Step-by-Step Malware Removal Instructions

BBVA Email Virus
Phishing/Scam

BBVA Email Virus

"BBVA" is a deceptive email designed to proliferate the Agent Tesla RAT (Remote Access Trojan). The text presented in these messages is in Spanish, and hence the intended targets are Spanish-speaking users. The email claims to contain information concerning due invoice payments. Instead, the atta

Yts.mx Suspicious Website
Adware

Yts.mx Suspicious Website

Yts[.]mx is one of many torrent websites. It is not safe to use these websites to download software, files or other content, since they are often used by cyber criminals to proliferate malicious programs. Furthermore, it is illegal to download copyrighted content via torrent web pages. Research s

Sekhmet Ransomware
Ransomware

Sekhmet Ransomware

Discovered by dnwls0719, Sekhmet is ransomware. This malicious program operates by encrypting data and demanding ransom payments for decryption. During the encryption process, all affected files are appended with an extension, consisting of random characters (e.g. ".HrUSsw", ".WNgh", ".NdWfEr", et

WinOptimizer Unwanted Application
Potentially unwanted application

WinOptimizer Unwanted Application

As its name suggests, WinOptimizer is software that supposedly analyzes and optimizes Windows computers. Like most programs of this type, it suggests that people can scan their computers for unnecessary files, registry entries and running services, invalid shortcuts, etc. In fact, this program is

Ramsay Malware
Trojan

Ramsay Malware

Ramsay is malware capable of scanning computers, removable drives and network shares/drives, which are isolated from unsecured networks (such as public internet, unsecured local area networks), for files such as Microsoft Office documents, PDF documents and ZIP archives. In this way, it can steal

Cooing.top POP-UP Scam (Mac)
Mac Virus

Cooing.top POP-UP Scam (Mac)

cooing[.]top is a deceptive website promoting a version of the "Latest version of Adobe Flash Player" scam. The scheme claims that the Adobe Flash Player installed on the system is outdated and requires updates. If fact, the updaters offered by cooing[.]top are fake. At the time of research, th

Polícia de Segurança Pública Email Virus
Phishing/Scam

Polícia de Segurança Pública Email Virus

There are various spam campaigns that are used to trick people into installing malicious programs on their computers. Generally, cyber criminals send emails that are disguised as important, official messages from legitimate companies/organizations and contain malicious attachments and/or website l

EpicSplit RAT
Trojan

EpicSplit RAT

Discovered by Blueteam 4 Life, EpicSplit is a malicious program classified as a Remote Access Trojan (RAT). Malware of this type allows remote access and control over an infected device. RATs can enable user-level control (or close to user-level control) of a machine. These programs have a wide v

Valak Malware
Trojan

Valak Malware

Valak is malicious software that downloads JScript files and executes them. What happens next depends on the actions performed by the executed JScript files. It is very likely that cyber criminals behind Valak attempt to use this malware to cause chain infections (i.e., using Valak to distribute o