Step-by-Step Malware Removal Instructions

IronBrowse Adware (Mac)
Mac Virus

IronBrowse Adware (Mac)

While testing IronBrowse, we found that this application displays intrusive advertisements. Apps that show unwanted apps are called advertising-supported apps (or adware). A big part of adware is promoted and distributed using questionable (often deceptive) methods. We discovered IronBrowse on a

Poshukach.com Redirect (Android)
Browser Hijacker

Poshukach.com Redirect (Android)

Similar to ubersear[.]ch, poshukach[.]com is the URL of an illegitimate search engine. Websites of this kind are typically promoted by browser hijackers. However, we discovered poshukach[.]com while inspecting a malicious Android application that does not modify browsers. Instead, this app create

Apple Invoice Email Scam
Phishing/Scam

Apple Invoice Email Scam

After inspecting the "Apple Invoice" email, we determined that it is spam mail. These scam emails are presented as invoices for Apple products that the recipients have supposedly purchased. Additionally, it is worth mentioning that we discovered spam text messages (SMSes) used to promote this "App

Ourhotposts.com Ads
Notification Spam

Ourhotposts.com Ads

After examining ourhotposts[.]com, our team learned that this page uses a clickbait technique to lure visitors into agreeing to receive notifications and redirects to other websites. This page was discovered by us while inspecting other pages that use rogue advertising networks. Usually, sites lik

Royal Ransomware
Ransomware

Royal Ransomware

Royal is the name of ransomware that encrypts files and appends the ".royal" extension to filenames (an updated variant of Royal ransomware appends ".royal_w" extension). It also creates a text file (named "README.TXT") containing a ransom note. Cybercriminals behind Royal ransomware attacks aim t

RealInfo Adware (Mac)
Mac Virus

RealInfo Adware (Mac)

RealInfo is a rogue app that our researchers discovered during a routine inspection of new submissions to VirusTotal. After analyzing this application, we determined that it is adware belonging to the AdLoad malware family. Adware operates by displaying advertisements on various interfac

Champse.click Ads
Notification Spam

Champse.click Ads

While inspecting champse[.]click, our team discovered that this page runs the "McAfee - Your PC is infected with 5 viruses!" scam and wants to show notifications. It is designed to trick visitors into believing that their computers are infected. We found champse[.]click while examining pages that

Desktopdefence.online Ads
Notification Spam

Desktopdefence.online Ads

Our researchers found the desktopdefence[.]online rogue page while inspecting suspect websites. It is designed to promote scams, push browser notification spam, and redirect users to other webpages (likely unreliable or harmful) sites. Most visitors to pages like desktopdefence[.]online access th

T_TEN Ransomware
Ransomware

T_TEN Ransomware

T_TEN is the name of a new DCRTR ransomware variant. It encrypts files and appends the ".T_TEN" extension to filenames. Also, it drops the "Readme.txt" file on the desktop and displays a pop-up window (both containing ransom notes). Our malware researchers discovered T_TEN while examining malware

Defenderpage.xyz Ads
Notification Spam

Defenderpage.xyz Ads

Defenderpage[.]xyz is a rogue webpage that our researchers discovered during a routine investigation of suspicious websites. It is designed to run online scams, promote spam browser notifications, and redirect visitors to other (likely unreliable/dangerous) sites. Users typically enter defenderpa