Step-by-Step Malware Removal Instructions

Shipping Bills & Export Declaration Form Email Virus
Phishing/Scam

Shipping Bills & Export Declaration Form Email Virus

After examining this letter, we have concluded that its intent is to deceive recipients into infecting their computers. The email appears as a correspondence related to shipping bills and export declaration forms, but it includes an attachment specifically crafted to introduce Remcos RAT into the

NIGHT CROW Ransomware
Ransomware

NIGHT CROW Ransomware

Our research team discovered the NIGHT CROW ransomware while inspecting new submissions to the VirusTotal website. This program is designed to encrypt data and demand payment for its decryption. On our test machine, NIGHT CROW encrypted files and appended their filenames with an extension. The ti

BBTok Malware
Trojan

BBTok Malware

The BBTok is a banking Trojan written in Delphi equipped with specialized functionality that mimics the interfaces of over 40 Mexican and Brazilian banks. Its deceptive tactics involve luring victims into divulging their 2FA codes for bank accounts or their payment card numbers. Additionally, BBT

IRATA Malware (Android)
Trojan

IRATA Malware (Android)

IRATA is the name of an Android-specific malware. This program has spyware and stealer capabilities. It was discovered after a smishing (SMS phishing) attack in Iran. This campaign entailed legitimate-looking SMSes containing a link to a fake governmental website. The page urged visitors to downlo

Shop and Watch Adware
Adware

Shop and Watch Adware

During an examination of the Shop and Watch browser extension, we discovered that it displays annoying advertisements. Thus, Shop and Watch can be classified as adware. Also, Shop and Watch adds the "Managed by your organization" feature to Chrome browsers and can read various data. Users should n

AnkylosaurusMagniventris Malicious Extension
Adware

AnkylosaurusMagniventris Malicious Extension

While analyzing an untrustworthy installer obtained from an unreliable website, we came across the AnkylosaurusMagniventris browser extension. The investigation revealed troubling attributes linked to this extension, including its capacity to enable the "Managed by your organization" setting in th

LostTrust Ransomware
Ransomware

LostTrust Ransomware

LostTrust is the name of a ransomware variant discovered by us while examining malware samples submitted to VirusTotal. The purpose of LostTrust is to encrypt data to make it inaccessible to victims. Also, LostTrust appends the ".losttrustencoded" extension to filenames and delivers a ransom note

NXD Fix Browser Hijacker
Browser Hijacker

NXD Fix Browser Hijacker

While investigating deceptive sites, we discovered an installer containing the NXD Fix browser extension. This piece of software is classified as a browser hijacker. However, NXD Fix does not operate as a standard hijacker, i.e., it does not modify browser settings and does not routinely redirect

Notif-next.com Ads
Notification Spam

Notif-next.com Ads

Upon examining notif-next[.]com, it has been discovered that the main purpose of this site is to trick unsuspecting visitors into allowing it to send them notifications. Additionally, notif-next[.]com may redirect visitors to other (potentially harmful) websites. For these reasons, users should no

News Directory Browser Hijacker
Browser Hijacker

News Directory Browser Hijacker

After assessing the News Directory application, it has been established that its primary function is to operate as a browser hijacker with the aim of promoting a legitimate search engine. This extension hijacks a web browser by changing its settings. Users often add browser hijackers without knowi