Step-by-Step Malware Removal Instructions

Duck Ransomware
Ransomware

Duck Ransomware

Duck is ransomware that is part of the Phobos ransomware family. Our team discovered Duck while inspecting malware samples submitted to the VirusTotal page. We found that it encrypts files, appends the victim's ID, supprecovery@torguard.tg email address, and the ".duck" extension to filenames. It

Movie Database Adware
Adware

Movie Database Adware

Our researchers discovered the Movie Database browser extension while investigating suspicious software-promoted websites. It is promoted as a quick-access tool to TMDB (The Move Database) - an online database for movies and TV shows. Having analyzed this extension, we determined that Movie Databa

EyeEase Adware
Adware

EyeEase Adware

After downloading and installing the EyeEase application, we learned that it has parameters of adware - it displays intrusive advertisements. Our team discovered EyeEase on a questionable (supposedly official) website. It is worth mentioning that most users download and install adware inadvertentl

VIRUS ALERT Ransomware
Ransomware

VIRUS ALERT Ransomware

Our research team discovered the VIRUS ALERT ransomware-type program while inspecting new submissions to VirusTotal. This malicious program is based on the Chaos ransomware. We found two variants of VIRUS ALERT and tested them. Both versions appended the encrypted files with an extension consisti

Markets Adware
Adware

Markets Adware

Markets is the name of an advertising-supported program we discovered after examining an ISO file downloaded from a deceptive page. We classified Markets as adware because it displays unwanted advertisements. We also found that this adware runs as "Markets tech Copyright © 2022" in the Task Manage

CRPT Ransomware
Ransomware

CRPT Ransomware

During a routine inspection of new submissions to VirusTotal, our researchers discovered a ransomware called CRPT. We determined that this malicious program is part of the VoidCrypt ransomware family. After we executed a sample of CRPT on our test machine, it encrypted files and altered their tit

Windows Defender Advanced Threat Protection Email Scam
Phishing/Scam

Windows Defender Advanced Threat Protection Email Scam

While examining this email, we learned that it is sent by scammers who aim to trick recipients into calling a fake support number. Scammers behind it claim that recipients have been charged a specified amount of money for the Windows Defender Advanced Threat Protection subscription. They disguised

Quick Online Recipes Adware
Adware

Quick Online Recipes Adware

Quick Online Recipes is a rogue browser extension that our researchers discovered while investigating suspicious software-promoting webpages. This extension is presented as an easy-access tool for food recipes and other cooking-related content. Our analysis of this piece of software revealed that

IntranetLookup Adware (Mac)
Mac Virus

IntranetLookup Adware (Mac)

While testing the IntranetLookup application, we found that it is an advertising-supported application - it shows annoying advertisements. Typically, users install such apps inadvertently. Our team discovered this IntranetLookup on a deceptive website claiming that the Adobe Flash Player is out

JourneyDrive Adware (Mac)
Mac Virus

JourneyDrive Adware (Mac)

Our researchers found the JourneyDrive application while inspecting new submissions to VirusTotal. After analyzing this app, we learned that it operates as adware and belongs to the AdLoad malware family. Adware is designed to enable the placement of third-party graphical content (variou