Step-by-Step Malware Removal Instructions

Bulwark Ransomware
Ransomware

Bulwark Ransomware

Our research team discovered the Bulwark ransomware during a routine inspection of new submissions to VirusTotal. This malicious program belongs to the MedusaLocker ransomware family. We launched a sample of Bulwark on our test machine, it encrypted files and appended their filenames with a ".bul

Multi-searches.com Browser Hijacker
Browser Hijacker

Multi-searches.com Browser Hijacker

While testing multi-searches.com, our team discovered that it is a search engine that does not generate its own results (it shows results generated by another search engine). Therefore, we classified multi-searches.com as a fake search engine. Typically, search engines of this type are promoted vi

ViewOrigin Adware (Mac)
Mac Virus

ViewOrigin Adware (Mac)

While examining the ViewOrigin application, we learned that it shows annoying advertisements can read sensitive information. Apps whose purpose is to display advertisements are called advertising-supported apps (or adware). We discovered the ViewOrigin application on a deceptive web page claimin

Cyberpunk Ransomware
Ransomware

Cyberpunk Ransomware

We discovered a new Dharma ransomware variant called Cyberpunk. It encrypts files, appends the victim's ID, cyberpunk@onionmail.org email address, and ".CYBER" extension to filenames, and provides two ransom notes. Cyberpunk provides one ransom note in a pop-up window and another in the "CYBER.txt

ArrowRAT Malware
Trojan

ArrowRAT Malware

ArrowRAT is the name of a Remote Access Trojan (RAT) that allows threat actors to perform various malicious activities on infected/accessed computers. ArrowRAT is offered as Malware-as-a-Service (MaaS). Its creators offer three subscription plans: monthly ($100), three months ($300), and lifetime

Suldo.click Ads
Notification Spam

Suldo.click Ads

While inspecting suspicious websites, our research team discovered the suldo[.]click rogue page. Sites of this kind are designed to promote deceptive material, push browser notification spam, and redirect visitors to other (likely unreliable/malicious) pages. When we investigated suldo[.]click, i

NFT Tab Browser Hijacker
Browser Hijacker

NFT Tab Browser Hijacker

NFT Tab is a rogue browser extension that our researchers discovered while inspecting untrustworthy sites. This extension is presented as a tool that provides easy access to trending NFTs (Non-Fungible Tokens) and other related news. Our analysis revealed that NFT Tab operates as a browser hijacke

HARDBIT Ransomware
Ransomware

HARDBIT Ransomware

HARDBIT is a piece of malicious software categorized as ransomware. It is designed to encrypt data and demand payment for the decryption. Once we executed a sample of HARDBIT on our test system, it began encrypting files and modified their titles. Original filenames were appended with a unique ID

Thepositiveimpactnow.com Ads
Notification Spam

Thepositiveimpactnow.com Ads

While examining thepositiveimpactnow[.]com, our team learned that this page is designed to lure visitors into allowing it to show notifications. Our other finding was that it redirects visitors to a similar deceptive website. We discovered thepositiveimpactnow[.]com while inspecting pages that use

Motivational Quotes Adware
Adware

Motivational Quotes Adware

While inspecting suspicious sites, our researchers found one promoting a browser extension called Motivational Quotes. It is endorsed as a tool that displays famous entrepreneur quotes on the Google homepage. However, our inspection of this extension revealed that it operates as adware. In other w