Step-by-Step Malware Removal Instructions

Ronin Wallet POP-UP Scam
Phishing/Scam

Ronin Wallet POP-UP Scam

During a routine inspection of sites that use rogue advertising networks, our research team discovered a webpage promoting a scam "Ronin Wallet". This phishing scam targets the log-in credentials of users' Ronin digital wallets. With this information in their possession, the cyber criminals may ga

Power-Cleaner Browser Hijacker
Browser Hijacker

Power-Cleaner Browser Hijacker

Discovered by our research team while inspecting dubious download webpages, Power-Cleaner is a rogue browser extension. After analyzing this piece of software, we determined that it operates as a browser hijacker and promotes the power-cleaner.xyz illegitimate search engine. With Power-Cle

Dark Browse Adware
Adware

Dark Browse Adware

Dark Browse is an adware-type browser extension promoted as a tool that enables dark mode for websites. While the functionalities promised by advertising-supported software are usually fake, after analyzing Dark Browse we learned that its promised function is operational. However, this browser ext

Mxf1bd Ransomware
Ransomware

Mxf1bd Ransomware

Mxf1bd is the name of a ransomware-type program, which our researchers discovered while looking through new submissions on VirusTotal. On our test system, this ransomware encrypted files and appended their filenames with a ".mxf1bd" extension. For example, a file initially titled "1.jpg" appeared

Anedukera.xyz Ads
Notification Spam

Anedukera.xyz Ads

Anedukera[.]xyz is a deceptive website that asks for permission to show notifications and redirects visitors to other pages of this type. We have discovered anedukera[.]xyz while analyzing websites that use rogue advertising networks (display shady ads and open dubious pages). After examin

Ginzo Stealer Malware
Trojan

Ginzo Stealer Malware

Ginzo (also known as ZingoStealer) is the name of an information-stealing malware that steals passwords, cookies, and other information from infected computers. We have found that cybercriminals use Telegram to distribute Ginzo. They offer to download it free of charge. Ginzo steals passwo

Soviet Locker Ransomware
Ransomware

Soviet Locker Ransomware

Soviet Locker ransomware is malware that was discovered by MalwareHunterTeam. It encrypts files and displays a pop-up window with a timer and an input field for entering a decryption password. Cybercriminals behind Soviet Locker do not demand payment. Files encrypted by this malware can be decrypt

Wdlo Ransomware
Ransomware

Wdlo Ransomware

Wdlo is one of the ransomware variants belonging to a ransomware family called Djvu. We have discovered this variant while examining the samples submitted to VirusTotal. After analyzing Wdlo, we have found that it encrypts files, appends its extension (".wdlo") to filenames, and generates a text f

Inancukan.xyz Ads
Notification Spam

Inancukan.xyz Ads

Our researchers found inancukan[.]xyz while inspecting untrustworthy sites. This webpage is designed to promote browser notification spam and redirect visitors to other (likely dubious/malicious) websites. Most users enter pages like inancukan[.]xyz via redirects caused by sites using rogue advert

Explus Ransomware
Ransomware

Explus Ransomware

Explus is a piece of malicious software classified as ransomware. Our researchers found it while inspecting new submissions on VirusTotal. After being launched on our test machine, this ransomware encrypted files and appended their filenames with a ".explus" extension. For example, a file initial