Step-by-Step Malware Removal Instructions

Getgadsgroup.com Ads
Notification Spam

Getgadsgroup.com Ads

During our investigation of websites utilizing rogue advertising networks, we came across getgadsgroup[.]com, a site that employs a deceptive tactic to lure visitors into subscribing to notifications. It is important to note that users do not deliberately navigate to pages like getgadsgroup[.]com.

BabyDuck Ransomware
Ransomware

BabyDuck Ransomware

BabyDuck is a ransomware-type program we discovered while examining new submissions to VirusTotal. This malicious program is based on Babuk ransomware. On our testing system, a sample of BabyDuck encrypted files and appended their filenames with a ".babyduck" extension. For example, a file origin

New Webmail Version Email Scam
Phishing/Scam

New Webmail Version Email Scam

After investigating the "New Webmail Version" email, we determined that it is spam. This letter encourages the recipient to switch their Webmail account to the latest version. The aim of this phishing mail is to obtain email account log-in credentials. The email with the subject "New lette

Keywordssearching.com Redirect
Browser Hijacker

Keywordssearching.com Redirect

Keywordssearching.com is the address of a fake search engine. Websites of this kind are usually promoted (via redirects) by browser hijackers. This software modifies browser settings for this purpose. Furthermore, both illegitimate search engines and browser-hijacking software typically collect us

Tapheshusurvey.space Ads
Notification Spam

Tapheshusurvey.space Ads

Upon investigating tapheshusurvey[.]space, we determined that it is an untrustworthy website that engages in survey scams. Additionally, tapheshusurvey[.]space wants to display notifications and redirects users to other websites. It is important to note that users do not intentionally visit pages

You've Received A Secure File Email Scam
Trojan

You've Received A Secure File Email Scam

After inspecting the "You've Received A Secure File" spam email, we determined that it operates as a phishing scam. The letter claims that the recipient was sent a protected document, which can only be accessed by providing their email account log-in credentials. The email with the subject

Atoionanruman.com Ads
Notification Spam

Atoionanruman.com Ads

During our investigation of suspicious advertising networks, our team discovered atoionanruman[.]com, a website known for displaying a deceptive message aimed at persuading visitors to enable notifications. It is worth noting that users often land on pages like atoionanruman[.]com unintentionally,

Fullpcchain.com Ads
Notification Spam

Fullpcchain.com Ads

While examining web pages associated with unreliable advertising networks, we came across fullpcchain[.]com. Our investigation uncovered that fullpcchain[.]com is an untrustworthy website that promotes the "McAfee - Your PC is infected with 5 viruses!" scam. Additionally, fullpcchain[.]com request

Bhui Ransomware
Ransomware

Bhui Ransomware

During the analysis of malware samples submitted to VirusTotal, our team discovered Bhui ransomware, which is part of the Djvu ransomware family. Once a computer is infected, Bhui encrypts files and appends the ".bhui" extension to their original filenames. For example, a file named "1.jpg" gets r

Bhtw Ransomware
Ransomware

Bhtw Ransomware

During our analysis of malware samples submitted to VirusTotal, we encountered Bhtw, a ransomware variant belonging to the Djvu family. Bhtw encrypts files and appends the ".bhtw" extension to their names. Additionally, it generates a ransom note, a text file named "_readme.txt". An example of ho