Step-by-Step Malware Removal Instructions

To Go Web Browser Hijacker
Browser Hijacker

To Go Web Browser Hijacker

To go web is a rogue browser extension. After analyzing this piece of software, we determined that it operates as a browser hijacker. To go web modifies browser settings to promote the togosearching.com fake search engine. Additionally, this browser hijacker spies on users' browsing activity.

Safemacpc.xyz Ads
Notification Spam

Safemacpc.xyz Ads

Safemacpc[.]xyz displays deceptive content (runs the "McAfee - Your PC is infected with 5 viruses!" scam) and asks for permission to show notifications. It uses a scare tactic to promote legitimate software. It is operated by affiliates who aim to collect illegitimate commissions. Our team has di

MajorSector Adware (Mac)
Mac Virus

MajorSector Adware (Mac)

While examining various shady/deceptive web pages, our team discovered an application called MajorSector. After installing and analyzing this app, they found that it generates advertisements. They also noticed that it can access sensitive information. Our malware researchers have classified Majo

BlackToxic Ransomware
Ransomware

BlackToxic Ransomware

While inspecting new submissions to VirusTotal, our research team discovered yet another malicious program based on Chaos ransomware. This ransomware-type program is called BlackToxic. We obtained a sample of it from VirusTotal and ran it in our test system. BlackToxic encrypted files and appende

BlueShtorm Stealer
Trojan

BlueShtorm Stealer

BlueShtorm is an information-stealing malware discovered by 3xp0rt. It is not known at this time what information this malware collects. Usually, information stealers target data that could be misused to steal money and (or) identities, hijack personal accounts, make fraudulent purchases, or black

Congratulations You Just Received TetherUSDT POP-UP Scam
Phishing/Scam

Congratulations You Just Received TetherUSDT POP-UP Scam

While inspecting deceptive sites, our researchers discovered the "Congratulations You just received TetherUSDT" scam. It is yet another phishing scam targeting cryptocurrency wallet credentials. When we accessed a website running this scam, it presented us with a statement claiming that th

Zpps Ransomware
Ransomware

Zpps Ransomware

Zpps is a ransomware-type program that our researchers found while inspecting new malware submissions to VirusTotal. This malicious program is part of the Djvu ransomware family. After launching a sample of Zpps ransomware on our test machine, it encrypted files and appended their filenames with

Qlln Ransomware
Ransomware

Qlln Ransomware

Qlln is the name of ransomware belonging to the ransomware family called Djvu. We have discovered this variant during our routine check for malware samples submitted to VirusTotal. It was found that Qlln encrypts files and appends ".qlln" extension to filenames, and provides a ransom note (creates

Nnuz Ransomware
Ransomware

Nnuz Ransomware

Nnuz is ransomware that encrypts files and appends the ".nnuz" extension to filenames. Also, it creates the "_readme.txt" file that contains instructions on how to contact the attackers and other information. Our malware researchers have discovered Nnuz while checking samples submitted to the Viru

Web Saver Adware
Adware

Web Saver Adware

We discovered the Web Saver application on a shady website offering to install it before continuing to the page. After installing this app, we learned that it functions as adware - it displays annoying advertisements. The download page for Web Saver states that this app removes error pages and pro