Step-by-Step Malware Removal Instructions

Healthy Adware
Adware

Healthy Adware

Healthy is a rogue application, which our analysis revealed to be advertising-supported software (adware). Apps within this classification operate by running intrusive advertisement campaigns, i.e., by displaying ads. Adware enables the placement of third-party graphical content (e.g., pop

H0lyGh0st Ransomware
Ransomware

H0lyGh0st Ransomware

H0lyGh0st, also known as HolyGhost, is a ransomware-type program. It is designed to encrypt data and demand ransom for the decryption. Furthermore, H0lyGh0st infections are known to involve double extortion tactics (i.e., additional threats involving data leaks). This malware has been linked to N

Cleancaptcha.top Ads
Notification Spam

Cleancaptcha.top Ads

Cleancaptcha[.]top is a deceptive website that we discovered while inspecting websites that use rogue advertising networks. It displays deceptive content (a fake CAPTCHA) to trick visitors into agreeing to receive notifications. Additionally, cleancaptcha[.]top redirects to scam websites.

Strength Adware
Adware

Strength Adware

While inspecting scam webpages, our researchers discovered one promoting the Strength rogue application. After analyzing this app, we determined that it operates as advertising-supported software (adware). Adware is designed to deliver intrusive advertisement campaigns (i.e., display ads o

ApolloRAT Malware
Trojan

ApolloRAT Malware

ApolloRAT is a piece of malicious software categorized as a RAT (Remote Access Trojan). Malware of this kind enables remote access and control over infected devices. ApolloRAT is written in Python. Programming languages like Python typically rely on compilers. The developers of this RAT used the

Ggwq Ransomware
Ransomware

Ggwq Ransomware

Our researchers discovered the Ggwq ransomware-type program during a routine inspection of new malware submissions to VirusTotal. This malicious program is part of the Djvu ransomware family. After being launched onto our test machine, Ggwq encrypted files and appended their names with the ".ggwq

Xrom Ransomware
Ransomware

Xrom Ransomware

While examining malware samples submitted to the VirusTotal page, our team came across ransomware called Xrom, which belongs to the Dharma family. Xrom encrypts files and appends the victim's ID, money21@onionmail.org email address, and the ".xrom" extension to filenames. Also, it drops the "FILES

Ggew Ransomware
Ransomware

Ggew Ransomware

Ggew is yet another ransomware belonging to the Djvu family, which our researchers discovered while inspecting new malware submissions to VirusTotal. We executed a sample of Ggew on our test machine, it encrypted files and appended their filenames with a ".ggew" extension. For example, a file ini

Ggyu Ransomware
Ransomware

Ggyu Ransomware

While examining malware samples submitted to VirusTotal, our malware researchers came across Ggyu - ransomware designed to encrypt files. We also found that Ggyu appends the ".ggyu" extension to filenames and drops the "_readme.txt" file (a file containing a ransom note). Our other finding was tha

Ggeo Ransomware
Ransomware

Ggeo Ransomware

While inspecting malware samples submitted to the VirusTotal page, we discovered ransomware (belonging to the Djvu family) called Ggeo. It encrypts files and appends its extension to filenames. For example, Ggeo renames "1.jpg" to "1.jpg.ggeo", "2.png" to "2.png.ggeo", etc. Also, it drops the "_re