Step-by-Step Malware Removal Instructions

Qehu Ransomware
Ransomware

Qehu Ransomware

Qehu is a type of ransomware that encrypts files, adds the ".qehu" extension to their filenames, and provides a ransom note ("README.txt"). For instance, it changes "1.jpg" to "1.jpg.qehu" and "2.png" to "2.png.qehu". We encountered Qehu while analyzing malware samples submitted to VirusTotal. It

Qepi Ransomware
Ransomware

Qepi Ransomware

Qepi is ransomware designed to encrypt files, append the ".qepi" extension to filenames, and provide a ransom note ("README.txt"). We discovered Qepi during an analysis of malware samples submitted to VirusTotal. It is important to mention that Qepi is part of the Djvu family and may be distribute

Colorattaches.com Ads
Notification Spam

Colorattaches.com Ads

Colorattaches[.]com is a rogue page discovered by our research team during a routine investigation of dubious websites. Upon examination, we determined that this webpage uses fake CAPTCHA verification to push browser notification spam. Additionally, it can redirect users to other (likely dubious/m

ProjectRootEducate Adware (Mac)
Mac Virus

ProjectRootEducate Adware (Mac)

While inspecting new file submissions to the VirusTotal site, our research team discovered the ProjectRootEducate app. After analyzing it, we learned that this application is adware from the AdLoad malware family. ProjectRootEducate is designed to generate revenue for its developers through adve

Datingkoe.info Ads
Notification Spam

Datingkoe.info Ads

While investigating suspicious websites, our researchers discovered the datingkoe[.]info rogue webpage. It operates by promoting browser notification spam and redirecting users to other (likely untrustworthy/dangerous) sites. Most visitors to datingkoe[.]info and pages akin to it access them thro

PayPal Crypto Purchase Invoice Email Scam
Phishing/Scam

PayPal Crypto Purchase Invoice Email Scam

We have examined the email and determined that it is a phishing email intended to steal personal information and (or) money from unsuspecting individuals. This scam email is disguised as a notification from PayPal regarding an invoice. Recipients should ignore this email. As we mentioned i

OpenProcess Adware (Mac)
Mac Virus

OpenProcess Adware (Mac)

OpenProcess is a piece of software that is classified as adware. Our researchers found this application during a routine investigation of new file submissions to the VirusTotal platform. OpenProcess belongs to the AdLoad malware family, and it runs intrusive advertisement campaigns. Adwa

Grayscale ($GRAY) Airdrop Scam
Phishing/Scam

Grayscale ($GRAY) Airdrop Scam

After investigating the "Grayscale ($GRAY) Airdrop", as promoted on event-grayscale[.]com, we determined that it is fake. This scam is an almost perfect copy of the Grayscale platform (grayscale.com). This bogus giveaway operates as a crypto drainer that siphons cryptocurrency from compromised di

PublicAnalog Adware (Mac)
Mac Virus

PublicAnalog Adware (Mac)

During our analysis of PublicAnalog we observed that the app functions as adware. While active, it delivers annoying advertisements. It is also common for apps like PublicAnalog to be capable of accessing (and gathering) various data. Thus, it is recommended to uninstall PublicAnalog from affect

WaveStealer Malware
Trojan

WaveStealer Malware

WaveStealer (also known as Wave Stealer) is a malware designed to steal information. Its developers are offering the malicious program for sale, and they promote it as a highly versatile tool. WaveStealer targets log-in credentials (usernames/passwords), credit card numbers, cryptocurrency wallets