Step-by-Step Malware Removal Instructions

Zodiac Search Browser Hijacker
Browser Hijacker

Zodiac Search Browser Hijacker

While investigating questionable websites, our researchers discovered a deceptive page endorsing an installer containing the Zodiac Search browser extension. It is promoted as a tool for easy access to horoscopes. Our analysis of Zodiac Search revealed that it is a browser hijacker. This extensio

Lifepcessentials.com Ads
Notification Spam

Lifepcessentials.com Ads

Our research team found the lifepcessentials[.]com rogue page while checking out untrustworthy websites. It runs online scams and pushes browser notification spam. Additionally, this webpage can redirect users to other (likely suspicious/malicious) sites. Most visitors to lifepcessentials[.]com a

Weather Search Browser Hijacker
Browser Hijacker

Weather Search Browser Hijacker

Weather Search is an extension that promises to display weather forecasts and related information relevant to the user's location, local time, and browser wallpapers. Our researchers discovered this piece of software while investigating dubious websites. After inspecting Weather Search, we determ

SempervivumTectorum Malicious Extension
Adware

SempervivumTectorum Malicious Extension

During our investigation of a malicious installer, we discovered concerning actions performed by the SempervivumTectorum browser extension, including enabling the "Managed by your organization" feature in Chrome settings and collecting user data. Thus, users who have SempervivumTectorum added to t

Your Google Account Has Been Locked! POP-UP Scam
Phishing/Scam

Your Google Account Has Been Locked! POP-UP Scam

While inspecting deceptive sites, our research team discovered the "Your Google Account Has Been Locked!" scam. Specifically, it is a technical support scam. It informs the website's visitor that their Google account has been blocked due to visits to harmful pages which pose significant threats.

Whatodo Browser Hijacker
Browser Hijacker

Whatodo Browser Hijacker

Our team assessed the Whatodo browser extension and determined that it functions as a browser hijacker. Its main objective is to promote gsrcunow.com, a fake search engine, by altering the settings of the compromised browser. Typically, users inadvertently introduce browser hijackers to their brow

Donation From Coca-Cola Email Scam
Phishing/Scam

Donation From Coca-Cola Email Scam

Following an analysis of this email, we have determined that it constitutes a fraudulent scheme. It masquerades as a communication from the Coca-Cola company. The scammers orchestrating such deceptive emails aim to obtain money or sensitive data from unsuspecting recipients. It is highly advisable

Arminuntor.com Ads
Notification Spam

Arminuntor.com Ads

While inspecting arminuntor[.]com, our team found that this page presents misleading content to trick visitors into allowing it to send notifications. Additionally, arminuntor[.]com redirects visitors to other unreliable websites. Thus, it is highly recommended to avoid visiting arminuntor[.]com a

Hgfu Ransomware
Ransomware

Hgfu Ransomware

While analyzing malware samples on the VirusTotal platform, we encountered the Hgfu ransomware belonging to the Djvu malware family. Upon infiltrating a computer, this ransomware encrypts data and adds the ".hgfu" extension to file names. For example, a file originally named "1.jpg" transforms int

Hgew Ransomware
Ransomware

Hgew Ransomware

During our examination of malware samples submitted to VirusTotal, we came across a ransomware variant identified as Hgew. This particular ransomware is designed to encrypt files and alter their filenames by appending the ".hgew" extension. Furthermore, Hgew generates a ransom note, which can be l