Step-by-Step Malware Removal Instructions

OpenSea Offer Alert Email Scam
Phishing/Scam

OpenSea Offer Alert Email Scam

Our team has examined this email and concluded that it is a scam email (a phishing attempt) masquerading as a notification from OpenSea regarding a new offer. Usually, scammers use phishing emails like this one to extract personal information. Recipients should ignore emails of this type.

News-wurinu.com Ads
Notification Spam

News-wurinu.com Ads

News-wurinu[.]com is the address of a rogue page discovered by our researchers during a routine investigation of suspicious websites. Upon examination, we learned that news-wurinu[.]com promotes browser notification spam and generates redirects to other (likely untrustworthy/hazardous) sites. Use

News-silasa.cc Ads
Notification Spam

News-silasa.cc Ads

While analyzing news-silasa[.]cc, we found that it uses clickbait (displays deceptive content) to trick visitors into allowing it to send notifications. Additionally, we discovered that news-silasa[.]cc can redirect visitors to other websites of this type. Users should avoid visiting news-silasa[.

Hlas Ransomware
Ransomware

Hlas Ransomware

Hlas is ransomware from the Djvu family. Once a computer is infected with the malware, files become encrypted and renamed (with the ".hlas" extension in their filenames). A ransom note (named "_readme.txt") is also provided. An example of how encrypted files are renamed is "1.jpg" being changed to

BlotchyQuasar RAT
Trojan

BlotchyQuasar RAT

BlotchyQuasar (variant of QuasarRAT) is a remote access Trojan (RAT). Typically, cybecriminals utilize RATs to steal sensitive information and (or) deploy other malware. Threat actors have been observed distributing BlotchyQuasar via email. Users should immediately eliminate BlotchyQuasar from inf

News-nuriga.com Ads
Notification Spam

News-nuriga.com Ads

News-nuriga[.]com is a rogue page found by our research team during a routine inspection of dubious websites. After investigating this webpage, we determined that it promotes spam browser notifications and redirects users to different (likely untrustworthy/harmful) sites. Visitors to news-nuriga[

Mykneads24.com Ads
Notification Spam

Mykneads24.com Ads

Upon inspection, we learned that the mykneads24[.]com rogue webpage promotes browser notification spam and redirects visitors to different (likely dubious/malicious) sites. Most users access pages like mykneads24[.]com through redirects caused by websites that employ rogue advertising networks. O

Trial_recovery Ransomware
Ransomware

Trial_recovery Ransomware

While investigating submissions to VirusTotal, our researchers discovered a ransomware identical to Available_for_trial named Trial_recovery. Malware within this class is designed to encrypt data and demand ransoms for its decryption. Trial_recovery also renames the files it locks following the "

JsTimer Unwanted Extension
Adware

JsTimer Unwanted Extension

JsTimer is presented as a simple timer extension for Chrome browsers. However, we found that it is distributed alongside other dubious extensions and apps. Also, it can read certain information. Therefore, we classified JsTimer as an unwanted extension. If this or any associated extension (like Fu

Mumpings.com Ads
Notification Spam

Mumpings.com Ads

Our researchers discovered the mumpings[.]com rogue page while investigating dubious websites. After examining this webpage, we determined that it operates by promoting browser notification spam and generating redirects to other (likely unreliable/dangerous) sites. Most users enter mumpings[.]com