Step-by-Step Malware Removal Instructions

Qore Ransomware
Ransomware

Qore Ransomware

Our team came across Qore ransomware during our analysis of malware samples submitted to VirusTotal. Qore is part of the Djvu ransomware family. It encrypts files and adds the ".qore" extension to their filenames. This ransomware also creates a "_readme.txt" file containing payment and contact inf

AuKill Malware
Trojan

AuKill Malware

AuKill is the name of a malware designed to terminate security processes, thus prepping the compromised system for further infections. This malicious software has been implemented in at least three attacks since January 2023. Twice AuKill was used preceding a Medusa Locker ransomware infection an

NodeStealer Malware
Trojan

NodeStealer Malware

NodeStealer is a type of malware written in JavaScript and executed through Node.js. It is used by threat actors to steal browser cookies and login credentials, enabling them to hijack Gmail, Facebook, Outlook, and possibly other accounts. The malware was initially discovered in late January of 20

Dispatchfeed.com Ads
Notification Spam

Dispatchfeed.com Ads

Our research team discovered the dispatchfeed[.]com rogue page while investigating suspicious websites. It is designed to promote spam browser notifications and redirect visitors to other (likely unreliable/harmful) sites. Users primarily enter webpages like dispatchfeed[.]com via redirects cause

Biserka.xyz Ads
Notification Spam

Biserka.xyz Ads

Our team's investigation of biserka[.]xyz revealed it to be an untrustworthy website that uses deceptive tactics to persuade visitors into subscribing to notifications. These types of websites are often accessed unintentionally by visitors. Biserka[.]xyz came to our attention while inspecting othe

Reianter.com Ads
Notification Spam

Reianter.com Ads

While investigating rogue webpages, our researchers discovered the reianter[.]com rogue site. It operates by pushing browser notification spam and redirecting visitors to other (likely untrustworthy/dangerous) websites. Most users enter pages like reianter[.]com via redirects caused by sites that

FluHorse Malware (Android)
Trojan

FluHorse Malware (Android)

FluHorse is a dangerous Android malware that targets users in Eastern Asia. The malware is distributed through emails and uses several malicious apps that mimic legitimate ones, stealing credentials and 2FA codes. FluHorse has the ability to evade detection for extended periods. FluHorse w

Pressrestraint.com Ads
Notification Spam

Pressrestraint.com Ads

Pressrestraint[.]com is a rogue page that our research team discovered while inspecting untrustworthy websites. This webpage promotes browser notification spam and redirects visitors to different (likely unreliable/malicious) sites. Most users access pages like pressrestraint[.]com through redire

IMAP/POP Configuration Error Email Scam
Phishing/Scam

IMAP/POP Configuration Error Email Scam

After inspecting the "IMAP/POP Configuration Error" email, we determined that it is spam. This letter falsely states that due to a configuration error, incoming messages have failed to reach the inbox. The goal of these claims is to trick recipients into attempting to restore their accounts throug

Vonsoocm.com Ads
Notification Spam

Vonsoocm.com Ads

During our investigation of websites that employ dubious advertising networks, we came across vonsoocm[.]com. This website displays deceptive content to deceive visitors into subscribing to its notifications. Moreover, vonsoocm[.]com redirects visitors to other sites. Vonsoocm[.]com displa