Step-by-Step Malware Removal Instructions

WebMail Server Manager Email Virus
Phishing/Scam

WebMail Server Manager Email Virus

Our examination of the "WebMail Server Manager" email revealed that it is malspam. This spam letter informs the recipient that multiple messages have failed to reach their inbox. Supposedly, the undelivered emails can be found in the attachments. The attached files are identical, and both are des

AdAssistant Adware
Adware

AdAssistant Adware

AdAssistant is an application that our researchers discovered while inspecting deceptive sites. After investigating this piece of software, we determined that it is adware. Additionally, the installation setup containing AdAssistant was bundled with the Shop and Watch, ChatGPT Check, and NXD Fix r

Shipping Bills & Export Declaration Form Email Virus
Phishing/Scam

Shipping Bills & Export Declaration Form Email Virus

After examining this letter, we have concluded that its intent is to deceive recipients into infecting their computers. The email appears as a correspondence related to shipping bills and export declaration forms, but it includes an attachment specifically crafted to introduce Remcos RAT into the

NIGHT CROW Ransomware
Ransomware

NIGHT CROW Ransomware

Our research team discovered the NIGHT CROW ransomware while inspecting new submissions to the VirusTotal website. This program is designed to encrypt data and demand payment for its decryption. On our test machine, NIGHT CROW encrypted files and appended their filenames with an extension. The ti

BBTok Malware
Trojan

BBTok Malware

The BBTok is a banking Trojan written in Delphi equipped with specialized functionality that mimics the interfaces of over 40 Mexican and Brazilian banks. Its deceptive tactics involve luring victims into divulging their 2FA codes for bank accounts or their payment card numbers. Additionally, BBT

IRATA Malware (Android)
Trojan

IRATA Malware (Android)

IRATA is the name of an Android-specific malware. This program has spyware and stealer capabilities. It was discovered after a smishing (SMS phishing) attack in Iran. This campaign entailed legitimate-looking SMSes containing a link to a fake governmental website. The page urged visitors to downlo

Shop and Watch Adware
Adware

Shop and Watch Adware

During an examination of the Shop and Watch browser extension, we discovered that it displays annoying advertisements. Thus, Shop and Watch can be classified as adware. Also, Shop and Watch adds the "Managed by your organization" feature to Chrome browsers and can read various data. Users should n

AnkylosaurusMagniventris Malicious Extension
Adware

AnkylosaurusMagniventris Malicious Extension

While analyzing an untrustworthy installer obtained from an unreliable website, we came across the AnkylosaurusMagniventris browser extension. The investigation revealed troubling attributes linked to this extension, including its capacity to enable the "Managed by your organization" setting in th

LostTrust Ransomware
Ransomware

LostTrust Ransomware

LostTrust is the name of a ransomware variant discovered by us while examining malware samples submitted to VirusTotal. The purpose of LostTrust is to encrypt data to make it inaccessible to victims. Also, LostTrust appends the ".losttrustencoded" extension to filenames and delivers a ransom note

NXD Fix Browser Hijacker
Browser Hijacker

NXD Fix Browser Hijacker

While investigating deceptive sites, we discovered an installer containing the NXD Fix browser extension. This piece of software is classified as a browser hijacker. However, NXD Fix does not operate as a standard hijacker, i.e., it does not modify browser settings and does not routinely redirect