Step-by-Step Malware Removal Instructions

Cities HD Backgrounds in Your New Tab Browser Hijacker
Browser Hijacker

Cities HD Backgrounds in Your New Tab Browser Hijacker

We tested the Cities HD Backgrounds in Your New Tab application and found that it operates as a browser hijacker. It promotes a fake search engine (spntextension.com) by changing the web browser's settings. We discovered Cities HD Backgrounds in Your New Tab browser extension on a deceptive web pa

Microsoft Request Verification Email Scam
Phishing/Scam

Microsoft Request Verification Email Scam

It is a scam email created to steal login information. It is disguised as a letter from Microsoft regarding account verification. It contains a link to a phishing page (a fake login website). This scam email should be marked as spam and deleted. This email requests recipients to verify the

InputView Adware (Mac)
Mac Virus

InputView Adware (Mac)

InputView is a rogue application that our researchers discovered while investigating new submissions to VirusTotal. After inspecting this app, we determined that it is adware belonging to the AdLoad malware family. Adware stands for advertising-supported software. It displays ads on vari

WASP Malware
Trojan

WASP Malware

WASP (W4SP) is the name of an information-stealing malware that steals victims' passwords, credit card details, Discord accounts, cryptocurrency wallets, and personal files and sends them to the threat actor. It sends stolen data via a Discord webhook address. WASP has been observed being sold to

Kevin Ransomware
Ransomware

Kevin Ransomware

While inspecting new malware submissions to VirusTotal, our research team discovered the Kevin ransomware. Malicious software within this classification operates by encrypting data in order to make ransom demands for the decryption keys/tools. When we executed a sample of Kevin ransomware on our

Daily Quarantined Message Report Email Scam
Phishing/Scam

Daily Quarantined Message Report Email Scam

Our analysis of the "Daily Quarantined Message Report" email revealed that it is spam. Letters belonging to this campaign are presented as genuine reports concerning recipients' inboxes. This spam mail aims to steal email accounts by promoting a phishing website. The email with the subject

Annual Leave Email Virus
Phishing/Scam

Annual Leave Email Virus

Our malware researchers examined this email and found that it is used by cybercriminals who aim to trick recipients into infecting their computers with FormBook malware. The email itself is disguised as a letter regarding some payment terms. It has a PDF document attached to it that downloads an I

NULLTHEGAME Ransomware
Ransomware

NULLTHEGAME Ransomware

NULLTHEGAME is ransomware based on the Chaos ransomware. We discovered it while inspecting malware samples submitted to VirusTotal. NULLTHEGAME encrypts files, appends the ".NULL" extension to filenames, changes the desktop wallpaper and drops a ransom note (the "read_it.txt" file). An example of

Winsafe.xyz Ads
Notification Spam

Winsafe.xyz Ads

While examining winsafe[.]xyz, our team found that this page uses a clickbait technique to lure visitors into agreeing to receive notifications. We also learned that winsafe[.]xyz has at least two designs. We discovered winsafe[.]xyz while inspecting websites that use rogue advertising networks.

lUUUUUUUUU Ransomware
Ransomware

lUUUUUUUUU Ransomware

lUUUUUUUUU is the name of a ransomware-type program that our researchers discovered while inspecting new submissions to VirusTotal. This malicious program is part of the Xorist ransomware family. After being launched on our testing system, this ransomware encrypted files and appended the filename