Step-by-Step Malware Removal Instructions

Nominatus Ransomware 2
Ransomware

Nominatus Ransomware 2

Nominatus Ransomware 2 is malware that encrypts files and generates a ransom note (the "NominatusRansomware2Message.txt" file). We have discovered this ransomware while inspecting malware samples submitted to the VirusTotal website. Unlike most ransomware variants, Nominatus Ransomware 2 does not

Words Malware
Trojan

Words Malware

Words is the name of a malicious program, which our research team found while inspecting fake "cracked" software download sites. The Words malware is capable of force-opening untrustworthy and hazardous websites, and it might have other harmful abilities as well. It is noteworthy that this progra

Shade Area Adware
Adware

Shade Area Adware

shade area adware is promoted as a tool for changing the color of the selected areas on websites. We have discovered this app on a deceptive website claiming that it is required to install a secure Chrome extension. After installing this app, we found that it generates advertisements. Thus, we cla

Safety Shield Malware
Trojan

Safety Shield Malware

Safety Shield is a malicious application designed to open various websites. We discovered this malware after downloading an installer from a fake website supposedly offering cracks for various software. The installer distributing Safety Shield may also contain other unwanted software. Safe

Dllhost.exe Malware
Trojan

Dllhost.exe Malware

While inspecting fake "cracked" software download websites, we discovered the Dllhost.exe malicious program. It masquerades as the legitimate Windows process - dllhost.exe (COM Surrogate), thereby attempting to avoid appearing suspicious on Task Manager. Following successful installation o

Nerbian RAT
Trojan

Nerbian RAT

Nerbian is the name of a remote access Trojan (RAT). RATs allow attackers to control infected computers remotely. Nerbian is a RAT written in the Go programming language. It can log keystrokes and capture the screen. It also may have additional capabilities. We discovered it after receiving an ema

Ifla Ransomware
Ransomware

Ifla Ransomware

During a routine inspection of new submissions to VirusTotal, our researchers found the Ifla ransomware-type program. We determined that this piece of malicious software is part of the Djvu ransomware family. After being launched onto our test system, this ransomware encrypted files and appended

Byya Ransomware
Ransomware

Byya Ransomware

Our team discovered Byya while examining the samples submitted to VirusTotal. They found that Byya is ransomware (malware that encrypts files). It appends the ".byya" extension to filenames (for example, renames "1.jpg" to "1.jpg.byya", "2.png" to "2.png.byya"), and generates the "_readme.txt" fil

Kruu Ransomware
Ransomware

Kruu Ransomware

Kruu is ransomware that our malware researchers have discovered while examining samples submitted to the VirusTotal page. We found that Kruu is part of the Djvu ransomware family. It encrypts files and appends the ".Kruu" extension to filenames. Also, it creates the "_readme.txt" file that contain

YouPDFSearch Browser Hijacker
Browser Hijacker

YouPDFSearch Browser Hijacker

After analyzing the YouPDFSearch browser extension, our researchers determined that it is a browser hijacker. Following successful installation onto our test machine, we learned that YouPDFSearch makes changes to browser settings in order to promote the youpdfsearch.com fake search engine.