game client programs. According to research published by McAfee Labs, the campaign has been active since J

Vitya Ransomware
Ransomware

Vitya Ransomware

Vitya Ransomware is ransomware that locks victims' files and demands payment for decryption. It appends the .vitek extension to encrypted filenames and displays a pop-up window containing the ransom demand and a countdown timer. On our test machine, Vitya Ransomware encrypted files and appended t

App Passwords Need To Be Updated Email Scam
Phishing/Scam

App Passwords Need To Be Updated Email Scam

We have examined this email and determined it is a phishing scam impersonating a Microsoft account security notification. The message falsely claims the recipient recently changed their password and must create new app passwords for two-step verification. It is designed to steal account credential