Step-by-Step Malware Removal Instructions

Cypher RAT (Android)
Trojan

Cypher RAT (Android)

Cypher is the name of a remote administration Trojan (RAT) targeting Android users. It allows threat actors to monitor and control infected devices (perform various actions on infected devices). Cypher's creators offer three subscription plans: $100 per month, $200 for three months, and $400 for a

AlphaExplorer Adware (Mac)
Mac Virus

AlphaExplorer Adware (Mac)

While checking out new submissions to VirusTotal, our researchers discovered the AlphaExplorer rogue app. This piece of software operates as adware. Additionally, it is worth mentioning that AlphaExplorer is part of the AdLoad malware family. Adware stands for advertising-supported softw

Alldefensepc.com Ads
Notification Spam

Alldefensepc.com Ads

Our team examined alldefensepc[.]com and found that the purpose of this deceptive site is to trick visitors into purchasing legitimate antivirus software. Additionally, alldefensepc[.]com asks for permission to show notifications. We discovered alldefensepc[.]com while inspecting pages that use ro

Eyedocx Ransomware
Ransomware

Eyedocx Ransomware

Our researchers discovered the Eyedocx ransomware-type program while inspecting new submissions to VirusTotal. Malware of this kind operates by encrypting data and demanding payment for the decryption keys/tools. When we executed a sample of Eyedocx on our test system, it encrypted files and appe

3D Tree Browser Hijacker
Browser Hijacker

3D Tree Browser Hijacker

While analyzing the 3D Tree application, we found that it is a browser extension designed to hijack a web browser. This app promotes a fake search engine (search.3dtree.net) by modifying the browser settings. Additionally, 3D Tree can read and change bookmarks and data on 3dtree.net. We discovered

Board Approved Payroll Email Scam
Phishing/Scam

Board Approved Payroll Email Scam

Our inspection of the "Board Approved Payroll" email revealed that it is spam operating as a phishing scam. It is presented as a notification regarding a shared document containing salary payments. The link to the fake file leads to a phishing site that requests users to provide their email accoun

D0ggerofficial Ransomware
Ransomware

D0ggerofficial Ransomware

D0ggerofficial is ransomware that encrypts files, appends the ".locked" extension to filenames, and displays a pop-up message containing a ransom note. Threat actors behind D0ggerofficial ransomware have one goal - to get paid for data decryption. An example of how D0ggerofficial modifies filenam

Mnlywjzi Ransomware
Ransomware

Mnlywjzi Ransomware

Mnlywjzi is ransomware belonging to the Snatch family. Threat actors use Mnlywjzi to encrypt files and demand victims pay a ransom for their decryption. Also, Mnlywjzi renames files by appending the ".mnlywjzi" extension to filenames. It creates the "HOW TO RESTORE YOUR FILES.TXT" file that contai

Defendpcpro.xyz Ads
Notification Spam

Defendpcpro.xyz Ads

While investigating suspect websites, our researchers discovered the defendpcpro[.]xyz rogue page. It is designed to load scams, promote browser notification spam, and redirect visitors to different (likely unreliable/malicious) sites. Most users access websites like defendpcpro[.]xyz via redirect

Files Converter Free Online Adware
Adware

Files Converter Free Online Adware

While inspecting questionable software-promoting websites, our research team discovered the Files Converter Free Online browser extension. It is promoted as a tool for converting various file formats. However, our analysis revealed that this browser extension also operates as adware. Files Convert