Step-by-Step Malware Removal Instructions

Mail Cloud System Update Email Scam
Phishing/Scam

Mail Cloud System Update Email Scam

Our examination has revealed that this is a phishing email presented as a system update notification from the email service provider. The scammers behind this fraudulent email aim to steal personal information via a fake login website. This scam email should be ignored to avoid the associated risk

EagleLocker Ransomware
Ransomware

EagleLocker Ransomware

EagleLocker is ransomware that our team has discovered during a routine inspection of samples uploaded to VirusTotal. Once executed, EagleLocker encrypts files and appends the ".daibang" extension. Also, it displays a pop-up containing a ransom note and changes the desktop wallpaper. An example o

IMAP/POP3 Mail Server Verification Failure Email Scam
Phishing/Scam

IMAP/POP3 Mail Server Verification Failure Email Scam

We have reviewed the email and found it to be a phishing attempt. The message is disguised as a notification from the email service provider. Its purpose is to trick recipients into opening the provided website and entering personal information on it. Recipients should ignore this fraudulent email

ICanFix Ransomware
Ransomware

ICanFix Ransomware

ICanFix is ransomware that our team has discovered while examining malware samples submitted to VirusTotal. Our analysis shows that ICanFix is part of the MedusaLocker family and is designed to encrypt files, append the ".icanfix" extension to files, drop a ransom note ("READ_NOTE.html"), and chan

Black Wallstreet ($TULSA) Airdrop Scam
Phishing/Scam

Black Wallstreet ($TULSA) Airdrop Scam

During our inspection, we discovered that this website (event-tulsa[.]fun) is a fraudulent copy of the original Black WallStreet page (black-wallstreet.netlify.app). Its purpose is to deceive visitors into believing that they can receive cryptocurrency through a giveaway. However, this airdrop is

Cdd Ransomware
Ransomware

Cdd Ransomware

Our researchers have discovered Cdd while inspecting samples uploaded to VirusTotal. Cdd is ransomware belonging to the Makop family. After execution, the ransomware encrypts files, provides a ransom note ("+README-WARNING+.txt"), and changes the desktop wallpaper. Cdd also renames files by appen

PYRA Airdrop Scam
Phishing/Scam

PYRA Airdrop Scam

Our team has analysed the page (event-pyra[.]fun) and concluded that it imitates the original PYRA website, pyrachain.io. The fake site promotes a fake cryptocurrency giveaway, an airdrop to lure visitors into taking steps that could lead to permanent cryptocurrency loss. Thus, it is highly advisa

Search.ansiblealgorithm.com Redirect
Browser Hijacker

Search.ansiblealgorithm.com Redirect

We have inspected search.ansiblealgorithm.com and found that it is a fake search engine because it does not generate results. Moreover, it may collect various data. It is also important to mention that fake search engines are often associated with browser hijackers. Users should not trust search.a

Goyin Airdrop Scam
Phishing/Scam

Goyin Airdrop Scam

After reviewing the website (claim-goyim.pages[.]dev), we identified it as a scam. It falsely offers visitors the opportunity to join a cryptocurrency airdrop. The attackers behind this site aim to steal funds from users' crypto wallets, meaning that engaging with it could lead to serious financia

Xillen Stealer
Trojan

Xillen Stealer

Xillen is an information stealer often distributed through other malware, such as Amadey. Once executed on the device, it gathers various information and sends it to cybercriminals. Having the system infected with Xillen can result in issues such as identity theft and financial loss. Thus, if dete