Step-by-Step Malware Removal Instructions

Gbhxtu.com Ads
Notification Spam

Gbhxtu.com Ads

Gbhxtu[.]com is a page that displays deceptive content to trick visitors into agreeing to receive its notifications. Moreover, it redirects to other untrustworthy websites. It is uncommon for pages like gbhxtu[.]com to be opened intentionally. Our team has discovered gbhxtu[.]com while examining p

Digitalpush.org Ads
Notification Spam

Digitalpush.org Ads

Digitalpush[.]org is a rogue webpage our research team discovered while inspecting shady sites. It is designed to push browser notification spam and redirect visitors to different (likely unreliable/malicious) websites. Users typically access pages of this kind via redirects caused by sites using

BestMapSearch Browser Hijacker
Browser Hijacker

BestMapSearch Browser Hijacker

BestMapSearch is a piece of software classified as a browser hijacker. We determined this by analyzing the browser extension's behavior following installation onto our test machine. BestMapSearch modifies browser settings in order to promote the bestmapsearch.com fake search engine. BestMa

Ads Skipping Adware
Adware

Ads Skipping Adware

Ads Skipping is the name of a piece of software promising to remove advertisements from YouTube. Our research team found this browser extension while inspecting dubious download webpages. After analyzing Ads Skipping, we found that it operates as adware. Adware-delivered adverts endorse un

Bumblebee Malware
Trojan

Bumblebee Malware

Bumblebee is the name of a malware loader. It is known that cybercriminals use it as a downloader for Cobalt Strike and possibly other malware such as ransomware. Bumblebee appears to be a replacement for BazaLoader - another malware loader. Bumblebee is delivered via ISO files that contai

Notificationsworld.com Ads
Notification Spam

Notificationsworld.com Ads

Notificationsworld[.]com is a rogue page that we discovered while inspecting untrustworthy sites. It operates by promoting browser notification spam and redirecting visitors to other (likely unreliable/malicious) websites. Most users enter such webpages through redirects caused by sites that use r

Energy Adware
Adware

Energy Adware

Energy is a rogue application that our researchers discovered while inspecting highly dubious download webpages. After analyzing it, we discovered that Energy operates as advertising-supported software (adware). We also found that this app is practically identical to Healthiness adware. Ad

Decryption#1222 Ransomware
Ransomware

Decryption#1222 Ransomware

Decryption#1222 is ransomware that encrypts files and appends ".n53yb34tbb2" extension to filenames. It also creates the "HOW TO DEYCRYPT.txt" text file, a ransom note containing contact and payment information. We have discovered Decryption#1222 ransomware while checking the VirusTotal page for r

Check-pcsecurity.com Ads
Notification Spam

Check-pcsecurity.com Ads

Check-pcsecurity[.]com is an untrustworthy website running the "McAfee - Your PC is infected with 5 viruses!" scam. It is designed to trick visitors into believing that their computers are infected. Also, this site asks for permission to show notifications and may redirect to other shady pages.

ONYX Ransomware
Ransomware

ONYX Ransomware

ONYX is ransomware based on another ransomware called CONTI. It encrypts files and appends a randomly generated extension to filenames. Moreover, it deletes files larger than 200 megabytes in size and replaces them with random files. Like most ransomware variants, ONYX also creates a ransom note.