Step-by-Step Malware Removal Instructions

Fast PDF Reader Adware
Adware

Fast PDF Reader Adware

Fast PDF Reader is a rogue browser extension that our researchers discovered while inspecting deceptive download webpages. This piece of software is promoted as a free file reader capable of opening PDF, DOC, XLS, and PPT formats. After analyzing Fast PDF Reader, we determined that it is adware.

BlockAll - Block Ads Adware
Adware

BlockAll - Block Ads Adware

While inspecting deceptive websites, our researchers discovered the "BlockAll - block ads" browser extension. Its promotional material endorses this extension as an ad-blocking tool (adblocker). After analyzing "BlockAll - block ads", we determined that it operates as advertising-supported softwar

Onlineportalsite.com Ads
Notification Spam

Onlineportalsite.com Ads

Onlineportalsite[.]com is a deceptive website that runs the "McAfee - Your PC is infected with 5 viruses!" scam. Also, it asks for permission to show notifications. Typically, websites like onlineportalsite[.]com are promoted using questionable methods. Our team has discovered this page while insp

Aytonus.com POP-UP Scam (Mac)
Mac Virus

Aytonus.com POP-UP Scam (Mac)

While inspecting untrustworthy sites, our research team found the aytonus[.]com deceptive webpage. This website is designed to load scams and redirect visitors to other (likely unreliable/malicious) pages. Most users enter webpages like aytonus[.]com via redirects caused by sites using rogue ad

News-gocuco.cc Ads
Notification Spam

News-gocuco.cc Ads

During a routine inspection of untrustworthy websites, our researchers found the news-gocuco[.]cc rogue site. It operates by promoting deceptive content, pushing browser notification spam, and redirecting visitors to different (likely unreliable/malicious) pages. Most users enter them via redirect

VistaQuantum Adware (Mac)
Mac Virus

VistaQuantum Adware (Mac)

VistaQuantum is a rogue application that we discovered while inspecting new submissions to VirusTotal. Our analysis of this piece of software revealed that it operates as adware. Additionally, VistaQuantum belongs to the AdLoad malware family. Adware enables the placement of third-party

WORLD GRASS Ransomware
Ransomware

WORLD GRASS Ransomware

WORLD GRASS (also known as EarthGrass/EarthGress) is a ransomware-type program that our research team found while inspecting new submissions to VirusTotal. After launching a sample of this ransomware on our test machine, we learned that it encrypts files and appends their filenames with a ".34r7h

Saitama Backdoor
Trojan

Saitama Backdoor

Saitama is the name of a backdoor malware (written in .Net) that abuses DNS protocol for C2 (Command and Control) communications. It can execute remote commands and drop files. We have discovered this backdoor during the analysis of an email containing a malicious attachment (an Excel document).

Redem Mikhail Ransomware
Ransomware

Redem Mikhail Ransomware

Our malware researchers have discovered a new ransomware variant called Redem Mikhail during a routine check of malware samples submitted to the VirusTotal page. They found that Redem Mikhail is part of the Spora ransomware family. Once executed, it encrypts files, modifies their filenames, and cr