Step-by-Step Malware Removal Instructions

Vypt Ransomware
Ransomware

Vypt Ransomware

Vypt is ransomware that encrypts files stored on a computer, modifies filenames of all affected files, and creates two ransom notes ("Restore_Your_Files.txt" and "ReadMe.hta"). Our malware researchers discovered Vypt during examination of malware samples submitted to the VirusTotal site. Vypt app

TrafficStealer Malware (Mac)
Mac Virus

TrafficStealer Malware (Mac)

The TrafficStealer malware employs open container APIs to redirect web traffic to specific sites and manipulate user interaction with ads. Through the use of Docker containers, this program generates profits by sending traffic to monetized destinations. Despite appearing to be legitimate, the so

Getbrowbeatgroup.com Ads
Notification Spam

Getbrowbeatgroup.com Ads

Getbrowbeatgroup[.]com is a rogue page that our research team found while inspecting questionable websites. It is designed to push browser notification spam and redirect visitors to other (likely unreliable/hazardous) sites. Users typically access webpages like getbrowbeatgroup[.]com through redi

AttackSystem Ransomware
Ransomware

AttackSystem Ransomware

Our research team discovered the AttackSystem ransomware-type program while investigating new submissions to the VirusTotal website. This program is part of the MedusaLocker ransomware family. On our testing machine, AttackSystem encrypted data. The filenames of the affected files were appended w

CrypBits256 Ransomware
Ransomware

CrypBits256 Ransomware

While investigating new submissions to VirusTotal, our researchers discovered the CrypBits256 ransomware. This program belongs to the Xorist ransomware family. It is designed to encrypt data and demand payment for its decryption. When CrypBits256 was executed on our test system, it began encrypti

CyclinGuru Browser Hijacker
Browser Hijacker

CyclinGuru Browser Hijacker

Upon examination of the CyclinGuru browser extension, we found that it takes over a web browser by altering its settings with the aim of promoting a fake search engine called privatesearchqry.com. As a result, we have classified CyclinGuru as a browser hijacker. CyclinGuru browser extensio

Npdnnsgg.com Ads
Notification Spam

Npdnnsgg.com Ads

Npdnnsgg[.]com is a rogue webpage that we discovered while investigating suspicious sites. It operates by promoting spam browser notifications and redirecting visitors to different (likely untrustworthy/harmful) websites. Most users access pages like npdnnsgg[.]com via redirects generated by sites

Drinking Well Browser Hijacker
Browser Hijacker

Drinking Well Browser Hijacker

Our researchers found the Drinking Well browser extension while inspecting dubious sites. It is endorsed as a tool for tracking and improving users' hydration habits. However, our analysis of Drinking Well revealed that it is a browser hijacker, i.e., the extension modifies browser settings to pr

H3r Ransomware
Ransomware

H3r Ransomware

H3r is a ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. This program is part of the Dharma ransomware family and operates by encrypting data in order to demand ransoms for its decryption. On our testing system, H3r renamed the encrypted file

MIMUS Ransomware
Ransomware

MIMUS Ransomware

MIMUS is ransomware that encrypts files, replaces their filenames with a string of random characters and appends the ".encrypted" extension, and drops the "READ_TO_DECRYPT.html" file that contains a ransom note. Our malware researchers discovered MIMUS during an examination of samples submitted to