Step-by-Step Malware Removal Instructions

Jirin.app Adware (Mac)
Mac Virus

Jirin.app Adware (Mac)

Our examination of the Jirin.app has revealed that this app is one of the many adware-type apps belonging to the Pirrit family. The purpose of this program is to deliver intrusive and potentially misleading advertisements to users. Thus, Jirin.app should be uninstalled from devices. Jiri

Alladvertisingdomclub.club Ads
Notification Spam

Alladvertisingdomclub.club Ads

Upon examining alladvertisingdomclub[.]club, we concluded that the purpose of this page is to deceive unsuspecting visitors into allowing it to show notifications. Also, alladvertisingdomclub[.]club can redirect users to other web pages. Overall, alladvertisingdomclub[.]club is an unreliable websi

Scrypt Ransomware
Ransomware

Scrypt Ransomware

While investigating new file submissions to the VirusTotal platform, our research team discovered Scrypt ransomware. Its purpose is to encrypt files and demand payment for their decryption. On our testing system, this ransomware encrypted files and appended their filenames with a ".scrypt" extens

Hedgies Giveaway Scam
Phishing/Scam

Hedgies Giveaway Scam

During our examination of nft-hedgies[.]com, we discovered that it is a scam website pretending to be a cryptocurrency airdrop (giveaway) launched by Hedgies (hedgies[.]wtf). Scammers behind nft-hedgies[.]com aim to lure potential participants into performing actions allowing scammers to steal cry

Vehu Ransomware
Ransomware

Vehu Ransomware

Vehu is ransomware that we discovered while examining malware samples uploaded to VirusTotal. Our findings are that Vehu belongs to the Djvu family, encrypts files, appends the ".vehu" extension to filenames, and provides a ransom note ("_README.txt"). It is worth noting that ransomware from the D

Paaa Ransomware
Ransomware

Paaa Ransomware

Paaa is a ransomware variant from the Djvu family. We discovered Paaa during our analysis of samples submitted to the VirusTotal site. This ransomware uses encryption to prevent victims from accessing their files. Additionally, it appends the ".paaa" extension to filenames and drops the "!!!README

Vepi Ransomware
Ransomware

Vepi Ransomware

Vepi is a ransomware variant belonging to the Djvu family. Our discovery of Vepi occurred during inspection of malware samples submitted to VirusTotal. Upon infiltration, Vepi encrypts files and appends the ".vepi" extension to filenames. It also provides a ransom note ("_readme.txt"). An example

Myxioslive.com Ads
Notification Spam

Myxioslive.com Ads

Our research team found the myxioslive[.]com page while browsing dubious websites. This rogue webpage endorses browser notification spam and generates redirects to other (likely untrustworthy/dangerous) sites. Users primarily access pages like myxioslive[.]com via redirects caused by websites util

Claim $ROCKY Scam
Phishing/Scam

Claim $ROCKY Scam

"Claim $ROCKY" refers to a fake website supposedly distributing the Rocky token. We found this scam promoted on rockybased[.]com, yet it could also be hosted elsewhere. "Claim $ROCKY" operates as a cryptocurrency drainer that steals digital assets from victims' cryptowallets. It must be emphasized

Artrade #RWA Scam
Phishing/Scam

Artrade #RWA Scam

After examining an "Artrade #RWA" webpage, we determined that it is fake. The page – distribution-artrade[.]app – hosts a crypto drainer scam (note that it could be hosted on other domains). It imitates Artrade (artrade.app) – however, the scam is not associated with this or any other existing pl