Step-by-Step Malware Removal Instructions

Erpringash.xyz Ads
Notification Spam

Erpringash.xyz Ads

Erpringash[.]xyz is a rogue page that we found during a routine inspection of dubious websites. This webpage promotes spam browser notifications and redirects visitors to other (likely untrustworthy/malicious) sites. Users typically enter pages like erpringash[.]xyz via redirects caused by website

Stormstone.top Ads
Notification Spam

Stormstone.top Ads

Stormstone[.]top is an untrustworthy website that uses a clickbait technique (shows a deceptive message) to lure visitors into agreeing to receive its notifications. Users open such pages unintentionally. Our team discovered stormstone[.]top while examining sites that use shady advertising network

Album Stealer Malware
Trojan

Album Stealer Malware

Album Stealer is an information-stealing malware, which spreads under the guise of an album containing explicit photographs of women. This stealer targets browsing-related data and log-in credentials, particularly information related to Facebook accounts. Album Stealer has been observed being dis

Buddyransome Ransomware
Ransomware

Buddyransome Ransomware

Buddyransome is ransomware that encrypts data and appends the ".buddyransome" extension to filenames. Also, it drops the "HOW_TO_RECOVERY_FILES.txt" text file (a ransom note). An example of how Buddyransome renames files: it changes "1.jpg" to "1.jpg.buddyransome", "2.png" to "2.png.buddyransome",

Nuothmen.com Ads
Notification Spam

Nuothmen.com Ads

Our team has examined nuothmen[.]com and learned that it is an untrustworthy website that shows a deceptive message to trick visitors into allowing it to show notifications. Usually, users open sites like nuothmen[.]com inadvertently. We discovered nuothmen.com while inspecting pages that use shad

MrWhite Ransomware
Ransomware

MrWhite Ransomware

While inspecting new submissions to VirusTotal, our researchers discovered the MrWhite malicious program. It belongs to a ransomware family called VoidCrypt. After we launched a sample of MrWhite ransomware on our test system, it encrypted files and altered their names. Original filenames were ap

Breaking News Adware
Adware

Breaking News Adware

While examining the Breaking News browser extension, we found that it displays intrusive advertisements and can read and change certain data. Apps that show ads are known as advertising-supported applications. It is common for apps of this type to be promoted and distributed using deceptive method

Fixgroupfactor.com Ads
Notification Spam

Fixgroupfactor.com Ads

Our researchers discovered the fixgroupfactor[.]com rogue page while investigating suspicious websites. This site is considered to be a device/user threat since it is designed to promote deceptive and malicious content, push spam browser notifications, and redirect visitors to other (likely unreli

Files Downloader Assist Adware
Adware

Files Downloader Assist Adware

Our researchers discovered the Files Downloader Assist browser extension while checking out suspicious websites. According to the extension's "official" promotional webpage, this piece of software is a download management tool. However, our inspection of Files Downloader Assist revealed that is ad

Advfandom.com Ads
Notification Spam

Advfandom.com Ads

Our researchers discovered the advfandom[.]com rogue page during a routine inspection of untrustworthy websites. This webpage is designed to push browser notification spam; at the time of research, it did so by using fake CAPTCHA verification. Additionally, this site can redirect visitors to other