Step-by-Step Malware Removal Instructions

Claim SatoshiDEX (SATX) Scam
Phishing/Scam

Claim SatoshiDEX (SATX) Scam

"Claim SatoshiDEX (SATX)" is a scam that is almost a perfect visual copy of SatoshiDEX (satoshidex.ai). Upon inspection, we determined that this fake page (satoshidex-ai[.]org and potentially others) is a cryptocurrency drainer. The scheme lures users into exposing their digital wallets to steal t

Payroll Report Status Email Scam
Phishing/Scam

Payroll Report Status Email Scam

We have inspected this email and learned that its purpose is to extract personal information from recipients. Emails of this type are classified as phishing emails. This particular email is disguised as a letter regarding a change in the payroll report status to appear legitimate and lure recipien

Aethir ($ATH) Allocation Scam
Phishing/Scam

Aethir ($ATH) Allocation Scam

"Aethir ($ATH) Allocation" is a scam imitating the Aethir platform (aethir.com). This scheme entices users to inadvertently expose their digital wallets to a crypto drainer by promoting an allocation increase of ATH cryptocurrency. Victims of this scam experience financial loss. IMPORTANT NO

UnicornSpy Malware
Trojan

UnicornSpy Malware

UnicornSpy is malware used to steal sensitive information. Cybercriminals have been observed using UnicornSpy to target energy companies, factories, and suppliers (and developers) of electronic components. The channel used for the distribution of this malware is email. However, threat actors may a

Guardflares.com Redirect
Browser Hijacker

Guardflares.com Redirect

We have inspected guardflares.com and discovered that it is a fake search engine. We also found that guardflares.com is promoted through a variety of browser hijackers, such as SpeedyLook, SearchNinja, BlazeSearch and many other. Search engines promoted through such extensions should not be truste

Ymir Ransomware
Ransomware

Ymir Ransomware

Ymir is a ransomware-type program. It operates by encrypting files (using ChaCha20 cryptographic algorithm) and demanding ransoms for the decryption. The filenames of files locked by Ymir are altered by being appended with an extension comprising a random character string. For example, a file ini

SpeedyLook Browser Hijacker
Browser Hijacker

SpeedyLook Browser Hijacker

Our examination of SpeedyLook has revealed that it is an unreliable browser extension designed to hijack a web browser by changing its settings. This extension forces users to visit guardflares.com. Additionally, SpeedyLook enables the "Managed by your organization" setting (in Chrome browsers).

Email Password Time Running Out Scam
Phishing/Scam

Email Password Time Running Out Scam

We have analysed this email and found that it is a scam email designed to appear like a notification from an email service provider. This email contains a link to a phishing website designed to steal personal information. Recipients should ignore such emails and know how to recognize them.

$testME Token Claim Scam
Phishing/Scam

$testME Token Claim Scam

Our examination of the site (testme.mefoundaiton[.]xyz) has shown that it is a deceptive platform offering individuals to claim $testME tokens. The true purpose of this web page is to steal cryptocurrency from victims. Therefore, this and similar sites should be avoided. IMPORTANT NOTE: We d

RunningRAT Malware
Trojan

RunningRAT Malware

RunningRAT is a Remote Access Trojan (RAT) that was known for stealing sensitive information from victims. Now, cybercriminals are using it to distribute cryptocurrency miners. RunningRAT is likely to lead to higher electricity costs and hardware damage for victims. Thus, it should be removed from