Step-by-Step Malware Removal Instructions

Dokookamida.com Ads
Notification Spam

Dokookamida.com Ads

We have analyzed dokookamida[.]com and found that it uses a clickbait technique (shows a deceptive message) to trick visitors into allowing it to show notifications. Our team has discovered dokookamida[.]com while inspecting pages that use shady advertising networks. Typically, users open pages li

LinkDownloader Adware
Adware

LinkDownloader Adware

While inspecting the LinkDownloader application, we discovered that it is a browser extension that functions as adware. While added to a web browser, LinkDownloader shows annoying advertisements. Most users install/add adware unintentionally. We discovered multiple deceptive pages promoting LinkDo

Proprotect2023.xyz Ads
Notification Spam

Proprotect2023.xyz Ads

Proprotect2023[.]xyz is one of the many deceptive pages running the "McAfee - Your PC is infected with 5 viruses!" scam. This page shows fake virus alerts to trick visitors into purchasing legitimate software. Also, proprotect2023[.]xyz asks for permission to show shady notifications. Thus, it can

Worry Ransomware
Ransomware

Worry Ransomware

Worry is one of the ransomware variants belonging to the Phobos family. It encrypts data, modifies filenames of all encrypted files, and creates two ransom notes ("info.hta" and "info.txt"). Our malware researchers discovered Worry while checking the VirusTotal for recently submitted samples. Wor

Contract Document Email Scam
Phishing/Scam

Contract Document Email Scam

We have examined this email and concluded that it is sent by scammers who aim to trick recipients into providing sensitive information on a phishing website. It is disguised as a letter regarding some contract document shared with recipients. This email should be marked as spam and deleted.

Demon Stealer
Trojan

Demon Stealer

Demon is the name of an information stealer. It is a rebranded version of the Luca stealer. Demon is written in Rust programming language. It exfiltrates stolen sensitive information via Telegram. This malware should be eliminated from infected computers as soon as possible. It is known De

Sunjun Ransomware
Ransomware

Sunjun Ransomware

Sunjun is ransomware that encrypts files and modifies their filenames. Also, it drops the "Read.txt" text file to provide contact information. Sunjun is part of the VoidCrypt ransomware family. We discovered it while examining malware samples submitted to VirusTotal. Sunjun appends the victim's I

Authenticguarding.com Ads
Notification Spam

Authenticguarding.com Ads

We have inspected authenticguarding[.]com and learned that it displays deceptive messages to trick visitors into believing that their computers are infected. Authenticguarding[.]com runs the "McAfee - Your PC is infected with 5 viruses!" scam. This site uses deceptive marketing to promote legitima

Expocaptcha.top Ads
Notification Spam

Expocaptcha.top Ads

While examining expocaptcha[.]top, we have found that it shows a deceptive message to trick visitors into agreeing to receive notifications. We have discovered expocaptcha[.]top while inspecting pages that use shady advertising networks. Users do not visit sites like expocaptcha[.]top on purpose.

Black Hunt Ransomware
Ransomware

Black Hunt Ransomware

Black Hunt is ransomware that blocks access to files by encrypting them, modifies filenames of all encrypted files, changes the desktop wallpaper, and drops "#BlackHunt_ReadMe.hta" and "#BlackHunt_ReadMe.txt" files (ransom notes). Black Hunt appends the victim's ID, sentafe@rape.lol email address