Step-by-Step Malware Removal Instructions

Roundcube - Unusual Login Attempt Email Scam
Phishing/Scam

Roundcube - Unusual Login Attempt Email Scam

Our team has checked this email and learned that it masquerades as an alert from an email service provider. Scammers behind this fraudulent email aim to lure recipients into opening a fake website and disclosing personal information. Scams of this type are known as phishing attempts. Recipients sh

XIXTEXRZ Ransomware
Ransomware

XIXTEXRZ Ransomware

While browsing new malware submissions to VirusTotal, our researchers discovered the XIXTEXRZ ransomware. Malicious software of this kind encrypts files and demands ransoms for the decryption. On our test machine, XIXTEXRZ encrypted files and appended their names with a ".crypted" extension. To e

Soneium Registration Scam
Phishing/Scam

Soneium Registration Scam

While inspecting rogue pages, our researchers discovered this fake "Soneium Registration" website (event-soneium[.]org; note that it could be hosted elsewhere). It is presented as a blockchain platform, but this scam page is not associated with existing ones or any legitimate entities. This schem

Node AI Scam
Phishing/Scam

Node AI Scam

We have inspected the page (register.nodeainetwork[.]com) and discovered that it is a fraudulent website mimicking nodes[.]ai, a legitimate platform. The purpose of the fake web page is to trick visitors into taking action that could lead to significant financial losses. Therefore, this website sh

Binance USDC Distribution Scam
Phishing/Scam

Binance USDC Distribution Scam

During our analysis of the page (binance-airdrop-carv[.]info), we determined that it is a scam website. It is designed to trick visitors into believing they can participate in a cryptocurrency giveaway. Scammers behind this fraudulent scheme aim to trick unsuspecting individuals into taking action

Ationiamcur.com Ads
Notification Spam

Ationiamcur.com Ads

Our researchers found ationiamcur[.]com while browsing untrustworthy sites. This rogue page is designed to promote spam browser notifications and generate redirects to various (likely dubious/dangerous) websites. Ationiamcur[.]com and similar webpages are most commonly accessed via redirects caus

Awksqa.com Ads
Notification Spam

Awksqa.com Ads

Our examination of awksqa[.]com has revealed that the website uses clickbait to deceive visitors into granting it permission to display notifications. Web pages like awksqa[.]com often promote other untrustworthy sites. Thus, users should not visit them and never accept their notifications.

Spider Ransomware
Ransomware

Spider Ransomware

Our researchers found the Spider ransomware during a routine inspection of new file submissions to the VirusTotal site. This program is part of the MedusaLocker ransomware family. Spider is designed to encrypt data and demand ransoms for its decryption; this malware utilizes double-extortion tacti

Bealanews.com Ads
Notification Spam

Bealanews.com Ads

During our inspection of bealanews[.]com, we learned that this website is designed to lure visitors into agreeing to receive its notifications. To achieve this, bealanews[.]com utilizes clickbait. Users should never permit sites like bealanews[.]com to send notifications and avoid visiting them.

Root (MedusaLocker) Ransomware
Ransomware

Root (MedusaLocker) Ransomware

During our analysis of malware samples uploaded to VirusTotal, we discovered Root, a ransomware variant belonging to the MedusaLocker family. We found that Root encrypts and renames files, and provides a ransom note ("How_to_back_files.html"). It appends the ".root4" extension to filenames (the nu