Step-by-Step Malware Removal Instructions

RL Stealer Malware
Trojan

RL Stealer Malware

RL Stealer is the name of the rebranded Ades information stealer. It can capture screenshots, steal data from various apps, and obtain system information and other data. Cybercriminals have been observed promoting RL Stealer on a hacker forum. This malware should be removed from infected computers

$ucyLocker Ransomware
Ransomware

$ucyLocker Ransomware

$ucyLocker is the name of a malicious program classed as ransomware. It is designed to encrypt data and make ransom demands for decryption. On our test machine, $ucyLocker encrypted files and appended their filenames with a ".WINDOWS" extension. For example, a file originally titled "1.jpg" appea

ENCODED Ransomware
Ransomware

ENCODED Ransomware

ENCODED is the name of ransomware that our team discovered while inspecting malware samples submitted to VirusTotal. We found that ENCODED encrypts data, appends the ".ENCODED" extension to filenames, drops the "HOW TO DECRYPT FILES.txt" file, and changes the desktop wallpaper. ENCODED's desktop

TapScroll Adware (Mac)
Mac Virus

TapScroll Adware (Mac)

TapScroll is a rogue application that our research team discovered while inspecting new submissions to VirusTotal. Our analysis of this app revealed that it operates as adware. Additionally, we learned that TapScroll belongs to the AdLoad malware family. Adware stands for advertising-sup

ProcessorPremiere Adware (Mac)
Mac Virus

ProcessorPremiere Adware (Mac)

While testing the ProcessorPremiere application, our team noticed that it shows annoying advertisements. Thus, we classified ProcessorPremiere as adware. We also found that ProcessorPremiere can read sensitive information. It is worth mentioning that users rarely download and install adware on p

Eredhadbeen.xyz Ads
Notification Spam

Eredhadbeen.xyz Ads

Our team has examined eredhadbeen[.]xyz and found that it displays a deceptive message to lure visitors into allowing it to show shady notifications. Also, eredhadbeen[.]xyz redirects visitors to other untrustworthy web pages. Typically, users open websites like eredhadbeen[.]xyz unintentionally.

STEEL (Phobos) Ransomware
Ransomware

STEEL (Phobos) Ransomware

While examining malware samples submitted to the VirusTotal website, our team discovered ransomware belonging to the Phobos family called STEEL. This ransomware encrypts files and appends the victim's ID, codeofhonor@tuta.io email address, and the ".STEEL" extension to filenames. Also, STEEL prov

Globaladvdomservices.com Ads
Notification Spam

Globaladvdomservices.com Ads

Our researchers discovered the globaladvdomservices[.]com rogue page while investigating dubious websites. It operates by promoting spam browser notifications, at the time of research, through the use of fake CAPTCHA verification. Additionally, this webpage can redirect visitors to other (likely u

InstantFresh Adware (Mac)
Mac Virus

InstantFresh Adware (Mac)

Our research team discovered the InstantFresh app while investigating new submissions to VirusTotal. Our inspection of this application revealed that it is advertising-supported software (adware) belonging to the AdLoad malware family. InstantFresh runs intrusive advertisement campaigns and may

GOGO Ransomware
Ransomware

GOGO Ransomware

GOGO is a ransomware-type program we discovered while checking out new submissions to VirusTotal. It belongs to the VoidCrypt ransomware family. We executed a sample of GOGO ransomware on our testing system, and we learned that it encrypts files and appends their filenames with a unique ID assign