Step-by-Step Malware Removal Instructions

Get Your Obituaries Now Browser Hijacker
Browser Hijacker

Get Your Obituaries Now Browser Hijacker

Get Your Obituaries Now is a potentially unwanted application (PUA), a browser hijacker which promotes search.getyourobituariesnowtab.com (the address of a fake search engine) by changing certain browser settings. In most cases, browser hijackers promote fake search engines and gather browsing dat

CU Ransomware
Ransomware

CU Ransomware

CU is the name of malware belonging to the Crysis/Dharma ransomware family. Systems infected with this program have data encrypted and users receive ransom demands for file decryption. When CU ransomware encrypts, all files are renamed according to the following pattern: original filename; unique

2fatoffers.xyz Ads
Notification Spam

2fatoffers.xyz Ads

When visited, 2fatoffers[.]xyz opens untrustworthy websites or loads dubious content. There are many other rogue websites that operate in this way including, for example, younwild[.]com, zahkit[.]pro and usinesmycete[.]info.  Typically, people do not open them intentionally - in most cases they a

Creasonsau.info Ads
Notification Spam

Creasonsau.info Ads

Sharing considerable similarities with wbamedia.net, sawhitpew.site, zahkit.pro and countless others, creasonsau[.]info is a rogue website, which operates by presenting visitors with dubious content and/or redirecting them to other untrusted or malicious sites. In most cases, web pages such as cr

Allow2continue.com Ads
Notification Spam

Allow2continue.com Ads

allow2continue[.]com is one of many rogue websites that are usually opened via other untrusted pages, deceptive ads or potentially unwanted applications (PUAs) that are installed on browsers and/or operating systems. When opened, sites such as allow2continue[.]com redirect visitors to a number of

CryptoPatronum Ransomware
Ransomware

CryptoPatronum Ransomware

CryptoPatronum was discovered by Amigo-A. Like most programs of this type, this ransomware is designed to block access to data by encryption. The program also changes names of all encrypted files by adding the "cryptopatronum@protonmail.com" email address and appending the ".enc" extension. For e

Cocketexercine.info Ads
Notification Spam

Cocketexercine.info Ads

Similar to younwild.com, zahkit.pro, pushbestdevice.com and many others, cocketexercine[.]info is a rogue website. When opened, it presents visitors with dubious content and/or redirects them to other untrusted, malicious web pages. Most users access cocketexercine[.]info and similar websites via

EnCiPhErEd Ransomware
Ransomware

EnCiPhErEd Ransomware

EnCiPhErEd is malicious software and part of the Xorist ransomware family. This malware is designed to encrypt data and demand payment for decryption. During the encryption process, all affected files are converted into executables and their filenames are appended with the ".EnCiPhErEd" extension.

.com (Phobos) Ransomware
Ransomware

.com (Phobos) Ransomware

Discovered by Karsten Hahn, .com (Phobos) is a part of the Phobos ransomware family. Like many other programs of this type, .com (Phobos) encrypts victims' files, changes filenames and provides instructions about how to contact the developers (and other details) in a ransom message. It renames al

IFC Global Development Funding Program Email Scam
Phishing/Scam

IFC Global Development Funding Program Email Scam

This email scam is disguised as a message regarding fund approval, supposedly by "IFC Global Development Funding Program". Scammers behind this email claim that recipients can receive a specific sum of money by sending various personal details. We strongly advise against replying to this email or