Step-by-Step Malware Removal Instructions

Mercurial Grabber Malware
Trojan

Mercurial Grabber Malware

While analyzing the Mercurial grabber, we have found that it is a piece of malware that steals browser data and files from Minecraft and Discord. We also learned that Mercurial grabber is written in C# programming language and uses a simple anti-debugging technique to avoid being analyzed/detected

NARUMI Ransomware
Ransomware

NARUMI Ransomware

NARUMI is the name of a ransomware-type program, which our researchers found when reviewing new malware submissions on VirusTotal. When testing the sample, we learned that this ransomware encrypts files (renders them inaccessible) and renames their filenames by appending them with a ".NARUMI" ext

Centredirect.net Ads
Notification Spam

Centredirect.net Ads

Centredirect[.]net is a deceptive website that has been discovered by our team while testing various torrent, illegal streaming, and similar pages (websites that use rogue advertising networks). We found that the purpose of centredirect[.]net is to trick visitors into allowing it to display notifi

Chrome Protect - Smart Search Browser Hijacker
Browser Hijacker

Chrome Protect - Smart Search Browser Hijacker

We have discovered the Chrome Protect — Smart Search application while examining various deceptive websites (a screenshot of one of these pages can be found below). After downloading and executing its installer, we have noticed that it has hijacked a web browser by changing its settings. W

Asistchinadecryption Ransomware
Ransomware

Asistchinadecryption Ransomware

We have analyzed the Asistchinadecryption ransomware (which was discovered by our malware researchers while examining samples submitted to VirusTotal) and discovered that it encrypts files and appends ".asistchinadecryption" and the victim's ID to filenames. For example, Asistchinadecryption rena

Finkeapp.com Ads
Notification Spam

Finkeapp.com Ads

Our team has examined finkeapp[.]com and found that it uses a clickbait technique to get permission to show notifications and redirects dubious pages. We have discovered this website while visiting pages that use questionable advertising networks. Finkeapp[.]com is similar to aucfuu[.]com, louses[

ELBOW Ransomware
Ransomware

ELBOW Ransomware

Our malware researchers have discovered the ELBOW ransomware while testing the samples submitted to VirusTotal. We found out that ELBOW is part of the Phobos ransomware family. While testing it, we learned that it encrypts and renames files and provides two ransom notes (in the "info.txt" file and

Maak Ransomware
Ransomware

Maak Ransomware

While testing the samples submitted to VirusTotal, we discovered that Maak is ransomware that belongs to Djvu family. We found that Maak encrypts files, appends the ".maak" extension to filenames (for example, it changes "1.jpg" to "1.jpg.maak", "file.txt" to "file.txt.maak"), and creates a text f

News-sojulu.cc Ads
Notification Spam

News-sojulu.cc Ads

While inspecting questionable sites, our researchers encountered news-sojulu[.]cc - a browser notification spam promoting webpage. Additionally, this website can redirect visitors to other dubious and harmful ones. Users seldom access pages like news-sojulu[.]cc intentionally; most enter them via

METAMASK POP-UP Scam
Phishing/Scam

METAMASK POP-UP Scam

We discovered this "METAMASK" scam while inspecting rogue websites. It is disguised as a log-in credential recovery page for MetaMask - a genuine cryptocurrency wallet designed to interact with the Ethereum blockchain. This scheme operates as a phishing scam. In other words, it aims to trick users