Step-by-Step Malware Removal Instructions

United Nations - Abandoned Shipment Email Scam
Phishing/Scam

United Nations - Abandoned Shipment Email Scam

After inspecting the "United Nations - Abandoned Shipment" email, we determined that it is spam. The letter is supposedly from a "Head Officer in Charge" and claims that a consignment intended for the recipient failed to reach them due to improper documentation and unpaid fees. The shipment consis

Next Of Kin Email Scam
Phishing/Scam

Next Of Kin Email Scam

We have examined this email and determined that it is used to trick unsuspecting recipients into parting with their money in an inheritance scam. It offers to share the unclaimed funds of a supposedly deceased person. We also found that there are at least two versions of this scam email. T

CatB Ransomware
Ransomware

CatB Ransomware

CatB is a ransomware-type program. It encrypts data and demands payment for the decryption. While testing this ransomware, we learned that it does not alter the filenames of encrypted files - an uncommon occurrence in these types of infections. CatB inserts ransom notes at the beginning of each e

Pupy RAT
Trojan

Pupy RAT

Pupy is the name of an open-source Remote Administration Trojan (RAT) written in Python. Malware of this type is used to gain remote control of a target computer. Threat actors have been observed using a legitimate a process that reports errors in Windows (and Windows applications) to distribute P

Cyclops Ransomware
Ransomware

Cyclops Ransomware

Cyclops is the name of a malicious program classified as ransomware. This malware is designed to encrypt data and demand ransoms for its decryption. After being launched on our test system, Cyclops ransomware began encrypting files. Typically, the affected files are renamed (often by being append

MintStealer Malware
Trojan

MintStealer Malware

MintStealer (also known as Mint Stealer) is an information stealer targeting web browsers, messengers, mail clients, VPN clients, game sessions, and more. It is used to extract sensitive data. MintStealer is being sold as Malware-as-a-service (MaaS). Other cybercriminals can purchase MintStealer f

Webaddictremind.xyz Ads
Notification Spam

Webaddictremind.xyz Ads

Webaddictremind[.]xyz is the address of a rogue website designed to run scams, promote spam browser notifications, and redirect visitors to other (likely unreliable/dangerous) pages. Our researchers discovered the webaddictremind[.]xyz webpage while inspecting sites that use rogue advertising net

Download Checker Adware
Adware

Download Checker Adware

While investigating deceptive websites, our researchers discovered the Download Checker browser extension. It is promoted as a tool for testing Internet speed. However, our analysis of Download Checker revealed that it operates as advertising-supported software (adware) instead. Adware is

Worlddecoding Ransomware
Ransomware

Worlddecoding Ransomware

During a routine inspection of new submissions to VirusTotal, we discovered the Worlddecoding malicious program that is practically identical to World2022decoding ransomware. After we executed a sample of Worlddecoding ransomware on our testing system, it encrypted files and appended their titles

Duplicatefinder Adware
Adware

Duplicatefinder Adware

While analyzing the Duplicatefinder application, our team found that it displays annoying advertisements. Apps that bombard users with ads are classified as adware. We discovered Duplicatefinder while examining a download assistant downloaded from a shady website. As its name suggests, Dup