Step-by-Step Malware Removal Instructions

MNX Ransomware
Ransomware

MNX Ransomware

MNX is one of the ransomware variants belonging to the Phobos family. We discovered MNX while checking the VirusTotal website for recently submitted malware samples. MNX encrypts files, modifies filenames, and generates two ransom notes ("info.txt" and "info.hta"). MNX appends the victim's ID, de

Onesoftwareupdater.com Ads
Notification Spam

Onesoftwareupdater.com Ads

Our researchers found the onesoftwareupdater[.]com rogue webpage while looking through untrustworthy sites. This page promotes browser notification spam and can redirect visitors to other (likely dubious/malicious) websites. At the time of research, onesoftwareupdater[.]com used fake CAPTCHA verif

Omni Convert - Search Settings for Omnibar Browser Hijacker
Browser Hijacker

Omni Convert - Search Settings for Omnibar Browser Hijacker

We tested the Omni Convert - Search Settings for Omnibar browser extension and found that it promotes a fake search engine. This app promotes app.clipconverter.site. It does that by hijacking a web browser (by changing its settings). We discovered Omni Convert - Search Settings for Omnibar on a de

Canvas Tab Browser Hijacker
Browser Hijacker

Canvas Tab Browser Hijacker

While inspecting dubious websites, our research team discovered Canvas Tab's "official" promotional page. This software is a browser extension endorsed as a tool capable of allowing users to draw on new browser tabs and save the created artwork. However, our inspection of Canvas Tab revealed that

Annual Email Version Upgrade Email Scam
Phishing/Scam

Annual Email Version Upgrade Email Scam

We have inspected this email and found that it is sent by scammers who aim to lure recipients into providing personal information. Scammers behind this email use a phishing page to extract information. They disguised the email as a letter from an email service provider. This email urges re

Weather-in.xyz Redirect
Browser Hijacker

Weather-in.xyz Redirect

Weather-in.xyz is the address (URL) of a fake search engine promoted using Weather In browser hijacker. Typically, websites of this kind are promoted by software classified as browser hijackers. They modify browser settings in order to cause redirects to illegitimate search engines. Additionally,

Super-Newtab Browser Hijacker
Browser Hijacker

Super-Newtab Browser Hijacker

While examining Super-Newtab, we discovered that it changes the web browser's settings. Apps of this type are known as browser hijackers. Most browser hijackers promote fake search engines. Users do not add apps of this type to browsers on purpose. Super-Newtab hijacks a web browser by cha

Full-mark.xyz Ads
Notification Spam

Full-mark.xyz Ads

We inspected full-mark[.]xyz and learned that the purpose of this page is to trick visitors into agreeing to receive notifications. It uses a clickbait technique (displays deceptive content) as a lure. Also, full-mark[.]xyz redirects to scam websites. Full-mark[.]xyz shows a deceptive mess

LATCHNETWORK Ransomware
Ransomware

LATCHNETWORK Ransomware

While inspecting new submissions to VirusTotal, our researchers discovered the LATCHNETWORK ransomware-type program. It is pertinent to mention that this malicious program is part of the MedusaLocker ransomware family. After we executed a sample of LATCHNETWORK on our test machine, it encrypted f

Vohuk Ransomware
Ransomware

Vohuk Ransomware

Vohuk is ransomware that prevents victims from accessing files by encrypting them. Also, it replaces filenames with a string of random characters and appends the ".Vohuk" extension to them, changes the desktop wallpaper, and drops the "README.txt" file. The dropped text file contains a ransom note