Step-by-Step Malware Removal Instructions

Wholefreshstories.com Ads
Notification Spam

Wholefreshstories.com Ads

Our researchers found the wholefreshstories[.]com rogue webpage while reviewing untrustworthy sites. It is designed to push browser notification spam and redirect users to different (likely dubious/malicious) websites. Most visitors to wholefreshstories[.]com and webpages akin to it access them t

Floscercurn.com Ads
Notification Spam

Floscercurn.com Ads

Floscercurn.com is a rogue webpage discovered by our research team during a routine investigation of dubious sites. This page promotes browser notification spam and redirects visitors to other (likely unreliable/dangerous) websites. Most users access webpages like floscercurn[.]com through redire

Trezor Upgrade Your Networks Scam
Phishing/Scam

Trezor Upgrade Your Networks Scam

"Trezor Upgrade Your Networks" is a scam that targets Trezor cryptowallet log-in credentials. The cyber criminals behind this scheme aim to steal the cryptocurrency stored in victims' wallets. It is pertinent to mention that this scam has been observed being promoted through spam emails. "

Your Errors Plug Adware
Adware

Your Errors Plug Adware

While investigating suspicious sites, our researchers discovered Your Errors Plug browser extension. It promises a "seamless" browsing experience with "relevant results on error-prone sites". For example, if a user enters a nonexistent URL – they are redirected to a webpage that informs them of th

Trojan.Hulk Malware
Trojan

Trojan.Hulk Malware

"Trojan.Hulk" is a detection name used by multiple security vendors for identifying rogue installers or illegal software ("cracks") tools, which are bundled with malicious content. Note that other detection names can be used for these setups. Content detected as "Trojan.Hulk" may include unwanted,

Gemheartartisan.top Ads
Notification Spam

Gemheartartisan.top Ads

While examining the page, it was revealed that it uses clickbait to receive permission to show notifications. Also, gemheartartisan[.]top may redirect visitors to similar pages. It is strongly recommended not to allow gemheartartisan[.]top or similar websites to show notifications. Usually, these

Lockxx Ransomware
Ransomware

Lockxx Ransomware

In our examination of the malware, we observed that Lockxx operates as ransomware: it encrypts files, appends its extension ".lockxx" to file names, and provides a ransom note ("lockxx.recovery_data.hta"). Additionally, Lockxx changes the victim's desktop wallpaper. An example of how Lockxx modif

CrotalusAtrox Malicious Extension
Adware

CrotalusAtrox Malicious Extension

Upon analyzing CrotalusAtrox, it was noted that it possesses the capability to both access and manipulate data on visited websites. Additionally, it can exert control over themes and extensions within the compromised browser and enable the "Managed by your organization" feature in Chrome and Edge

AconitumNapellus Malicious Extension
Adware

AconitumNapellus Malicious Extension

AconitumNapellus is a malicious browser extension discovered by our researchers in an installer promoted on a dubious webpage. This piece of software makes alterations to browsers and spies on users' browsing activity. It is noteworthy that installation setups like the one containing AconitumNape

Cashier Check Email Scam
Phishing/Scam

Cashier Check Email Scam

After careful examination, it has been established that this email is a fraudulent scheme designed to deceive recipients into thinking they have been selected as beneficiaries with the prospect of receiving a substantial sum of money. Typically, the perpetrators behind such emails aim to extract p