Step-by-Step Malware Removal Instructions

Validate Now Email Scam
Phishing/Scam

Validate Now Email Scam

After analyzing the "Validate Now" email, we determined that it is a phishing email. This letter attempts to lure recipients into providing their email log-in credentials by claiming that their email accounts will be closed. The "Validate Now" letter states that the recipient's email accou

SearchTab Default Search Browser Hijacker
Browser Hijacker

SearchTab Default Search Browser Hijacker

Our malware researchers have discovered the SearchTab Default Search browser extension while examining questionable websites that use advertising networks. They found that this app promotes searchtab.xyz (a fake search engine) by changing the settings of a browser. Thus, it was concluded that Sear

ZEON Ransomware
Ransomware

ZEON Ransomware

ZEON was discovered by dnwls0719. After doing our research, we learned that ZEON is ransomware written in the Python programming language. It encrypts files, changes the desktop wallpaper, and appends the ".zeon" extension to filenames. For instance, it renames "1.jpg" to "1.jpg.zeon", "2.png" to

Pro Dark Adware
Adware

Pro Dark Adware

Our researchers discovered the Pro Dark browser extension while inspecting content promoted by deceptive download webpages. This piece of software promises to enable dark mode for websites. However, after analyzing Pro Dark, we determined that it operates as adware. Following successful in

NOKOYAWA Ransomware
Ransomware

NOKOYAWA Ransomware

NOKOYAWA is a piece of malicious software classified as ransomware, which our research team found and sampled from VirusTotal. It is designed to encrypt data and demand payment for the decryption. On our test machine, this ransomware encrypted files and appended their filenames with a ".NOKOYAWA"

Email policy & privacy violation Email Scam
Phishing/Scam

Email policy & privacy violation Email Scam

Our team has examined this email and learned that scammers use it to steal sensitive information. It is disguised as a letter from Microsoft. It also contains a hyperlink designed to open a phishing website requesting an email address and password. The email is disguised as a letter regard

HorizonLiving Adware (Mac)
Mac Virus

HorizonLiving Adware (Mac)

HorizonLiving is an adware-type application our researchers discovered while inspecting new submissions to VirusTotal. It is designed to run intrusive advertisement campaigns, and this app has data tracking abilities. Additionally, we have determined that HorizonLiving belongs to the AdLoad malw

ShareAdvantage Adware (Mac)
Mac Virus

ShareAdvantage Adware (Mac)

ShareAdvantage is a rogue app that our researchers found when a user reported it on a support forum. After analyzing this application, we determined that it operates as advertising-supported software (adware). Furthermore, ShareAdvantage is part of the AdLoad malware family. Adware may n

RURansom Ransomware
Ransomware

RURansom Ransomware

RURansom is a piece of malicious software classified as ransomware. Typically, malware within this classification operates by encrypting files (rendering them inaccessible) to make ransom demands for the decryption (access recovery). However, we learned from the message created by RURansom that th