Step-by-Step Malware Removal Instructions

Windows Defender Email Scam
Phishing/Scam

Windows Defender Email Scam

"Windows Defender email scam" refers to spam emails disguised as messages regarding a contract renewal for "Windows Defender". It must be emphasized that these letters are fake and in no way associated with the Microsoft Defender Antivirus (formerly named Windows Defender) or its developers - the

RokRAT Malware
Trojan

RokRAT Malware

RokRAT is the name of a Remote Administration Trojan (RAT). Cybercriminals use RATs to access infected computers remotely and perform malicious tasks. RATs allow them to achieve almost any objective on the infected system. Usually, RATs are used to drop additional payloads (inject other malware) o

888 RAT (Android)
Trojan

888 RAT (Android)

888 (also known as LodaRAT and Gaza007) is a Remote Access Trojan (RAT) targeting Android operating systems. Trojans of this type enable remote access/control over infected devices. Initially, the 888 RAT's developers offered this piece of malicious software for sale as Windows OS (Operating Syst

Carefully-to-remind.xyz Ads
Notification Spam

Carefully-to-remind.xyz Ads

After inspecting carefully-to-remind[.]xyz, we concluded that it is one of the deceptive websites running the "McAfee - Your PC is infected with 5 viruses!" scam. Creators of this page aim to trick visitors into believing that their computers are infected and purchasing antivirus software. Also, c

Iq20 Ransomware
Ransomware

Iq20 Ransomware

Iq20 is ransomware that belongs to the Dharma ransomware family. It encrypts files and appends the victim's ID, iq200@tutanota.com email address, and ".iq20" extension to filenames. It also shows a pop-up window and creates the "info.txt" file containing ransom notes. We discovered Iq20 while chec

Diamond Ransomware
Ransomware

Diamond Ransomware

Diamond is ransomware - malware that encrypts files to make them inaccessible until a decryption tool purchased from the attackers is used for their decryption. Also, Diamond ransomware replaces the names of encrypted files with random characters and appends the ".diamond" extension to filenames.

Protection-availability.xyz Ads
Notification Spam

Protection-availability.xyz Ads

While checking out suspicious websites, our researchers discovered the protection-availability[.]xyz rogue page. It runs scams, promotes spam browser notifications, and redirects visitors to different (likely unreliable/hazardous) webpages. Sites like protection-availability[.]xyz are typically ac

NativeLightning Adware (Mac)
Mac Virus

NativeLightning Adware (Mac)

Our researchers discovered NativeLightning during a routine inspection of new submissions to VirusTotal. After analyzing this application, we learned that it is advertising-supported software (adware) belonging to the AdLoad malware family. Adware may require specific conditions to run i

Stally.click Ads
Notification Spam

Stally.click Ads

Stally[.]click is a rogue webpage that our research team found while investigating questionable websites. It operates by running scams, promoting browser notification spam, and redirecting users to different (likely unreliable or malicious) sites. Pages like stally[.]click are most commonly acces

NullMixer Malware
Trojan

NullMixer Malware

NullMixer is a malicious program designed to cause chain infections and, as such, is classified as a dropper. This program has been observed infiltrating a wide variety of malware into infected devices, ranging from information-stealers to loaders. It is noteworthy that NullMixer is actively sprea