Step-by-Step Malware Removal Instructions

WalletConnect Token (WCT) Airdrop Scam
Phishing/Scam

WalletConnect Token (WCT) Airdrop Scam

While investigating suspicious websites, our researchers discovered this fake "WalletConnect Token (WCT) Airdrop". The scam offers an unbelievable discount for WalletConnect Tokens (WCT), yet after victims make the purchase – they receive nothing. It must be emphasized that this scam is in no way

Gastaldo.app Adware (Mac)
Mac Virus

Gastaldo.app Adware (Mac)

We have examined Gastaldo.app and discovered that it displays unwanted advertisements. Thus, we classified Gastaldo.app as adware. In addition to delivering ads, Gastaldo.app may gather user data and other information. Another reason to avoid the app is that it is flagged as malicious by multipl

Stashalinamme.com Ads
Notification Spam

Stashalinamme.com Ads

While examining suspicious pages, our researchers discovered stashalinamme[.]com. This rogue site endorses spam browser notifications and redirects users to different (likely unreliable/harmful) webpages. The majority of visitors to stashalinamme[.]com and analogous pages access them via redirects

Copyroticirung.co.in Ads
Notification Spam

Copyroticirung.co.in Ads

Our research team discovered copyroticirung.co[.]in while browsing dubious websites. This is a rogue page promoting browser notification spam and redirecting visitors to other (likely unreliable/dangerous) sites. Copyroticirung.co[.]in and webpages akin to it are primarily accessed via redirects c

Searcherbright.com Redirect
Browser Hijacker

Searcherbright.com Redirect

While testing searcherbright.com, we found that it is a fake search engine. Using fake search engines can expose users to various online threats. It is also common for them to be promoted through unwanted extensions known as browser hijackers. If searcherbright.com is encountered, it should be rem

Hedera (HDR) Airdrop Scam
Phishing/Scam

Hedera (HDR) Airdrop Scam

We have reviewed the site (hedera-airdrop[.]org) and concluded that it is designed to trick users into participating in a fake giveaway (cryptocurrency airdrop). This scam web page is created to steal cryptocurrency from victims. Users should be careful when landing on sites hosting giveaways and

ZV Ransomware
Ransomware

ZV Ransomware

ZV is ransomware belonging to the Dharma family. Our team has discovered it while inspecting samples submitted to VirusTotal. Once executed, ZV encrypts files and appends the victim's ID, an email address, and the ".ZV" extension to them. For example, it changes "1.jpg" to "1.jpg.id-9ECFA84E.[zele

Dofirewall.co.in Ads
Notification Spam

Dofirewall.co.in Ads

Our analysis of dofirewall.co[.]in indicates that the site is crafted to present misleading content in an attempt to persuade visitors to allow it to send notifications. Once this consent is given, it can push deceptive messages to manipulate users into engaging with them. These notifications can

Rushuplab.co.in Ads
Notification Spam

Rushuplab.co.in Ads

Our researchers discovered this rushuplab.co[.]in rogue page while inspecting suspicious websites. It endorses browser notification spam and produces redirects to different (likely unreliable/dangerous) sites. Rushuplab.co[.]in and similar webpages are most commonly accessed via redirects caused b

Nkw-protect.pro Ads
Notification Spam

Nkw-protect.pro Ads

Nkw-protect[.]pro is a rogue page discovered by our researchers during a routine investigation. This webpage is designed to promote browser notification spam and redirect visitors to other (likely unreliable/hazardous) sites. Most users access pages like nkw-protect[.]pro via redirects caused by w