Step-by-Step Malware Removal Instructions

Cream Airdrop Scam
Phishing/Scam

Cream Airdrop Scam

In our examination of the website cream-fi[.]com, we discovered it to be a scam site impersonating another crypto-related platform, cream[.]finance. The primary aim of this scam is to deceive individuals into taking actions that enable scammers to steal their cryptocurrency. Therefore, exercising

Diamond (Duckcryptor) Ransomware
Ransomware

Diamond (Duckcryptor) Ransomware

Our researchers discovered Diamond (Duckcryptor) ransomware during a routine inspection of new submissions to the VirusTotal platform. This malicious program is designed to encrypt data and demand payment for the decryption. On our testing system, Diamond (Duckcryptor) ransomware encrypted files

ProcessField Adware (Mac)
Mac Virus

ProcessField Adware (Mac)

Through our examination, we discovered that ProcessField operates as adware. Upon installation, it inundates users with intrusive advertisements and potentially collects various user data. Users should avoid installing applications similar to ProcessField, and, if already installed, promptly uni

EngineMapper Adware (Mac)
Mac Virus

EngineMapper Adware (Mac)

During our investigation, we found that EngineMapper is a program that functions as adware. Once installed, it bombards users with bothersome advertisements and may gather diverse user information. It is recommended that users steer clear of installing apps like EngineMapper (and uninstall alrea

RotatorLauncher Adware (Mac)
Mac Virus

RotatorLauncher Adware (Mac)

During our examination, we discovered that RotatorLauncher is an ad-supported application. Upon installation, it inundates users with irritating advertisements. Additionally, there is a likelihood that this app collects various user data. It is advisable for users to avoid installing apps simila

Degen Airdrop 2 Scam
Phishing/Scam

Degen Airdrop 2 Scam

In our analysis of the website (distributions-degen[.]tips), we found it to be a fraudulent page posing as another crypto platform (degen[.]tips), promoting a second cryptocurrency airdrop (giveaway). Scammers utilize this deceptive site to steal cryptocurrency from unsuspecting individuals. Thus,

Bgjs Ransomware
Ransomware

Bgjs Ransomware

Upon analysis of the malware samples available on the VirusTotal platform, it has been confirmed that Bgjs is a member of the Djvu ransomware family. Bgjs operates by encrypting files and modifying their filenames (appending the ".bgjs" extension). For instance, it replaces "1.jpg" with "1.jpg.bgj

Bgzq Ransomware
Ransomware

Bgzq Ransomware

After examining the malware samples accessible through the VirusTotal platform, it has been determined that Bgzq belongs to the Djvu ransomware family. Bgzq encrypts files and adjusts their filenames, adding the ".bgzq" extension. For instance, it transforms "1.jpg" into "1.jpg.bgzq", "2.png" into

Bitcoin L2 Restaking Scam
Phishing/Scam

Bitcoin L2 Restaking Scam

After examining this "Bitcoin L2 Restaking" online platform, we determined it is fake. This scam operates as a cryptocurrency drainer. Once a digital wallet is "connected" to this scheme, a mechanism is initiated that begins emptying it of funds. This scam imitates a staking platform that

Quotation Request Email Virus
Phishing/Scam

Quotation Request Email Virus

Upon examination, we determined that "Quotation Request" is malspam. This email is presented as a potential purchase inquiry. The goal is to deceive recipients into opening the malicious attachment and infecting their devices with the Agent Tesla malware. The spam email with the subject "Q