Step-by-Step Malware Removal Instructions

Rar (VoidCrypt) Ransomware
Ransomware

Rar (VoidCrypt) Ransomware

Rar is ransomware - malware that uses encryption to prevent victims from accessing their files. We found that Rar appends the victim's ID, spystar1@onionmail.com email address, and ".Rar" extension to the filenames of all encrypted files. Also, it creates the "Read.txt" file that contains a ransom

ZEUS (Chaos) Ransomware
Ransomware

ZEUS (Chaos) Ransomware

While inspecting new submissions to VirusTotal, our researchers found the ZEUS malicious program, which is based on the Chaos ransomware. Once we executed a sample of the ZEUS (Chaos) ransomware on our testing system, it began encrypting files and changed their names. Original filenames were appe

Prime-scanner.com Ads
Notification Spam

Prime-scanner.com Ads

Prime-scanner[.]com is one of the many deceptive websites running the "McAfee - Your PC is infected with 5 viruses!" scam. The purpose of this site is to trick visitors into purchasing legitimate antivirus software. Also, prime-scanner[.]com asks for permission to show notifications. We discovered

Bookmark Drag And Drop Browser Hijacker
Browser Hijacker

Bookmark Drag And Drop Browser Hijacker

While checking out suspicious software promoting sites, our research team discovered the Bookmark Drag and Drop browser extension. It is endorsed as a bookmark management and quick access tool. Our inspection of Bookmark Drag and Drop revealed that it operates as a browser hijacker. This extensio

Flame Ransomware
Ransomware

Flame Ransomware

Flame is ransomware based on the Chaos ransomware. It encrypts files, appends four random characters to filenames (appends its extension), changes the desktop wallpaper, and creates the "read_it.txt" file containing a ransom note. We discovered Flame ransomware while inspecting samples submitted t

Control-scanning.com Ads
Notification Spam

Control-scanning.com Ads

Our researchers discovered the control-scanning[.]com rogue page during a routine investigation of suspicious websites. It is designed to run scams, promote spam browser notifications, and redirect visitors to other (likely untrustworthy/malicious) sites. Users typically enter webpages like contr

InitialConnection Adware (Mac)
Mac Virus

InitialConnection Adware (Mac)

While inspecting new submissions to VirusTotal, our researchers found the InitialConnection rogue application. Our analysis of this app revealed that it operates as adware and belongs to the AdLoad malware family. InitialConnection is designed to run intrusive advertisement campaigns, and it may

FocusAhead Adware (Mac)
Mac Virus

FocusAhead Adware (Mac)

FocusAhead is an untrustworthy application that displays intrusive advertisements and can read sensitive information. Apps that show ads are called adware (advertising-supported software). Typically, users install adware on their computers unintentionally. We discovered FocusAhead while inspecti

Email Security Update Scam
Phishing/Scam

Email Security Update Scam

"Email Security Update Scam" refers to an email spam campaign that we have analyzed. We determined that it is a phishing scam targeting email account log-in credentials (passwords). These fake emails attempt to extract this information from recipients by claiming that security issues have occurred

Protect2023.xyz Ads
Notification Spam

Protect2023.xyz Ads

Protect2023[.]xyz is an untrustworthy website that runs the "McAfee - Your PC is infected with 5 viruses!" scam and wants to show notifications. All messages displayed on this page are fake. We discovered protect2023[.]xyz while examining dubious pages that use rogue advertising networks.