Step-by-Step Malware Removal Instructions

Weekly Stock Loader Adware
Adware

Weekly Stock Loader Adware

While checking out deceptive sites, we discovered the Weekly Stock Loader browser extension. It is promoted as a tool that provides weekly information about users' favorite stocks. However, our analysis of Weekly Stock Loader revealed that it operates as advertising-supported software (adware).

Encrypto Ransomware
Ransomware

Encrypto Ransomware

Encrypto is a ransomware-type program that our researchers discovered during a routine inspection of new submissions to VirusTotal. When we executed a sample of Encrypto on our testing system, it encrypted files and appended their filenames with a ".Encrypto" extension. To elaborate, a file initi

Pending Payment Email Virus
Phishing/Scam

Pending Payment Email Virus

Our inspection of the "Pending Payment" email revealed that it is spam. The fake letter is presented as a final warning regarding a pending payment. This mail aims to lure recipients into following the provided link that leads to the download of a likely malicious file. The scam email with

Loading Timer Adware
Adware

Loading Timer Adware

While examining the Loading Timer browser extension, our team found that it shows unwanted intrusive advertisements. Apps that display ads are categorized as advertising-supported applications. Users rarely download and install (or add) adware knowingly. We discovered multiple deceptive websites p

Alltimetopdefender.site Ads
Notification Spam

Alltimetopdefender.site Ads

While inspecting questionable websites, our researchers discovered the alltimetopdefender[.]site rogue webpage. It operates by running scams, promoting browser notification spam, and redirecting visitors to other (likely unreliable/dangerous) websites. Most users access sites like alltimetopdefen

G-Stars Ransomware
Ransomware

G-Stars Ransomware

While checking the VirusTotal page for recently submitted samples, our team discovered ransomware dubbed G-Stars. This malware encrypts files to prevent victims from accessing/opening them. Also, G-Stars appends a string of random characters and the ".G-Stars" extension to filenames and drops its

Crypto Currency Converter Browser Hijacker
Browser Hijacker

Crypto Currency Converter Browser Hijacker

While inspecting dubious websites, our research team discovered a page endorsing the Crypto Currency Converter browser extension. It is presented as a tool that converts cryptocurrencies, thus allowing users to compare conversion rates easily. Our inspection of this piece of software revealed tha

UniversalSource Adware (Mac)
Mac Virus

UniversalSource Adware (Mac)

While testing the UniversalSource application, our team noticed that it displays intrusive advertisements. Therefore, we categorized UniversalSource as adware (advertising-supported software). In most cases, users install adware unintentionally. We discovered UniversalSource while inspecting dec

Crustom Ransomware
Ransomware

Crustom Ransomware

Crustom is a ransomware-type program. It operates by encrypting victims' files to demand ransoms for the data decryption. After we executed a sample of Crustom on our test machine, it encrypted files and changed their filenames. The affected files were renamed with a random character string, e.g.

Bpto Ransomware
Ransomware

Bpto Ransomware

Bpto is a ransomware variant belonging to the Djvu family. We discovered Bpto while examining malware samples submitted to the VirusTotal page. Bpto encrypts data, appends its extension (".bpto") to filenames, and drops its ransom note (the "_readme.txt" file). An example of how Bpto modifies fil