Step-by-Step Malware Removal Instructions

DarkTortilla RAT
Trojan

DarkTortilla RAT

DarkTortilla RAT is a Remote Access Trojan with significant information-stealing capabilities. It quietly harvests saved browser passwords, session cookies, and payment card details from infected machines without displaying any visible signs of activity. According to analysis published by kaandem

ZigCryptoStealer Malware
Trojan

ZigCryptoStealer Malware

ZigCryptoStealer is a cryptocurrency-stealing malware written in the Zig programming language. It works as a clipper - it watches the Windows clipboard and, when the victim copies a cryptocurrency wallet address, quietly swaps it for an address that belongs to the attacker. Payments the victim thi

PollCat RAT
Trojan

PollCat RAT

PollCat is a Remote Access Trojan (RAT) written in obfuscated JavaScript. It gives attackers remote control over infected computers, letting them run commands, steal files, manage processes, and execute additional code. PollCat is cross-platform and works on Windows, Linux, and macOS. Kaspersky r

NodeRabbit RAT
Trojan

NodeRabbit RAT

NodeRabbit is a Remote Access Trojan (RAT) written in Node.js. It lets attackers secretly run commands, manage files, collect information about the device and network, and load additional code on infected computers. The malware is cross-platform and works on Windows, Linux, and macOS. Kaspersky r

Official Purchase Order Email Scam
Phishing/Scam

Official Purchase Order Email Scam

We have examined this email and determined it is a phishing scam. The message is disguised as a legitimate business purchase order and carries an HTML file attachment. Opening the attachment reveals a fake Adobe-locked document interface designed to steal the recipient's email password. This email

Notice Of Payment Email Virus
Phishing/Scam

Notice Of Payment Email Virus

We have inspected this email and determined that it is malspam. The message impersonates official correspondence from Absa bank to trick recipients into opening an attached PDF file. That PDF contains a link which downloads a malicious script designed to inject malware onto the victim's device. Th

Overbridgenet.com Adware
Other

Overbridgenet.com Adware

Overbridgenet.com is a domain contacted in the background by an adware-type browser extension. We analyzed the campaign after it was documented by Qi'anxin Threat Intelligence Center, which named the extension responsible "Ghost Extension". The extension adds sponsored shopping results to Google

Your Avast Protection Expired POP-UP Scam
Phishing/Scam

Your Avast Protection Expired POP-UP Scam

We inspected this page and found that it runs a fabricated Avast alert built to frighten visitors into buying antivirus software through an affiliate link. The scan results, the virus names, and the expiry date shown on the page are all invented. Avast is a real security company and has no connect

Mail Capacity Guide Email Scam
Phishing/Scam

Mail Capacity Guide Email Scam

We have inspected this email and determined that it is a phishing scam. The message is disguised as an automated notification from an email service provider, falsely warning the recipient that their mailbox storage is nearly full. This email should be ignored to avoid handing login credentials ove

Proposed Contract Changes Email Virus
Phishing/Scam

Proposed Contract Changes Email Virus

Our team has inspected this email and concluded it is malspam. The message poses as a business communication from a purchasing manager, claiming to include a PDF attachment with proposed contract revisions. Its true purpose is to deliver malware through a multi-stage infection chain hidden inside