Step-by-Step Malware Removal Instructions

Drinik Malware (Android)
Trojan

Drinik Malware (Android)

Drinik is the name of an Android malware that previously functioned as an SMS stealer that has now evolved into a banking Trojan. There are at least three variants of Drinik malware. The latest one can record the victim's screen, harvest credentials, log keystrokes and manage incoming calls.

QuiDDoss Ransomware
Ransomware

QuiDDoss Ransomware

QuiDDoss is the name of a ransomware variant. Malware of this type uses cryptography to encrypt files. In addition to encrypting files, QuiDDoss appends the ".Прочти меня" extension to filenames and drops a ransom note (creates the "Прочти меня.txt" file. An example of how QuiDDoss modifies filen

Captchatotal.live Ads
Notification Spam

Captchatotal.live Ads

While analyzing captchatotal[.]live, we found that it uses a clickbait technique to lure visitors into allowing it to show notifications. Also, it redirects to a scam website. Thus, we concluded that captchatotal[.]live is an untrustworthy page. We discovered it while inspecting other websites and

ExtendedSample Adware (Mac)
Mac Virus

ExtendedSample Adware (Mac)

While testing ExtendedSample, our team learned that this application displays intrusive advertisements. Thus, we classified ExtendedSample as adware (advertising-supported software). We discovered this app after executing a fake installer masquerading as the installer for Adobe Flash Player.

Pozq Ransomware
Ransomware

Pozq Ransomware

While investigating Pozq, we found that is one of the Djvu ransomware variants. It encrypts files, appends the ".pozq" extension to filenames, and creates the "_readme.txt" file (a ransom note). Our researchers discovered Pozq while inspecting malware samples on the VirusTotal page. It is importa

CRYPTONITE Ransomware
Ransomware

CRYPTONITE Ransomware

CRYPTONITE is ransomware based on another ransomware called Chaos. Our team discovered CRYPTONITE while checking the VirusTotal site for recently submitted malware samples. During our analysis, this ransomware encrypted files and appended four random characters as their new extension. Also, CRYPT

MainFrameSelect Adware (Mac)
Mac Virus

MainFrameSelect Adware (Mac)

While inspecting deceptive websites offering to download "useful" applications, update outdated software, etc., we discovered an application called MainFrameSelect. During our analysis, we learned that MainFrameSelect is advertising-supported software (adware) that shows intrusive advertisements

Recif.click Ads
Notification Spam

Recif.click Ads

We examined the recif[.]click and found that it runs the "McAfee - Your PC is infected with 5 viruses!" scam. Also, it can show untrustworthy notifications (if allowed). Our team discovered recif[.]click while inspecting illegal movie streaming pages, torrent sites, and other pages of this kind th

Authenticate Account Email Scam
Phishing/Scam

Authenticate Account Email Scam

Our team analyzed this email letter and learned that it was sent to obtain personal information from the recipient. It is disguised as a letter from an email service provider. It contains a website link designed to open a phishing page. This email must be ignored. The email states that the

Venolock Ransomware
Ransomware

Venolock Ransomware

Venolock is one of the ransomware variants from the ZEPPELIN ransomware family. We discovered Venolock while inspecting malware samples submitted to VirusTotal. Our team learned that this ransomware encrypts and renames files. It appends ".vn2" and the victim's ID to filenames. For example, Venol