Step-by-Step Malware Removal Instructions

Hnx911 Ransomware
Ransomware

Hnx911 Ransomware

Hnx911 is ransomware from the Xorist family. Our team discovered it during an inspection of malware samples uploaded to VirusTotal. Once executed, Hnx911 encrypts the victim's files and appends the ".hnx911" extension. It also creates a ransom note "HOW TO DECRYPT FILES.txt" and displays another o

Cloud Storage Plan Has Been Paused Email Scam
Phishing/Scam

Cloud Storage Plan Has Been Paused Email Scam

Our team has reviewed the email and found that it is disguised as a notification regarding the recipient's cloud storage plan. It urges the recipient to solve the "issue" through the provided link as soon as possible. The included link leads to deceptive websites. This scam email should be ignored

Cooked Ransomware
Ransomware

Cooked Ransomware

Our team discovered Cooked while analyzing samples submitted to VirusTotal. Our examination has shown that this is ransomware designed to encrypt files, provide a ransom note ("Readme.txt"), and add its extension (".cooked") to files. For example, it renames "1.jpg" to "1.jpg.cooked", "2.png" to "

Cloud Account Scheduled For Deletion Email Scam
Phishing/Scam

Cloud Account Scheduled For Deletion Email Scam

Our analysis indicates that this is a scam email intended to deceive recipients into thinking their cloud account has been scheduled for deletion. It directs users to fraudulent websites. All claims made in the email and on the linked sites are false and should not be trusted. If you receive this

Document Status Update Email Scam
Phishing/Scam

Document Status Update Email Scam

We have reviewed the email and determined that it is a phishing message containing a link to a fake website. The scammers behind this email seek to steal personal information that can be misused to hijack accounts. Stolen accounts can be misused for malicious purposes. Overall, this scam email sho

Draxo Ransomware
Ransomware

Draxo Ransomware

We have examined the malware and found that Draxo is ransomware. Our discovery of this ransomware occurred during an inspection of samples uploaded to VirusTotal. Once launched, Draxo encrypts files and appends four random characters to filenames. For instance, it renames "1.jpg" to "1.jpg.uuwf" a

Your Cloud Account Suspended Email Scam
Phishing/Scam

Your Cloud Account Suspended Email Scam

Our analysis shows that this is a scam email designed to trick recipients into believing that their cloud account has been suspended. It promotes deceptive websites. No claims in this email or the linked scam websites are true, so they should be ignored. If received, this scam email should be dele

Black TENGU Ransomware
Ransomware

Black TENGU Ransomware

Black TENGU is ransomware that our team found while examining samples uploaded to VirusTotal. Once executed, Black TENGU encrypts files and changes their names by appending the ".TENGU" extension. For instance, it renames "1.jpg" to "1.jpg.TENGU" and "2.png" to "2.png.TENGU". Also, Black TENGU cre

Storm Stealer
Trojan

Storm Stealer

Storm is an information stealer that is sold for between $300 and $1,800. It is written in C++ and is capable of stealing files and information from various apps and extensions, taking screenshots, and loading and executing files. Victims may encounter issues like identity theft, financial loss, a