Step-by-Step Malware Removal Instructions

SoftwareHelper Adware (Mac)
Mac Virus

SoftwareHelper Adware (Mac)

SoftwareHelper is an adware-type application that our research team discovered while inspecting new submissions to VirusTotal. This piece of software operates by running intrusive advertisement campaigns (displaying ads), and it can have other harmful functionalities. We also learned that it bel

Separashpar.xyz Ads
Notification Spam

Separashpar.xyz Ads

Separashpar[.]xyz is an untrustworthy web page that uses a clickbait technique to trick visitors into allowing it to show notifications. Also, it redirects visitors to other questionable sites. Our team has discovered separashpar[.]xyz while examining pages that use shady advertising networks.

Korplug Malware
Trojan

Korplug Malware

Korplug (also known as Hodur, PlugX) is the name of the malware that has different variants with different functionalities. Korplug is distributed by a group of cybercriminals known as Mustang Panda. They are known for targeting non-governmental organizations. Korplug is a Remote Access Tr

Dotchaudou.com Ads
Notification Spam

Dotchaudou.com Ads

Dotchaudou[.]com is a rogue webpage that our research team discovered while inspecting questionable sites. It operates by pushing browser notification spam and redirecting visitors to other (likely untrustworthy or malicious) websites. Rogue sites are seldom accessed intentionally. Most users ent

GuideService Adware (Mac)
Mac Virus

GuideService Adware (Mac)

Discovered by our research team while inspecting new submissions to VirusTotal, GuideService is a rogue application. Following our analysis, we determined that this piece of software operates as adware and belongs to the AdLoad malware family. It is noteworthy that adware may require sui

OnlinePlatform Adware (Mac)
Mac Virus

OnlinePlatform Adware (Mac)

OnlinePlatform is the name of an untrustworthy application that our team has discovered while examining a deceptive website. After downloading and installing this app, we found that it operates as adware - it generates advertisements. Apps like OnlinePlatform display advertisements used

89N3PDyZzakoH7W6n8ZrjGDDktjh8iWFG6eKRvi3kvpQ Malware
Trojan

89N3PDyZzakoH7W6n8ZrjGDDktjh8iWFG6eKRvi3kvpQ Malware

89N3PDyZzakoH7W6n8ZrjGDDktjh8iWFG6eKRvi3kvpQ is the name of a malicious program. After analyzing it, we determined that this malware operates as a clipboard hijacker. We discovered this program while inspecting websites offering "cracked" software. It is noteworthy that the installation setup tha

8b5lc Ransomware
Ransomware

8b5lc Ransomware

Our researchers found 8b5lc ransomware while inspecting new malware submissions to VirusTotal. We determined that this malicious program belongs to the Hive ransomware family. On our test machine, this ransomware encrypted files and appended their filenames with a random character string and the

Chos Ransomware
Ransomware

Chos Ransomware

Chos is the name of a ransomware variant that we have discovered while checking the VirusTotal page for recently submitted malware samples. It encrypts files and appends the ".Chos" extension to filenames (for example, it renames "1.jpg" to "1.jpg.Chos", "2.png" to "2.png.Chos"). Also, Chos change

GIMMICK Malware (Mac)
Mac Virus

GIMMICK Malware (Mac)

Discovered by the Volexity cyber security firm, GIMMICK is an information-stealing malware. According to Volexity's analysis, this malicious program is used by Storm Cloud - a Chinese espionage group. GIMMICK is a cross-platform malware; the macOS variant is (mostly) written in Objective C and